Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 1060 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: A7F1B43BB75327181BF5535F6EAB329D) - InstallUtil.exe (PID: 4876 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57)
- cmd.exe (PID: 3224 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\Q 266LY31DJu BkUgU7rnVY 9MU.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5936 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 4024 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\N 7dCpczI2KM QNpAzS7xas jkw.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5844 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 1524 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\U knphp3q7QN TU5S7JDQd3 95T.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3512 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 4416 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\7 jqZT4DOBm3 RwAn2PcA57 5yH.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3576 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 3648 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\a QqevjV3RV9 JJaF7h5x7E xf9.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3276 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 7084 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\p ltF0lsLekf h4Kak6kjaR OUd.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3380 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 4616 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\0 aZULhs3yjK zrM4jdcsdY 0pG.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6520 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 6744 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\b PdKjWiyihu tETqOInbK2 Mh7.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5844 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DarkTortilla | DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks Counter Threat Unit (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging.From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
Click to see the 5 entries |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | DNS query: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_0918B4C8 |
Source: | Code function: | 0_2_00D2A3C8 | |
Source: | Code function: | 0_2_00D29778 | |
Source: | Code function: | 0_2_00DA0368 | |
Source: | Code function: | 0_2_05E72488 | |
Source: | Code function: | 0_2_05E7A794 | |
Source: | Code function: | 0_2_05E72479 | |
Source: | Code function: | 0_2_05E7C368 | |
Source: | Code function: | 0_2_0722B6F5 | |
Source: | Code function: | 0_2_07221D58 | |
Source: | Code function: | 0_2_0722CC8B | |
Source: | Code function: | 0_2_0722CC88 | |
Source: | Code function: | 0_2_0722CC98 | |
Source: | Code function: | 0_2_0722CCE3 | |
Source: | Code function: | 0_2_07311C70 | |
Source: | Code function: | 0_2_0732D380 | |
Source: | Code function: | 0_2_0732DD50 | |
Source: | Code function: | 0_2_0732EC60 | |
Source: | Code function: | 0_2_0732CC58 | |
Source: | Code function: | 0_2_0732B048 | |
Source: | Code function: | 0_2_073210ED | |
Source: | Code function: | 0_2_0732FB08 | |
Source: | Code function: | 0_2_0732EBAA | |
Source: | Code function: | 0_2_0732BEA0 | |
Source: | Code function: | 0_2_0732FAF8 | |
Source: | Code function: | 0_2_0732C018 | |
Source: | Code function: | 0_2_07320006 | |
Source: | Code function: | 0_2_07320040 | |
Source: | Code function: | 0_2_0732EC4A | |
Source: | Code function: | 0_2_0732CC49 | |
Source: | Code function: | 0_2_09184100 | |
Source: | Code function: | 0_2_09185868 | |
Source: | Code function: | 0_2_0918F338 | |
Source: | Code function: | 0_2_09185B70 | |
Source: | Code function: | 0_2_091867EC | |
Source: | Code function: | 0_2_0918BA60 | |
Source: | Code function: | 0_2_09180D18 | |
Source: | Code function: | 0_2_09180D08 | |
Source: | Code function: | 0_2_09188508 | |
Source: | Code function: | 0_2_09189DF8 | |
Source: | Code function: | 0_2_09180012 | |
Source: | Code function: | 0_2_09181805 | |
Source: | Code function: | 0_2_09185858 | |
Source: | Code function: | 0_2_09180040 | |
Source: | Code function: | 0_2_09181860 | |
Source: | Code function: | 0_2_09185098 | |
Source: | Code function: | 0_2_091808D8 | |
Source: | Code function: | 0_2_091884F8 | |
Source: | Code function: | 0_2_091840F0 | |
Source: | Code function: | 0_2_091808E8 | |
Source: | Code function: | 0_2_09180330 | |
Source: | Code function: | 0_2_09184390 | |
Source: | Code function: | 0_2_091843A0 | |
Source: | Code function: | 0_2_09184A30 | |
Source: | Code function: | 0_2_091806B0 | |
Source: | Code function: | 0_2_091806A0 | |
Source: | Code function: | 0_2_091896C8 | |
Source: | Code function: | 0_2_07311C57 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | .Net Code: |
Source: | Code function: | 0_2_07221748 | |
Source: | Code function: | 0_2_0731AC43 | |
Source: | Code function: | 0_2_0731AC43 | |
Source: | Code function: | 0_2_07310DD0 | |
Source: | Code function: | 0_2_07310ECF | |
Source: | Code function: | 0_2_0732CBB1 | |
Source: | Code function: | 0_2_0732CBB1 |
Boot Survival |
---|
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 11 Scripting | 1 Valid Accounts | Windows Management Instrumentation | 1 Valid Accounts | 1 Valid Accounts | 1 Masquerading | OS Credential Dumping | 11 Security Software Discovery | Remote Services | 1 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 11 Scripting | 1 Access Token Manipulation | 1 Valid Accounts | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 2 Registry Run Keys / Startup Folder | 311 Process Injection | 1 Access Token Manipulation | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 1 DLL Side-Loading | 2 Registry Run Keys / Startup Folder | 1 Disable or Modify Tools | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSA Secrets | 1 System Network Configuration Discovery | SSH | Keylogging | 4 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 311 Process Injection | Cached Domain Credentials | 2 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Hidden Files and Directories | DCSync | 12 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 Obfuscated Files or Information | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Software Packing | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 1 DLL Side-Loading | Network Sniffing | Network Service Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Win32.Trojan.InjectorX | ||
100% | Avira | HEUR/AGEN.1304599 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
yip.su | 188.114.96.3 | true | false | unknown | |
pastebin.com | 172.67.19.24 | true | true | unknown | |
iplogger.com | 172.67.188.178 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.67.19.24 | pastebin.com | United States | 13335 | CLOUDFLARENETUS | true | |
188.114.96.3 | yip.su | European Union | 13335 | CLOUDFLARENETUS | false | |
172.67.188.178 | iplogger.com | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1490825 |
Start date and time: | 2024-08-09 22:59:09 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 21s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 24 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winEXE@28/8@3/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target InstallUtil.exe, PID 4876 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
17:00:51 | API Interceptor | |
17:00:52 | API Interceptor | |
23:00:54 | Autostart | |
23:01:07 | Autostart | |
23:01:16 | Autostart | |
23:01:29 | Autostart | |
23:01:37 | Autostart | |
23:01:45 | Autostart | |
23:01:58 | Autostart | |
23:02:07 | Autostart | |
23:02:15 | Autostart | |
23:02:23 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.67.19.24 | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
188.114.96.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | Azorult | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
172.67.188.178 | Get hash | malicious | Amadey, DarkTortilla, RedLine, XWorm | Browse | ||
Get hash | malicious | Cryptbot, Vidar, Xmrig | Browse | |||
Get hash | malicious | Metamorfo | Browse | |||
Get hash | malicious | EICAR, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | PureLog Stealer | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | PureLog Stealer, zgRAT | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
yip.su | Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| |
Get hash | malicious | Cryptbot, Neoreklami | Browse |
| ||
Get hash | malicious | Cryptbot, Vidar, Xmrig | Browse |
| ||
Get hash | malicious | Bdaejec | Browse |
| ||
Get hash | malicious | Amadey, Glupteba | Browse |
| ||
Get hash | malicious | Amadey, Mars Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Amadey, Glupteba, LummaC Stealer, Mars Stealer, SmokeLoader, Socks5Systemz, Stealc | Browse |
