Windows
Analysis Report
mtuXDnH1Di.exe
Overview
General Information
Sample name: | mtuXDnH1Di.exerenamed because original name is a hash value |
Original sample name: | 475c13ae1d446c61824315961e5838916ac4a3f28bc441aa8a2b39b81383ea4a.exe |
Analysis ID: | 1488113 |
MD5: | e4b47c06b5eed80fb44cfea757525634 |
SHA1: | 78b5133cd84e3d89ebca4b36f33273df6e70c3f4 |
SHA256: | 475c13ae1d446c61824315961e5838916ac4a3f28bc441aa8a2b39b81383ea4a |
Tags: | exe |
Infos: | |
Detection
Score: | 88 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- mtuXDnH1Di.exe (PID: 2064 cmdline:
"C:\Users\ user\Deskt op\mtuXDnH 1Di.exe" MD5: E4B47C06B5EED80FB44CFEA757525634) - qbf30bzbv7f7qnhdav.exe (PID: 5064 cmdline:
"C:\whfkpb h\qbf30bzb v7f7qnhdav .exe" MD5: E4B47C06B5EED80FB44CFEA757525634) - idtpqzltyfy.exe (PID: 7276 cmdline:
"C:\whfkpb h\idtpqzlt yfy.exe" MD5: E4B47C06B5EED80FB44CFEA757525634)
- idtpqzltyfy.exe (PID: 3452 cmdline:
C:\whfkpbh \idtpqzlty fy.exe MD5: E4B47C06B5EED80FB44CFEA757525634) - amdrhfskpcu.exe (PID: 7240 cmdline:
wudcwbel2z fb "c:\whf kpbh\idtpq zltyfy.exe " MD5: E4B47C06B5EED80FB44CFEA757525634) - idtpqzltyfy.exe (PID: 7912 cmdline:
"c:\whfkpb h\idtpqzlt yfy.exe" MD5: E4B47C06B5EED80FB44CFEA757525634) - amdrhfskpcu.exe (PID: 7944 cmdline:
wudcwbel2z fb "c:\whf kpbh\idtpq zltyfy.exe " MD5: E4B47C06B5EED80FB44CFEA757525634)
- svchost.exe (PID: 7208 cmdline:
C:\Windows \system32\ svchost.ex e -k Local Service -s W32Time MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- svchost.exe (PID: 7616 cmdline:
C:\Windows \System32\ svchost.ex e -k Local Service -p -s Licens eManager MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source: | Author: vburov: |
Timestamp: | 2024-08-05T16:24:59.509195+0200 |
SID: | 2018316 |
Source Port: | 53 |
Destination Port: | 60261 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:03.262802+0200 |
SID: | 2815568 |
Source Port: | 49701 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:00.468164+0200 |
SID: | 2815568 |
Source Port: | 49700 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:27.903814+0200 |
SID: | 2018316 |
Source Port: | 53 |
Destination Port: | 62372 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:24:18.320810+0200 |
SID: | 2815568 |
Source Port: | 59623 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:16.089201+0200 |
SID: | 2018316 |
Source Port: | 53 |
Destination Port: | 65063 |
Protocol: | UDP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:07.857815+0200 |
SID: | 2037771 |
Source Port: | 80 |
Destination Port: | 49702 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:07.848514+0200 |
SID: | 2815568 |
Source Port: | 49702 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:21.358671+0200 |
SID: | 2037771 |
Source Port: | 80 |
Destination Port: | 49715 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:13.975372+0200 |
SID: | 2815568 |
Source Port: | 49708 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:24:48.786301+0200 |
SID: | 2815568 |
Source Port: | 59624 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:23:03.286503+0200 |
SID: | 2037771 |
Source Port: | 80 |
Destination Port: | 49701 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 2024-08-05T16:24:48.791817+0200 |
SID: | 2037771 |
Source Port: | 80 |
Destination Port: | 59624 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 2_2_009E0920 | |
Source: | Code function: | 3_2_00150920 | |
Source: | Code function: | 11_2_00150920 |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00EE9580 | |
Source: | Code function: | 2_2_009F9580 | |
Source: | Code function: | 3_2_00169580 | |
Source: | Code function: | 5_2_00A59580 | |
Source: | Code function: | 6_2_00169580 | |
Source: | Code function: | 11_2_00169580 | |
Source: | Code function: | 12_2_00CF9580 |
Networking |
---|
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00EE0D80 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Code function: | 0_2_00EC7A04 | |
Source: | Code function: | 0_2_00ED5200 | |
Source: | Code function: | 0_2_00ED30F0 | |
Source: | Code function: | 0_2_00EDA0A6 | |
Source: | Code function: | 0_2_00EC1490 | |
Source: | Code function: | 0_2_00EE55E0 | |
Source: | Code function: | 0_2_00EDE1C0 | |
Source: | Code function: | 0_2_00EE0D80 | |
Source: | Code function: | 0_2_00EDF160 | |
Source: | Code function: | 0_2_00ECE550 | |
Source: | Code function: | 0_2_00EDA930 | |
Source: | Code function: | 0_2_00EF5930 | |
Source: | Code function: | 0_2_00EE66E7 | |
Source: | Code function: | 0_2_00EE4EA0 | |
Source: | Code function: | 0_2_00EE22A0 | |
Source: | Code function: | 0_2_00EF0A90 | |
Source: | Code function: | 0_2_00EE6A7B | |
Source: | Code function: | 0_2_00EF0220 | |
Source: | Code function: | 0_2_00ED97B0 | |
Source: | Code function: | 0_2_00ECD760 | |
Source: | Code function: | 0_2_00ECF330 | |
Source: | Code function: | 0_2_00EEE70B | |
Source: | Code function: | 0_2_00EE9B00 | |
Source: | Code function: | 2_2_009EA930 | |
Source: | Code function: | 2_2_009D7A04 | |
Source: | Code function: | 2_2_009E5200 | |
Source: | Code function: | 2_2_009F9B00 | |
Source: | Code function: | 2_2_009D1490 | |
Source: | Code function: | 2_2_009EA0A6 | |
Source: | Code function: | 2_2_009E30F0 | |
Source: | Code function: | 2_2_009F0D80 | |
Source: | Code function: | 2_2_009EE1C0 | |
Source: | Code function: | 2_2_009F55E0 | |
Source: | Code function: | 2_2_00A05930 | |
Source: | Code function: | 2_2_009DE550 | |
Source: | Code function: | 2_2_009EF160 | |
Source: | Code function: | 2_2_00A00A90 | |
Source: | Code function: | 2_2_009F4EA0 | |
Source: | Code function: | 2_2_009F22A0 | |
Source: | Code function: | 2_2_009F66E7 | |
Source: | Code function: | 2_2_00A00220 | |
Source: | Code function: | 2_2_009F6A7B | |
Source: | Code function: | 2_2_009E97B0 | |
Source: | Code function: | 2_2_009FE70B | |
Source: | Code function: | 2_2_009DF330 | |
Source: | Code function: | 2_2_009DD760 | |
Source: | Code function: | 3_2_0015A930 | |
Source: | Code function: | 3_2_00160D80 | |
Source: | Code function: | 3_2_00147A04 | |
Source: | Code function: | 3_2_00155200 | |
Source: | Code function: | 3_2_001622A0 | |
Source: | Code function: | 3_2_00169B00 | |
Source: | Code function: | 3_2_00141490 | |
Source: | Code function: | 3_2_0015A0A6 | |
Source: | Code function: | 3_2_001530F0 | |
Source: | Code function: | 3_2_00175930 | |
Source: | Code function: | 3_2_0014E550 | |
Source: | Code function: | 3_2_0015F160 | |
Source: | Code function: | 3_2_0015E1C0 | |
Source: | Code function: | 3_2_001655E0 | |
Source: | Code function: | 3_2_00170220 | |
Source: | Code function: | 3_2_00166A7B | |
Source: | Code function: | 3_2_00170A90 | |
Source: | Code function: | 3_2_00164EA0 | |
Source: | Code function: | 3_2_001666E7 | |
Source: | Code function: | 3_2_0016E70C | |
Source: | Code function: | 3_2_0014F330 | |
Source: | Code function: | 3_2_0014D760 | |
Source: | Code function: | 3_2_001597B0 | |
Source: | Code function: | 5_2_00A45200 | |
Source: | Code function: | 5_2_00A37A04 | |
Source: | Code function: | 5_2_00A4A0A6 | |
Source: | Code function: | 5_2_00A31490 | |
Source: | Code function: | 5_2_00A430F0 | |
Source: | Code function: | 5_2_00A50D80 | |
Source: | Code function: | 5_2_00A555E0 | |
Source: | Code function: | 5_2_00A4E1C0 | |
Source: | Code function: | 5_2_00A4A930 | |
Source: | Code function: | 5_2_00A65930 | |
Source: | Code function: | 5_2_00A4F160 | |
Source: | Code function: | 5_2_00A3E550 | |
Source: | Code function: | 5_2_00A54EA0 | |
Source: | Code function: | 5_2_00A522A0 | |
Source: | Code function: | 5_2_00A60A90 | |
Source: | Code function: | 5_2_00A566E7 | |
Source: | Code function: | 5_2_00A60220 | |
Source: | Code function: | 5_2_00A56A7B | |
Source: | Code function: | 5_2_00A497B0 | |
Source: | Code function: | 5_2_00A5E726 | |
Source: | Code function: | 5_2_00A3F330 | |
Source: | Code function: | 5_2_00A59B00 | |
Source: | Code function: | 5_2_00A3D760 | |
Source: | Code function: | 6_2_00147A04 | |
Source: | Code function: | 6_2_00155200 | |
Source: | Code function: | 6_2_00141490 | |
Source: | Code function: | 6_2_0015A0A6 | |
Source: | Code function: | 6_2_001530F0 | |
Source: | Code function: | 6_2_0015A930 | |
Source: | Code function: | 6_2_00175930 | |
Source: | Code function: | 6_2_0014E550 | |
Source: | Code function: | 6_2_0015F160 | |
Source: | Code function: | 6_2_00160D80 | |
Source: | Code function: | 6_2_0015E1C0 | |
Source: | Code function: | 6_2_001655E0 | |
Source: | Code function: | 6_2_00170220 | |
Source: | Code function: | 6_2_00166A7B | |
Source: | Code function: | 6_2_00170A90 | |
Source: | Code function: | 6_2_00164EA0 | |
Source: | Code function: | 6_2_001622A0 | |
Source: | Code function: | 6_2_001666E7 | |
Source: | Code function: | 6_2_00169B00 | |
Source: | Code function: | 6_2_0016E70C | |
Source: | Code function: | 6_2_0014F330 | |
Source: | Code function: | 6_2_0014D760 | |
Source: | Code function: | 6_2_001597B0 | |
Source: | Code function: | 11_2_0015A930 | |
Source: | Code function: | 11_2_00160D80 | |
Source: | Code function: | 11_2_00147A04 | |
Source: | Code function: | 11_2_00155200 | |
Source: | Code function: | 11_2_001622A0 | |
Source: | Code function: | 11_2_00169B00 | |
Source: | Code function: | 11_2_00141490 | |
Source: | Code function: | 11_2_0015A0A6 | |
Source: | Code function: | 11_2_001530F0 | |
Source: | Code function: | 11_2_00175930 | |
Source: | Code function: | 11_2_0014E550 | |
Source: | Code function: | 11_2_0015F160 | |
Source: | Code function: | 11_2_0015E1C0 | |
Source: | Code function: | 11_2_001655E0 | |
Source: | Code function: | 11_2_00170220 | |
Source: | Code function: | 11_2_00166A7B | |
Source: | Code function: | 11_2_00170A90 | |
Source: | Code function: | 11_2_00164EA0 | |
Source: | Code function: | 11_2_001666E7 | |
Source: | Code function: | 11_2_0016E70C | |
Source: | Code function: | 11_2_0014F330 | |
Source: | Code function: | 11_2_0014D760 | |
Source: | Code function: | 11_2_001597B0 | |
Source: | Code function: | 12_2_00CD7A04 | |
Source: | Code function: | 12_2_00CE5200 | |
Source: | Code function: | 12_2_00CE30F0 | |
Source: | Code function: | 12_2_00CD1490 | |
Source: | Code function: | 12_2_00CEA0A6 | |
Source: | Code function: | 12_2_00CEE1C0 | |
Source: | Code function: | 12_2_00CF55E0 | |
Source: | Code function: | 12_2_00CF0D80 | |
Source: | Code function: | 12_2_00CDE550 | |
Source: | Code function: | 12_2_00CEF160 | |
Source: | Code function: | 12_2_00D05930 | |
Source: | Code function: | 12_2_00CEA930 | |
Source: | Code function: | 12_2_00CF66E7 | |
Source: | Code function: | 12_2_00D00A90 | |
Source: | Code function: | 12_2_00CF4EA0 | |
Source: | Code function: | 12_2_00CF22A0 | |
Source: | Code function: | 12_2_00CF6A7B | |
Source: | Code function: | 12_2_00D00220 | |
Source: | Code function: | 12_2_00CE97B0 | |
Source: | Code function: | 12_2_00CDD760 | |
Source: | Code function: | 12_2_00CFE70C | |
Source: | Code function: | 12_2_00CF9B00 | |
Source: | Code function: | 12_2_00CDF330 |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00ED0500 | |
Source: | Code function: | 2_2_009E0500 | |
Source: | Code function: | 3_2_00150500 | |
Source: | Code function: | 5_2_00A40500 | |
Source: | Code function: | 6_2_00150500 | |
Source: | Code function: | 11_2_00150500 | |
Source: | Code function: | 12_2_00CE0500 |
Source: | Code function: | 0_2_00ED2120 |
Source: | Code function: | 0_2_00ED0500 |
Source: | Code function: | 0_2_00ECC660 | |
Source: | Code function: | 2_2_009DC660 | |
Source: | Code function: | 3_2_0014C660 | |
Source: | Code function: | 5_2_00A3C660 | |
Source: | Code function: | 6_2_0014C660 | |
Source: | Code function: | 11_2_0014C660 | |
Source: | Code function: | 12_2_00CDC660 |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 0_2_00EDA930 |
Source: | Code function: | 0_2_00EEE45F | |
Source: | Code function: | 0_2_00EECE70 | |
Source: | Code function: | 0_2_00EECE6B | |
Source: | Code function: | 2_2_009FE45F | |
Source: | Code function: | 2_2_009FCE70 | |
Source: | Code function: | 3_2_0016E45F | |
Source: | Code function: | 3_2_0016CE70 | |
Source: | Code function: | 3_2_0016CE6B | |
Source: | Code function: | 5_2_00A5E45F | |
Source: | Code function: | 5_2_00A5CE70 | |
Source: | Code function: | 5_2_00A5CE6B | |
Source: | Code function: | 6_2_0016E45F | |
Source: | Code function: | 6_2_0016CE70 | |
Source: | Code function: | 6_2_0016CE6B | |
Source: | Code function: | 11_2_0016E45F | |
Source: | Code function: | 11_2_0016CE70 | |
Source: | Code function: | 11_2_0016CE6B | |
Source: | Code function: | 12_2_00CFE45F | |
Source: | Code function: | 12_2_00CFCE70 | |
Source: | Code function: | 12_2_00CFCE6B |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Registry key value modified: | Jump to behavior |
Source: | Code function: | 0_2_00ED0500 |
Source: | Code function: | 0_2_00ECAF20 | |
Source: | Code function: | 2_2_009DAF20 | |
Source: | Code function: | 3_2_0014AF20 | |
Source: | Code function: | 5_2_00A3AF20 | |
Source: | Code function: | 6_2_0014AF20 | |
Source: | Code function: | 11_2_0014AF20 | |
Source: | Code function: | 12_2_00CDAF20 |
Source: | Code function: | 2_2_009EA930 | |
Source: | Code function: | 3_2_0015A930 | |
Source: | Code function: | 11_2_0015A930 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Decision node followed by non-executed suspicious API: | graph_2-11326 | ||
Source: | Decision node followed by non-executed suspicious API: | graph_0-11289 | ||
Source: | Decision node followed by non-executed suspicious API: | graph_5-11374 | ||
Source: | Decision node followed by non-executed suspicious API: | graph_3-11264 |
Source: | Evasive API call chain: | graph_0-9791 | ||
Source: | Evasive API call chain: | graph_2-10024 | ||
Source: | Evasive API call chain: | graph_3-10273 | ||
Source: | Evasive API call chain: | graph_5-9834 |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 0_2_00EE9580 | |
Source: | Code function: | 2_2_009F9580 | |
Source: | Code function: | 3_2_00169580 | |
Source: | Code function: | 5_2_00A59580 | |
Source: | Code function: | 6_2_00169580 | |
Source: | Code function: | 11_2_00169580 | |
Source: | Code function: | 12_2_00CF9580 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-9573 | ||
Source: | API call chain: | graph_0-9567 | ||
Source: | API call chain: | graph_0-9585 | ||
Source: | API call chain: | graph_0-9528 | ||
Source: | API call chain: | graph_0-9931 | ||
Source: | API call chain: | graph_0-10308 | ||
Source: | API call chain: | graph_0-9514 | ||
Source: | API call chain: | graph_2-9636 | ||
Source: | API call chain: | graph_2-9619 | ||
Source: | API call chain: | graph_2-9601 | ||
Source: | API call chain: | graph_2-9652 | ||
Source: | API call chain: | graph_3-9574 | ||
Source: | API call chain: | graph_3-9550 | ||
Source: | API call chain: | graph_3-9563 | ||
Source: | API call chain: | graph_3-9495 | ||
Source: | API call chain: | graph_3-9509 | ||
Source: | API call chain: | graph_3-9534 | ||
Source: | API call chain: | graph_3-9483 | ||
Source: | API call chain: | graph_5-9623 | ||
Source: | API call chain: | graph_5-9994 | ||
Source: | API call chain: | graph_5-9650 | ||
Source: | API call chain: | graph_5-9587 | ||
Source: | API call chain: | graph_5-9574 | ||
Source: | API call chain: | graph_5-9435 | ||
Source: | API call chain: | graph_5-9606 | ||
Source: | API call chain: | graph_6-9593 | ||
Source: | API call chain: | graph_6-9951 | ||
Source: | API call chain: | graph_6-9583 | ||
Source: | API call chain: | graph_6-9609 | ||
Source: | API call chain: | graph_6-9548 | ||
Source: | API call chain: | graph_6-9565 | ||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00EDA930 |
Source: | Code function: | 0_2_00ECE2C0 |
Source: | Code function: | 0_2_00ECB7A0 |
Source: | Code function: | 0_2_00EF50E0 |
Source: | Code function: | 0_2_00ED5200 |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Service Execution | 14 Windows Service | 14 Windows Service | 1 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 2 Native API | 1 DLL Side-Loading | 1 Process Injection | 11 Virtualization/Sandbox Evasion | LSASS Memory | 111 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 Process Injection | Security Account Manager | 11 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 2 Obfuscated Files or Information | NTDS | 2 Process Discovery | Distributed Component Object Model | Input Capture | 3 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Software Packing | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 1 System Service Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 File Deletion | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 1 File and Directory Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 4 System Information Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
92% | ReversingLabs | Win32.Spyware.Nivdort | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
92% | ReversingLabs | Win32.Spyware.Nivdort | ||
92% | ReversingLabs | Win32.Spyware.Nivdort | ||
92% | ReversingLabs | Win32.Spyware.Nivdort |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
crowdtrust.net | 170.187.200.48 | true | false | unknown | |
watersystem.net | 64.190.63.222 | true | false | unknown | |
thoughtsystem.net | 213.171.195.105 | true | false | unknown | |
membersystem.net | 85.13.130.3 | true | false | unknown | |
partygeneral.net | 3.33.130.190 | true | false | unknown | |
womanbelieve.net | 15.197.142.173 | true | false | unknown | |
womanhonor.net | 54.244.188.177 | true | false | unknown | |
membertrust.net | 3.33.130.190 | true | false | unknown | |
memberreceive.net | 35.164.78.200 | true | false | unknown | |
followfriend.net | 188.225.40.227 | true | false | unknown | |
partybelieve.net | 15.197.192.55 | true | false | unknown | |
freshfancy.net | 81.169.145.88 | true | false | unknown | |
alreadyfriend.net | 15.197.192.55 | true | false | unknown | |
thoughtbranch.net | 34.246.200.160 | true | false | unknown | |
beginhonor.net | unknown | unknown | true | unknown | |
memberlaughter.net | unknown | unknown | true | unknown | |
freshneither.net | unknown | unknown | true | unknown | |
thoughtneither.net | unknown | unknown | true | unknown | |
experiencefancy.net | unknown | unknown | true | unknown | |
