Windows
Analysis Report
cheat_roblox.exe
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- cheat_roblox.exe (PID: 3192 cmdline:
"C:\Users\ user\Deskt op\cheat_r oblox.exe" MD5: D49B1A211CE49BED3E766471501819C6) - cmd.exe (PID: 4180 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \Temp\coin .bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6536 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 5020 cmdline:
cmd MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4000 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chrome.exe (PID: 6712 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// 2no.co/24R Xx6 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 3136 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =1688 --fi eld-trial- handle=198 0,i,328690 8272416009 532,389662 7819344561 856,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - RobloxPlayerInstaller.exe (PID: 1220 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Roblox PlayerInst aller.exe" MD5: 27469372591B14FF1C57654FACB5E020)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security |
Timestamp: | 2024-07-30T00:56:50.218743+0200 |
SID: | 2022930 |
Source Port: | 443 |
Destination Port: | 49730 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-07-30T00:57:27.842535+0200 |
SID: | 2022930 |
Source Port: | 443 |
Destination Port: | 49753 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Binary or memory string: | memstr_f3f82e14-9 |
Source: | HTTPS traffic detected: |
Source: | File created: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF693E7B190 | |
Source: | Code function: | 0_2_00007FF693E640BC | |
Source: | Code function: | 0_2_00007FF693E8FCA0 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FF693E5C2F0 |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Code function: | 0_2_00007FF693E6A4AC | |
Source: | Code function: | 0_2_00007FF693E73484 | |
Source: | Code function: | 0_2_00007FF693E7B190 | |
Source: | Code function: | 0_2_00007FF693E64928 | |
Source: | Code function: | 0_2_00007FF693E5F930 | |
Source: | Code function: | 0_2_00007FF693E80754 | |
Source: | Code function: | 0_2_00007FF693E71F20 | |
Source: | Code function: | 0_2_00007FF693E7CE88 | |
Source: | Code function: | 0_2_00007FF693E55E24 | |
Source: | Code function: | 0_2_00007FF693E6B534 | |
Source: | Code function: | 0_2_00007FF693E753F0 | |
Source: | Code function: | 0_2_00007FF693E5A310 | |
Source: | Code function: | 0_2_00007FF693E5C2F0 | |
Source: | Code function: | 0_2_00007FF693E57288 | |
Source: | Code function: | 0_2_00007FF693E6126C | |
Source: | Code function: | 0_2_00007FF693E721D0 | |
Source: | Code function: | 0_2_00007FF693E6F180 | |
Source: | Code function: | 0_2_00007FF693E8C838 | |
Source: | Code function: | 0_2_00007FF693E54840 | |
Source: | Code function: | 0_2_00007FF693E576C0 | |
Source: | Code function: | 0_2_00007FF693E92550 | |
Source: | Code function: | 0_2_00007FF693E88C1C | |
Source: | Code function: | 0_2_00007FF693E74B98 | |
Source: | Code function: | 0_2_00007FF693E6BB90 | |
Source: | Code function: | 0_2_00007FF693E65B60 | |
Source: | Code function: | 0_2_00007FF693E95AF8 | |
Source: | Code function: | 0_2_00007FF693E72AB0 | |
Source: | Code function: | 0_2_00007FF693E51AA4 | |
Source: | Code function: | 0_2_00007FF693E8FA94 | |
Source: | Code function: | 0_2_00007FF693E61A48 | |
Source: | Code function: | 0_2_00007FF693E889A0 | |
Source: | Code function: | 0_2_00007FF693E6C96C | |
Source: | Code function: | 0_2_00007FF693E73964 | |
Source: | Code function: | 0_2_00007FF693E92080 | |
Source: | Code function: | 0_2_00007FF693E6AF18 | |
Source: | Code function: | 0_2_00007FF693E80754 | |
Source: | Code function: | 0_2_00007FF693E78DF4 | |
Source: | Code function: | 0_2_00007FF693E72D58 |
Source: | Dropped File: | ||
Source: | Dropped File: |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF693E5B6D8 |
Source: | Code function: | 0_2_00007FF693E78624 |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Static PE information: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF693E95167 | |
Source: | Code function: | 0_2_00007FF693E95157 | |
Source: | Code function: | 4_2_01233188 |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | RDTSC instruction interceptor: |
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Evasive API call chain: | graph_4-1888 |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF693E7B190 | |
Source: | Code function: | 0_2_00007FF693E640BC | |
Source: | Code function: | 0_2_00007FF693E8FCA0 |
Source: | Code function: | 0_2_00007FF693E816A4 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF693E83170 |
Source: | Code function: | 4_2_0125D0F8 | |
Source: | Code function: | 4_2_0125D13C | |
Source: | Code function: | 4_2_012543AC |
Source: | Code function: | 0_2_00007FF693E90D20 |
Source: | Code function: | 0_2_00007FF693E82510 | |
Source: | Code function: | 0_2_00007FF693E83354 | |
Source: | Code function: | 0_2_00007FF693E83170 | |
Source: | Code function: | 0_2_00007FF693E876D8 | |
Source: | Code function: | 4_2_01232F78 | |
Source: | Code function: | 4_2_0123E378 |
Source: | Code function: | 0_2_00007FF693E7B190 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00007FF693E958E0 |
Source: | Code function: | 0_2_00007FF693E7A2CC |
Source: | Code function: | 0_2_00007FF693E80754 |
Source: | Code function: | 0_2_00007FF693E651A4 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 1 Native API | 1 Scripting | 1 Exploitation for Privilege Escalation | 22 Masquerading | 1 Input Capture | 1 System Time Discovery | Remote Services | 1 Input Capture | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 11 Process Injection | 11 Virtualization/Sandbox Evasion | LSASS Memory | 221 Security Software Discovery | Remote Desktop Protocol | 12 Archive Collected Data | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 11 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 5 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 21 Software Packing | Cached Domain Credentials | 3 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Timestomp | DCSync | 126 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 File Deletion | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
59% | ReversingLabs | ByteCode-MSIL.Backdoor.XWormRAT | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Spy.Gen | ||
100% | Avira | TR/Spy.Gen | ||
100% | Avira | TR/Spy.Gen | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
76% | ReversingLabs | ByteCode-MSIL.Backdoor.XWormRAT | ||
76% | ReversingLabs | ByteCode-MSIL.Backdoor.XWormRAT | ||
82% | ReversingLabs | ByteCode-MSIL.Backdoor.XWormRAT | ||
0% | ReversingLabs | |||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
counter.yadro.ru | 88.212.201.204 | true | false | unknown | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | unknown | |
edge-term4-ams2.roblox.com | 128.116.21.3 | true | false | unknown | |
2no.co | 104.21.79.229 | true | false | unknown | |
cdn.iplogger.org | 172.67.132.113 | true | false | unknown | |
www.google.com | 142.250.186.100 | true | false | unknown | |
d2v57ias1m20gl.cloudfront.net | 13.32.110.82 | true | false | unknown | |
ecsv2.roblox.com | unknown | unknown | false | unknown | |
client-telemetry.roblox.com | unknown | unknown | false | unknown | |
clientsettingscdn.roblox.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
88.212.201.198 | unknown | Russian Federation | 39134 | UNITEDNETRU | false | |
128.116.21.3 | edge-term4-ams2.roblox.com | United States | 22697 | ROBLOX-PRODUCTIONUS | false | |
128.116.21.4 | unknown | United States | 22697 | ROBLOX-PRODUCTIONUS | false | |
104.21.79.229 | 2no.co | United States | 13335 | CLOUDFLARENETUS | false | |
172.67.132.113 | cdn.iplogger.org | United States | 13335 | CLOUDFLARENETUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false | |
142.250.186.100 | www.google.com | United States | 15169 | GOOGLEUS | false | |
88.212.201.204 | counter.yadro.ru | Russian Federation | 39134 | UNITEDNETRU | false | |
13.32.110.82 | d2v57ias1m20gl.cloudfront.net | United States | 16509 | AMAZON-02US | false |
IP |
---|
192.168.2.7 |
192.168.2.6 |
127.0.0.1 |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1484385 |
Start date and time: | 2024-07-30 00:55:41 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Run with higher sleep bypass |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | cheat_roblox.exe |
Detection: | MAL |
Classification: | mal52.troj.spyw.evad.winEXE@33/28@20/13 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.16.43.25, 142.250.185.78, 108.177.15.84, 216.58.212.131, 192.229.221.95, 34.104.35.123, 199.232.214.172, 216.58.212.163, 199.232.210.172, 23.51.111.252, 216.58.212.142, 142.250.185.163
- Excluded domains from analysis (whitelisted): clients1.google.com, client.wns.windows.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, clientsettingscdn.roblox.com.edgekey.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, e7229.f.akamaiedge.net, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: cheat_roblox.exe
Time | Type | Description |
---|---|---|
18:57:17 | API Interceptor |
Input | Output |
---|---|
URL: https://2no.co/24RXx6 Model: Perplexity: mixtral-8x7b-instruct | {"loginform": false,"urgency": false,"captcha": false,"reasons": ["The webpage does not contain a login form, as there is no explicit request for sensitive information such as passwords, email addresses, usernames, phone numbers, or credit card numbers.","The text does not create a sense of urgency, as it does not use phrases such as 'click here to view document' or 'to view secured document click here'.","The webpage does not contain a CAPTCHA or any other anti-robot detection mechanism.","The webpage emphasizes the user's privacy, and provides a link to its privacy policy and terms & conditions, indicating a commitment to data protection."]} |
Title: Branded Short Domain OCR: *landshake We value your privacy This link was created by the user of URL Shortener Service IPLagger_ By clicking on this link, you can give your consent to the provision ot your personal data, SUCII as IP address, browser type anc operating system and other data, as well as using cookies to IPLogger, as well as to its partners and users. You can learn more about data processing and removing your data in IPLogger Privacy Policy. You can also follow this link without any data being recorded and processed. We value your privacy, that is why we are seeking your consent prior to collecting any Cata. Agree & Continue Ey clicking on "Agree & Continuer you egree with the Privazpolicy. I Terms &. Conditions For continue without consent click here |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.21.79.229 | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | Bdaejec, BitCoin Miner, Xmrig | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos, Blank Grabber, PrivateLoader, SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | RHADAMANTHYS | Browse | |||
Get hash | malicious | RHADAMANTHYS | Browse | |||
Get hash | malicious | RHADAMANTHYS | Browse | |||
88.212.201.198 | Get hash | malicious | GRQ Scam | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
128.116.21.3 | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | Unknown | Browse | |||
128.116.21.4 | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
counter.yadro.ru | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Babadeda, Bdaejec | Browse |
| ||
Get hash | malicious | Babadeda, Bdaejec | Browse |
| ||
Get hash | malicious | XenoRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
2no.co | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Bdaejec, BitCoin Miner, Xmrig | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XenoRAT | Browse |
| ||
Get hash | malicious | Remcos, Blank Grabber, PrivateLoader, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
edge-term4-ams2.roblox.com | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UNITEDNETRU | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Babadeda, Bdaejec | Browse |
| ||
Get hash | malicious | Babadeda, Bdaejec | Browse |
| ||
Get hash | malicious | XenoRAT | Browse |
| ||
ROBLOX-PRODUCTIONUS | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
ROBLOX-PRODUCTIONUS | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
1138de370e523e824bbca92d049a3777 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | XWorm | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\ msedge.exe | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | XWorm | Browse | |||
C:\Users\user\AppData\Local\Temp\BitCoin_miner.exe | Get hash | malicious | XWorm | Browse | ||
Get hash | malicious | XWorm | Browse |
Process: | C:\Users\user\AppData\Local\Temp\RobloxPlayerInstaller.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3995 |
Entropy (8bit): | 5.355780161863253 |
Encrypted: | false |
SSDEEP: | 96:qXsr8s8i8JuRdrbqNbSJ8JE1JEiJcgO24s55FJMH:q8r8s8i8J+dmUJ8JCJXJbJJs |
MD5: | 6920C83041459894F0469F4C24F2A6C8 |
SHA1: | B96D5A47F4606E8F15DE8B55B59773F75D727A73 |
SHA-256: | F06AEFB69965DFD61CBBDEB8FCAFD28AB3B0091900B748B2EEBD1788AB673482 |