| ||
Get hash | malicious | Glupteba, Mars Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Babuk, Djvu, RedLine, SmokeLoader, Xmrig | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Babuk, Djvu, RedLine, SmokeLoader, Xmrig | Browse |
| ||
pastebin.com | Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| |
Get hash | malicious | StormKitty, XWorm | Browse |
| ||
Get hash | malicious | Cryptbot, Neoreklami | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine, Xmrig | Browse |
| ||
Get hash | malicious | RedLine, Xmrig | Browse |
| ||
Get hash | malicious | RedLine, Xmrig | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Cryptbot, Vidar, Xmrig | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, XWorm | Browse |
| ||
iplogger.com | Get hash | malicious | Cryptbot, Vidar, Xmrig | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, Tycoon2FA | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | DarkTortilla, Neoreklami | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | StormKitty, XWorm | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
|
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4x84qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4j:MIHK5HKH1qHxviYHKh3oPtHo6hAHKzea |
MD5: | 7B709BC412BEC5C3CFD861C041DAD408 |
SHA1: | 532EA6BB3018AE3B51E7A5788F614A6C49252BCF |
SHA-256: | 733765A1599E02C53826A4AE984426862AA714D8B67F889607153888D40BBD75 |
SHA-512: | B35CFE36A1A40123FDC8A5E7C804096FF33F070F40CBA5812B98F46857F30BA2CE6F86E1B5D20F9B6D00D6A8194B8FA36C27A0208C7886512877058872277963 |
Malicious: | true |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\N7dCpczI2KMQNpAzS7xasjkw.bat
Download File
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.86924805016808 |
Encrypted: | false |
SSDEEP: | 3:Ljn9m1N+E2J5JtbX3EczbiF:fE1N723jbEcXm |
MD5: | F0CADC91C7B3B58616C49687D377FD10 |
SHA1: | BE08F749CFF27555A847B40D0BBAE9B123B44D99 |
SHA-256: | C1EFA09C10A2AEBD0A914729EA4DDF4A312BBA8D403EA0E7FE61E0DD39966E9D |
SHA-512: | FA676321EF0BAE3A75924A97C3A0F7C764ED46D0CD02ABF132883C45E1DD6909E8A88AED2B672C88BF98090A1B104B96B21A8C6C41205EDD3E803779C0EDF2BD |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Q266LY31DJuBkUgU7rnVY9MU.bat
Download File
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72 |
Entropy (8bit): | 4.850567800613269 |
Encrypted: | false |
SSDEEP: | 3:Ljn9m1N+E2J5cGGXHOMFn:fE1N723crHOMF |
MD5: | 7376752613C7B530196EBDA552841E3E |
SHA1: | 84EF1E10BB0910485F6E4A7A8AB84F3D7C3BC8EA |
SHA-256: | 00F9BC5007271E3A50C295E4080E0F505932055D53F0B9895BE2E87618D2E725 |
SHA-512: | A62A9EAC4623FE33E3FACD035E566C88D34701F3399EC462C308BAD796A8EFE98D7F2AE3EE70837E02DEDF1350CDE528E1F3A1132711794BA9767994BBE78D63 |
Malicious: | true |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.465924024716172 |
Encrypted: | false |
SSDEEP: | 6144:mzZfpi6ceLPx9skLmb0fBZWSP3aJG8nAgeiJRMMhA2zX4WABluuNLjDH5S:oZHtBZWOKnMM6bFpZj4 |
MD5: | 632899DC17D6A19101A805A6EA909154 |
SHA1: | 961621A2727B0E8670B192B2D22967520D02C79F |
SHA-256: | 12FFB714E44F1EDFFF3B56F70029F5C1AD305297A7274BEA65B7B594E78399ED |
SHA-512: | B527BA1A888E6E298612FA77264674630743396431417E630D2C447E6C86D3AB8AC10AAE55441B15AA960CB9EFCDAFAFF69367BD0FD3BC0A1E23DADDC63CB1A9 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.968804538165683 |
TrID: |
|
File name: | file.exe |
File size: | 9'643'376 bytes |
MD5: | a7f1b43bb75327181bf5535f6eab329d |
SHA1: | b7d03ad2e90ea8f81ba755c6e5c551e2686c679c |
SHA256: | 79cf97a156358a7dfba188f7b6d516e62279a11fb15b828bbd676b15633c008e |
SHA512: | 5024b110c1bda506e2e07d285643791d2cfcd3fe4ade981b5d92306df0d4f7bf1061d36eb6feef36c8a058bc5990bff96f1011b2a0aa1701276c189b176fb4d6 |
SSDEEP: | 196608:yt2OL8IgYaEYShQuM4PaZaCFO5lThlQcqsFDFP/4Qbp/xHKd3fc2obL:ycOL85ShLzPdcqVqsFJHXB9K3fcTbL |
TLSH: | 76A6331A95D80C6ED416D2BEC34026D39E9232415297E3C27E9D8BFE1FB29DB46CC385 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....U.J....................."........... ........@.. ....................... ............`................................ |
Icon Hash: | 4e1616963371238e |
Entrypoint: | 0xd1c4fe |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x4A0655ED [Sun May 10 04:19:57 2009 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Signature Valid: | false |
Signature Issuer: | CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US |
Signature Validation Error: | The digital signature of the object did not verify |
Error Number: | -2146869232 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | E995C628AAD797E68CAE9D6374BC8ACE |
Thumbprint SHA-1: | CCF8C4F9272D8A25477AF13EC71F97A3027C7319 |
Thumbprint SHA-256: | 13D255CB1919425FC94170917F458E0CEC043372B844B95AA70C9E6B488E1909 |
Serial: | 09D08EBDA06BE07C815EA7AF25EF6875 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x91c4a4 | 0x57 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x91e000 | 0x11f52 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x92ca00 | 0x5b70 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x930000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x91a504 | 0x91a600 | 6e47b3687675ea870f59f777edd90d68 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x91e000 | 0x11f52 | 0x12000 | 5b2074da2c80f566d7550c481bce9965 | False | 0.8323296440972222 | data | 7.329922630205283 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x930000 | 0xc | 0x200 | 3926ca23ce0c8eecdfac90c478c10619 | False | 0.041015625 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x91e190 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | 0.44133574007220217 | ||
RT_ICON | 0x91ea38 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | 0.30057803468208094 | ||
RT_ICON | 0x91efa0 | 0xd49e | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9958478780084512 | ||
RT_ICON | 0x92c440 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | 0.34221991701244814 | ||
RT_ICON | 0x92e9e8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | 0.37570356472795496 | ||
RT_ICON | 0x92fa90 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | 0.524822695035461 | ||
RT_GROUP_ICON | 0x92fef8 | 0x5a | data | 0.7777777777777778 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 9, 2024 23:00:52.596740007 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:52.596760988 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:52.596833944 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:52.613301039 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:52.613312006 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.104732990 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.104801893 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.109249115 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.109258890 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.109658003 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.155082941 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.170970917 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.216500998 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.275763988 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.275904894 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.275955915 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.275969028 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.276060104 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.276252031 CEST | 443 | 49721 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:53.276300907 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.285284042 CEST | 49721 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:53.412687063 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.412719011 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:53.412900925 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.413238049 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.413252115 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:53.886483908 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:53.886569977 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.888478994 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.888489008 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:53.888894081 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:53.890635967 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:53.932519913 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390140057 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390290976 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390346050 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:54.390355110 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390441895 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390539885 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:54.390539885 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390567064 