followconsider.net | unknown | unknown | true | unknown | |
alreadyhonor.net | unknown | unknown | true | unknown | |
fighttrust.net | unknown | unknown | true | unknown | |
knownsystem.net | unknown | unknown | true | unknown | |
gentlemanhonor.net | unknown | unknown | true | unknown | |
memberfriend.net | unknown | unknown | true | unknown | |
freshtrust.net | unknown | unknown | true | unknown | |
experiencetrust.net | unknown | unknown | true | unknown | |
alreadybelieve.net | unknown | unknown | true | unknown | |
partyclear.net | unknown | unknown | true | unknown | |
waterquarter.net | unknown | unknown | true | unknown | |
fightbranch.net | unknown | unknown | true | unknown | |
knownlaughter.net | unknown | unknown | true | unknown | |
followtrust.net | unknown | unknown | true | unknown | |
experiencebelieve.net | unknown | unknown | true | unknown | |
summerhonor.net | unknown | unknown | true | unknown | |
thoughttrust.net | unknown | unknown | true | unknown | |
freshhonor.net | unknown | unknown | true | unknown | |
followfancy.net | unknown | unknown | true | unknown | |
freshfriend.net | unknown | unknown | true | unknown | |
freshconsider.net | unknown | unknown | true | unknown | |
summerquarter.net | unknown | unknown | true | unknown | |
gentlemantrust.net | unknown | unknown | true | unknown | |
fightinclude.net | unknown | unknown | true | unknown | |
gentlemanlaughter.net | unknown | unknown | true | unknown | |
memberbelieve.net | unknown | unknown | true | unknown | |
alreadylaughter.net | unknown | unknown | true | unknown | |
summerreceive.net | unknown | unknown | true | unknown | |
smokequarter.net | unknown | unknown | true | unknown | |
experiencesystem.net | unknown | unknown | true | unknown | |
thoughthonor.net | unknown | unknown | true | unknown | |
followbelieve.net | unknown | unknown | true | unknown | |
knowntrust.net | unknown | unknown | true | unknown | |
partybranch.net | unknown | unknown | true | unknown | |
crowdneither.net | unknown | unknown | true | unknown | |
womaninclude.net | unknown | unknown | true | unknown | |
smokebelieve.net | unknown | unknown | true | unknown | |
fightnorth.net | unknown | unknown | true | unknown | |
gentlemanneither.net | unknown | unknown | true | unknown | |
followquarter.net | unknown | unknown | true | unknown | |
knownhonor.net | unknown | unknown | true | unknown | |
womantrust.net | unknown | unknown | true | unknown | |
memberquarter.net | unknown | unknown | true | unknown | |
experiencefriend.net | unknown | unknown | true | unknown | |
waterbranch.net | unknown | unknown | true | unknown | |
smoketrust.net | unknown | unknown | true | unknown | |
gentlemanreceive.net | unknown | unknown | true | unknown | |
fightsystem.net | unknown | unknown | true | unknown | |
memberfancy.net | unknown | unknown | true | unknown | |
crowdhonor.net | unknown | unknown | true | unknown | |
summerbelieve.net | unknown | unknown | true | unknown | |
womanbranch.net | unknown | unknown | true | unknown | |
crowdbranch.net | unknown | unknown | true | unknown | |
beginbranch.net | unknown | unknown | true | unknown | |
experiencehonor.net | unknown | unknown | true | unknown | |
waterreceive.net | unknown | unknown | true | unknown | |
gentlemansystem.net | unknown | unknown | true | unknown | |
crowdsystem.net | unknown | unknown | true | unknown | |
knownbelieve.net | unknown | unknown | true | unknown | |
knownquarter.net | unknown | unknown | true | unknown | |
beginsystem.net | unknown | unknown | true | unknown | |
followsystem.net | unknown | unknown | true | unknown | |
crowdreceive.net | unknown | unknown | true | unknown | |
alreadyquarter.net | unknown | unknown | true | unknown | |
beginquarter.net | unknown | unknown | true | unknown | |
freshbelieve.net | unknown | unknown | true | unknown | |
alreadyconsider.net | unknown | unknown | true | unknown | |
alreadytrust.net | unknown | unknown | true | unknown | |
freshquarter.net | unknown | unknown | true | unknown | |
gentlemanfriend.net | unknown | unknown | true | unknown | |
beginbelieve.net | unknown | unknown | true | unknown | |
memberhonor.net | unknown | unknown | true | unknown | |
summersystem.net | unknown | unknown | true | unknown | |
partyquarter.net | unknown | unknown | true | unknown | |
alreadyfancy.net | unknown | unknown | true | unknown | |
fightneither.net | unknown | unknown | true | unknown | |
alreadybranch.net | unknown | unknown | true | unknown | |
partynorth.net | unknown | unknown | true | unknown | |
womangeneral.net | unknown | unknown | true | unknown | |
thoughtreceive.net | unknown | unknown | true | unknown | |
smokegeneral.net | unknown | unknown | true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
188.225.40.227 | followfriend.net | Russian Federation | 9123 | TIMEWEB-ASRU | false | |
34.246.200.160 | thoughtbranch.net | United States | 16509 | AMAZON-02US | false | |
35.164.78.200 | memberreceive.net | United States | 16509 | AMAZON-02US | false | |
15.197.142.173 | womanbelieve.net | United States | 7430 | TANDEMUS | false | |
64.190.63.222 | watersystem.net | United States | 11696 | NBS11696US | false | |
85.13.130.3 | membersystem.net | Germany | 34788 | NMM-ASD-02742FriedersdorfHauptstrasse68DE | false | |
170.187.200.48 | crowdtrust.net | United States | 7018 | ATT-INTERNET4US | false | |
54.244.188.177 | womanhonor.net | United States | 16509 | AMAZON-02US | false | |
15.197.192.55 | partybelieve.net | United States | 7430 | TANDEMUS | false | |
3.33.130.190 | partygeneral.net | United States | 8987 | AMAZONEXPANSIONGB | false | |
213.171.195.105 | thoughtsystem.net | United Kingdom | 8560 | ONEANDONE-ASBrauerstrasse48DE | false | |
81.169.145.88 | freshfancy.net | Germany | 6724 | STRATOSTRATOAGDE | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1488113 |
Start date and time: | 2024-08-05 16:21:56 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | mtuXDnH1Di.exerenamed because original name is a hash value |
Original Sample Name: | 475c13ae1d446c61824315961e5838916ac4a3f28bc441aa8a2b39b81383ea4a.exe |
Detection: | MAL |
Classification: | mal88.troj.winEXE@14/5@215/12 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 40.119.148.38
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, twc.trafficmanager.net, ctldl.windowsupdate.com, d.3.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.8.0.4.0.0.3.0.1.3.0.6.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
- VT rate limit hit for: mtuXDnH1Di.exe
Time | Type | Description |
---|---|---|
11:45:33 | API Interceptor | |
11:46:18 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
188.225.40.227 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
34.246.200.160 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
35.164.78.200 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
membertrust.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
watersystem.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
memberreceive.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
partybelieve.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
crowdtrust.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
thoughtsystem.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
womanbelieve.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
womanhonor.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
partygeneral.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
membersystem.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | ZTrat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TIMEWEB-ASRU | Get hash | malicious | DCRat | Browse |
| |
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Emotet | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | ZTrat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TANDEMUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Process: | C:\Users\user\Desktop\mtuXDnH1Di.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7 |
Entropy (8bit): | 2.5216406363433186 |
Encrypted: | false |
SSDEEP: | 3:zon:8 |
MD5: | 68678699ABEA681A3BEF7BC9C04AA0DB |
SHA1: | 645AEBCE823CBFA211ECD2FA4878A586CC4ABE8E |
SHA-256: | 10F46E566F4A87C8973338326C4C0E497E0920983CCFE6BA82F734B5A00C3C64 |
SHA-512: | 7D197C701C93120144A167E7AF27009583D56D80DF9861DE0897C4E16A45AE12B94457EA048D4D4C3978E6EF32EED3B49185356B201E282B955C8FD80713ED94 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\whfkpbh\idtpqzltyfy.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 279552 |
Entropy (8bit): | 7.1352696053252345 |
Encrypted: | false |
SSDEEP: | 6144:TLg1drHvFTdNWJDRm03jJGxoyApQU/waqElD:Te5RTWr/TJpZ/h |
MD5: | E4B47C06B5EED80FB44CFEA757525634 |
SHA1: | 78B5133CD84E3D89EBCA4B36F33273DF6E70C3F4 |
SHA-256: | 475C13AE1D446C61824315961E5838916AC4A3F28BC441AA8A2B39B81383EA4A |
SHA-512: | BEF0195A513A28E7C9868BCA359A4F1726C9F8D15204B743C0E2467E6F6C68A67994E737C82997FEF0C2BB9DCFC206100A0A52E756D286FBAF1E56D2E04E7843 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\mtuXDnH1Di.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7 |
Entropy (8bit): | 2.5216406363433186 |
Encrypted: | false |
SSDEEP: | 3:zon:8 |
MD5: | 68678699ABEA681A3BEF7BC9C04AA0DB |
SHA1: | 645AEBCE823CBFA211ECD2FA4878A586CC4ABE8E |
SHA-256: | 10F46E566F4A87C8973338326C4C0E497E0920983CCFE6BA82F734B5A00C3C64 |
SHA-512: | 7D197C701C93120144A167E7AF27009583D56D80DF9861DE0897C4E16A45AE12B94457EA048D4D4C3978E6EF32EED3B49185356B201E282B955C8FD80713ED94 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\whfkpbh\qbf30bzbv7f7qnhdav.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 279552 |
Entropy (8bit): | 7.1352696053252345 |
Encrypted: | false |
SSDEEP: | 6144:TLg1drHvFTdNWJDRm03jJGxoyApQU/waqElD:Te5RTWr/TJpZ/h |
MD5: | E4B47C06B5EED80FB44CFEA757525634 |
SHA1: | 78B5133CD84E3D89EBCA4B36F33273DF6E70C3F4 |
SHA-256: | 475C13AE1D446C61824315961E5838916AC4A3F28BC441AA8A2B39B81383EA4A |
SHA-512: | BEF0195A513A28E7C9868BCA359A4F1726C9F8D15204B743C0E2467E6F6C68A67994E737C82997FEF0C2BB9DCFC206100A0A52E756D286FBAF1E56D2E04E7843 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\mtuXDnH1Di.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 279552 |
Entropy (8bit): | 7.1352696053252345 |
Encrypted: | false |
SSDEEP: | 6144:TLg1drHvFTdNWJDRm03jJGxoyApQU/waqElD:Te5RTWr/TJpZ/h |
MD5: | E4B47C06B5EED80FB44CFEA757525634 |
SHA1: | 78B5133CD84E3D89EBCA4B36F33273DF6E70C3F4 |
SHA-256: | 475C13AE1D446C61824315961E5838916AC4A3F28BC441AA8A2B39B81383EA4A |
SHA-512: | BEF0195A513A28E7C9868BCA359A4F1726C9F8D15204B743C0E2467E6F6C68A67994E737C82997FEF0C2BB9DCFC206100A0A52E756D286FBAF1E56D2E04E7843 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.1352696053252345 |
TrID: |
|
File name: | mtuXDnH1Di.exe |
File size: | 279'552 bytes |
MD5: | e4b47c06b5eed80fb44cfea757525634 |
SHA1: | 78b5133cd84e3d89ebca4b36f33273df6e70c3f4 |
SHA256: | 475c13ae1d446c61824315961e5838916ac4a3f28bc441aa8a2b39b81383ea4a |
SHA512: | bef0195a513a28e7c9868bca359a4f1726c9f8d15204b743c0e2467e6f6c68a67994e737c82997fef0c2bb9dcfc206100a0a52e756d286fbaf1e56d2e04e7843 |
SSDEEP: | 6144:TLg1drHvFTdNWJDRm03jJGxoyApQU/waqElD:Te5RTWr/TJpZ/h |
TLSH: | 98549D44CD39512ACC968EFE4ABB37B2F45E587567E915C3438431C424602F8FABA78B |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........2f..S...S...S....s..S...S...S.......S.......S.......S..Rich.S..........................PE..L....0.V.................R......... |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x424590 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x568930F7 [Sun Jan 3 14:32:23 2016 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 6f0f6728fed938390cd1a7b493280d77 |
Instruction |
---|
mov eax, dword ptr [0043F75Ch] |
sar eax, 07h |
sub eax, 0E724248h |
and eax, 638AD6B6h |
cmp eax, D4FE12C8h |
je 00007FBADCDE5E96h |
movzx ecx, word ptr [00473A94h] |
or ecx, 9A29B7C6h |
mov word ptr [00473A94h], cx |
call 00007FBADCDE1ED3h |
mov edx, dword ptr [0043F5C4h] |
not edx |
sub edx, 2D98DF04h |
xor edx, 86D84936h |
cmp edx, D7ABF1EFh |
je 00007FBADCDE5E8Ch |
add dword ptr [0044A8A4h], 24D523FCh |
push esi |
call 00007FBADCDF1677h |
mov eax, dword ptr [00445EB0h] |
sub eax, 13C02B78h |
push 00437190h |
mov dword ptr [00447688h], eax |
inc dword ptr [00445EB0h] |
push 00437188h |
call 00007FBADCDDAC83h |
fld dword ptr [0047ACD4h] |
fadd qword ptr [0045F648h] |
add esp, 08h |
fld qword ptr [0044FAB0h] |
fld qword ptr [00459DF0h] |
fsubp st(2), st(0) |
fsubrp st(1), st(0) |
fstp qword ptr [0044FAB0h] |
call 00007FBADCDF2EA9h |
fld dword ptr [0047D39Ch] |
mov esi, eax |
fmul dword ptr [00486544h] |
fld dword ptr [0047A424h] |
fcomip st(0), st(1) |
fstp st(0) |
jbe 00007FBADCDE5E99h |
dec dword ptr [00000000h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3b0e0 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x8b000 | 0x9ca4 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x37000 | 0x188 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x351ea | 0x35200 | b8a604ad7d1ad7d6f5659a8bfca32505 | False | 0.6966911764705882 | data | 6.86562473291782 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x37000 | 0x4928 | 0x4a00 | 9fa4f015e03b624e77fc713f54352d1c | False | 0.8504539695945946 | COM executable for DOS | 7.1602946748436205 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3c000 | 0x4ef2c | 0x200 | 07b5472d347d42780469fb2654b7fc54 | False | 0.02734375 | data | 0.020393135236084953 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x8b000 | 0xa012 | 0xa200 | a9d11539c5aa2bd739792d7ebff48b74 | False | 0.6754195601851852 | data | 6.7897361685185675 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
GDI32.dll | SetTextCharacterExtra, SetSystemPaletteUse, GetTextCharsetInfo, GetTextCharset, GetMapMode, GetTextColor, SetTextJustification, GetCurrentObject, GetMetaRgn, GetClipRgn, GetFontUnicodeRanges, GetTextCharacterExtra, GetSystemPaletteUse, GetFontLanguageInfo, GetStretchBltMode, GetPolyFillMode, GetObjectType, GetRandomRgn, SetTextAlign, GetNearestPaletteIndex, GetTextAlign, GetPixelFormat, GetDCBrushColor, GetBkColor, GetNearestColor, SetPixel |
USER32.dll | EndPaint, GetCursor, GetDlgItem, GetMenuItemCount, SetWindowTextA, GetPropA, SendMessageA, MoveWindow, GetWindowDC, SetFocus, IsWindowUnicode, WindowFromDC, GetDC, LoadIconA, GetQueueStatus, EnableWindow, GetKeyboardType, EndDialog, GetDlgItemInt, GetInputState, CallWindowProcA, GetMenu, PostMessageA, GetMenuItemID, IsWindowEnabled, SetDlgItemTextA, GetWindowContextHelpId, CheckDlgButton, GetScrollPos, DrawTextA, GetForegroundWindow, RemovePropA, GetMenuState, BeginPaint, GetWindowLongA, ShowWindow, GetMenuContextHelpId |
KERNEL32.dll | HeapAlloc, GetStdHandle, GlobalAlloc, GetModuleHandleA, GetCurrentThreadId, GetTickCount, GetLastError, GlobalSize, IsDebuggerPresent, GlobalFlags, MoveFileA, GlobalHandle, SizeofResource, IsProcessorFeaturePresent, LocalFlags, GetProcAddress, GetDriveTypeA, GetCurrentProcessId, GetFileTime, GetCurrentProcess, FlushFileBuffers, SetFilePointer, WriteFile, LockResource, GetFileType, CloseHandle, GetVersion, QueryPerformanceCounter, LoadResource, FindResourceA, DeleteFileA, GetProcessHeap |
Timestamp | Protocol | SID | Signature | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
2024-08-05T16:24:59.509195+0200 | UDP | 2018316 | ET MALWARE Possible Zeus GameOver/FluBot Related DGA NXDOMAIN Responses | 53 | 60261 | 1.1.1.1 | 192.168.2.7 |
2024-08-05T16:23:03.262802+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
2024-08-05T16:23:00.468164+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
2024-08-05T16:23:27.903814+0200 | UDP | 2018316 | ET MALWARE Possible Zeus GameOver/FluBot Related DGA NXDOMAIN Responses | 53 | 62372 | 1.1.1.1 | 192.168.2.7 |
2024-08-05T16:24:18.320810+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
2024-08-05T16:23:16.089201+0200 | UDP | 2018316 | ET MALWARE Possible Zeus GameOver/FluBot Related DGA NXDOMAIN Responses | 53 | 65063 | 1.1.1.1 | 192.168.2.7 |
2024-08-05T16:23:07.857815+0200 | TCP | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
2024-08-05T16:23:07.848514+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
2024-08-05T16:23:21.358671+0200 | TCP | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
2024-08-05T16:23:13.975372+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
2024-08-05T16:24:48.786301+0200 | TCP | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
2024-08-05T16:23:03.286503+0200 | TCP | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
2024-08-05T16:24:48.791817+0200 | TCP | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 5, 2024 16:23:00.003330946 CEST | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:00.011713982 CEST | 80 | 49700 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:00.011903048 CEST | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:00.012031078 CEST | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:00.017030001 CEST | 80 | 49700 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:00.467889071 CEST | 80 | 49700 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:00.468163967 CEST | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:00.468492985 CEST | 80 | 49700 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:00.468573093 CEST | 49700 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:00.474752903 CEST | 80 | 49700 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:02.490242004 CEST | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:23:02.497309923 CEST | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:23:02.497425079 CEST | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:23:02.497464895 CEST | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:23:02.502305984 CEST | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:23:03.262451887 CEST | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:23:03.262646914 CEST | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:23:03.262801886 CEST | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:23:03.281527042 CEST | 49701 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:23:03.286503077 CEST | 80 | 49701 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:23:07.082170963 CEST | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
Aug 5, 2024 16:23:07.088511944 CEST | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