SHA-512: | BC25D90F6DCFD90CBA5764BD8E46A27E54A70B2CF35CAE2332CE0528D7C58A6CE31C6362508ED33B6EF2D59D0C489921EFB252402720262358AC47533DC60DDA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\RobloxPlayerInstaller.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 233235 |
Entropy (8bit): | 6.025218023713329 |
Encrypted: | false |
SSDEEP: | 3072:OhGvwW6Jj7ITWYv0yoVH283rz9WqIAsjjg4DsUQS88UP4TFf3xVOVkCC554jMN/C:M5W+j8chWf8xyvp5iIzB4CNxza/MK |
MD5: | 0194EB945475F93844C0FAE769C0FA0B |
SHA1: | D72876A801C702348EA5B4B4A333C484F2A721FD |
SHA-256: | A6BC06B8255E4AFE2EEFF34684605D04DF9EC246FC201BF5E44137987189A0D3 |
SHA-512: | 72A00FE6B9111CAB22F1F424F815A617BE2041A3857A6265B004CA1BFD10F345CA33369CD43009B483F9436CCBCD69C70F7033A85D94527B1F39846B75B43C17 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\cheat_roblox.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 166912 |
Entropy (8bit): | 6.251413929646261 |
Encrypted: | false |
SSDEEP: | 3072:TmnOFd9UhOMQRUGKXs+S++7KFSbxeY+qDDrMK:3d9YGqStKEbxI |
MD5: | D653AEF66E218FB009B43365919BBCE3 |
SHA1: | D38CAFCD950B901EE79FF72EBB87FEC8B2D9582A |
SHA-256: | E85AF6A36635490B2FC2793B50C7EBC841DA95BC202A5FC9E7A4DBB17F172A2B |
SHA-512: | FF4776B44ACD815251908B7D726980FA9DE5E02AED32026C5A72B64A7B0A464399BE730EE37473FDE3406AE7D7D43284018ADE4D32FC160F579764344DA06EF6 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Joe Sandbox View: | |
Preview: |
Process: | C:\Users\user\Desktop\cheat_roblox.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 140288 |
Entropy (8bit): | 5.566968845764678 |
Encrypted: | false |
SSDEEP: | 3072:6mnOFd9U8OM+fe295liNgTddwY0JwsR4TbswYqkX5bEdGDOjESHhddJWjjY/ffIo:Wd9UH95D |
MD5: | 3AFF3B824FC5BCD05EF4D8EEE176E443 |
SHA1: | 422883493E21D605CB47CC08FD48CAEAD73F414C |
SHA-256: | 79750B0F34A49A75406A0D7D6949AFD83DF2B2FF946E35A94AEA6BFE1D399599 |
SHA-512: | 126818953B72233B2B0C50523ACE1EA8D1004F80EEDD0414A4FD3E4E385A3CB1D29E3D9BF7B50FA28AE5CC8EF2BF543D6416531F05FB977A79E60E51A82B03AE |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Joe Sandbox View: | |
Preview: |
Process: | C:\Users\user\Desktop\cheat_roblox.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 168960 |
Entropy (8bit): | 5.30703099621005 |
Encrypted: | false |
SSDEEP: | 3072:PV8w386j+bSL1OGtLJBz65/M6If+3Js+3JFkKeTnY:PN6bsrxBt25 |
MD5: | 520E97797B27B752130B3E982953CEAF |
SHA1: | AB460DA7E69D43747D98A4F45F5BB09D0E971789 |
SHA-256: | 8BC3BD8F0FF442D3C83DA8ED7DE13C8E44D095823E2480465BE866C08F7E8700 |
SHA-512: | 3219E4FE6B23411B48930FCE21DA24C8CE9BB07C6B069FA38B26B32DCC102C668F32AE816BD526CFBB44480F8279586509EBB11E9B75138A1F59AE771AA53664 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\cheat_roblox.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5720984 |
Entropy (8bit): | 6.362394353465928 |
Encrypted: | false |
SSDEEP: | 98304:v7v3kcOmmcMxGf3Yi4bg38mky2aB173qgDDzGxSP8R7fTA7pksuq7:70cB3djgmggDaRXAtHB |
MD5: | 27469372591B14FF1C57654FACB5E020 |
SHA1: | 492C166CD0E6C8D122CA4687659BF047CD48AFD7 |
SHA-256: | 3B8FCD52686095049B1563FBB6BA0BF73113A01B13C303BEBCB36D8339A1519F |
SHA-512: | 0CFA845DE57ACF6F17F295F0771C2A61CD846EFDEE79DA012DEF474BCAA91D9E99D3D528CF5698E6112A310C4F97E98AE74B6CFC601B2988C51E92270EBF92A2 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\cheat_roblox.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 477 |
Entropy (8bit): | 5.082252715861135 |
Encrypted: | false |
SSDEEP: | 12:Z0DtzHGtzs22yZOVqZwGJbShOVqZwGJbKy5i1bhH0HR:ZMz0zsBiO4Z+O4ZOKoQR |
MD5: | AAA81C149A8D65AC899AF053ECF582BC |
SHA1: | A784DDE9304A2B8108180A652C9374BEF71500D9 |
SHA-256: | 98818D1694AE946A32DEC4CAEA1FDD219650EF5A915CCA6A68E974C028A2FD69 |
SHA-512: | 74B6B9A1EF22CE12E3CE5076C8A3B6D0BE1C52642C6E004D52255D23AFD3506496D84049CDF6F5E37F5238C5645E014E26D88046D196CDBD3DDA90B3A27BEA92 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1851964843\Google.Widevine.CDM.dll
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2877728 |
Entropy (8bit): | 6.868480682648069 |
Encrypted: | false |
SSDEEP: | 49152:GB6BoH5sOI2CHusbKOdskuoHHVjcY94RNETO2WYA4oPToqnQ3dK5zuqvGKGxofFo:M67hlnVjcYGRNETO2WYA4oLoqnJuZI5 |
MD5: | 477C17B6448695110B4D227664AA3C48 |
SHA1: | 949FF1136E0971A0176F6ADEA8ADCC0DD6030F22 |
SHA-256: | CB190E7D1B002A3050705580DD51EBA895A19EB09620BDD48D63085D5D88031E |
SHA-512: | 1E267B01A78BE40E7A02612B331B1D9291DA8E4330DEA10BF786ACBC69F25E0BAECE45FB3BAFE1F4389F420EBAA62373E4F035A45E34EADA6F72C7C61D2302ED |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1851964843\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1778 |
Entropy (8bit): | 6.02086725086136 |
Encrypted: | false |
SSDEEP: | 48:p/hCdQAdJjRkakCi0LXjX9mqjW6JmfQkNWQzXXf2gTs:RtQ1aaxXrjW6JuQEWQKas |
MD5: | 3E839BA4DA1FFCE29A543C5756A19BDF |
SHA1: | D8D84AC06C3BA27CCEF221C6F188042B741D2B91 |
SHA-256: | 43DAA4139D3ED90F4B4635BD4D32346EB8E8528D0D5332052FCDA8F7860DB729 |
SHA-512: | 19B085A9CFEC4D6F1B87CC6BBEEB6578F9CBA014704D05C9114CFB0A33B2E7729AC67499048CB33823C884517CBBDC24AA0748A9BB65E9C67714E6116365F1AB |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1851964843\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.974403644129192 |
Encrypted: | false |
SSDEEP: | 3:SLVV8T+WSq2ykFDJp9qBn:SLVqZS5p0B |
MD5: | D30A5BBC00F7334EEDE0795D147B2E80 |
SHA1: | 78F3A6995856854CAD0C524884F74E182F9C3C57 |
SHA-256: | A08C1BC41DE319392676C7389048D8B1C7424C4B74D2F6466BCF5732B8D86642 |
SHA-512: | DACF60E959C10A3499D55DC594454858343BF6A309F22D73BDEE86B676D8D0CED10E86AC95ECD78E745E8805237121A25830301680BD12BFC7122A82A885FF4B |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1851964843\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 145 |
Entropy (8bit): | 4.595307058143632 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFooG+HhFFKS18CWjhXLXGPQ3TRpvF/FHddTcplFHddTcVYA:F6VlM5PpKS18hRIA |
MD5: | BBC03E9C7C5944E62EFC9C660B7BD2B6 |
SHA1: | 83F161E3F49B64553709994B048D9F597CDE3DC6 |
SHA-256: | 6CCE5AD8D496BC5179FA84AF8AFC568EEBA980D8A75058C6380B64FB42298C28 |
SHA-512: | FB80F091468A299B5209ACC30EDAF2001D081C22C3B30AAD422CBE6FEA7E5FE36A67A8E000D5DD03A30C60C30391C85FA31F3931E804C351AB0A71E9A978CC0F |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1926064875\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1796 |
Entropy (8bit): | 6.030369721181362 |
Encrypted: | false |
SSDEEP: | 24:pZRj/flTT479GpqYNJpFTN+R7aoXaBOs9pbt5dWpuck0iXfkhApoXB2XktSqDhs:p/hcI1NJpFN+R7aka8s9pbwp+zpkntI |
MD5: | 4CE34645BA96EBAAFF71D8B9ED570881 |
SHA1: | 7DD920E922A66E276CFE162B4D51D0EE862321FD |
SHA-256: | 8453F66B3179AB56365D2C053F73AD5F90CDDC344EA09F88CBA77D9199E1291D |
SHA-512: | 1F3E116B3DBAFCEAC4C8E0958431218281A6647F8BC8AFA742B2C759CD368A3A9551BEE284D5971DE004ABC88C810B82DF372BAA38AA549899D79B2460A9D493 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1926064875\cr_en-us_500000_index.bin
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7883519 |
Entropy (8bit): | 6.572648868768043 |
Encrypted: | false |
SSDEEP: | 98304:zP9pZvIxJcGGgPFckavBTC0fxiR9AEosZWD:zFW/QZxiROPD |
MD5: | F1F7280460CB0976FDBFBC9E809000EC |
SHA1: | 99A5AB5B99482A7ED596C9C664C2A1755B215D85 |
SHA-256: | A49478B4959707E94BAA235551FAE89089386CD962D906F78A36553E371F358C |
SHA-512: | 2A43B2B89506FC3D82CCC413A78F9A670D0B99838F990DC68B6B7A899E68A68D96734EADCCAA3EB4069898003B7574659FDD1D85AD11C89CB2C42CECD94B91A0 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1926064875\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.85910606118318 |
Encrypted: | false |
SSDEEP: | 3:STAE4+g6KQXTKth2vaUDXHuIRQyTcn:SzghQDKSvaaX0yQ |
MD5: | 9AFC3C6A8D9349FCB25061F1A9BD2028 |
SHA1: | 2569EDDE33E0F02C4D57A625DF0FB324856CEA86 |
SHA-256: | 7C418C921DE2AF6C70D526A1EAE6A0F133E0D10F538B345A365C3FE2B3686CB2 |
SHA-512: | 719E56123C5F9D134CBEF107AC4D595C07C3D623D29E3F39B8FD8983050ADAEE8C1AA7228B33A6EC9D8C44F4CDC6464A4B748BAD75E4A15EACD22F5EEC5387CB |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_1926064875\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 108 |
Entropy (8bit): | 4.880870753312092 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifF0AAGAR3CKG/w/VpKS1802Qc6vY:F6VlMT2C7Y/VUS1802Qc6A |
MD5: | 91B1C49B99FE2B26C28B2027A08CE05C |
SHA1: | 2BBF126EA07204A4877D777B358C6E6A327AB943 |
SHA-256: | 41C41526EA9847C8157416F243FE23D4150FAC13075AE535371C06942C2CE770 |
SHA-512: | 069B05CAEFC788303A6EB07CC3578A7AD080979653BE08E51B5BFD359DF158C2F12C587B3CEA3D26B62EA2504E5ED46A5EA64B5D72B08BE689A5CFF81C823C46 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_666048289\LICENSE
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1558 |
Entropy (8bit): | 5.11458514637545 |
Encrypted: | false |
SSDEEP: | 48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH |
MD5: | EE002CB9E51BB8DFA89640A406A1090A |
SHA1: | 49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2 |
SHA-256: | 3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B |
SHA-512: | D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_666048289\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 5.993417646222111 |
Encrypted: | false |
SSDEEP: | 48:p/hUI1JfE4hAdIs7akUEQNV3N8kIL8F64leu38k7ObMARcqk:RnqOQIs7azN/8n4leus+cMASqk |
MD5: | 2295CEA75E046B34E7209F41B03CEC14 |
SHA1: | 1099DCE991021E31A33BD12106E4FD23AA763D33 |
SHA-256: | B2EDA3181D68EFAA7AC3EE4DAC3207F922CCA956186A7AFBFB8E88A64E84BB3F |
SHA-512: | FBEAA1FFF2FBAFD6FD3A5076DDC4F5DAC024EAB72C3061BE3F32EB5D6F8883DF028254824790A0471FFB57D0314DB733F3AE9E2E8CD423B78EAF5D847C2CF4B7 |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_666048289\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.967367379785099 |
Encrypted: | false |
SSDEEP: | 3:Sc4EddulfeAQQgBD4RdNRWS3Ug5:Sc4EddulfeAQtDsfVEi |
MD5: | D981AE71ED66833759DDCCEC52FB948A |
SHA1: | E0DB4693A7B1BB80C9D3DE020273728F32389574 |
SHA-256: | 679A53419459DF7FE54CCC32F752D38A15CD6856FFFC9086C29EF7B7D8E2C7CB |
SHA-512: | 3F86B3363BC1A906C899035CDE4E8A89828EE274C17B92C6F88CEAB912FB043B5544925B33914DF8452F52DB0802427B03D2F674500A8340609FCB54026F997B |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_666048289\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85 |
Entropy (8bit): | 4.424014792499492 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFCmMARWHJqS1iLBRvY:F6VlM8aRWpqS1iLBW |
MD5: | 9A094D744241B990256BD73A9F0DE35B |
SHA1: | 0B903320B690921724C04EB0A97C92E5F1A446A4 |
SHA-256: | A018F1695956AAEB88D70F496D3E115C47E49931DA7AE48B0DF3D10238CC1C5A |
SHA-512: | 38AF8E23CC8CE4825CF974CA55144E8907C65091F411CED19E650CCE164CC9F1B4F8D854F4506C70377899615AB570609E8236633F2211C7328E462EB0043C4D |
Malicious: | false |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping6712_666048289\sets.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9482 |
Entropy (8bit): | 4.628404350796629 |
Encrypted: | false |
SSDEEP: | 96:Mon4mvCSqX1gs1blbw/BNKLcxbdmf56MFJtRTGXvcxN43uP+8qJq:v5CSqlKBkIVmtRTGXvcxBsq |
MD5: | 5BE545A21EBEEA747EAA08C476DEC2C7 |
SHA1: | 3F6670F5C43147FA3DE5E768CF959DE2DAA34053 |
SHA-256: | B7C919CE2670AC0D8966E83AE141AE1B30EE8AD68581D42D92AC1C09BB161BED |
SHA-512: | 18DBC4779704D730584D02B4A5C2D1B9089F2503CB6DC847DA8128EA2215C0D70965CB3384934F5657C22F26DD68496EFAD05FD4AC95105BED7F3DB6351B24C6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 2833 |
Entropy (8bit): | 7.876846206921263 |
Encrypted: | false |
SSDEEP: | 48:Kw15hc/Pj2itdgjeVVO/SzBdCvhaHAlJX7XnF/HDoSH8T78atjZeHMBx/F/WssM:J15hc/Pj2mdgjMjusgl5XFD3MoIx9eg |
MD5: | 18C023BC439B446F91BF942270882422 |
SHA1: | 768D59E3085976DBA252232A65A4AF562675F782 |
SHA-256: | E0E71ACEF1EFBFAB69A1A60CD8FADDED948D0E47A0A27C59A0BE7033F6A84482 |
SHA-512: | A95AD7B48596BC0AF23D05D1E58681E5D65E707247F96C5BC088880F4525312A1834A89615A0E33AEA6B066793088A193EC29B5C96EA216F531C443487AE0735 |
Malicious: | false |
URL: | https://cdn.iplogger.org/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 445 |
Entropy (8bit): | 7.051559084988302 |
Encrypted: | false |
SSDEEP: | 6:tj+cYUFqb9Oq2EWxiWlb+hKI526WogYAGJe9UCZE12REqtVv6n:tqeqZF3WxiHKI5KopAMQUD10EqtVv6 |
MD5: | 1BD6EB140EC5E09AF54808BCE2BE74BE |
SHA1: | 00746108650919B88014CE35AABF72B0F20B2046 |
SHA-256: | 3E13369E5C528A4598007330A7D572DADD181E268D0CF87BA7B62FD7668597F8 |
SHA-512: | FA58EB9D8DB6819BCD39EC73089942D7F16CA602322E3EFA592A3418FB735A87DF9FD5388830F8E1E699CB5457234626F2B09DACEC83E265F300CE19AA907DBE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2833 |
Entropy (8bit): | 7.876846206921263 |
Encrypted: | false |
SSDEEP: | 48:Kw15hc/Pj2itdgjeVVO/SzBdCvhaHAlJX7XnF/HDoSH8T78atjZeHMBx/F/WssM:J15hc/Pj2mdgjMjusgl5XFD3MoIx9eg |
MD5: | 18C023BC439B446F91BF942270882422 |
SHA1: | 768D59E3085976DBA252232A65A4AF562675F782 |
SHA-256: | E0E71ACEF1EFBFAB69A1A60CD8FADDED948D0E47A0A27C59A0BE7033F6A84482 |
SHA-512: | A95AD7B48596BC0AF23D05D1E58681E5D65E707247F96C5BC088880F4525312A1834A89615A0E33AEA6B066793088A193EC29B5C96EA216F531C443487AE0735 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 445 |
Entropy (8bit): | 7.051559084988302 |
Encrypted: | false |
SSDEEP: | 6:tj+cYUFqb9Oq2EWxiWlb+hKI526WogYAGJe9UCZE12REqtVv6n:tqeqZF3WxiHKI5KopAMQUD10EqtVv6 |
MD5: | 1BD6EB140EC5E09AF54808BCE2BE74BE |
SHA1: | 00746108650919B88014CE35AABF72B0F20B2046 |
SHA-256: | 3E13369E5C528A4598007330A7D572DADD181E268D0CF87BA7B62FD7668597F8 |
SHA-512: | FA58EB9D8DB6819BCD39EC73089942D7F16CA602322E3EFA592A3418FB735A87DF9FD5388830F8E1E699CB5457234626F2B09DACEC83E265F300CE19AA907DBE |
Malicious: | false |