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390688896 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:54.390693903 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.390856981 CEST | 443 | 49722 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:00:54.391202927 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:54.391593933 CEST | 49722 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:00:58.417087078 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.417161942 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:58.417237997 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.417587042 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.417618990 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:58.915621996 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:58.915745020 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.917769909 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.917802095 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:58.918279886 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:58.919621944 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:58.960505962 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039024115 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039143085 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039184093 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039226055 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039244890 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.039268970 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039300919 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.039315939 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039360046 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.039366007 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039417028 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039460897 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039508104 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.039515972 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.039558887 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.043725967 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.092597961 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.092619896 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.129797935 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.129880905 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.129904032 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.130055904 CEST | 443 | 49723 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:00:59.130815983 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.131167889 CEST | 49723 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:00:59.250060081 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.250092030 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.250159979 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.250579119 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.250595093 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.718180895 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.764466047 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.860126019 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.860140085 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960163116 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960292101 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960349083 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.960361004 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960438013 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960491896 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.960500956 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960665941 CEST | 443 | 49724 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:00:59.960721016 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:00:59.963488102 CEST | 49724 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:00.172801018 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.172909021 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.172988892 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.173240900 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.173294067 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.674892902 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.676676989 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.676733971 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896115065 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896164894 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896205902 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896236897 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896270990 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896308899 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896393061 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.896409988 CEST | 443 | 49725 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:00.896450043 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.896473885 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:00.896986961 CEST | 49725 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:05.303216934 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.303263903 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.303654909 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.307037115 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.307053089 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.784703970 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.787836075 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.787858009 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912022114 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912058115 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912082911 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912101984 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912108898 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.912127972 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912143946 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.912180901 CEST | 443 | 49727 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:05.912230015 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.913146019 CEST | 49727 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:05.975584030 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:05.975617886 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:05.975687027 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:05.975914955 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:05.975929022 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.461864948 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.463610888 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.463633060 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695455074 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695538044 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695580006 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695621967 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695624113 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.695636034 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695688963 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.695698977 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695730925 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695759058 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.695770979 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695832968 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.695838928 CEST | 443 | 49728 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:06.695892096 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:06.696294069 CEST | 49728 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:11.093653917 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.093713045 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.093785048 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.094022036 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.094041109 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.576076031 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.578613043 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.578650951 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.721693039 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.721862078 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.721924067 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.721940041 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.722062111 