Aug 5, 2024 16:23:07.088696003 CEST | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
Aug 5, 2024 16:23:07.088696003 CEST | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
Aug 5, 2024 16:23:07.095143080 CEST | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
Aug 5, 2024 16:23:07.847978115 CEST | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
Aug 5, 2024 16:23:07.848292112 CEST | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
Aug 5, 2024 16:23:07.848514080 CEST | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
Aug 5, 2024 16:23:07.848514080 CEST | 49702 | 80 | 192.168.2.7 | 34.246.200.160 |
Aug 5, 2024 16:23:07.857815027 CEST | 80 | 49702 | 34.246.200.160 | 192.168.2.7 |
Aug 5, 2024 16:23:08.690298080 CEST | 49703 | 80 | 192.168.2.7 | 15.197.142.173 |
Aug 5, 2024 16:23:08.695185900 CEST | 80 | 49703 | 15.197.142.173 | 192.168.2.7 |
Aug 5, 2024 16:23:08.695266008 CEST | 49703 | 80 | 192.168.2.7 | 15.197.142.173 |
Aug 5, 2024 16:23:08.695300102 CEST | 49703 | 80 | 192.168.2.7 | 15.197.142.173 |
Aug 5, 2024 16:23:08.700143099 CEST | 80 | 49703 | 15.197.142.173 | 192.168.2.7 |
Aug 5, 2024 16:23:09.183926105 CEST | 80 | 49703 | 15.197.142.173 | 192.168.2.7 |
Aug 5, 2024 16:23:09.184087992 CEST | 49703 | 80 | 192.168.2.7 | 15.197.142.173 |
Aug 5, 2024 16:23:09.185036898 CEST | 80 | 49703 | 15.197.142.173 | 192.168.2.7 |
Aug 5, 2024 16:23:09.185087919 CEST | 49703 | 80 | 192.168.2.7 | 15.197.142.173 |
Aug 5, 2024 16:23:09.189647913 CEST | 80 | 49703 | 15.197.142.173 | 192.168.2.7 |
Aug 5, 2024 16:23:09.592803001 CEST | 49704 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:09.597723007 CEST | 80 | 49704 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:09.597918987 CEST | 49704 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:09.598023891 CEST | 49704 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:09.602919102 CEST | 80 | 49704 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:10.119362116 CEST | 80 | 49704 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:10.119513988 CEST | 80 | 49704 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:10.119585991 CEST | 49704 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:10.120306969 CEST | 49704 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:10.124830008 CEST | 80 | 49704 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:13.313822985 CEST | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
Aug 5, 2024 16:23:13.324901104 CEST | 80 | 49708 | 85.13.130.3 | 192.168.2.7 |
Aug 5, 2024 16:23:13.325017929 CEST | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
Aug 5, 2024 16:23:13.325212002 CEST | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
Aug 5, 2024 16:23:13.330817938 CEST | 80 | 49708 | 85.13.130.3 | 192.168.2.7 |
Aug 5, 2024 16:23:13.975238085 CEST | 80 | 49708 | 85.13.130.3 | 192.168.2.7 |
Aug 5, 2024 16:23:13.975256920 CEST | 80 | 49708 | 85.13.130.3 | 192.168.2.7 |
Aug 5, 2024 16:23:13.975372076 CEST | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
Aug 5, 2024 16:23:13.977924109 CEST | 49708 | 80 | 192.168.2.7 | 85.13.130.3 |
Aug 5, 2024 16:23:13.984775066 CEST | 80 | 49708 | 85.13.130.3 | 192.168.2.7 |
Aug 5, 2024 16:23:14.254503965 CEST | 49709 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:14.259618998 CEST | 80 | 49709 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:14.259712934 CEST | 49709 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:14.259835958 CEST | 49709 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:14.264890909 CEST | 80 | 49709 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:14.771369934 CEST | 80 | 49709 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:14.772214890 CEST | 80 | 49709 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:14.774360895 CEST | 49709 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:14.776906967 CEST | 49709 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:23:14.783245087 CEST | 80 | 49709 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:23:16.594660997 CEST | 49712 | 80 | 192.168.2.7 | 170.187.200.48 |
Aug 5, 2024 16:23:16.599700928 CEST | 80 | 49712 | 170.187.200.48 | 192.168.2.7 |
Aug 5, 2024 16:23:16.599788904 CEST | 49712 | 80 | 192.168.2.7 | 170.187.200.48 |
Aug 5, 2024 16:23:16.599848986 CEST | 49712 | 80 | 192.168.2.7 | 170.187.200.48 |
Aug 5, 2024 16:23:16.604943991 CEST | 80 | 49712 | 170.187.200.48 | 192.168.2.7 |
Aug 5, 2024 16:23:17.110980034 CEST | 80 | 49712 | 170.187.200.48 | 192.168.2.7 |
Aug 5, 2024 16:23:17.111160040 CEST | 80 | 49712 | 170.187.200.48 | 192.168.2.7 |
Aug 5, 2024 16:23:17.111236095 CEST | 49712 | 80 | 192.168.2.7 | 170.187.200.48 |
Aug 5, 2024 16:23:17.111284018 CEST | 49712 | 80 | 192.168.2.7 | 170.187.200.48 |
Aug 5, 2024 16:23:17.116209984 CEST | 80 | 49712 | 170.187.200.48 | 192.168.2.7 |
Aug 5, 2024 16:23:17.750214100 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:17.755048990 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:17.755119085 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:17.755304098 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:17.760118961 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628709078 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628727913 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628766060 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628777981 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628788948 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.628818035 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:18.628858089 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:18.629002094 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:18.631206989 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.631252050 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:18.633377075 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.633435965 CEST | 49713 | 80 | 192.168.2.7 | 213.171.195.105 |
Aug 5, 2024 16:23:18.634927034 CEST | 80 | 49713 | 213.171.195.105 | 192.168.2.7 |
Aug 5, 2024 16:23:18.665146112 CEST | 49714 | 80 | 192.168.2.7 | 64.190.63.222 |
Aug 5, 2024 16:23:18.674597979 CEST | 80 | 49714 | 64.190.63.222 | 192.168.2.7 |
Aug 5, 2024 16:23:18.674680948 CEST | 49714 | 80 | 192.168.2.7 | 64.190.63.222 |
Aug 5, 2024 16:23:18.674741983 CEST | 49714 | 80 | 192.168.2.7 | 64.190.63.222 |
Aug 5, 2024 16:23:18.681945086 CEST | 80 | 49714 | 64.190.63.222 | 192.168.2.7 |
Aug 5, 2024 16:23:19.359216928 CEST | 80 | 49714 | 64.190.63.222 | 192.168.2.7 |
Aug 5, 2024 16:23:19.359422922 CEST | 80 | 49714 | 64.190.63.222 | 192.168.2.7 |
Aug 5, 2024 16:23:19.359484911 CEST | 49714 | 80 | 192.168.2.7 | 64.190.63.222 |
Aug 5, 2024 16:23:19.359519005 CEST | 49714 | 80 | 192.168.2.7 | 64.190.63.222 |
Aug 5, 2024 16:23:19.364831924 CEST | 80 | 49714 | 64.190.63.222 | 192.168.2.7 |
Aug 5, 2024 16:23:20.533049107 CEST | 49715 | 80 | 192.168.2.7 | 54.244.188.177 |
Aug 5, 2024 16:23:20.542155027 CEST | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
Aug 5, 2024 16:23:20.542252064 CEST | 49715 | 80 | 192.168.2.7 | 54.244.188.177 |
Aug 5, 2024 16:23:20.542334080 CEST | 49715 | 80 | 192.168.2.7 | 54.244.188.177 |
Aug 5, 2024 16:23:20.549489975 CEST | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
Aug 5, 2024 16:23:21.353359938 CEST | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
Aug 5, 2024 16:23:21.353450060 CEST | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
Aug 5, 2024 16:23:21.353598118 CEST | 49715 | 80 | 192.168.2.7 | 54.244.188.177 |
Aug 5, 2024 16:23:21.353634119 CEST | 49715 | 80 | 192.168.2.7 | 54.244.188.177 |
Aug 5, 2024 16:23:21.358670950 CEST | 80 | 49715 | 54.244.188.177 | 192.168.2.7 |
Aug 5, 2024 16:23:22.883011103 CEST | 49716 | 80 | 192.168.2.7 | 81.169.145.88 |
Aug 5, 2024 16:23:22.892601013 CEST | 80 | 49716 | 81.169.145.88 | 192.168.2.7 |
Aug 5, 2024 16:23:22.892690897 CEST | 49716 | 80 | 192.168.2.7 | 81.169.145.88 |
Aug 5, 2024 16:23:22.892755985 CEST | 49716 | 80 | 192.168.2.7 | 81.169.145.88 |
Aug 5, 2024 16:23:22.897691011 CEST | 80 | 49716 | 81.169.145.88 | 192.168.2.7 |
Aug 5, 2024 16:23:23.542732000 CEST | 80 | 49716 | 81.169.145.88 | 192.168.2.7 |
Aug 5, 2024 16:23:23.542943001 CEST | 49716 | 80 | 192.168.2.7 | 81.169.145.88 |
Aug 5, 2024 16:23:23.543235064 CEST | 80 | 49716 | 81.169.145.88 | 192.168.2.7 |
Aug 5, 2024 16:23:23.543292999 CEST | 49716 | 80 | 192.168.2.7 | 81.169.145.88 |
Aug 5, 2024 16:23:23.547940016 CEST | 80 | 49716 | 81.169.145.88 | 192.168.2.7 |
Aug 5, 2024 16:23:25.604696989 CEST | 49717 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:25.609764099 CEST | 80 | 49717 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:25.609869957 CEST | 49717 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:25.609951019 CEST | 49717 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:25.614748955 CEST | 80 | 49717 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:26.152344942 CEST | 80 | 49717 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:26.152359962 CEST | 80 | 49717 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:26.152488947 CEST | 49717 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:26.152559996 CEST | 49717 | 80 | 192.168.2.7 | 15.197.192.55 |
Aug 5, 2024 16:23:26.160790920 CEST | 80 | 49717 | 15.197.192.55 | 192.168.2.7 |
Aug 5, 2024 16:23:26.943135023 CEST | 49718 | 80 | 192.168.2.7 | 188.225.40.227 |
Aug 5, 2024 16:23:26.948126078 CEST | 80 | 49718 | 188.225.40.227 | 192.168.2.7 |
Aug 5, 2024 16:23:26.948220968 CEST | 49718 | 80 | 192.168.2.7 | 188.225.40.227 |
Aug 5, 2024 16:23:26.948259115 CEST | 49718 | 80 | 192.168.2.7 | 188.225.40.227 |
Aug 5, 2024 16:23:26.955096960 CEST | 80 | 49718 | 188.225.40.227 | 192.168.2.7 |
Aug 5, 2024 16:23:27.646753073 CEST | 80 | 49718 | 188.225.40.227 | 192.168.2.7 |
Aug 5, 2024 16:23:27.646975994 CEST | 49718 | 80 | 192.168.2.7 | 188.225.40.227 |
Aug 5, 2024 16:23:27.648046970 CEST | 80 | 49718 | 188.225.40.227 | 192.168.2.7 |
Aug 5, 2024 16:23:27.648243904 CEST | 49718 | 80 | 192.168.2.7 | 188.225.40.227 |
Aug 5, 2024 16:23:27.652918100 CEST | 80 | 49718 | 188.225.40.227 | 192.168.2.7 |
Aug 5, 2024 16:24:17.743669987 CEST | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:24:17.780210018 CEST | 80 | 59623 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:24:17.780306101 CEST | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:24:17.780365944 CEST | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:24:17.785518885 CEST | 80 | 59623 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:24:18.320534945 CEST | 80 | 59623 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:24:18.320739031 CEST | 80 | 59623 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:24:18.320810080 CEST | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:24:18.320839882 CEST | 59623 | 80 | 192.168.2.7 | 3.33.130.190 |
Aug 5, 2024 16:24:18.325735092 CEST | 80 | 59623 | 3.33.130.190 | 192.168.2.7 |
Aug 5, 2024 16:24:48.047780037 CEST | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:24:48.053183079 CEST | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:24:48.053263903 CEST | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:24:48.053297043 CEST | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:24:48.059143066 CEST | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:24:48.786004066 CEST | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:24:48.786231041 CEST | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Aug 5, 2024 16:24:48.786300898 CEST | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:24:48.786475897 CEST | 59624 | 80 | 192.168.2.7 | 35.164.78.200 |
Aug 5, 2024 16:24:48.791816950 CEST | 80 | 59624 | 35.164.78.200 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 5, 2024 16:22:56.747797012 CEST | 59709 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:58.827097893 CEST | 55017 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.072036982 CEST | 53 | 55017 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.073581934 CEST | 51934 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.314816952 CEST | 53 | 51934 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.317177057 CEST | 58757 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.488140106 CEST | 53 | 58757 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.489187002 CEST | 57900 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.501302004 CEST | 53 | 57900 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.502075911 CEST | 59206 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.515988111 CEST | 53 | 59206 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.516791105 CEST | 64188 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.528374910 CEST | 53 | 64188 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.529134989 CEST | 61322 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.768841028 CEST | 53 | 61322 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.769958973 CEST | 53612 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.780859947 CEST | 53 | 53612 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.781807899 CEST | 64835 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.797418118 CEST | 53 | 64835 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.798938036 CEST | 53131 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.818885088 CEST | 53 | 53131 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:22:59.819806099 CEST | 60895 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:22:59.994450092 CEST | 53 | 60895 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.468913078 CEST | 52868 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.481833935 CEST | 53 | 52868 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.482680082 CEST | 63268 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.494982958 CEST | 53 | 63268 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.495657921 CEST | 56009 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.507364988 CEST | 53 | 56009 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.508002043 CEST | 63889 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.518084049 CEST | 53 | 63889 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.518887043 CEST | 61278 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.768618107 CEST | 53 | 61278 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.769462109 CEST | 62757 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.781193972 CEST | 53 | 62757 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.781996965 CEST | 53075 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.793140888 CEST | 53 | 53075 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.793869019 CEST | 54646 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.804402113 CEST | 53 | 54646 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.805071115 CEST | 55442 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.817480087 CEST | 53 | 55442 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.818147898 CEST | 59430 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.829871893 CEST | 53 | 59430 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.844660997 CEST | 54571 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.857202053 CEST | 53 | 54571 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.873730898 CEST | 61706 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:00.884138107 CEST | 53 | 61706 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:00.885044098 CEST | 56498 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.125931978 CEST | 53 | 56498 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.126734018 CEST | 65313 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.139688969 CEST | 53 | 65313 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.140727043 CEST | 54121 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.151774883 CEST | 53 | 54121 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.152507067 CEST | 59727 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.166131020 CEST | 53 | 59727 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.167009115 CEST | 52231 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.179567099 CEST | 53 | 52231 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.180201054 CEST | 54779 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.191646099 CEST | 53 | 54779 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.192198038 CEST | 54088 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.204541922 CEST | 53 | 54088 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.206293106 CEST | 64851 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.446283102 CEST | 53 | 64851 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.447448015 CEST | 57662 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.459589958 CEST | 53 | 57662 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.460310936 CEST | 53661 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.474405050 CEST | 53 | 53661 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.475070000 CEST | 55073 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.486325979 CEST | 53 | 55073 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.488322973 CEST | 60773 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.733985901 CEST | 53 | 60773 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.734870911 CEST | 59044 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:01.987286091 CEST | 53 | 59044 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:01.988740921 CEST | 63624 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:02.155164003 CEST | 53 | 63624 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:02.156263113 CEST | 55575 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:02.489639044 CEST | 53 | 55575 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:03.282030106 CEST | 58324 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:03.294171095 CEST | 53 | 58324 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:03.295202971 CEST | 53276 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:03.306982040 CEST | 53 | 53276 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:03.315262079 