URL: | https://counter.yadro.ru/hit?q;t38.6;r;s1280*1024*24;uhttps%3A//2no.co/redirect-2;hBranded%20Short%20Domain;0.07021634166148738 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 9909 |
Entropy (8bit): | 5.402425739040007 |
Encrypted: | false |
SSDEEP: | 192:DLlw+00cv13xV1cSHYu+zogDwIIhWp6psOsW4rqSxVEGz5R2WxSi1yz:D5w+Pcv13T1FH0fkIIm6QXxzP20u |
MD5: | B7200222968BE4C34BD8C8902D298EC9 |
SHA1: | E197DCA77C595D0BD625A65CEF2B19A8625012CF |
SHA-256: | 0B2479797BDEA905C6E9DFEA1B675D8D99263EFFAF2206653600E3C8BC1EEAF8 |
SHA-512: | BAC81BCF0D3F47BC3A98FA501934BC331EAF6317CE682EEC5113A8D1B4249FEA7E70446F8F63C5EEF0B3A64FA74D979AC7F16D440D89BD643B80E03C8D2A2909 |
Malicious: | false |
URL: | https://2no.co/24RXx6 |
Preview: |
File type: | |
Entropy (8bit): | 7.909822900338073 |
TrID: |
|
File name: | cheat_roblox.exe |
File size: | 2'675'335 bytes |
MD5: | d49b1a211ce49bed3e766471501819c6 |
SHA1: | ed8f8b0d45ad556115c14a00247c080fa82d56e9 |
SHA256: | 1673b4f5f2d5ae3e3d2c5816534bf904ed1d2653b4a40bbb2a320231eca8259a |
SHA512: | 2a0ec111c39ed2d5e02555a18a94f84bb546d1fc4f827ddeb24709b9b86259318611626a578918c5d8e60a5667e774c0d36241b6b668afb466a8806d37c2b7d2 |
SSDEEP: | 49152:1Djlabwz97DQNxlq9fFQXLkL9g+/kW/4JNe0OL108Jgwya3fj8kSbn17:Zqw5skLZbaWL108JgwnvS5 |
TLSH: | 48C5120AF3A509F8E073E57889474906F67A3C1A13319BCF13A5556B2F673A1CE2E352 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......$.2.`.\.`.\.`.\..y..h.\..y....\..y..m.\.....b.\...X.r.\..._.j.\...Y.Y.\.i...i.\.i...b.\.i...g.\.`.].C.\...Y.R.\...\.a.\.....a.\ |
Icon Hash: | 1515d4d4442f2d2d |
Entrypoint: | 0x140032ee0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66409723 [Sun May 12 10:17:07 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 2 |
File Version Major: | 5 |
File Version Minor: | 2 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 2 |
Import Hash: | b1c5b1beabd90d9fdabd1df0779ea832 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007FB81CC4F3F8h |
dec eax |
add esp, 28h |
jmp 00007FB81CC4ED8Fh |
int3 |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+08h], ebx |
dec eax |
mov dword ptr [eax+10h], ebp |
dec eax |
mov dword ptr [eax+18h], esi |
dec eax |
mov dword ptr [eax+20h], edi |
inc ecx |
push esi |
dec eax |
sub esp, 20h |
dec ebp |
mov edx, dword ptr [ecx+38h] |
dec eax |
mov esi, edx |
dec ebp |
mov esi, eax |
dec eax |
mov ebp, ecx |
dec ecx |
mov edx, ecx |
dec eax |
mov ecx, esi |
dec ecx |
mov edi, ecx |
inc ecx |
mov ebx, dword ptr [edx] |
dec eax |
shl ebx, 04h |
dec ecx |
add ebx, edx |
dec esp |
lea eax, dword ptr [ebx+04h] |
call 00007FB81CC4E213h |
mov eax, dword ptr [ebp+04h] |
and al, 66h |
neg al |
mov eax, 00000001h |
sbb edx, edx |
neg edx |
add edx, eax |
test dword ptr [ebx+04h], edx |
je 00007FB81CC4EF23h |
dec esp |
mov ecx, edi |
dec ebp |
mov eax, esi |
dec eax |
mov edx, esi |
dec eax |
mov ecx, ebp |
call 00007FB81CC50F37h |
dec eax |
mov ebx, dword ptr [esp+30h] |
dec eax |
mov ebp, dword ptr [esp+38h] |
dec eax |
mov esi, dword ptr [esp+40h] |
dec eax |
mov edi, dword ptr [esp+48h] |
dec eax |
add esp, 20h |
inc ecx |
pop esi |
ret |
int3 |
int3 |
int3 |
dec eax |
sub esp, 48h |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007FB81CC3D7A3h |
dec eax |
lea edx, dword ptr [00025747h] |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007FB81CC4FFF2h |
int3 |
jmp 00007FB81CC561D4h |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x597a0 | 0x34 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x597d4 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x70000 | 0xe3bc | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x6a000 | 0x306c | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7f000 | 0x970 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x536c0 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x53780 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x4b3f0 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x48000 | 0x508 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x588bc | 0x120 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4676e | 0x46800 | f06bb06e02377ae8b223122e53be35c2 | False | 0.5372340425531915 | data | 6.47079645411382 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x48000 | 0x128c4 | 0x12a00 | 2de06d4a6920a6911e64ff20000ea72f | False | 0.4499003775167785 | data | 5.273999097784603 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x5b000 | 0xe75c | 0x1a00 | 0dbdb901a7d477980097e42e511a94fb | False | 0.28275240384615385 | data | 3.2571023907881185 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x6a000 | 0x306c | 0x3200 | b0ce0f057741ad2a4ef4717079fa34e9 | False | 0.483359375 | data | 5.501810413666288 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.didat | 0x6e000 | 0x360 | 0x400 | 1fcc7b1d7a02443319f8fcc2be4ca936 | False | 0.2578125 | data | 3.0459938492946015 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
_RDATA | 0x6f000 | 0x15c | 0x200 | 3f331ec50f09ba861beaf955b33712d5 | False | 0.408203125 | data | 3.3356393424384843 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x70000 | 0xe3bc | 0xe400 | 1b279dad3e3d77fcdfb269a130bf474b | False | 0.6334121436403509 | data | 6.778407783727912 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7f000 | 0x970 | 0xa00 | 77a9ddfc47a5650d6eebbcc823e39532 | False | 0.52421875 | data | 5.336289720085303 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
PNG | 0x70674 | 0xb45 | PNG image data, 93 x 302, 8-bit/color RGB, non-interlaced | 1.0027729636048528 | ||
PNG | 0x711bc | 0x15a9 | PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced | 0.9363390441839495 | ||
RT_ICON | 0x72768 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, resolution 2834 x 2834 px/m, 256 important colors | 0.47832369942196534 | ||
RT_ICON | 0x72cd0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, resolution 2834 x 2834 px/m, 256 important colors | 0.5410649819494585 | ||
RT_ICON | 0x73578 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, resolution 2834 x 2834 px/m, 256 important colors | 0.4933368869936034 | ||
RT_ICON | 0x74420 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2834 x 2834 px/m | 0.5390070921985816 | ||
RT_ICON | 0x74888 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2834 x 2834 px/m | 0.41393058161350843 | ||
RT_ICON | 0x75930 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2834 x 2834 px/m | 0.3479253112033195 | ||
RT_ICON | 0x77ed8 | 0x3d71 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9809269502193401 | ||
RT_DIALOG | 0x7bc4c | 0x2ba | data | 0.5286532951289399 | ||
RT_DIALOG | 0x7bf08 | 0x13a | data | 0.6560509554140127 | ||
RT_DIALOG | 0x7c044 | 0xf2 | data | 0.71900826446281 | ||
RT_DIALOG | 0x7c138 | 0x14a | data | 0.6 | ||
RT_DIALOG | 0x7c284 | 0x314 | data | 0.47588832487309646 | ||
RT_DIALOG | 0x7c598 | 0x24a | data | 0.6279863481228669 | ||
RT_STRING | 0x7c7e4 | 0x1fc | data | 0.421259842519685 | ||
RT_STRING | 0x7c9e0 | 0x246 | data | 0.41924398625429554 | ||
RT_STRING | 0x7cc28 | 0x1a6 | data | 0.514218009478673 | ||
RT_STRING | 0x7cdd0 | 0xdc | data | 0.65 | ||
RT_STRING | 0x7ceac | 0x470 | data | 0.3873239436619718 | ||
RT_STRING | 0x7d31c | 0x164 | data | 0.5056179775280899 | ||
RT_STRING | 0x7d480 | 0x110 | data | 0.5772058823529411 | ||
RT_STRING | 0x7d590 | 0x158 | data | 0.4563953488372093 | ||
RT_STRING | 0x7d6e8 | 0xe8 | data | 0.5948275862068966 | ||
RT_STRING | 0x7d7d0 | 0x1c6 | data | 0.5242290748898678 | ||
RT_STRING | 0x7d998 | 0x268 | data | 0.4837662337662338 | ||
RT_GROUP_ICON | 0x7dc00 | 0x68 | data | 0.7019230769230769 | ||
RT_MANIFEST | 0x7dc68 | 0x753 | XML 1.0 document, ASCII text, with CRLF line terminators | 0.3957333333333333 |
DLL | Import |
---|---|
KERNEL32.dll | LocalFree, GetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, GetCurrentProcessId, CreateDirectoryW, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, GetVersionExW, GetModuleFileNameW, SetCurrentDirectoryW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, ExpandEnvironmentStringsW, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, GlobalMemoryStatusEx, LoadResource, SizeofResource, GetTimeFormatW, GetDateFormatW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetNumberFormatW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, IsValidCodePage, FindNextFileA, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, InitializeCriticalSectionAndSpinCount, WaitForSingleObjectEx, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RtlPcToFileHeader, RtlUnwindEx, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, GetStringTypeW, HeapReAlloc, LCMapStringW, FindFirstFileExA |
OLEAUT32.dll | SysAllocString, SysFreeString, VariantClear |
gdiplus.dll | GdipCloneImage, GdipFree, GdipDisposeImage, GdipCreateBitmapFromStream, GdipCreateHBITMAPFromBitmap, GdiplusStartup, GdiplusShutdown, GdipAlloc |
Timestamp | Protocol | SID | Signature | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
2024-07-30T00:56:50.218743+0200 | TCP | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
2024-07-30T00:57:27.842535+0200 | TCP | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 30, 2024 00:56:27.772205114 CEST | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:27.772205114 CEST | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:28.100399971 CEST | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:33.383233070 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:33.383271933 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:33.383347988 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:33.385003090 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:33.385027885 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:34.113610029 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:34.118654013 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:34.118674040 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:34.120057106 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:34.120156050 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:34.121599913 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:34.121758938 CEST | 443 | 49712 | 128.116.21.3 | 192.168.2.6 |
Jul 30, 2024 00:56:34.121779919 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:34.121934891 CEST | 49712 | 443 | 192.168.2.6 | 128.116.21.3 |
Jul 30, 2024 00:56:34.148832083 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.148932934 CEST | 443 | 49715 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:56:34.151866913 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.152766943 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.152818918 CEST | 443 | 49715 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:56:34.865238905 CEST | 443 | 49715 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:56:34.866760969 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.866772890 CEST | 443 | 49715 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:56:34.867810965 CEST | 443 | 49715 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:56:34.867888927 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.869061947 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:34.869162083 CEST | 49715 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:56:35.774575949 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:35.774599075 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:35.774677038 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:35.775298119 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:35.775311947 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.593595982 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.593683004 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.628010988 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.628026962 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.628335953 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.679516077 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.758900881 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.759052992 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.759067059 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.759354115 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.804507017 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.957379103 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.957583904 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.957715988 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.962513924 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:36.962532997 CEST | 443 | 49719 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:36.962598085 CEST | 49719 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:37.382491112 CEST | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:37.382580996 CEST | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:37.702573061 CEST | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:39.399722099 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:39.399842978 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:44.016822100 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.016864061 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.016963959 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.017560959 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.017577887 