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.722275019 CEST | 443 | 49729 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:11.722328901 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.722604990 CEST | 49729 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:11.760236979 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:11.760293961 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:11.760360956 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:11.760586023 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:11.760603905 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.221765041 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.223670959 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:12.223706007 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453083992 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453212976 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453279018 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:12.453305960 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453397036 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453448057 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:12.453458071 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453576088 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453622103 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:12.453629971 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453836918 CEST | 443 | 49730 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:12.453895092 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:12.454579115 CEST | 49730 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:17.100682974 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.100718975 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.100894928 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.101150036 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.101170063 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.590229988 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.592499018 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.592516899 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.778815031 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.778951883 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.779023886 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.779037952 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.779119968 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.779196978 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.779206038 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.779323101 CEST | 443 | 49731 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:17.779464006 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.779813051 CEST | 49731 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:17.812412024 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:17.812470913 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:17.812561989 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:17.812817097 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:17.812834978 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.307362080 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.315116882 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:18.315150976 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538100004 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538234949 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538332939 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538402081 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:18.538431883 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538505077 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538516998 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:18.538536072 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538590908 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:18.538642883 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538897991 CEST | 443 | 49732 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:18.538974047 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:18.539303064 CEST | 49732 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:22.937983036 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:22.938013077 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:22.938086987 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:22.938385010 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:22.938397884 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.428222895 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.429900885 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:23.429924011 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577271938 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577514887 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577636003 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577696085 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:23.577707052 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577878952 CEST | 443 | 49733 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:23.577995062 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:23.578305006 CEST | 49733 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:23.602176905 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:23.602215052 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:23.602422953 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:23.602559090 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:23.602565050 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.085793972 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.089205980 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:24.089222908 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321209908 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321347952 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321424961 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:24.321444988 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321474075 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321640968 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321729898 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.321865082 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:24.321865082 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:24.321891069 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.322015047 CEST | 443 | 49734 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:24.323801994 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:24.324119091 CEST | 49734 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:28.609488964 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:28.609539032 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:28.609622002 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:28.610011101 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:28.610025883 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.067082882 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.068934917 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.068958998 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205149889 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205238104 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205275059 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205286026 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.205307961 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205348969 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.205355883 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205845118 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205892086 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205909967 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.205918074 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205944061 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.205957890 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.205965042 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.206012964 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.206655979 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.248884916 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.248908997 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.295766115 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.472121000 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.472402096 CEST | 443 | 49735 | 172.67.188.178 | 192.168.2.6 |
Aug 9, 2024 23:01:29.472487926 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.472845078 CEST | 49735 | 443 | 192.168.2.6 | 172.67.188.178 |