CEST | 60354 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:03.327703953 CEST | 53 | 60354 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:03.337171078 CEST | 57028 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:03.603338003 CEST | 53 | 57028 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:03.604362011 CEST | 61365 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:04.608788967 CEST | 61365 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:04.834971905 CEST | 53 | 61365 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:04.835983992 CEST | 50387 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:04.840406895 CEST | 53 | 61365 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:04.846358061 CEST | 53 | 50387 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:04.847100973 CEST | 59669 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.089771986 CEST | 53 | 59669 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.090862989 CEST | 65100 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.340581894 CEST | 53 | 65100 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.341633081 CEST | 56171 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.584233999 CEST | 53 | 56171 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.585297108 CEST | 56200 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.597199917 CEST | 53 | 56200 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.597881079 CEST | 51235 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.839589119 CEST | 53 | 51235 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.840672970 CEST | 52352 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.852792978 CEST | 53 | 52352 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.853703976 CEST | 56450 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:05.865334988 CEST | 53 | 56450 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:05.866008997 CEST | 52399 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:06.115442991 CEST | 53 | 52399 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:06.116499901 CEST | 58005 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:06.127631903 CEST | 53 | 58005 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:06.128492117 CEST | 58733 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:06.490065098 CEST | 53 | 58733 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:06.490979910 CEST | 63848 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:06.734385967 CEST | 53 | 63848 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:06.735596895 CEST | 64852 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:06.746968031 CEST | 53 | 64852 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:06.747950077 CEST | 62289 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:07.081515074 CEST | 53 | 62289 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:07.849172115 CEST | 62881 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:07.865104914 CEST | 53 | 62881 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:07.865964890 CEST | 49421 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:07.879404068 CEST | 53 | 49421 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:07.887386084 CEST | 49279 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.140649080 CEST | 53 | 49279 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.141685009 CEST | 50559 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.153228998 CEST | 53 | 50559 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.154092073 CEST | 61386 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.167778015 CEST | 53 | 61386 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.168565035 CEST | 55794 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.408706903 CEST | 53 | 55794 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.409615040 CEST | 50674 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.422204971 CEST | 53 | 50674 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.423027039 CEST | 52979 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.434189081 CEST | 53 | 52979 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.434900999 CEST | 55272 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.676603079 CEST | 53 | 55272 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:08.677520990 CEST | 62955 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:08.689861059 CEST | 53 | 62955 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.184705973 CEST | 56242 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.345818043 CEST | 53 | 56242 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.346751928 CEST | 59792 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.357867956 CEST | 53 | 59792 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.358485937 CEST | 54101 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.368531942 CEST | 53 | 54101 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.369172096 CEST | 56835 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.381783962 CEST | 53 | 56835 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.382386923 CEST | 56259 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.393115044 CEST | 53 | 56259 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.394016981 CEST | 54638 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.403856039 CEST | 53 | 54638 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.404695988 CEST | 62152 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.415358067 CEST | 53 | 62152 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:09.415920019 CEST | 55233 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:09.591981888 CEST | 53 | 55233 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:10.120335102 CEST | 53006 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:10.131587029 CEST | 53 | 53006 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:10.132428885 CEST | 58328 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:10.144226074 CEST | 53 | 58328 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:10.144993067 CEST | 60958 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.140019894 CEST | 60958 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.333298922 CEST | 53 | 60958 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.338663101 CEST | 54640 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.339821100 CEST | 53 | 60958 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.584297895 CEST | 53 | 54640 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.585304022 CEST | 58620 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.595113039 CEST | 53 | 58620 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.596183062 CEST | 58069 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.607228041 CEST | 53 | 58069 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.608077049 CEST | 51967 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.619980097 CEST | 53 | 51967 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.620794058 CEST | 51618 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.869426966 CEST | 53 | 51618 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.870515108 CEST | 52611 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:11.881941080 CEST | 53 | 52611 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:11.882783890 CEST | 64310 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.123236895 CEST | 53 | 64310 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.124109030 CEST | 61816 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.136425018 CEST | 53 | 61816 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.137336016 CEST | 64727 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.148866892 CEST | 53 | 64727 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.149853945 CEST | 62879 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.387614965 CEST | 53 | 62879 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.388535023 CEST | 55461 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.403403044 CEST | 53 | 55461 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.404055119 CEST | 58337 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.416208982 CEST | 53 | 58337 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.419003010 CEST | 56045 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.669958115 CEST | 53 | 56045 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.670917988 CEST | 54304 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.690047026 CEST | 53 | 54304 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.690764904 CEST | 60713 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.703558922 CEST | 53 | 60713 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.704890013 CEST | 50763 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.715862989 CEST | 53 | 50763 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.716545105 CEST | 53985 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.955599070 CEST | 53 | 53985 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.956458092 CEST | 60154 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.972373962 CEST | 53 | 60154 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.973203897 CEST | 64376 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.985363007 CEST | 53 | 64376 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.986319065 CEST | 61437 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:12.998255014 CEST | 53 | 61437 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:12.999150991 CEST | 59730 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:13.018498898 CEST | 53 | 59730 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:13.019520044 CEST | 63224 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:13.264501095 CEST | 53 | 63224 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:13.265332937 CEST | 59003 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:13.277185917 CEST | 53 | 59003 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:13.278017044 CEST | 55778 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:13.313076973 CEST | 53 | 55778 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:13.982986927 CEST | 49944 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:14.233246088 CEST | 53 | 49944 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:14.234230995 CEST | 49282 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:14.253881931 CEST | 53 | 49282 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:14.778151989 CEST | 53669 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.023370981 CEST | 53 | 53669 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.024501085 CEST | 49433 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.035974026 CEST | 53 | 49433 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.036873102 CEST | 57744 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.286478043 CEST | 53 | 57744 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.287492990 CEST | 60749 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.529511929 CEST | 53 | 60749 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.530410051 CEST | 54801 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.543267012 CEST | 53 | 54801 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.543965101 CEST | 57065 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.786616087 CEST | 53 | 57065 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.788389921 CEST | 50453 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.800870895 CEST | 53 | 50453 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.802088022 CEST | 50446 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.817239046 CEST | 53 | 50446 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.818175077 CEST | 57552 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:15.832911968 CEST | 53 | 57552 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:15.833758116 CEST | 52985 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.076066017 CEST | 53 | 52985 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.076986074 CEST | 65063 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.089200974 CEST | 53 | 65063 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.089977026 CEST | 57998 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.105436087 CEST | 53 | 57998 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.106254101 CEST | 55385 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.116499901 CEST | 53 | 55385 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.118916988 CEST | 59470 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.128622055 CEST | 53 | 59470 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.135863066 CEST | 49456 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.147651911 CEST | 53 | 49456 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:16.148502111 CEST | 62441 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:16.594046116 CEST | 53 | 62441 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:17.111905098 CEST | 57978 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:17.131805897 CEST | 53 | 57978 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:17.132673979 CEST | 56358 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:17.151833057 CEST | 53 | 56358 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:17.155555010 CEST | 60463 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:17.166604042 CEST | 53 | 60463 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:17.176980972 CEST | 60706 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:17.492526054 CEST | 53 | 60706 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:17.493551970 CEST | 62344 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:17.749679089 CEST | 53 | 62344 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:18.629637957 CEST | 56435 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:18.664453030 CEST | 53 | 56435 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:19.360114098 CEST | 58990 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:19.603269100 CEST | 53 | 58990 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:19.604113102 CEST | 51384 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:20.041341066 CEST | 53 | 51384 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:20.042613983 CEST | 56555 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:20.532397985 CEST | 53 | 56555 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:21.354139090 CEST | 62743 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:21.594518900 CEST | 53 | 62743 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:21.599212885 CEST | 60564 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:21.612550020 CEST | 53 | 60564 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:21.615145922 CEST | 50429 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:21.626259089 CEST | 53 | 50429 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:21.626872063 CEST | 55407 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:21.800091982 CEST | 53 | 55407 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:21.801013947 CEST | 53573 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.050182104 CEST | 53 | 53573 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.051450968 CEST | 59932 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.062438965 CEST | 53 | 59932 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.063122034 CEST | 50482 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.307908058 CEST | 53 | 50482 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.308860064 CEST | 54875 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.318873882 CEST | 53 | 54875 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.321954966 CEST | 58294 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.333545923 CEST | 53 | 58294 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.334274054 CEST | 50062 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.348253965 CEST | 53 | 50062 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.349205017 CEST | 64033 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.364134073 CEST | 53 | 64033 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.364785910 CEST | 52262 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.527837992 CEST | 53 | 52262 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.528754950 CEST | 54859 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.563729048 CEST | 53 | 54859 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.564809084 CEST | 53985 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.575617075 CEST | 53 | 53985 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.576502085 CEST | 49870 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.586731911 CEST | 53 | 49870 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.587383986 CEST | 51640 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.602020025 CEST | 53 | 51640 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.602730989 CEST | 63049 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.852274895 CEST | 53 | 63049 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:22.853321075 CEST | 53093 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:22.882518053 CEST | 53 | 53093 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:23.543642044 CEST | 61996 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:23.785722971 CEST | 53 | 61996 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:23.786580086 CEST | 55028 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.031197071 CEST | 53 | 55028 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.032265902 CEST | 51140 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.276823997 CEST | 53 | 51140 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.278073072 CEST | 61061 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.289036989 CEST | 53 | 61061 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.289673090 CEST | 56103 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.538819075 CEST | 53 | 56103 