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.865710974 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.865854979 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.868757963 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.868772984 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.869028091 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.870874882 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.870934010 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.870940924 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:44.871073008 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:44.916500092 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:45.056077003 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:45.056282043 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:45.056410074 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:45.056526899 CEST | 49720 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:45.056545019 CEST | 443 | 49720 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:48.468806982 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.468853951 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:48.468943119 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.565579891 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.565627098 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:48.565691948 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.672595024 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.672622919 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:48.675889015 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:48.675900936 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.063507080 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:49.063555002 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:49.063677073 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:49.065767050 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:49.065779924 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:49.158268929 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.158653021 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.158680916 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.160262108 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.160303116 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.160365105 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.160449028 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.160454988 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.161465883 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.161516905 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.162347078 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.162461042 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.162983894 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.163049936 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.163436890 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.163446903 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.206513882 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.206513882 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.206525087 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.254252911 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.635289907 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.635325909 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.635353088 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.635405064 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.635425091 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.635499954 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.635507107 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.636673927 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.636775970 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.636782885 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.636796951 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.636847973 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.669837952 CEST | 49722 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:56:49.669857025 CEST | 443 | 49722 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:56:49.696535110 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:49.696611881 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:49.726114988 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:49.726140022 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:49.726213932 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:49.726407051 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:49.726421118 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:49.732652903 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:49.732682943 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:49.733036995 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:49.749429941 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:49.749466896 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:49.749540091 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:49.749877930 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:49.749891996 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:49.776523113 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.011502981 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.052509069 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.100539923 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.100828886 CEST | 49705 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.101648092 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.101696014 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:50.101876020 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.103559971 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.103575945 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:50.117347956 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:50.117790937 CEST | 443 | 49705 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:50.210753918 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.211029053 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.211042881 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.212104082 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.212182999 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.213346958 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.213421106 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.213586092 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.216331959 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216356039 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216363907 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216384888 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216464996 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.216464996 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.216490984 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216497898 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.216537952 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.218543053 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.218614101 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.218621016 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.218631983 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.218683004 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.256505013 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.258892059 CEST | 49730 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:56:50.258932114 CEST | 443 | 49730 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:56:50.268529892 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.268544912 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.315501928 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.362931967 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363010883 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363037109 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363061905 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.363070965 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363080978 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363112926 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.363221884 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.363257885 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.363265991 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.364509106 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.364564896 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.364573002 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.365966082 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.366009951 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.366017103 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.368669033 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.368707895 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.368851900 CEST | 443 | 49732 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:50.368902922 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.368921995 CEST | 49732 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:50.388577938 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.388600111 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.388694048 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.388889074 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.388899088 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.721860886 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.722141027 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.722157001 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.723431110 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.723520994 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.727186918 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.727272987 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.727814913 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.727823019 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.735444069 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:50.735526085 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:50.773693085 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.880680084 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.883083105 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.883095980 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.884207010 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.884274960 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.888339043 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.888417006 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.888552904 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.932651043 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.932661057 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.958937883 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.959017992 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.959101915 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.980217934 CEST | 49733 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.980240107 CEST | 443 | 49733 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.980504036 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:50.983280897 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.983310938 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:50.983607054 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.983783007 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:50.983798981 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:51.028923988 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.029143095 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.029381990 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.029563904 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.029577017 CEST | 443 | 49739 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.029596090 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.029622078 CEST | 49739 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.030339956 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.030366898 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.030726910 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.031225920 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.031240940 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.116796970 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.116835117 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.117372036 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.117440939 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.118068933 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.118102074 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.118833065 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.164509058 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.356446981 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.356524944 CEST | 443 | 49738 | 173.222.162.64 | 192.168.2.6 |