Aug 9, 2024 23:01:29.577930927 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:29.577965021 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:29.582683086 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:29.582683086 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:29.582725048 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.138207912 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.150506973 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:30.150518894 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341182947 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341303110 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341392040 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341460943 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341494083 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:30.341516972 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341546059 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:30.341651917 CEST | 443 | 49737 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:30.341818094 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:30.344521999 CEST | 49737 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:30.394396067 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:30.394437075 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:30.394527912 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:30.394735098 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:30.394741058 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:30.860182047 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:30.873194933 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:30.873209000 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078003883 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078118086 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078202963 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:31.078212976 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078242064 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078299999 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:31.078361988 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078540087 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078624964 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078632116 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:31.078649998 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078775883 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:31.078783989 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.078844070 CEST | 443 | 49738 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:31.079006910 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:31.079158068 CEST | 49738 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:35.516829014 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:35.516855001 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:35.516930103 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:35.517335892 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:35.517349958 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.006444931 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.009080887 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:36.009099960 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151344061 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151375055 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151398897 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151416063 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151470900 CEST | 443 | 49739 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:36.151479959 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:36.151505947 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:36.151530981 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:36.152162075 CEST | 49739 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:36.180640936 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.180679083 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.180798054 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.181039095 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.181052923 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.661516905 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.675709963 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.675724030 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787467957 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787503004 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787547112 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787574053 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787627935 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787658930 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787744045 CEST | 443 | 49740 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:36.787755013 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.787755013 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.789832115 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:36.790777922 CEST | 49740 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:41.296988964 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.297008038 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.297122955 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.297450066 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.297462940 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.839065075 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.841507912 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.841523886 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985264063 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985400915 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985493898 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985557079 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.985569954 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985615015 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.985620975 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985750914 CEST | 443 | 49741 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:41.985816956 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:41.986190081 CEST | 49741 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:42.010904074 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.010936975 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.011210918 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.011611938 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.011626005 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.499125004 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.508479118 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.508503914 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633027077 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633162022 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633219957 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.633232117 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633320093 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633414984 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633459091 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.633471966 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633519888 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.633528948 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633714914 CEST | 443 | 49742 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:42.633775949 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:42.634080887 CEST | 49742 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:47.126025915 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.126053095 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.126396894 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.126753092 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.126764059 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.657671928 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.659442902 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.659452915 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871463060 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871606112 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871697903 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871776104 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.871784925 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871814013 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.871891022 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.871932030 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.872000933 