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.539998055 CEST | 51263 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.549678087 CEST | 53 | 51263 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.550476074 CEST | 50575 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.718214989 CEST | 53 | 50575 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.729669094 CEST | 50928 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.981952906 CEST | 53 | 50928 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.982945919 CEST | 55446 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:24.994797945 CEST | 53 | 55446 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:24.995552063 CEST | 49739 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:25.008431911 CEST | 53 | 49739 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:25.009118080 CEST | 60530 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:25.019424915 CEST | 53 | 60530 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:25.019994974 CEST | 61774 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:25.272799015 CEST | 53 | 61774 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:25.274055004 CEST | 53846 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:25.603921890 CEST | 53 | 53846 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.153218985 CEST | 50711 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.173346996 CEST | 53 | 50711 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.174304962 CEST | 56194 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.184062004 CEST | 53 | 56194 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.184897900 CEST | 51827 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.427146912 CEST | 53 | 51827 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.428072929 CEST | 52298 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.439620018 CEST | 53 | 52298 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.448745012 CEST | 64729 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.458301067 CEST | 53 | 64729 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.460000992 CEST | 51249 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.470509052 CEST | 53 | 51249 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:26.473237991 CEST | 50123 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:26.942564964 CEST | 53 | 50123 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:27.647510052 CEST | 49566 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:27.891237020 CEST | 53 | 49566 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:27.892193079 CEST | 62372 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:27.903814077 CEST | 53 | 62372 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:27.904778004 CEST | 52650 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:23:27.914954901 CEST | 53 | 52650 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:23:45.178628922 CEST | 53 | 50058 | 162.159.36.2 | 192.168.2.7 |
Aug 5, 2024 16:23:46.033658028 CEST | 53 | 51844 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:19.329459906 CEST | 57563 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:19.342288017 CEST | 53 | 57563 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:20.344276905 CEST | 59894 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:20.593597889 CEST | 53 | 59894 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:21.609978914 CEST | 56723 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:21.624454021 CEST | 53 | 56723 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:22.641103029 CEST | 51859 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:22.656313896 CEST | 53 | 51859 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:23.672787905 CEST | 62063 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:23.691430092 CEST | 53 | 62063 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:24.703435898 CEST | 51973 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:24.714538097 CEST | 53 | 51973 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:25.719153881 CEST | 57065 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:25.730051994 CEST | 53 | 57065 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:26.734932899 CEST | 55499 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:26.745863914 CEST | 53 | 55499 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:27.750502110 CEST | 59649 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:27.762432098 CEST | 53 | 59649 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:28.766252041 CEST | 56028 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:29.008287907 CEST | 53 | 56028 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:30.016100883 CEST | 54120 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:30.028261900 CEST | 53 | 54120 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:31.033252954 CEST | 52810 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:31.274490118 CEST | 53 | 52810 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:32.281800985 CEST | 52456 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:32.644752026 CEST | 53 | 52456 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:33.656968117 CEST | 59715 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:33.900650978 CEST | 53 | 59715 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:34.907303095 CEST | 62067 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:34.919079065 CEST | 53 | 62067 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:35.922257900 CEST | 63101 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:36.160528898 CEST | 53 | 63101 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:37.172446966 CEST | 54422 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:37.414206982 CEST | 53 | 54422 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:38.422349930 CEST | 62141 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:38.432774067 CEST | 53 | 62141 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:39.438189983 CEST | 57175 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:39.679007053 CEST | 53 | 57175 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:40.688630104 CEST | 59852 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:40.700752974 CEST | 53 | 59852 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:41.703542948 CEST | 61875 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:41.714907885 CEST | 53 | 61875 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:42.719425917 CEST | 51934 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:42.730444908 CEST | 53 | 51934 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:43.734996080 CEST | 55229 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:43.746114969 CEST | 53 | 55229 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:44.753750086 CEST | 59474 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:44.764403105 CEST | 53 | 59474 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:45.766043901 CEST | 49274 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:45.778937101 CEST | 53 | 49274 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:46.781923056 CEST | 55332 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:47.033505917 CEST | 53 | 55332 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:49.797646046 CEST | 61974 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:49.808259010 CEST | 53 | 61974 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:50.813277960 CEST | 58451 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:50.952276945 CEST | 53 | 58451 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:51.969788074 CEST | 57834 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:51.980510950 CEST | 53 | 57834 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:52.985311985 CEST | 55428 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:52.995425940 CEST | 53 | 55428 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:53.978466034 CEST | 53414 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:54.220349073 CEST | 53 | 53414 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:55.157414913 CEST | 56887 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:55.169265985 CEST | 53 | 56887 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:56.079106092 CEST | 52806 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:56.089919090 CEST | 53 | 52806 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:56.969827890 CEST | 64907 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:56.982188940 CEST | 53 | 64907 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:57.828845024 CEST | 49917 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:58.484996080 CEST | 53 | 49917 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.438075066 CEST | 57899 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.447949886 CEST | 53 | 57899 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.448775053 CEST | 54739 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.459800959 CEST | 53 | 54739 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.460437059 CEST | 59384 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.473557949 CEST | 53 | 59384 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.474095106 CEST | 60113 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.484698057 CEST | 53 | 60113 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.485200882 CEST | 61701 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.497405052 CEST | 53 | 61701 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.497925997 CEST | 60261 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.509195089 CEST | 53 | 60261 | 1.1.1.1 | 192.168.2.7 |
Aug 5, 2024 16:24:59.509829044 CEST | 54697 | 53 | 192.168.2.7 | 1.1.1.1 |
Aug 5, 2024 16:24:59.670346975 CEST | 53 | 54697 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 5, 2024 16:22:56.747797012 CEST | 192.168.2.7 | 1.1.1.1 | 0xf93d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:58.827097893 CEST | 192.168.2.7 | 1.1.1.1 | 0x910a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.073581934 CEST | 192.168.2.7 | 1.1.1.1 | 0x7047 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.317177057 CEST | 192.168.2.7 | 1.1.1.1 | 0x94ad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.489187002 CEST | 192.168.2.7 | 1.1.1.1 | 0xeb47 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.502075911 CEST | 192.168.2.7 | 1.1.1.1 | 0xdbbe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.516791105 CEST | 192.168.2.7 | 1.1.1.1 | 0x6697 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.529134989 CEST | 192.168.2.7 | 1.1.1.1 | 0x6e1b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.769958973 CEST | 192.168.2.7 | 1.1.1.1 | 0xd2ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.781807899 CEST | 192.168.2.7 | 1.1.1.1 | 0x4731 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.798938036 CEST | 192.168.2.7 | 1.1.1.1 | 0x3847 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.819806099 CEST | 192.168.2.7 | 1.1.1.1 | 0x3ec1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.468913078 CEST | 192.168.2.7 | 1.1.1.1 | 0x820b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.482680082 CEST | 192.168.2.7 | 1.1.1.1 | 0x99fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.495657921 CEST | 192.168.2.7 | 1.1.1.1 | 0xd8b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.508002043 CEST | 192.168.2.7 | 1.1.1.1 | 0x5209 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.518887043 CEST | 192.168.2.7 | 1.1.1.1 | 0x2d7a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.769462109 CEST | 192.168.2.7 | 1.1.1.1 | 0x5f2a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.781996965 CEST | 192.168.2.7 | 1.1.1.1 | 0xc9c9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.793869019 CEST | 192.168.2.7 | 1.1.1.1 | 0x16d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.805071115 CEST | 192.168.2.7 | 1.1.1.1 | 0x5f15 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.818147898 CEST | 192.168.2.7 | 1.1.1.1 | 0x1ee3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.844660997 CEST | 192.168.2.7 | 1.1.1.1 | 0x37b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.873730898 CEST | 192.168.2.7 | 1.1.1.1 | 0xa4ab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.885044098 CEST | 192.168.2.7 | 1.1.1.1 | 0x6fcd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.126734018 CEST | 192.168.2.7 | 1.1.1.1 | 0xccac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.140727043 CEST | 192.168.2.7 | 1.1.1.1 | 0xe403 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.152507067 CEST | 192.168.2.7 | 1.1.1.1 | 0xdaef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.167009115 CEST | 192.168.2.7 | 1.1.1.1 | 0x677b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.180201054 CEST | 192.168.2.7 | 1.1.1.1 | 0x39fa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.192198038 CEST | 192.168.2.7 | 1.1.1.1 | 0x2c0b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.206293106 CEST | 192.168.2.7 | 1.1.1.1 | 0x4b02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.447448015 CEST | 192.168.2.7 | 1.1.1.1 | 0x2644 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.460310936 CEST | 192.168.2.7 | 1.1.1.1 | 0x4cba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.475070000 CEST | 192.168.2.7 | 1.1.1.1 | 0xeb68 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.488322973 CEST | 192.168.2.7 | 1.1.1.1 | 0x2bb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.734870911 CEST | 192.168.2.7 | 1.1.1.1 | 0x8529 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.988740921 CEST | 192.168.2.7 | 1.1.1.1 | 0x6965 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:02.156263113 CEST | 192.168.2.7 | 1.1.1.1 | 0xa408 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.282030106 CEST | 192.168.2.7 | 1.1.1.1 | 0x6b64 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.295202971 CEST | 192.168.2.7 | 1.1.1.1 | 0xe563 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.315262079 CEST | 192.168.2.7 | 1.1.1.1 | 0x1065 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.337171078 CEST | 192.168.2.7 | 1.1.1.1 | 0x4e44 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.604362011 CEST | 192.168.2.7 | 1.1.1.1 | 0x94c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.608788967 CEST | 192.168.2.7 | 1.1.1.1 | 0x94c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.835983992 CEST | 192.168.2.7 | 1.1.1.1 | 0xa61b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.847100973 CEST | 192.168.2.7 | 1.1.1.1 | 0x60b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.090862989 CEST | 192.168.2.7 | 1.1.1.1 | 0xc3b8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.341633081 CEST | 192.168.2.7 | 1.1.1.1 | 0x9190 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.585297108 CEST | 192.168.2.7 | 1.1.1.1 | 0xa3ce | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.597881079 CEST | 192.168.2.7 | 1.1.1.1 | 0x2466 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.840672970 CEST | 192.168.2.7 | 1.1.1.1 | 0x95d6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.853703976 CEST | 192.168.2.7 | 1.1.1.1 | 0xaa58 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.866008997 CEST | 192.168.2.7 | 1.1.1.1 | 0x812 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.116499901 CEST | 192.168.2.7 | 1.1.1.1 | 0xe050 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.128492117 CEST | 192.168.2.7 | 1.1.1.1 | 0xec85 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.490979910 CEST | 192.168.2.7 | 1.1.1.1 | 0xaf40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.735596895 CEST | 192.168.2.7 | 1.1.1.1 | 0xd1e9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.747950077 CEST | 192.168.2.7 | 1.1.1.1 | 0xefe4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:07.849172115 CEST | 192.168.2.7 | 1.1.1.1 | 0xa031 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:07.865964890 CEST | 192.168.2.7 | 1.1.1.1 | 0x3d40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:07.887386084 CEST | 192.168.2.7 | 1.1.1.1 | 0xf352 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.141685009 CEST | 192.168.2.7 | 1.1.1.1 | 0x1e49 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.154092073 CEST | 192.168.2.7 | 1.1.1.1 | 0x29ec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.168565035 CEST | 192.168.2.7 | 1.1.1.1 | 0xbcd1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.409615040 CEST | 192.168.2.7 | 1.1.1.1 | 0xd06c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.423027039 CEST | 192.168.2.7 | 1.1.1.1 | 0xe8dd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.434900999 CEST | 192.168.2.7 | 1.1.1.1 | 0x31e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.677520990 CEST | 192.168.2.7 | 1.1.1.1 | 0xfc2f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.184705973 CEST | 192.168.2.7 | 1.1.1.1 | 0x3e92 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.346751928 CEST | 192.168.2.7 | 1.1.1.1 | 0x8bb3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.358485937 CEST | 192.168.2.7 | 1.1.1.1 | 0x852a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.369172096 CEST | 192.168.2.7 | 1.1.1.1 | 0x43f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.382386923 CEST | 192.168.2.7 | 1.1.1.1 | 0x6394 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.394016981 CEST | 192.168.2.7 | 1.1.1.1 | 0x684d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.404695988 CEST | 192.168.2.7 | 1.1.1.1 | 0x5ee0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.415920019 CEST | 192.168.2.7 | 1.1.1.1 | 0xd087 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:10.120335102 CEST | 192.168.2.7 | 1.1.1.1 | 0xc6a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:10.132428885 CEST | 192.168.2.7 | 1.1.1.1 | 0xf832 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:10.144993067 CEST | 192.168.2.7 | 1.1.1.1 | 0x480e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.140019894 CEST | 192.168.2.7 | 1.1.1.1 | 0x480e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.338663101 CEST | 192.168.2.7 | 1.1.1.1 | 