Jul 30, 2024 00:56:51.356530905 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.356565952 CEST | 49738 | 443 | 192.168.2.6 | 173.222.162.64 |
Jul 30, 2024 00:56:51.529314995 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.529577971 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.529608965 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.529958010 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.530401945 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.530479908 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.530642033 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.576505899 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.683990002 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.684070110 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.684150934 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.684448957 CEST | 49741 | 443 | 192.168.2.6 | 35.190.80.1 |
Jul 30, 2024 00:56:51.684472084 CEST | 443 | 49741 | 35.190.80.1 | 192.168.2.6 |
Jul 30, 2024 00:56:51.707248926 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:51.708117962 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:51.708129883 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:51.708540916 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:51.708949089 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:51.709074974 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:51.709255934 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:51.756505966 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:52.154375076 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:52.154459953 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:52.154503107 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:52.169770002 CEST | 49740 | 443 | 192.168.2.6 | 88.212.201.204 |
Jul 30, 2024 00:56:52.169791937 CEST | 443 | 49740 | 88.212.201.204 | 192.168.2.6 |
Jul 30, 2024 00:56:52.177232981 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.177263021 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.177436113 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.178388119 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.178400993 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.203452110 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:52.203488111 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:52.203542948 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:52.203769922 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:52.203779936 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:52.649357080 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:52.649404049 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:52.649677992 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:52.649883032 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:52.649895906 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:52.711601019 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.711894989 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.711910963 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.712929010 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.712997913 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.713458061 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.713524103 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.713673115 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.713682890 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.770508051 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.869601965 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.869656086 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.869723082 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.869771957 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.869817019 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.869817019 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.870618105 CEST | 49744 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.870635986 CEST | 443 | 49744 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.895627975 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.895658970 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:52.895726919 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.896291018 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:52.896307945 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.182607889 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.231154919 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.231178045 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.232462883 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.233012915 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.237950087 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.238050938 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.238080978 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.280505896 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.281591892 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.281600952 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.324906111 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:53.325140953 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:53.325160027 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:53.326216936 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:53.326276064 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:53.327241898 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:53.327301979 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:53.329529047 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.387224913 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.387967110 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.387981892 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.388997078 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.389166117 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.389380932 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.389442921 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.389511108 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.436497927 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.441629887 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.441643953 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.453757048 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:53.453810930 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:53.453962088 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:53.455034018 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:53.455046892 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:53.475647926 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.475722075 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.475862026 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.477168083 CEST | 49745 | 443 | 192.168.2.6 | 88.212.201.198 |
Jul 30, 2024 00:56:53.477185965 CEST | 443 | 49745 | 88.212.201.198 | 192.168.2.6 |
Jul 30, 2024 00:56:53.489523888 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.536495924 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:56:53.536561966 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:56:53.547614098 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.547669888 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.547714949 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.547772884 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:53.547794104 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.547899008 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.548808098 CEST | 49747 | 443 | 192.168.2.6 | 172.67.132.113 |
Jul 30, 2024 00:56:53.548825979 CEST | 443 | 49747 | 172.67.132.113 | 192.168.2.6 |
Jul 30, 2024 00:56:54.167462111 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.167558908 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.177174091 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.177187920 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.177534103 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.223510981 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.268507004 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.471956015 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.472012043 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.472110987 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.472203016 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.472219944 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.472243071 CEST | 49748 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.472249031 CEST | 443 | 49748 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.516036987 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.516067982 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:54.516148090 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.516427994 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:54.516442060 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.186089039 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.186321020 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.188678026 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.188687086 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.189075947 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.191690922 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.232500076 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.472949982 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.473123074 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.477664948 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.564567089 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.564599991 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:55.564613104 CEST | 49749 | 443 | 192.168.2.6 | 23.32.185.164 |
Jul 30, 2024 00:56:55.564620018 CEST | 443 | 49749 | 23.32.185.164 | 192.168.2.6 |
Jul 30, 2024 00:56:56.752614975 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:56.752645016 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:56.752769947 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:56.753621101 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:56.753634930 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.606822014 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.607052088 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.610641003 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.610661983 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.611268997 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.613611937 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.613800049 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.613811970 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.613945007 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.656495094 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.814050913 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.814166069 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:56:57.814362049 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.814616919 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.814616919 CEST | 49750 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:56:57.814640999 CEST | 443 | 49750 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:03.443037033 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:03.443109989 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:03.443260908 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:04.066725016 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:57:04.066812038 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:57:04.066857100 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:57:05.141479015 CEST | 49721 | 443 | 192.168.2.6 | 104.21.79.229 |
Jul 30, 2024 00:57:05.141519070 CEST | 443 | 49721 | 104.21.79.229 | 192.168.2.6 |