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.872009993 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.872055054 CEST | 443 | 49743 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:47.872136116 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:47.872512102 CEST | 49743 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:48.240981102 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.241019964 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.241082907 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.241352081 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.241365910 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.699888945 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.701611042 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.701631069 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834393978 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834459066 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834495068 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834506035 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.834516048 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834554911 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.834561110 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834676027 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834708929 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834726095 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.834733009 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834769964 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.834775925 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834793091 CEST | 443 | 49744 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:48.834839106 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:48.835093021 CEST | 49744 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:53.359860897 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:53.359900951 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:53.359991074 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:53.360536098 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:53.360552073 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.140505075 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.145987034 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:54.145994902 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.271761894 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.271898031 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.271961927 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:54.271970034 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.274032116 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.274096012 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:54.274101973 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.274233103 CEST | 443 | 49745 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:54.274291039 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:54.274636030 CEST | 49745 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:54.292675018 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:54.292702913 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:54.292840958 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:54.293085098 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:54.293095112 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:54.762191057 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:54.763964891 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:54.763979912 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008452892 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008619070 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008682013 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:55.008692980 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008790016 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008883953 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.008913994 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:55.008922100 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.009025097 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.009076118 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:55.009083986 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.009218931 CEST | 443 | 49746 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:01:55.009272099 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:55.009573936 CEST | 49746 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:01:59.406830072 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:59.406919003 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:59.407162905 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:59.407593966 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:59.407632113 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:59.876869917 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:01:59.879887104 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:01:59.879951954 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.003840923 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.003987074 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.004064083 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.004362106 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:00.004427910 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.004533052 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:00.004960060 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.005218029 CEST | 443 | 49747 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:00.005292892 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:00.005681038 CEST | 49747 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:00.022212982 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.022249937 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.022346973 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.022583961 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.022592068 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.614370108 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.616087914 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.616105080 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854552031 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854615927 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854657888 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854703903 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854717016 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.854732990 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854760885 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.854782104 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854830980 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854871988 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.854882002 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854923010 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.854931116 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854943991 CEST | 443 | 49748 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:00.854989052 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:00.855894089 CEST | 49748 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:05.141285896 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.141323090 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.141406059 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.141690016 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.141707897 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.619554043 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.621740103 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.621759892 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767247915 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767378092 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767465115 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767549038 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767611027 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.767627954 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767751932 CEST | 443 | 49749 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:05.767817020 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.768198967 CEST | 49749 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:05.804466009 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:05.804521084 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:05.804606915 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:05.804930925 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:05.804948092 