0x42b2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.585304022 CEST | 192.168.2.7 | 1.1.1.1 | 0x2855 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.596183062 CEST | 192.168.2.7 | 1.1.1.1 | 0x970 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.608077049 CEST | 192.168.2.7 | 1.1.1.1 | 0xdcd4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.620794058 CEST | 192.168.2.7 | 1.1.1.1 | 0xa235 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.870515108 CEST | 192.168.2.7 | 1.1.1.1 | 0x6e26 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.882783890 CEST | 192.168.2.7 | 1.1.1.1 | 0x862b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.124109030 CEST | 192.168.2.7 | 1.1.1.1 | 0x7de3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.137336016 CEST | 192.168.2.7 | 1.1.1.1 | 0x13c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.149853945 CEST | 192.168.2.7 | 1.1.1.1 | 0xf617 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.388535023 CEST | 192.168.2.7 | 1.1.1.1 | 0x4524 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.404055119 CEST | 192.168.2.7 | 1.1.1.1 | 0xd3bb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.419003010 CEST | 192.168.2.7 | 1.1.1.1 | 0x1557 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.670917988 CEST | 192.168.2.7 | 1.1.1.1 | 0x92f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.690764904 CEST | 192.168.2.7 | 1.1.1.1 | 0xcebf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.704890013 CEST | 192.168.2.7 | 1.1.1.1 | 0xc33e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.716545105 CEST | 192.168.2.7 | 1.1.1.1 | 0x4832 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.956458092 CEST | 192.168.2.7 | 1.1.1.1 | 0x1bb4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.973203897 CEST | 192.168.2.7 | 1.1.1.1 | 0x86a9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.986319065 CEST | 192.168.2.7 | 1.1.1.1 | 0x41c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.999150991 CEST | 192.168.2.7 | 1.1.1.1 | 0x11c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.019520044 CEST | 192.168.2.7 | 1.1.1.1 | 0x64ac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.265332937 CEST | 192.168.2.7 | 1.1.1.1 | 0xaa11 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.278017044 CEST | 192.168.2.7 | 1.1.1.1 | 0x8b99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.982986927 CEST | 192.168.2.7 | 1.1.1.1 | 0x8c56 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:14.234230995 CEST | 192.168.2.7 | 1.1.1.1 | 0x145c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:14.778151989 CEST | 192.168.2.7 | 1.1.1.1 | 0x38b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.024501085 CEST | 192.168.2.7 | 1.1.1.1 | 0x72f7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.036873102 CEST | 192.168.2.7 | 1.1.1.1 | 0xc9ad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.287492990 CEST | 192.168.2.7 | 1.1.1.1 | 0xca5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.530410051 CEST | 192.168.2.7 | 1.1.1.1 | 0x37cf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.543965101 CEST | 192.168.2.7 | 1.1.1.1 | 0xc5b0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.788389921 CEST | 192.168.2.7 | 1.1.1.1 | 0x382 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.802088022 CEST | 192.168.2.7 | 1.1.1.1 | 0x5ad0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.818175077 CEST | 192.168.2.7 | 1.1.1.1 | 0xc6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.833758116 CEST | 192.168.2.7 | 1.1.1.1 | 0x4b9b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.076986074 CEST | 192.168.2.7 | 1.1.1.1 | 0x676f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.089977026 CEST | 192.168.2.7 | 1.1.1.1 | 0xc2a4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.106254101 CEST | 192.168.2.7 | 1.1.1.1 | 0x3455 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.118916988 CEST | 192.168.2.7 | 1.1.1.1 | 0x9f3d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.135863066 CEST | 192.168.2.7 | 1.1.1.1 | 0x6058 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.148502111 CEST | 192.168.2.7 | 1.1.1.1 | 0xbb52 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.111905098 CEST | 192.168.2.7 | 1.1.1.1 | 0xfa40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.132673979 CEST | 192.168.2.7 | 1.1.1.1 | 0x8b28 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.155555010 CEST | 192.168.2.7 | 1.1.1.1 | 0x5995 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.176980972 CEST | 192.168.2.7 | 1.1.1.1 | 0x205f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.493551970 CEST | 192.168.2.7 | 1.1.1.1 | 0xcd7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:18.629637957 CEST | 192.168.2.7 | 1.1.1.1 | 0x9eff | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:19.360114098 CEST | 192.168.2.7 | 1.1.1.1 | 0x2cb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:19.604113102 CEST | 192.168.2.7 | 1.1.1.1 | 0xb6c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:20.042613983 CEST | 192.168.2.7 | 1.1.1.1 | 0xdcbf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.354139090 CEST | 192.168.2.7 | 1.1.1.1 | 0x5909 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.599212885 CEST | 192.168.2.7 | 1.1.1.1 | 0x4ad2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.615145922 CEST | 192.168.2.7 | 1.1.1.1 | 0x391 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.626872063 CEST | 192.168.2.7 | 1.1.1.1 | 0x4709 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.801013947 CEST | 192.168.2.7 | 1.1.1.1 | 0xe1bb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.051450968 CEST | 192.168.2.7 | 1.1.1.1 | 0xd725 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.063122034 CEST | 192.168.2.7 | 1.1.1.1 | 0x581b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.308860064 CEST | 192.168.2.7 | 1.1.1.1 | 0xc380 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.321954966 CEST | 192.168.2.7 | 1.1.1.1 | 0xaee2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.334274054 CEST | 192.168.2.7 | 1.1.1.1 | 0x94a9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.349205017 CEST | 192.168.2.7 | 1.1.1.1 | 0xfd7b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.364785910 CEST | 192.168.2.7 | 1.1.1.1 | 0xf73b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.528754950 CEST | 192.168.2.7 | 1.1.1.1 | 0xc7a9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.564809084 CEST | 192.168.2.7 | 1.1.1.1 | 0x4c8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.576502085 CEST | 192.168.2.7 | 1.1.1.1 | 0x68dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.587383986 CEST | 192.168.2.7 | 1.1.1.1 | 0x5cb1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.602730989 CEST | 192.168.2.7 | 1.1.1.1 | 0x2b38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.853321075 CEST | 192.168.2.7 | 1.1.1.1 | 0x6bce | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:23.543642044 CEST | 192.168.2.7 | 1.1.1.1 | 0xca35 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:23.786580086 CEST | 192.168.2.7 | 1.1.1.1 | 0x3aff | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.032265902 CEST | 192.168.2.7 | 1.1.1.1 | 0xcd72 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.278073072 CEST | 192.168.2.7 | 1.1.1.1 | 0xf72f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.289673090 CEST | 192.168.2.7 | 1.1.1.1 | 0xa8f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.539998055 CEST | 192.168.2.7 | 1.1.1.1 | 0x2a4c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.550476074 CEST | 192.168.2.7 | 1.1.1.1 | 0xdebe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.729669094 CEST | 192.168.2.7 | 1.1.1.1 | 0xa304 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.982945919 CEST | 192.168.2.7 | 1.1.1.1 | 0xad30 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.995552063 CEST | 192.168.2.7 | 1.1.1.1 | 0x4323 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.009118080 CEST | 192.168.2.7 | 1.1.1.1 | 0xb373 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.019994974 CEST | 192.168.2.7 | 1.1.1.1 | 0x1406 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.274055004 CEST | 192.168.2.7 | 1.1.1.1 | 0xce48 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.153218985 CEST | 192.168.2.7 | 1.1.1.1 | 0xcccf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.174304962 CEST | 192.168.2.7 | 1.1.1.1 | 0x5336 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.184897900 CEST | 192.168.2.7 | 1.1.1.1 | 0x7589 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.428072929 CEST | 192.168.2.7 | 1.1.1.1 | 0xe3c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.448745012 CEST | 192.168.2.7 | 1.1.1.1 | 0x88cb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.460000992 CEST | 192.168.2.7 | 1.1.1.1 | 0x75b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.473237991 CEST | 192.168.2.7 | 1.1.1.1 | 0xbdad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:27.647510052 CEST | 192.168.2.7 | 1.1.1.1 | 0x1fb5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:27.892193079 CEST | 192.168.2.7 | 1.1.1.1 | 0x33bd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:27.904778004 CEST | 192.168.2.7 | 1.1.1.1 | 0xf139 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:19.329459906 CEST | 192.168.2.7 | 1.1.1.1 | 0x5c47 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:20.344276905 CEST | 192.168.2.7 | 1.1.1.1 | 0x83c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:21.609978914 CEST | 192.168.2.7 | 1.1.1.1 | 0xafd8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:22.641103029 CEST | 192.168.2.7 | 1.1.1.1 | 0x7ea5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:23.672787905 CEST | 192.168.2.7 | 1.1.1.1 | 0xf4d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:24.703435898 CEST | 192.168.2.7 | 1.1.1.1 | 0xaf5c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:25.719153881 CEST | 192.168.2.7 | 1.1.1.1 | 0xd700 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:26.734932899 CEST | 192.168.2.7 | 1.1.1.1 | 0xe137 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:27.750502110 CEST | 192.168.2.7 | 1.1.1.1 | 0x66f0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:28.766252041 CEST | 192.168.2.7 | 1.1.1.1 | 0xdb1a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:30.016100883 CEST | 192.168.2.7 | 1.1.1.1 | 0xc187 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:31.033252954 CEST | 192.168.2.7 | 1.1.1.1 | 0x5c0c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:32.281800985 CEST | 192.168.2.7 | 1.1.1.1 | 0x2692 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:33.656968117 CEST | 192.168.2.7 | 1.1.1.1 | 0x51d1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:34.907303095 CEST | 192.168.2.7 | 1.1.1.1 | 0xaa78 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:35.922257900 CEST | 192.168.2.7 | 1.1.1.1 | 0xb06a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:37.172446966 CEST | 192.168.2.7 | 1.1.1.1 | 0x9d5c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:38.422349930 CEST | 192.168.2.7 | 1.1.1.1 | 0x82e4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:39.438189983 CEST | 192.168.2.7 | 1.1.1.1 | 0x2386 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:40.688630104 CEST | 192.168.2.7 | 1.1.1.1 | 0xe78f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:41.703542948 CEST | 192.168.2.7 | 1.1.1.1 | 0xcf58 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:42.719425917 CEST | 192.168.2.7 | 1.1.1.1 | 0x2d4f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:43.734996080 CEST | 192.168.2.7 | 1.1.1.1 | 0x3267 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:44.753750086 CEST | 192.168.2.7 | 1.1.1.1 | 0x3987 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:45.766043901 CEST | 192.168.2.7 | 1.1.1.1 | 0x560d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:46.781923056 CEST | 192.168.2.7 | 1.1.1.1 | 0xc023 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:49.797646046 CEST | 192.168.2.7 | 1.1.1.1 | 0x4a36 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:50.813277960 CEST | 192.168.2.7 | 1.1.1.1 | 0x56e9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:51.969788074 CEST | 192.168.2.7 | 1.1.1.1 | 0x4074 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:52.985311985 CEST | 192.168.2.7 | 1.1.1.1 | 0x53e1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:53.978466034 CEST | 192.168.2.7 | 1.1.1.1 | 0xc849 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:55.157414913 CEST | 192.168.2.7 | 1.1.1.1 | 0x4c7e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:56.079106092 CEST | 192.168.2.7 | 1.1.1.1 | 0x1fb0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:56.969827890 CEST | 192.168.2.7 | 1.1.1.1 | 0xeab3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:57.828845024 CEST | 192.168.2.7 | 1.1.1.1 | 0x1b9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.438075066 CEST | 192.168.2.7 | 1.1.1.1 | 0x29ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.448775053 CEST | 192.168.2.7 | 1.1.1.1 | 0xddac | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.460437059 CEST | 192.168.2.7 | 1.1.1.1 | 0x1534 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.474095106 CEST | 192.168.2.7 | 1.1.1.1 | 0xac3c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.485200882 CEST | 192.168.2.7 | 1.1.1.1 | 0x3733 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.497925997 CEST | 192.168.2.7 | 1.1.1.1 | 0x720a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.509829044 CEST | 192.168.2.7 | 1.1.1.1 | 0xa86c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 5, 2024 16:22:56.758208036 CEST | 1.1.1.1 | 192.168.2.7 | 0xf93d | No error (0) | twc.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Aug 5, 2024 16:22:59.072036982 CEST | 1.1.1.1 | 192.168.2.7 | 0x910a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.314816952 CEST | 1.1.1.1 | 192.168.2.7 | 0x7047 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.488140106 CEST | 1.1.1.1 | 192.168.2.7 | 0x94ad | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.501302004 CEST | 1.1.1.1 | 192.168.2.7 | 0xeb47 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.515988111 CEST | 1.1.1.1 | 192.168.2.7 | 0xdbbe | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.528374910 CEST | 1.1.1.1 | 192.168.2.7 | 0x6697 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.768841028 CEST | 1.1.1.1 | 192.168.2.7 | 0x6e1b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.780859947 CEST | 1.1.1.1 | 192.168.2.7 | 0xd2ba | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.797418118 CEST | 1.1.1.1 | 192.168.2.7 | 0x4731 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.818885088 CEST | 1.1.1.1 | 192.168.2.7 | 0x3847 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:22:59.994450092 CEST | 1.1.1.1 | 192.168.2.7 | 0x3ec1 | No error (0) | 3.33.130.190 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:22:59.994450092 CEST | 1.1.1.1 | 192.168.2.7 | 0x3ec1 | No error (0) | 15.197.148.33 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:00.481833935 CEST | 1.1.1.1 | 192.168.2.7 | 0x820b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.494982958 CEST | 1.1.1.1 | 192.168.2.7 | 0x99fe | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.507364988 CEST | 1.1.1.1 | 192.168.2.7 | 0xd8b1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.518084049 CEST | 1.1.1.1 | 192.168.2.7 | 0x5209 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.768618107 CEST | 1.1.1.1 | 192.168.2.7 | 0x2d7a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.781193972 CEST | 1.1.1.1 | 192.168.2.7 | 0x5f2a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.793140888 CEST | 1.1.1.1 | 192.168.2.7 | 0xc9c9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.804402113 CEST | 1.1.1.1 | 192.168.2.7 | 0x16d1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.817480087 CEST | 1.1.1.1 | 192.168.2.7 | 0x5f15 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.829871893 CEST | 1.1.1.1 | 192.168.2.7 | 0x1ee3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.857202053 CEST | 1.1.1.1 | 192.168.2.7 | 0x37b4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:00.884138107 CEST | 1.1.1.1 | 192.168.2.7 | 0xa4ab | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.125931978 CEST | 1.1.1.1 | 192.168.2.7 | 0x6fcd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.139688969 CEST | 1.1.1.1 | 192.168.2.7 | 0xccac | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.151774883 CEST | 1.1.1.1 | 192.168.2.7 | 0xe403 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.166131020 CEST | 1.1.1.1 | 192.168.2.7 | 0xdaef | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.179567099 CEST | 1.1.1.1 | 192.168.2.7 | 0x677b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.191646099 CEST | 1.1.1.1 | 192.168.2.7 | 0x39fa | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.204541922 CEST | 1.1.1.1 | 192.168.2.7 | 0x2c0b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.446283102 CEST | 1.1.1.1 | 192.168.2.7 | 0x4b02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.459589958 CEST | 1.1.1.1 | 192.168.2.7 | 0x2644 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.474405050 CEST | 1.1.1.1 | 192.168.2.7 | 0x4cba | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.486325979 CEST | 1.1.1.1 | 192.168.2.7 | 0xeb68 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.733985901 CEST | 1.1.1.1 | 192.168.2.7 | 0x2bb8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:01.987286091 CEST | 1.1.1.1 | 192.168.2.7 | 0x8529 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:02.155164003 CEST | 1.1.1.1 | 192.168.2.7 | 0x6965 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:02.489639044 CEST | 1.1.1.1 | 192.168.2.7 | 0xa408 | No error (0) | 35.164.78.200 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:03.294171095 CEST | 1.1.1.1 | 192.168.2.7 | 0x6b64 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.306982040 CEST | 1.1.1.1 | 192.168.2.7 | 0xe563 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.327703953 CEST | 1.1.1.1 | 192.168.2.7 | 0x1065 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:03.603338003 CEST | 1.1.1.1 | 192.168.2.7 | 0x4e44 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.834971905 CEST | 1.1.1.1 | 