Jul 30, 2024 00:57:05.141577005 CEST | 49746 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:05.141632080 CEST | 443 | 49746 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:16.949985981 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:16.950088024 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:16.950239897 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:16.964029074 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:16.964065075 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.803046942 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.803266048 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.805610895 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.805643082 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.805965900 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.808310986 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.808384895 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.808398008 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.808521986 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.856503963 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.993268967 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.993360996 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:17.993443966 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.993725061 CEST | 49751 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:17.993769884 CEST | 443 | 49751 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:26.609961033 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:26.610064983 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:26.610194921 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:26.610702991 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:26.610742092 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.618172884 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.618278980 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.622320890 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.622359037 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.622685909 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.635925055 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.676500082 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.838368893 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.838399887 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.838417053 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.838582039 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.838649035 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.838684082 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.838712931 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.842300892 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.842345953 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.842396021 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.842406988 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.842420101 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.842420101 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.842673063 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.844537973 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.844567060 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:27.844597101 CEST | 49753 | 443 | 192.168.2.6 | 20.12.23.50 |
Jul 30, 2024 00:57:27.844602108 CEST | 443 | 49753 | 20.12.23.50 | 192.168.2.6 |
Jul 30, 2024 00:57:44.685390949 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:44.685431004 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:44.685514927 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:44.689668894 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:44.689682961 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.538291931 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.538465977 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.541152954 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.541160107 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.541405916 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.543879032 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.543951988 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.543960094 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.544146061 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.584496975 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.727072001 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.727410078 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:45.727564096 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.727880001 CEST | 49754 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:57:45.727900982 CEST | 443 | 49754 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:57:52.681859016 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:52.681915998 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:52.682152987 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:52.682431936 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:52.682442904 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:53.339844942 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:53.340281010 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:53.340306044 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:53.340651989 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:53.341042995 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:53.341110945 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:57:53.384718895 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:57:57.009581089 CEST | 58786 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:57:57.025928974 CEST | 53 | 58786 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:57.026488066 CEST | 58786 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:57:57.026488066 CEST | 58786 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:57:57.042280912 CEST | 53 | 58786 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:57.513586998 CEST | 53 | 58786 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:57.514988899 CEST | 58786 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:57:57.539103985 CEST | 53 | 58786 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:57.539159060 CEST | 58786 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:58:03.251549006 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:58:03.251616001 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:58:03.251777887 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:58:05.154359102 CEST | 49758 | 443 | 192.168.2.6 | 142.250.186.100 |
Jul 30, 2024 00:58:05.154386997 CEST | 443 | 49758 | 142.250.186.100 | 192.168.2.6 |
Jul 30, 2024 00:58:17.732601881 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:17.732647896 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:17.732717037 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:17.733367920 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:17.733386040 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.572107077 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.572216034 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.579072952 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.579097986 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.579298973 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.581891060 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.581995964 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.582007885 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.582351923 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.628498077 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.766479969 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.766566992 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:58:18.766618967 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.766850948 CEST | 58795 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:58:18.766875029 CEST | 443 | 58795 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.122247934 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.122313023 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.122581959 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.123147964 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.123168945 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.954035997 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.956083059 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.956470966 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.956492901 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.957078934 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:09.961766005 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.961766005 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.961766005 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:09.961786032 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:10.008497000 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:10.145749092 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:10.145991087 CEST | 443 | 58797 | 40.113.110.67 | 192.168.2.6 |
Jul 30, 2024 00:59:10.146059990 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:10.146245956 CEST | 58797 | 443 | 192.168.2.6 | 40.113.110.67 |
Jul 30, 2024 00:59:16.563091040 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:16.563132048 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:16.563235044 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:16.565164089 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:16.565176010 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:17.331162930 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:17.332058907 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:17.332113981 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:17.333882093 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:17.333955050 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:17.335726976 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:17.335928917 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:17.335936069 CEST | 443 | 58801 | 13.32.110.82 | 192.168.2.6 |
Jul 30, 2024 00:59:17.336030960 CEST | 58801 | 443 | 192.168.2.6 | 13.32.110.82 |
Jul 30, 2024 00:59:19.899090052 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:19.899132967 CEST | 443 | 58804 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:59:19.900010109 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:19.901248932 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:19.901266098 CEST | 443 | 58804 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:59:20.686125994 CEST | 443 | 58804 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:59:20.686938047 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:20.686960936 CEST | 443 | 58804 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:59:20.688011885 CEST | 443 | 58804 | 128.116.21.4 | 192.168.2.6 |
Jul 30, 2024 00:59:20.688069105 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:20.690402031 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Jul 30, 2024 00:59:20.690558910 CEST | 58804 | 443 | 192.168.2.6 | 128.116.21.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jul 30, 2024 00:56:33.361526012 CEST | 51256 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:33.379079103 CEST | 53 | 51256 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:34.127734900 CEST | 58918 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:34.146291971 CEST | 53 | 58918 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:35.067919970 CEST | 65341 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:48.308696032 CEST | 51518 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:48.308979988 CEST | 53115 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:48.429425001 CEST | 53 | 65073 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:48.429920912 CEST | 53 | 59715 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:48.432893038 CEST | 53 | 53115 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:48.434175014 CEST | 53 | 51518 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:49.704432964 CEST | 64213 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:49.704626083 CEST | 61759 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:49.724371910 CEST | 53 | 64213 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:49.724828005 CEST | 53 | 61759 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:49.730747938 CEST | 59026 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:49.731116056 CEST | 51905 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:49.748725891 CEST | 53 | 59026 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:49.748974085 CEST | 53 | 51905 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:49.775507927 CEST | 53 | 55960 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.369602919 CEST | 64344 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:50.369925976 CEST | 52648 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:50.388063908 CEST | 53 | 64344 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:50.388122082 CEST | 53 | 52648 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.184640884 CEST | 62397 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.184813976 CEST | 60186 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.202683926 CEST | 53 | 60186 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.202953100 CEST | 53 | 62397 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.630474091 CEST | 62355 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.631124020 CEST | 60223 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.648118019 CEST | 53 | 62355 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.648458958 CEST | 53 | 60223 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.874556065 CEST | 65468 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.874861002 CEST | 62292 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:56:52.893346071 CEST | 53 | 65468 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:56:52.895145893 CEST | 53 | 62292 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:06.691802979 CEST | 53 | 58680 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:25.640033960 CEST | 53 | 56974 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:47.858498096 CEST | 53 | 51922 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:48.175936937 CEST | 53 | 56915 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:57:57.008881092 CEST | 53 | 57155 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:58:07.593827009 CEST | 57077 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:59:10.476824999 CEST | 53 | 53703 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:59:16.543349028 CEST | 50600 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:59:16.561095953 CEST | 53 | 50600 | 1.1.1.1 | 192.168.2.6 |