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.283023119 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.287727118 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.287749052 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555501938 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555571079 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555612087 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555651903 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555671930 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.555686951 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555731058 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555732965 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.555773973 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555775881 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.555799007 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.555929899 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.555941105 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.556035042 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.556394100 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.556406975 CEST | 443 | 49750 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:06.556423903 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:06.556454897 CEST | 49750 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:10.938368082 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:10.938395977 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:10.938517094 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:10.938772917 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:10.938788891 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.402133942 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.404109955 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:11.404131889 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518301964 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518435001 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518487930 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:11.518500090 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518596888 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518681049 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:11.518686056 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518789053 CEST | 443 | 49751 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:11.518850088 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:11.519218922 CEST | 49751 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:11.538305044 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:11.538345098 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:11.538781881 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:11.538781881 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:11.538825989 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.016896009 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.045058966 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.045072079 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250238895 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250292063 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250334024 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250364065 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.250374079 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250387907 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.250443935 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.251169920 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.251207113 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.251235008 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.251247883 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.251315117 CEST | 443 | 49752 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:12.251394987 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.251394987 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:12.251796961 CEST | 49752 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:16.656441927 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:16.656487942 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:16.656578064 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:16.656908989 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:16.656927109 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.127821922 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.130824089 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:17.130840063 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275160074 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275284052 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275337934 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:17.275356054 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275443077 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275504112 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:17.275511980 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275630951 CEST | 443 | 49753 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:17.275692940 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:17.276096106 CEST | 49753 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:17.296720982 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:17.296761036 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:17.296833038 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:17.297099113 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:17.297110081 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:17.903621912 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:17.910645962 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:17.910666943 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045468092 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045619011 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045671940 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:18.045689106 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045785904 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045872927 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.045936108 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:18.045944929 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.046039104 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.046096087 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:18.046103001 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.046160936 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:18.046179056 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.046305895 CEST | 443 | 49754 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:18.046365976 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:18.054223061 CEST | 49754 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:22.406577110 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:22.406599045 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:22.406929016 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:22.407228947 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:22.407243967 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:22.889147043 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:22.891628027 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:22.891644955 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021106958 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021167040 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021234989 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021270990 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021323919 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:23.021342039 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021356106 CEST | 443 | 49755 | 172.67.19.24 | 192.168.2.6 |
Aug 9, 2024 23:02:23.021374941 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:23.021475077 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:23.022047997 CEST | 49755 | 443 | 192.168.2.6 | 172.67.19.24 |