192.168.2.7 | 0x94c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.840406895 CEST | 1.1.1.1 | 192.168.2.7 | 0x94c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:04.846358061 CEST | 1.1.1.1 | 192.168.2.7 | 0xa61b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.089771986 CEST | 1.1.1.1 | 192.168.2.7 | 0x60b4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.340581894 CEST | 1.1.1.1 | 192.168.2.7 | 0xc3b8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.584233999 CEST | 1.1.1.1 | 192.168.2.7 | 0x9190 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.597199917 CEST | 1.1.1.1 | 192.168.2.7 | 0xa3ce | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.839589119 CEST | 1.1.1.1 | 192.168.2.7 | 0x2466 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.852792978 CEST | 1.1.1.1 | 192.168.2.7 | 0x95d6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:05.865334988 CEST | 1.1.1.1 | 192.168.2.7 | 0xaa58 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.115442991 CEST | 1.1.1.1 | 192.168.2.7 | 0x812 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.127631903 CEST | 1.1.1.1 | 192.168.2.7 | 0xe050 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.490065098 CEST | 1.1.1.1 | 192.168.2.7 | 0xec85 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.734385967 CEST | 1.1.1.1 | 192.168.2.7 | 0xaf40 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:06.746968031 CEST | 1.1.1.1 | 192.168.2.7 | 0xd1e9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:07.081515074 CEST | 1.1.1.1 | 192.168.2.7 | 0xefe4 | No error (0) | 34.246.200.160 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:07.865104914 CEST | 1.1.1.1 | 192.168.2.7 | 0xa031 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:07.879404068 CEST | 1.1.1.1 | 192.168.2.7 | 0x3d40 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.140649080 CEST | 1.1.1.1 | 192.168.2.7 | 0xf352 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.153228998 CEST | 1.1.1.1 | 192.168.2.7 | 0x1e49 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.167778015 CEST | 1.1.1.1 | 192.168.2.7 | 0x29ec | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.408706903 CEST | 1.1.1.1 | 192.168.2.7 | 0xbcd1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.422204971 CEST | 1.1.1.1 | 192.168.2.7 | 0xd06c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.434189081 CEST | 1.1.1.1 | 192.168.2.7 | 0xe8dd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.676603079 CEST | 1.1.1.1 | 192.168.2.7 | 0x31e5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:08.689861059 CEST | 1.1.1.1 | 192.168.2.7 | 0xfc2f | No error (0) | 15.197.142.173 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:08.689861059 CEST | 1.1.1.1 | 192.168.2.7 | 0xfc2f | No error (0) | 3.33.152.147 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:09.345818043 CEST | 1.1.1.1 | 192.168.2.7 | 0x3e92 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.357867956 CEST | 1.1.1.1 | 192.168.2.7 | 0x8bb3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.368531942 CEST | 1.1.1.1 | 192.168.2.7 | 0x852a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.381783962 CEST | 1.1.1.1 | 192.168.2.7 | 0x43f9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.393115044 CEST | 1.1.1.1 | 192.168.2.7 | 0x6394 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.403856039 CEST | 1.1.1.1 | 192.168.2.7 | 0x684d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.415358067 CEST | 1.1.1.1 | 192.168.2.7 | 0x5ee0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:09.591981888 CEST | 1.1.1.1 | 192.168.2.7 | 0xd087 | No error (0) | 15.197.192.55 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:10.131587029 CEST | 1.1.1.1 | 192.168.2.7 | 0xc6a6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:10.144226074 CEST | 1.1.1.1 | 192.168.2.7 | 0xf832 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.333298922 CEST | 1.1.1.1 | 192.168.2.7 | 0x480e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.339821100 CEST | 1.1.1.1 | 192.168.2.7 | 0x480e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.584297895 CEST | 1.1.1.1 | 192.168.2.7 | 0x42b2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.595113039 CEST | 1.1.1.1 | 192.168.2.7 | 0x2855 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.607228041 CEST | 1.1.1.1 | 192.168.2.7 | 0x970 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.619980097 CEST | 1.1.1.1 | 192.168.2.7 | 0xdcd4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.869426966 CEST | 1.1.1.1 | 192.168.2.7 | 0xa235 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:11.881941080 CEST | 1.1.1.1 | 192.168.2.7 | 0x6e26 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.123236895 CEST | 1.1.1.1 | 192.168.2.7 | 0x862b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.136425018 CEST | 1.1.1.1 | 192.168.2.7 | 0x7de3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.148866892 CEST | 1.1.1.1 | 192.168.2.7 | 0x13c0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.387614965 CEST | 1.1.1.1 | 192.168.2.7 | 0xf617 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.403403044 CEST | 1.1.1.1 | 192.168.2.7 | 0x4524 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.416208982 CEST | 1.1.1.1 | 192.168.2.7 | 0xd3bb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.669958115 CEST | 1.1.1.1 | 192.168.2.7 | 0x1557 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.690047026 CEST | 1.1.1.1 | 192.168.2.7 | 0x92f4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.703558922 CEST | 1.1.1.1 | 192.168.2.7 | 0xcebf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.715862989 CEST | 1.1.1.1 | 192.168.2.7 | 0xc33e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.955599070 CEST | 1.1.1.1 | 192.168.2.7 | 0x4832 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.972373962 CEST | 1.1.1.1 | 192.168.2.7 | 0x1bb4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.985363007 CEST | 1.1.1.1 | 192.168.2.7 | 0x86a9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:12.998255014 CEST | 1.1.1.1 | 192.168.2.7 | 0x41c2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.018498898 CEST | 1.1.1.1 | 192.168.2.7 | 0x11c7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.264501095 CEST | 1.1.1.1 | 192.168.2.7 | 0x64ac | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.277185917 CEST | 1.1.1.1 | 192.168.2.7 | 0xaa11 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:13.313076973 CEST | 1.1.1.1 | 192.168.2.7 | 0x8b99 | No error (0) | 85.13.130.3 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:14.233246088 CEST | 1.1.1.1 | 192.168.2.7 | 0x8c56 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:14.253881931 CEST | 1.1.1.1 | 192.168.2.7 | 0x145c | No error (0) | 3.33.130.190 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:14.253881931 CEST | 1.1.1.1 | 192.168.2.7 | 0x145c | No error (0) | 15.197.148.33 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:15.023370981 CEST | 1.1.1.1 | 192.168.2.7 | 0x38b6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.035974026 CEST | 1.1.1.1 | 192.168.2.7 | 0x72f7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.286478043 CEST | 1.1.1.1 | 192.168.2.7 | 0xc9ad | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.529511929 CEST | 1.1.1.1 | 192.168.2.7 | 0xca5e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.543267012 CEST | 1.1.1.1 | 192.168.2.7 | 0x37cf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.786616087 CEST | 1.1.1.1 | 192.168.2.7 | 0xc5b0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.800870895 CEST | 1.1.1.1 | 192.168.2.7 | 0x382 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.817239046 CEST | 1.1.1.1 | 192.168.2.7 | 0x5ad0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:15.832911968 CEST | 1.1.1.1 | 192.168.2.7 | 0xc6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.076066017 CEST | 1.1.1.1 | 192.168.2.7 | 0x4b9b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.089200974 CEST | 1.1.1.1 | 192.168.2.7 | 0x676f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.105436087 CEST | 1.1.1.1 | 192.168.2.7 | 0xc2a4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.116499901 CEST | 1.1.1.1 | 192.168.2.7 | 0x3455 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.128622055 CEST | 1.1.1.1 | 192.168.2.7 | 0x9f3d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.147651911 CEST | 1.1.1.1 | 192.168.2.7 | 0x6058 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:16.594046116 CEST | 1.1.1.1 | 192.168.2.7 | 0xbb52 | No error (0) | 170.187.200.48 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:17.131805897 CEST | 1.1.1.1 | 192.168.2.7 | 0xfa40 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.151833057 CEST | 1.1.1.1 | 192.168.2.7 | 0x8b28 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.166604042 CEST | 1.1.1.1 | 192.168.2.7 | 0x5995 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.492526054 CEST | 1.1.1.1 | 192.168.2.7 | 0x205f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:17.749679089 CEST | 1.1.1.1 | 192.168.2.7 | 0xcd7 | No error (0) | 213.171.195.105 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:18.664453030 CEST | 1.1.1.1 | 192.168.2.7 | 0x9eff | No error (0) | 64.190.63.222 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:19.603269100 CEST | 1.1.1.1 | 192.168.2.7 | 0x2cb9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:20.041341066 CEST | 1.1.1.1 | 192.168.2.7 | 0xb6c1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:20.532397985 CEST | 1.1.1.1 | 192.168.2.7 | 0xdcbf | No error (0) | 54.244.188.177 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:21.594518900 CEST | 1.1.1.1 | 192.168.2.7 | 0x5909 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.612550020 CEST | 1.1.1.1 | 192.168.2.7 | 0x4ad2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.626259089 CEST | 1.1.1.1 | 192.168.2.7 | 0x391 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:21.800091982 CEST | 1.1.1.1 | 192.168.2.7 | 0x4709 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.050182104 CEST | 1.1.1.1 | 192.168.2.7 | 0xe1bb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.062438965 CEST | 1.1.1.1 | 192.168.2.7 | 0xd725 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.307908058 CEST | 1.1.1.1 | 192.168.2.7 | 0x581b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.318873882 CEST | 1.1.1.1 | 192.168.2.7 | 0xc380 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.333545923 CEST | 1.1.1.1 | 192.168.2.7 | 0xaee2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.348253965 CEST | 1.1.1.1 | 192.168.2.7 | 0x94a9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.364134073 CEST | 1.1.1.1 | 192.168.2.7 | 0xfd7b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.527837992 CEST | 1.1.1.1 | 192.168.2.7 | 0xf73b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.575617075 CEST | 1.1.1.1 | 192.168.2.7 | 0x4c8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.586731911 CEST | 1.1.1.1 | 192.168.2.7 | 0x68dc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.602020025 CEST | 1.1.1.1 | 192.168.2.7 | 0x5cb1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.852274895 CEST | 1.1.1.1 | 192.168.2.7 | 0x2b38 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:22.882518053 CEST | 1.1.1.1 | 192.168.2.7 | 0x6bce | No error (0) | 81.169.145.88 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:23.785722971 CEST | 1.1.1.1 | 192.168.2.7 | 0xca35 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.031197071 CEST | 1.1.1.1 | 192.168.2.7 | 0x3aff | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.276823997 CEST | 1.1.1.1 | 192.168.2.7 | 0xcd72 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.289036989 CEST | 1.1.1.1 | 192.168.2.7 | 0xf72f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.538819075 CEST | 1.1.1.1 | 192.168.2.7 | 0xa8f4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.549678087 CEST | 1.1.1.1 | 192.168.2.7 | 0x2a4c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.718214989 CEST | 1.1.1.1 | 192.168.2.7 | 0xdebe | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.981952906 CEST | 1.1.1.1 | 192.168.2.7 | 0xa304 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:24.994797945 CEST | 1.1.1.1 | 192.168.2.7 | 0xad30 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.008431911 CEST | 1.1.1.1 | 192.168.2.7 | 0x4323 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.019424915 CEST | 1.1.1.1 | 192.168.2.7 | 0xb373 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.272799015 CEST | 1.1.1.1 | 192.168.2.7 | 0x1406 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:25.603921890 CEST | 1.1.1.1 | 192.168.2.7 | 0xce48 | No error (0) | 15.197.192.55 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:26.173346996 CEST | 1.1.1.1 | 192.168.2.7 | 0xcccf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.184062004 CEST | 1.1.1.1 | 192.168.2.7 | 0x5336 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.427146912 CEST | 1.1.1.1 | 192.168.2.7 | 0x7589 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.439620018 CEST | 1.1.1.1 | 192.168.2.7 | 0xe3c1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.458301067 CEST | 1.1.1.1 | 192.168.2.7 | 0x88cb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.470509052 CEST | 1.1.1.1 | 192.168.2.7 | 0x75b7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:26.942564964 CEST | 1.1.1.1 | 192.168.2.7 | 0xbdad | No error (0) | 188.225.40.227 | A (IP address) | IN (0x0001) | false | ||
Aug 5, 2024 16:23:27.891237020 CEST | 1.1.1.1 | 192.168.2.7 | 0x1fb5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:27.903814077 CEST | 1.1.1.1 | 192.168.2.7 | 0x33bd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:23:27.914954901 CEST | 1.1.1.1 | 192.168.2.7 | 0xf139 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:19.342288017 CEST | 1.1.1.1 | 192.168.2.7 | 0x5c47 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:20.593597889 CEST | 1.1.1.1 | 192.168.2.7 | 0x83c2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:21.624454021 CEST | 1.1.1.1 | 192.168.2.7 | 0xafd8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:22.656313896 CEST | 1.1.1.1 | 192.168.2.7 | 0x7ea5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:23.691430092 CEST | 1.1.1.1 | 192.168.2.7 | 0xf4d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:24.714538097 CEST | 1.1.1.1 | 192.168.2.7 | 0xaf5c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:25.730051994 CEST | 1.1.1.1 | 192.168.2.7 | 0xd700 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:26.745863914 CEST | 1.1.1.1 | 192.168.2.7 | 0xe137 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:27.762432098 CEST | 1.1.1.1 | 192.168.2.7 | 0x66f0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:29.008287907 CEST | 1.1.1.1 | 192.168.2.7 | 0xdb1a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:30.028261900 CEST | 1.1.1.1 | 192.168.2.7 | 0xc187 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:31.274490118 CEST | 1.1.1.1 | 192.168.2.7 | 0x5c0c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:32.644752026 CEST | 1.1.1.1 | 192.168.2.7 | 0x2692 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:33.900650978 CEST | 1.1.1.1 | 192.168.2.7 | 0x51d1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:34.919079065 CEST | 1.1.1.1 | 192.168.2.7 | 0xaa78 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:36.160528898 CEST | 1.1.1.1 | 192.168.2.7 | 0xb06a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:37.414206982 CEST | 1.1.1.1 | 192.168.2.7 | 0x9d5c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:38.432774067 CEST | 1.1.1.1 | 192.168.2.7 | 0x82e4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:39.679007053 CEST | 1.1.1.1 | 192.168.2.7 | 0x2386 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:40.700752974 CEST | 1.1.1.1 | 192.168.2.7 | 0xe78f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:41.714907885 CEST | 1.1.1.1 | 192.168.2.7 | 0xcf58 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:42.730444908 CEST | 1.1.1.1 | 192.168.2.7 | 0x2d4f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:43.746114969 CEST | 1.1.1.1 | 192.168.2.7 | 0x3267 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:44.764403105 CEST | 1.1.1.1 | 192.168.2.7 | 0x3987 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:45.778937101 CEST | 1.1.1.1 | 192.168.2.7 | 0x560d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:47.033505917 CEST | 1.1.1.1 | 192.168.2.7 | 0xc023 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:49.808259010 CEST | 1.1.1.1 | 192.168.2.7 | 0x4a36 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:50.952276945 CEST | 1.1.1.1 | 192.168.2.7 | 0x56e9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:51.980510950 CEST | 1.1.1.1 | 192.168.2.7 | 0x4074 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:52.995425940 CEST | 1.1.1.1 | 192.168.2.7 | 0x53e1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:54.220349073 CEST | 1.1.1.1 | 192.168.2.7 | 0xc849 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:55.169265985 CEST | 1.1.1.1 | 192.168.2.7 | 0x4c7e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:56.089919090 CEST | 1.1.1.1 | 192.168.2.7 | 0x1fb0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:56.982188940 CEST | 1.1.1.1 | 192.168.2.7 | 0xeab3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:58.484996080 CEST | 1.1.1.1 | 192.168.2.7 | 0x1b9e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.447949886 CEST | 1.1.1.1 | 192.168.2.7 | 0x29ba | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.459800959 CEST | 1.1.1.1 | 192.168.2.7 | 0xddac | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.473557949 CEST | 1.1.1.1 | 192.168.2.7 | 0x1534 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.484698057 CEST | 1.1.1.1 | 192.168.2.7 | 0xac3c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.497405052 CEST | 1.1.1.1 | 192.168.2.7 | 0x3733 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.509195089 CEST | 1.1.1.1 | 192.168.2.7 | 0x720a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Aug 5, 2024 16:24:59.670346975 CEST | 1.1.1.1 | 192.168.2.7 | 0xa86c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49700 | 3.33.130.190 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:00.012031078 CEST | 83 | OUT | |