Jul 30, 2024 00:59:19.864056110 CEST | 56410 | 53 | 192.168.2.6 | 1.1.1.1 |
Jul 30, 2024 00:59:19.881989002 CEST | 53 | 56410 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jul 30, 2024 00:56:33.361526012 CEST | 192.168.2.6 | 1.1.1.1 | 0xa2e1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:34.127734900 CEST | 192.168.2.6 | 1.1.1.1 | 0x9a3c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:35.067919970 CEST | 192.168.2.6 | 1.1.1.1 | 0xb1a1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:48.308696032 CEST | 192.168.2.6 | 1.1.1.1 | 0x6fb3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:48.308979988 CEST | 192.168.2.6 | 1.1.1.1 | 0xd09 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:49.704432964 CEST | 192.168.2.6 | 1.1.1.1 | 0x51fb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:49.704626083 CEST | 192.168.2.6 | 1.1.1.1 | 0x729b | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:49.730747938 CEST | 192.168.2.6 | 1.1.1.1 | 0x95bd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:49.731116056 CEST | 192.168.2.6 | 1.1.1.1 | 0x5d2 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:50.369602919 CEST | 192.168.2.6 | 1.1.1.1 | 0xb3b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:50.369925976 CEST | 192.168.2.6 | 1.1.1.1 | 0x5816 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.184640884 CEST | 192.168.2.6 | 1.1.1.1 | 0x6fe4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.184813976 CEST | 192.168.2.6 | 1.1.1.1 | 0xa708 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.630474091 CEST | 192.168.2.6 | 1.1.1.1 | 0x361f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.631124020 CEST | 192.168.2.6 | 1.1.1.1 | 0xc7eb | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.874556065 CEST | 192.168.2.6 | 1.1.1.1 | 0x7579 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:56:52.874861002 CEST | 192.168.2.6 | 1.1.1.1 | 0x5ef1 | Standard query (0) | 65 | IN (0x0001) | false | |
Jul 30, 2024 00:58:07.593827009 CEST | 192.168.2.6 | 1.1.1.1 | 0x207 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:59:16.543349028 CEST | 192.168.2.6 | 1.1.1.1 | 0x754e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jul 30, 2024 00:59:19.864056110 CEST | 192.168.2.6 | 1.1.1.1 | 0x4fb8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jul 30, 2024 00:56:33.379079103 CEST | 1.1.1.1 | 192.168.2.6 | 0xa2e1 | No error (0) | titanium.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:33.379079103 CEST | 1.1.1.1 | 192.168.2.6 | 0xa2e1 | No error (0) | edge-term4.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:33.379079103 CEST | 1.1.1.1 | 192.168.2.6 | 0xa2e1 | No error (0) | edge-term4-ams2.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:33.379079103 CEST | 1.1.1.1 | 192.168.2.6 | 0xa2e1 | No error (0) | 128.116.21.3 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:34.146291971 CEST | 1.1.1.1 | 192.168.2.6 | 0x9a3c | No error (0) | titanium.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:34.146291971 CEST | 1.1.1.1 | 192.168.2.6 | 0x9a3c | No error (0) | edge-term4.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:34.146291971 CEST | 1.1.1.1 | 192.168.2.6 | 0x9a3c | No error (0) | edge-term4-ams2.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:34.146291971 CEST | 1.1.1.1 | 192.168.2.6 | 0x9a3c | No error (0) | 128.116.21.4 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:35.085570097 CEST | 1.1.1.1 | 192.168.2.6 | 0xb1a1 | No error (0) | clientsettingscdn.roblox.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:48.432893038 CEST | 1.1.1.1 | 192.168.2.6 | 0xd09 | No error (0) | 65 | IN (0x0001) | false | |||
Jul 30, 2024 00:56:48.434175014 CEST | 1.1.1.1 | 192.168.2.6 | 0x6fb3 | No error (0) | 104.21.79.229 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:48.434175014 CEST | 1.1.1.1 | 192.168.2.6 | 0x6fb3 | No error (0) | 172.67.149.76 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:49.724371910 CEST | 1.1.1.1 | 192.168.2.6 | 0x51fb | No error (0) | 172.67.132.113 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:49.724371910 CEST | 1.1.1.1 | 192.168.2.6 | 0x51fb | No error (0) | 104.21.4.208 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:49.724828005 CEST | 1.1.1.1 | 192.168.2.6 | 0x729b | No error (0) | 65 | IN (0x0001) | false | |||
Jul 30, 2024 00:56:49.748725891 CEST | 1.1.1.1 | 192.168.2.6 | 0x95bd | No error (0) | 88.212.201.204 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:49.748725891 CEST | 1.1.1.1 | 192.168.2.6 | 0x95bd | No error (0) | 88.212.201.198 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:49.748725891 CEST | 1.1.1.1 | 192.168.2.6 | 0x95bd | No error (0) | 88.212.202.52 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:50.388063908 CEST | 1.1.1.1 | 192.168.2.6 | 0xb3b0 | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.202953100 CEST | 1.1.1.1 | 192.168.2.6 | 0x6fe4 | No error (0) | 88.212.201.198 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.202953100 CEST | 1.1.1.1 | 192.168.2.6 | 0x6fe4 | No error (0) | 88.212.201.204 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.202953100 CEST | 1.1.1.1 | 192.168.2.6 | 0x6fe4 | No error (0) | 88.212.202.52 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.648118019 CEST | 1.1.1.1 | 192.168.2.6 | 0x361f | No error (0) | 142.250.186.100 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.648458958 CEST | 1.1.1.1 | 192.168.2.6 | 0xc7eb | No error (0) | 65 | IN (0x0001) | false | |||
Jul 30, 2024 00:56:52.893346071 CEST | 1.1.1.1 | 192.168.2.6 | 0x7579 | No error (0) | 172.67.132.113 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.893346071 CEST | 1.1.1.1 | 192.168.2.6 | 0x7579 | No error (0) | 104.21.4.208 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:56:52.895145893 CEST | 1.1.1.1 | 192.168.2.6 | 0x5ef1 | No error (0) | 65 | IN (0x0001) | false | |||
Jul 30, 2024 00:58:08.045675039 CEST | 1.1.1.1 | 192.168.2.6 | 0x207 | No error (0) | clientsettingscdn.roblox.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:16.561095953 CEST | 1.1.1.1 | 192.168.2.6 | 0x754e | No error (0) | d2v57ias1m20gl.cloudfront.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:16.561095953 CEST | 1.1.1.1 | 192.168.2.6 | 0x754e | No error (0) | 13.32.110.82 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:16.561095953 CEST | 1.1.1.1 | 192.168.2.6 | 0x754e | No error (0) | 13.32.110.9 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:16.561095953 CEST | 1.1.1.1 | 192.168.2.6 | 0x754e | No error (0) | 13.32.110.128 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:16.561095953 CEST | 1.1.1.1 | 192.168.2.6 | 0x754e | No error (0) | 13.32.110.101 | A (IP address) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:19.881989002 CEST | 1.1.1.1 | 192.168.2.6 | 0x4fb8 | No error (0) | titanium.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:19.881989002 CEST | 1.1.1.1 | 192.168.2.6 | 0x4fb8 | No error (0) | edge-term4.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:19.881989002 CEST | 1.1.1.1 | 192.168.2.6 | 0x4fb8 | No error (0) | edge-term4-ams2.roblox.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jul 30, 2024 00:59:19.881989002 CEST | 1.1.1.1 | 192.168.2.6 | 0x4fb8 | No error (0) | 128.116.21.4 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49719 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:36 UTC | 71 | OUT | |
2024-07-29 22:56:36 UTC | 249 | OUT | |
2024-07-29 22:56:36 UTC | 1064 | OUT | |
2024-07-29 22:56:36 UTC | 218 | OUT | |
2024-07-29 22:56:36 UTC | 14 | IN | |
2024-07-29 22:56:36 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.6 | 49720 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:44 UTC | 71 | OUT | |
2024-07-29 22:56:44 UTC | 249 | OUT | |
2024-07-29 22:56:44 UTC | 1064 | OUT | |
2024-07-29 22:56:44 UTC | 218 | OUT | |
2024-07-29 22:56:45 UTC | 14 | IN | |
2024-07-29 22:56:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49722 | 104.21.79.229 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:49 UTC | 655 | OUT | |
2024-07-29 22:56:49 UTC | 1086 | IN | |
2024-07-29 22:56:49 UTC | 283 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 1369 | IN | |
2024-07-29 22:56:49 UTC | 51 | IN | |
2024-07-29 22:56:49 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49730 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:50 UTC | 306 | OUT | |
2024-07-29 22:56:50 UTC | 560 | IN | |
2024-07-29 22:56:50 UTC | 15824 | IN | |
2024-07-29 22:56:50 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49732 | 172.67.132.113 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:50 UTC | 588 | OUT | |
2024-07-29 22:56:50 UTC | 1285 | IN | |
2024-07-29 22:56:50 UTC | 691 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN | |
2024-07-29 22:56:50 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49733 | 88.212.201.204 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:50 UTC | 666 | OUT | |
2024-07-29 22:56:50 UTC | 603 | IN | |
2024-07-29 22:56:50 UTC | 32 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49739 | 35.190.80.1 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:50 UTC | 535 | OUT | |
2024-07-29 22:56:51 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
7 | 192.168.2.6 | 49738 | 173.222.162.64 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:51 UTC | 2256 | OUT | |
2024-07-29 22:56:51 UTC | 1 | OUT | |
2024-07-29 22:56:51 UTC | 515 | OUT | |
2024-07-29 22:56:51 UTC | 480 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49741 | 35.190.80.1 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:51 UTC | 476 | OUT | |
2024-07-29 22:56:51 UTC | 424 | OUT | |
2024-07-29 22:56:51 UTC | 168 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49740 | 88.212.201.204 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:51 UTC | 707 | OUT | |
2024-07-29 22:56:52 UTC | 481 | IN | |
2024-07-29 22:56:52 UTC | 445 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.6 | 49744 | 172.67.132.113 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:52 UTC | 577 | OUT | |
2024-07-29 22:56:52 UTC | 763 | IN | |
2024-07-29 22:56:52 UTC | 606 | IN | |
2024-07-29 22:56:52 UTC | 1369 | IN | |
2024-07-29 22:56:52 UTC | 858 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.6 | 49745 | 88.212.201.198 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:53 UTC | 511 | OUT | |
2024-07-29 22:56:53 UTC | 459 | IN | |
2024-07-29 22:56:53 UTC | 445 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.6 | 49747 | 172.67.132.113 | 443 | 3136 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:53 UTC | 351 | OUT | |
2024-07-29 22:56:53 UTC | 757 | IN | |
2024-07-29 22:56:53 UTC | 612 | IN | |
2024-07-29 22:56:53 UTC | 1369 | IN | |
2024-07-29 22:56:53 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.6 | 49748 | 23.32.185.164 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:54 UTC | 161 | OUT | |
2024-07-29 22:56:54 UTC | 467 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.6 | 49749 | 23.32.185.164 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:55 UTC | 239 | OUT | |
2024-07-29 22:56:55 UTC | 535 | IN | |
2024-07-29 22:56:55 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
15 | 192.168.2.6 | 49750 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:56:57 UTC | 71 | OUT | |
2024-07-29 22:56:57 UTC | 249 | OUT | |
2024-07-29 22:56:57 UTC | 1064 | OUT | |
2024-07-29 22:56:57 UTC | 218 | OUT | |
2024-07-29 22:56:57 UTC | 14 | IN | |
2024-07-29 22:56:57 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
16 | 192.168.2.6 | 49751 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:57:17 UTC | 71 | OUT | |
2024-07-29 22:57:17 UTC | 249 | OUT | |
2024-07-29 22:57:17 UTC | 1064 | OUT | |
2024-07-29 22:57:17 UTC | 218 | OUT | |
2024-07-29 22:57:17 UTC | 14 | IN | |
2024-07-29 22:57:17 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.6 | 49753 | 20.12.23.50 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:57:27 UTC | 306 | OUT | |
2024-07-29 22:57:27 UTC | 560 | IN | |
2024-07-29 22:57:27 UTC | 15824 | IN | |
2024-07-29 22:57:27 UTC | 14181 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
18 | 192.168.2.6 | 49754 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:57:45 UTC | 71 | OUT | |
2024-07-29 22:57:45 UTC | 249 | OUT | |
2024-07-29 22:57:45 UTC | 1064 | OUT | |
2024-07-29 22:57:45 UTC | 218 | OUT | |
2024-07-29 22:57:45 UTC | 14 | IN | |
2024-07-29 22:57:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
19 | 192.168.2.6 | 58795 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:58:18 UTC | 71 | OUT | |
2024-07-29 22:58:18 UTC | 249 | OUT | |
2024-07-29 22:58:18 UTC | 1064 | OUT | |
2024-07-29 22:58:18 UTC | 218 | OUT | |
2024-07-29 22:58:18 UTC | 14 | IN | |
2024-07-29 22:58:18 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
20 | 192.168.2.6 | 58797 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-07-29 22:59:09 UTC | 71 | OUT | |
2024-07-29 22:59:09 UTC | 249 | OUT | |
2024-07-29 22:59:09 UTC | 1064 | OUT | |
2024-07-29 22:59:09 UTC | 218 | OUT | |
2024-07-29 22:59:10 UTC | 14 | IN | |
2024-07-29 22:59:10 UTC | 58 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 18:56:29 |
Start date: | 29/07/2024 |
Path: | C:\Users\user\Desktop\cheat_roblox.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff693e50000 |
File size: | 2'675'335 bytes |
MD5 hash: | D49B1A211CE49BED3E766471501819C6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 18:56:32 |
Start date: | 29/07/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e0370000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 18:56:32 |
Start date: | 29/07/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 18:56:32 |
Start date: | 29/07/2024 |
Path: | C:\Users\user\AppData\Local\Temp\RobloxPlayerInstaller.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xf40000 |
File size: | 5'720'984 bytes |
MD5 hash: | 27469372591B14FF1C57654FACB5E020 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 18:56:45 |
Start date: | 29/07/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e0370000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 18:56:45 |
Start date: | 29/07/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 18:56:46 |
Start date: | 29/07/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 18:56:47 |
Start date: | 29/07/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff684c40000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 11.7% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 27.6% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 26 |
Graph
Function 00007FF693E7B190 Relevance: 123.9, APIs: 60, Strings: 10, Instructions: 1421windowfilesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7CE88 Relevance: 65.0, APIs: 26, Strings: 10, Instructions: 1963fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E80754 Relevance: 45.9, APIs: 21, Strings: 5, Instructions: 380filesleeptimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6A4AC Relevance: 23.0, APIs: 11, Strings: 2, Instructions: 250COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E78624 Relevance: 19.4, APIs: 10, Strings: 1, Instructions: 101memorywindowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5F930 Relevance: 17.2, APIs: 8, Strings: 1, Instructions: 1417COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E54840 Relevance: 12.1, APIs: 5, Strings: 1, Instructions: 1624COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E55E24 Relevance: 7.6, APIs: 3, Strings: 1, Instructions: 586COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E71F20 Relevance: .3, Instructions: 337COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E73484 Relevance: .3, Instructions: 302COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E64928 Relevance: .1, Instructions: 136COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6DFD0 Relevance: 143.9, APIs: 16, Strings: 66, Instructions: 440libraryfileloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E698DC Relevance: 25.2, APIs: 3, Strings: 11, Instructions: 702COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E81900 Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 195libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7F4E0 Relevance: 17.8, APIs: 6, Strings: 4, Instructions: 285COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E624C0 Relevance: 9.2, APIs: 6, Instructions: 164filetimeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7B014 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 54windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E791E8 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 33COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6EAA4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 42threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7946C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 26comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8D90C Relevance: 3.0, APIs: 2, Instructions: 19threadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E81558 Relevance: 1.5, APIs: 1, Instructions: 38COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8FA04 Relevance: 1.5, APIs: 1, Instructions: 36memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8D94C Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E67FC4 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5C2F0 Relevance: 49.8, APIs: 24, Strings: 4, Instructions: 754fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6F180 Relevance: 43.2, APIs: 22, Strings: 2, Instructions: 1205COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E92550 Relevance: 22.3, APIs: 8, Strings: 4, Instructions: 1310COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E61A48 Relevance: 17.9, APIs: 9, Strings: 1, Instructions: 375fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E876D8 Relevance: 9.1, APIs: 6, Instructions: 83COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8FA94 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 164COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E92080 Relevance: 4.8, APIs: 3, Instructions: 340COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8FCA0 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 97COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E95AF8 Relevance: 3.2, APIs: 2, Instructions: 227COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E88C1C Relevance: 1.5, Strings: 1, Instructions: 219COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E889A0 Relevance: 1.4, Strings: 1, Instructions: 199COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E73964 Relevance: .9, Instructions: 931COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E576C0 Relevance: .9, Instructions: 893COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E753F0 Relevance: .9, Instructions: 891COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6BB90 Relevance: .6, Instructions: 587COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E74B98 Relevance: .6, Instructions: 578COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E57288 Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E72D58 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6AF18 Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5A310 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6B534 Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E721D0 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E72AB0 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E958E0 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E83354 Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5D7D0 Relevance: 26.3, APIs: 1, Strings: 14, Instructions: 98COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E82A10 Relevance: 21.1, APIs: 8, Strings: 4, Instructions: 61libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E66A0C Relevance: 16.2, APIs: 6, Strings: 3, Instructions: 444COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7A440 Relevance: 16.0, APIs: 7, Strings: 2, Instructions: 257COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8E650 Relevance: 15.9, APIs: 1, Strings: 8, Instructions: 117COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7F390 Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 85COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E76E80 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 204memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7AE90 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 94COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6B9B4 Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 84libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E787D8 Relevance: 12.7, APIs: 5, Strings: 2, Instructions: 415COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E857EC Relevance: 10.8, APIs: 3, Strings: 3, Instructions: 317COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E64F38 Relevance: 10.7, APIs: 1, Strings: 5, Instructions: 158COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E872EC Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 88libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E81604 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 43libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E67918 Relevance: 9.0, APIs: 1, Strings: 4, Instructions: 233COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E85CE8 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 191COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E84F80 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 144COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5CEE0 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 139COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E77B28 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 122COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7FD0C Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 76COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7FED4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 52COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8BFB0 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 29libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E63AF8 Relevance: 7.7, APIs: 5, Instructions: 164filetimeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8F414 Relevance: 7.6, APIs: 5, Instructions: 114libraryloaderCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E956D8 Relevance: 7.6, APIs: 5, Instructions: 56COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E7FE24 Relevance: 7.5, APIs: 5, Instructions: 29windowsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8625C Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 163COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E880F4 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 145COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E91758 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 126COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E866A0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 117COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E94360 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 100fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E790B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 83COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6E870 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 53COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E785E0 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 19COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8DB5C Relevance: 6.1, APIs: 4, Instructions: 104COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8D440 Relevance: 6.0, APIs: 4, Instructions: 43COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E5E34C Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 176COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8E1F4 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 138COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E69408 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 108COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8C2C0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 107COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E79B40 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 104COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E69638 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 84COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E8EB04 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 70COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E84078 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 42COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6EA5C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF693E6A43C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 15COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 21.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 2.1% |
Total number of Nodes: | 481 |
Total number of Limit Nodes: | 7 |
Graph
Callgraph
Function 0125D0F8 Relevance: .0, Instructions: 29COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125C9FF Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 74COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012444F4 Relevance: 4.5, APIs: 3, Instructions: 30threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125437B Relevance: 4.5, APIs: 3, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0124443F Relevance: 3.0, APIs: 2, Instructions: 38threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125A4B0 Relevance: 3.0, APIs: 2, Instructions: 22memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125A1C5 Relevance: 2.6, APIs: 2, Instructions: 125COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125B99B Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125A4EA Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01257A3B Relevance: 1.5, APIs: 1, Instructions: 20COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0125D13C Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012543AC Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012543CE Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|