Aug 5, 2024 16:23:00.467889071 CEST | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49701 | 35.164.78.200 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:02.497464895 CEST | 84 | OUT | |
Aug 5, 2024 16:23:03.262451887 CEST | 382 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49702 | 34.246.200.160 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:07.088696003 CEST | 84 | OUT | |
Aug 5, 2024 16:23:07.847978115 CEST | 382 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49703 | 15.197.142.173 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:08.695300102 CEST | 83 | OUT | |
Aug 5, 2024 16:23:09.183926105 CEST | 266 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49704 | 15.197.192.55 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:09.598023891 CEST | 83 | OUT | |
Aug 5, 2024 16:23:10.119362116 CEST | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49708 | 85.13.130.3 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:13.325212002 CEST | 83 | OUT | |
Aug 5, 2024 16:23:13.975238085 CEST | 452 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49709 | 3.33.130.190 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:14.259835958 CEST | 82 | OUT | |
Aug 5, 2024 16:23:14.771369934 CEST | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49712 | 170.187.200.48 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:16.599848986 CEST | 81 | OUT | |
Aug 5, 2024 16:23:17.110980034 CEST | 289 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49713 | 213.171.195.105 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:17.755304098 CEST | 84 | OUT | |
Aug 5, 2024 16:23:18.628709078 CEST | 1236 | IN | |
Aug 5, 2024 16:23:18.628727913 CEST | 1236 | IN | |
Aug 5, 2024 16:23:18.628766060 CEST | 448 | IN | |
Aug 5, 2024 16:23:18.628777981 CEST | 187 | IN | |
Aug 5, 2024 16:23:18.633377075 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49714 | 64.190.63.222 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:18.674741983 CEST | 82 | OUT | |
Aug 5, 2024 16:23:19.359216928 CEST | 208 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49715 | 54.244.188.177 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:20.542334080 CEST | 81 | OUT | |
Aug 5, 2024 16:23:21.353359938 CEST | 379 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49716 | 81.169.145.88 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:22.892755985 CEST | 81 | OUT | |
Aug 5, 2024 16:23:23.542732000 CEST | 374 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49717 | 15.197.192.55 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:25.609951019 CEST | 84 | OUT | |
Aug 5, 2024 16:23:26.152344942 CEST | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49718 | 188.225.40.227 | 80 | 3452 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:23:26.948259115 CEST | 83 | OUT | |
Aug 5, 2024 16:23:27.646753073 CEST | 373 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 59623 | 3.33.130.190 | 80 | 7912 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:24:17.780365944 CEST | 83 | OUT | |
Aug 5, 2024 16:24:18.320534945 CEST | 254 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 59624 | 35.164.78.200 | 80 | 7912 | C:\whfkpbh\idtpqzltyfy.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Aug 5, 2024 16:24:48.053297043 CEST | 84 | OUT | |
Aug 5, 2024 16:24:48.786004066 CEST | 382 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 10:22:53 |
Start date: | 05/08/2024 |
Path: | C:\Users\user\Desktop\mtuXDnH1Di.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xec0000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 10:22:54 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\qbf30bzbv7f7qnhdav.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9d0000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 10:22:54 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\idtpqzltyfy.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x140000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 10:22:55 |
Start date: | 05/08/2024 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 10:22:55 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\amdrhfskpcu.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa30000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 10:22:56 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\idtpqzltyfy.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x140000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:45:45 |
Start date: | 05/08/2024 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 11:46:17 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\idtpqzltyfy.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x140000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 12 |
Start time: | 11:46:18 |
Start date: | 05/08/2024 |
Path: | C:\whfkpbh\amdrhfskpcu.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xcd0000 |
File size: | 279'552 bytes |
MD5 hash: | E4B47C06B5EED80FB44CFEA757525634 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 7.4% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 46.6% |
Total number of Nodes: | 1706 |
Total number of Limit Nodes: | 14 |
Graph
Function 00EC7A04 Relevance: 60.1, APIs: 28, Strings: 5, Instructions: 2326sleepfilesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED5200 Relevance: 30.9, APIs: 12, Strings: 5, Instructions: 1106fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECB7A0 Relevance: 3.1, APIs: 2, Instructions: 89memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECE2C0 Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECCA40 Relevance: 10.8, APIs: 7, Instructions: 345fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EEFA80 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 133processCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED1D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED2EB0 Relevance: 3.0, APIs: 2, Instructions: 40memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE45A9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EC2800 Relevance: 1.5, APIs: 1, Instructions: 16COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECA4E0 Relevance: 1.3, APIs: 1, Instructions: 33stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EDA930 Relevance: 21.8, APIs: 11, Strings: 1, Instructions: 829memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE6A7B Relevance: 16.4, Strings: 12, Instructions: 1391COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF50E0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 134timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EDF160 Relevance: 4.9, Strings: 3, Instructions: 1183COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE55E0 Relevance: 4.1, Strings: 2, Instructions: 1592COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EDE1C0 Relevance: 3.7, APIs: 2, Instructions: 732COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED30F0 Relevance: 2.3, Strings: 1, Instructions: 1008COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE9B00 Relevance: 2.2, APIs: 1, Instructions: 701COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EEE70B Relevance: 2.0, Strings: 1, Instructions: 773COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE22A0 Relevance: 1.8, APIs: 1, Instructions: 598sleepCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE66E7 Relevance: 1.8, Strings: 1, Instructions: 554COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECD760 Relevance: 1.7, Strings: 1, Instructions: 473COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF0A90 Relevance: 1.5, Strings: 1, Instructions: 296COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF5930 Relevance: 1.5, Strings: 1, Instructions: 274COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECC660 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED97B0 Relevance: .9, Instructions: 866COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EC1490 Relevance: .4, Instructions: 409COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EE4EA0 Relevance: .4, Instructions: 386COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF0220 Relevance: .4, Instructions: 361COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECF330 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EDA0A6 Relevance: .3, Instructions: 310COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED6C10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 187registrysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00EF5440 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 71synchronizationthreadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECBD08 Relevance: 7.6, APIs: 5, Instructions: 141COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ECD000 Relevance: 6.3, APIs: 4, Instructions: 269fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ED68D0 Relevance: 6.1, APIs: 4, Instructions: 64memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.7% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 3.1% |
Total number of Nodes: | 1717 |
Total number of Limit Nodes: | 22 |
Graph
Function 009D7A04 Relevance: 63.6, APIs: 29, Strings: 6, Instructions: 2326sleepfilesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E5200 Relevance: 30.9, APIs: 12, Strings: 5, Instructions: 1106fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009EA930 Relevance: 25.3, APIs: 13, Strings: 1, Instructions: 829memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E0920 Relevance: 4.8, APIs: 3, Instructions: 254libraryloaderencryptionCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F9B00 Relevance: 2.2, APIs: 1, Instructions: 701COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009FFA80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 133processCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DD000 Relevance: 6.3, APIs: 4, Instructions: 269fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E1D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DB7A0 Relevance: 3.1, APIs: 2, Instructions: 89memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E2EB0 Relevance: 3.0, APIs: 2, Instructions: 40memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DE2C0 Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F3CF0 Relevance: 1.6, APIs: 1, Instructions: 120fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F45A9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009D2800 Relevance: 1.5, APIs: 1, Instructions: 16COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DA4E0 Relevance: 1.3, APIs: 1, Instructions: 33stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E6C10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 187registrysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E4380 Relevance: 14.4, APIs: 7, Strings: 1, Instructions: 387processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DCA40 Relevance: 10.8, APIs: 7, Instructions: 345fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009DBD08 Relevance: 7.6, APIs: 5, Instructions: 141COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A05440 Relevance: 7.6, APIs: 5, Instructions: 71synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009E68D0 Relevance: 6.1, APIs: 4, Instructions: 64memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A050E0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 134timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 15.7% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 1717 |
Total number of Limit Nodes: | 38 |
Graph
Function 00147A04 Relevance: 65.3, APIs: 29, Strings: 7, Instructions: 2326sleepfilesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00155200 Relevance: 30.9, APIs: 12, Strings: 5, Instructions: 1106fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015A930 Relevance: 25.3, APIs: 13, Strings: 1, Instructions: 829memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001622A0 Relevance: 5.1, APIs: 1, Strings: 2, Instructions: 598sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00150920 Relevance: 4.8, APIs: 3, Instructions: 254libraryloaderencryptionCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00169B00 Relevance: 2.2, APIs: 1, Instructions: 701COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014C660 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00156C10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 187registrysynchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0016FA80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 133processCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014B7A0 Relevance: 4.6, APIs: 3, Instructions: 89memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00152EB0 Relevance: 3.0, APIs: 2, Instructions: 40memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014A4E0 Relevance: 3.0, APIs: 2, Instructions: 33stringCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014E2C0 Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00150DC0 Relevance: 1.7, APIs: 1, Instructions: 182fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00163CF0 Relevance: 1.6, APIs: 1, Instructions: 120fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001645A9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151200 Relevance: 1.4, APIs: 1, Instructions: 165sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00154380 Relevance: 14.4, APIs: 7, Strings: 1, Instructions: 387processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014CA40 Relevance: 10.8, APIs: 7, Instructions: 345fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014BD08 Relevance: 7.6, APIs: 5, Instructions: 141COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00175440 Relevance: 7.6, APIs: 5, Instructions: 71synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014D000 Relevance: 6.3, APIs: 4, Instructions: 269fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001568D0 Relevance: 6.1, APIs: 4, Instructions: 64memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001750E0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 134timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 7.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 1712 |
Total number of Limit Nodes: | 17 |
Graph
Function 00A37A04 Relevance: 60.1, APIs: 28, Strings: 5, Instructions: 2326sleepfilesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A45200 Relevance: 30.9, APIs: 12, Strings: 5, Instructions: 1106fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3BD08 Relevance: 7.6, APIs: 5, Instructions: 141COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A5FA80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 133processCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A41D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3B7A0 Relevance: 3.1, APIs: 2, Instructions: 89memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A42EB0 Relevance: 3.0, APIs: 2, Instructions: 40memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3E2C0 Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A545A9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A32800 Relevance: 1.5, APIs: 1, Instructions: 16COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3A4E0 Relevance: 1.3, APIs: 1, Instructions: 33stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A46C10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 187registrysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3CA40 Relevance: 10.8, APIs: 7, Instructions: 345fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A65440 Relevance: 7.6, APIs: 5, Instructions: 71synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3D000 Relevance: 6.3, APIs: 4, Instructions: 269fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A468D0 Relevance: 6.1, APIs: 4, Instructions: 64memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A650E0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 134timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 1713 |
Total number of Limit Nodes: | 13 |
Graph
Function 00147A04 Relevance: 60.1, APIs: 28, Strings: 5, Instructions: 2326sleepfilesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00155200 Relevance: 30.9, APIs: 12, Strings: 5, Instructions: 1106fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014B7A0 Relevance: 3.1, APIs: 2, Instructions: 89memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00152EB0 Relevance: 3.0, APIs: 2, Instructions: 40memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014E2C0 Relevance: 3.0, APIs: 2, Instructions: 19memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00163CF0 Relevance: 1.6, APIs: 1, Instructions: 120fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001645A9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00142800 Relevance: 1.5, APIs: 1, Instructions: 16COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014A4E0 Relevance: 1.3, APIs: 1, Instructions: 33stringCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00156C10 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 187registrysynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014CA40 Relevance: 10.8, APIs: 7, Instructions: 345fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014BD08 Relevance: 7.6, APIs: 5, Instructions: 141COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00175440 Relevance: 7.6, APIs: 5, Instructions: 71synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0016FA80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 133processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014D000 Relevance: 6.3, APIs: 4, Instructions: 269fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001568D0 Relevance: 6.1, APIs: 4, Instructions: 64memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001750E0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 134timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0015A930 Relevance: 25.3, APIs: 13, Strings: 1, Instructions: 829memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00150920 Relevance: 4.8, APIs: 3, Instructions: 254libraryloaderencryptionCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00151D90 Relevance: 4.7, APIs: 3, Instructions: 187fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00163CF0 Relevance: 1.6, APIs: 1, Instructions: 120fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0014A4E0 Relevance: 1.3, APIs: 1, Instructions: 33stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|