Aug 9, 2024 23:02:23.131951094 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:23.131989956 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:23.132059097 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:23.134130001 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:23.134145975 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:23.615622997 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:23.655155897 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.368506908 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.368540049 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581317902 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581453085 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581558943 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581679106 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.581696033 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581804991 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581830978 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.581840992 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.581955910 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.582164049 CEST | 443 | 49756 | 188.114.96.3 | 192.168.2.6 |
Aug 9, 2024 23:02:24.582174063 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.582437992 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Aug 9, 2024 23:02:24.586442947 CEST | 49756 | 443 | 192.168.2.6 | 188.114.96.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Aug 9, 2024 23:00:52.584353924 CEST | 63450 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 9, 2024 23:00:52.592073917 CEST | 53 | 63450 | 1.1.1.1 | 192.168.2.6 |
Aug 9, 2024 23:00:53.401336908 CEST | 63917 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 9, 2024 23:00:53.412178040 CEST | 53 | 63917 | 1.1.1.1 | 192.168.2.6 |
Aug 9, 2024 23:00:58.405965090 CEST | 60789 | 53 | 192.168.2.6 | 1.1.1.1 |
Aug 9, 2024 23:00:58.416543007 CEST | 53 | 60789 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Aug 9, 2024 23:00:52.584353924 CEST | 192.168.2.6 | 1.1.1.1 | 0x2aaf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 9, 2024 23:00:53.401336908 CEST | 192.168.2.6 | 1.1.1.1 | 0x542f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Aug 9, 2024 23:00:58.405965090 CEST | 192.168.2.6 | 1.1.1.1 | 0xe83d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Aug 9, 2024 23:00:52.592073917 CEST | 1.1.1.1 | 192.168.2.6 | 0x2aaf | No error (0) | 172.67.19.24 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:52.592073917 CEST | 1.1.1.1 | 192.168.2.6 | 0x2aaf | No error (0) | 104.20.3.235 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:52.592073917 CEST | 1.1.1.1 | 192.168.2.6 | 0x2aaf | No error (0) | 104.20.4.235 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:53.412178040 CEST | 1.1.1.1 | 192.168.2.6 | 0x542f | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:53.412178040 CEST | 1.1.1.1 | 192.168.2.6 | 0x542f | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:58.416543007 CEST | 1.1.1.1 | 192.168.2.6 | 0xe83d | No error (0) | 172.67.188.178 | A (IP address) | IN (0x0001) | false | ||
Aug 9, 2024 23:00:58.416543007 CEST | 1.1.1.1 | 192.168.2.6 | 0xe83d | No error (0) | 104.21.76.57 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49721 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:00:53 UTC | 74 | OUT | |
2024-08-09 21:00:53 UTC | 222 | IN | |
2024-08-09 21:00:53 UTC | 1147 | IN | |
2024-08-09 21:00:53 UTC | 1369 | IN | |
2024-08-09 21:00:53 UTC | 1369 | IN | |
2024-08-09 21:00:53 UTC | 529 | IN | |
2024-08-09 21:00:53 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49722 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:00:53 UTC | 65 | OUT | |
2024-08-09 21:00:54 UTC | 906 | IN | |
2024-08-09 21:00:54 UTC | 463 | IN | |
2024-08-09 21:00:54 UTC | 1369 | IN | |
2024-08-09 21:00:54 UTC | 1369 | IN | |
2024-08-09 21:00:54 UTC | 1369 | IN | |
2024-08-09 21:00:54 UTC | 1369 | IN | |
2024-08-09 21:00:54 UTC | 1369 | IN | |
2024-08-09 21:00:54 UTC | 162 | IN | |
2024-08-09 21:00:54 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49723 | 172.67.188.178 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:00:58 UTC | 68 | OUT | |
2024-08-09 21:00:59 UTC | 1285 | IN | |
2024-08-09 21:00:59 UTC | 687 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49724 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:00:59 UTC | 74 | OUT | |
2024-08-09 21:00:59 UTC | 222 | IN | |
2024-08-09 21:00:59 UTC | 1147 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 1369 | IN | |
2024-08-09 21:00:59 UTC | 529 | IN | |
2024-08-09 21:00:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49725 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:00 UTC | 65 | OUT | |
2024-08-09 21:01:00 UTC | 900 | IN | |
2024-08-09 21:01:00 UTC | 469 | IN | |
2024-08-09 21:01:00 UTC | 1369 | IN | |
2024-08-09 21:01:00 UTC | 1369 | IN | |
2024-08-09 21:01:00 UTC | 1369 | IN | |
2024-08-09 21:01:00 UTC | 1369 | IN | |
2024-08-09 21:01:00 UTC | 1369 | IN | |
2024-08-09 21:01:00 UTC | 156 | IN | |
2024-08-09 21:01:00 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49727 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:05 UTC | 74 | OUT | |
2024-08-09 21:01:05 UTC | 222 | IN | |
2024-08-09 21:01:05 UTC | 1147 | IN | |
2024-08-09 21:01:05 UTC | 1369 | IN | |
2024-08-09 21:01:05 UTC | 1369 | IN | |
2024-08-09 21:01:05 UTC | 529 | IN | |
2024-08-09 21:01:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49728 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:06 UTC | 65 | OUT | |
2024-08-09 21:01:06 UTC | 898 | IN | |
2024-08-09 21:01:06 UTC | 471 | IN | |
2024-08-09 21:01:06 UTC | 1369 | IN | |
2024-08-09 21:01:06 UTC | 1369 | IN | |
2024-08-09 21:01:06 UTC | 1369 | IN | |
2024-08-09 21:01:06 UTC | 1369 | IN | |
2024-08-09 21:01:06 UTC | 1369 | IN | |
2024-08-09 21:01:06 UTC | 154 | IN | |
2024-08-09 21:01:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49729 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:11 UTC | 74 | OUT | |
2024-08-09 21:01:11 UTC | 222 | IN | |
2024-08-09 21:01:11 UTC | 1147 | IN | |
2024-08-09 21:01:11 UTC | 1369 | IN | |
2024-08-09 21:01:11 UTC | 1369 | IN | |
2024-08-09 21:01:11 UTC | 529 | IN | |
2024-08-09 21:01:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49730 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:12 UTC | 65 | OUT | |
2024-08-09 21:01:12 UTC | 902 | IN | |
2024-08-09 21:01:12 UTC | 467 | IN | |
2024-08-09 21:01:12 UTC | 1369 | IN | |
2024-08-09 21:01:12 UTC | 1369 | IN | |
2024-08-09 21:01:12 UTC | 1369 | IN | |
2024-08-09 21:01:12 UTC | 1369 | IN | |
2024-08-09 21:01:12 UTC | 1369 | IN | |
2024-08-09 21:01:12 UTC | 158 | IN | |
2024-08-09 21:01:12 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49731 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:17 UTC | 74 | OUT | |
2024-08-09 21:01:17 UTC | 222 | IN | |
2024-08-09 21:01:17 UTC | 1147 | IN | |
2024-08-09 21:01:17 UTC | 1369 | IN | |
2024-08-09 21:01:17 UTC | 1369 | IN | |
2024-08-09 21:01:17 UTC | 529 | IN | |
2024-08-09 21:01:17 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.6 | 49732 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:18 UTC | 65 | OUT | |
2024-08-09 21:01:18 UTC | 904 | IN | |
2024-08-09 21:01:18 UTC | 465 | IN | |
2024-08-09 21:01:18 UTC | 1369 | IN | |
2024-08-09 21:01:18 UTC | 1369 | IN | |
2024-08-09 21:01:18 UTC | 1369 | IN | |
2024-08-09 21:01:18 UTC | 1369 | IN | |
2024-08-09 21:01:18 UTC | 1369 | IN | |
2024-08-09 21:01:18 UTC | 160 | IN | |
2024-08-09 21:01:18 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.6 | 49733 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:23 UTC | 74 | OUT | |
2024-08-09 21:01:23 UTC | 222 | IN | |
2024-08-09 21:01:23 UTC | 1147 | IN | |
2024-08-09 21:01:23 UTC | 1369 | IN | |
2024-08-09 21:01:23 UTC | 1369 | IN | |
2024-08-09 21:01:23 UTC | 529 | IN | |
2024-08-09 21:01:23 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.6 | 49734 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:24 UTC | 65 | OUT | |
2024-08-09 21:01:24 UTC | 900 | IN | |
2024-08-09 21:01:24 UTC | 469 | IN | |
2024-08-09 21:01:24 UTC | 1369 | IN | |
2024-08-09 21:01:24 UTC | 1369 | IN | |
2024-08-09 21:01:24 UTC | 1369 | IN | |
2024-08-09 21:01:24 UTC | 1369 | IN | |
2024-08-09 21:01:24 UTC | 1369 | IN | |
2024-08-09 21:01:24 UTC | 156 | IN | |
2024-08-09 21:01:24 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.6 | 49735 | 172.67.188.178 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:29 UTC | 68 | OUT | |
2024-08-09 21:01:29 UTC | 1285 | IN | |
2024-08-09 21:01:29 UTC | 685 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN | |
2024-08-09 21:01:29 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.6 | 49737 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:30 UTC | 74 | OUT | |
2024-08-09 21:01:30 UTC | 222 | IN | |
2024-08-09 21:01:30 UTC | 1147 | IN | |
2024-08-09 21:01:30 UTC | 1369 | IN | |
2024-08-09 21:01:30 UTC | 1369 | IN | |
2024-08-09 21:01:30 UTC | 529 | IN | |
2024-08-09 21:01:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.6 | 49738 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:30 UTC | 65 | OUT | |
2024-08-09 21:01:31 UTC | 898 | IN | |
2024-08-09 21:01:31 UTC | 471 | IN | |
2024-08-09 21:01:31 UTC | 1369 | IN | |
2024-08-09 21:01:31 UTC | 1369 | IN | |
2024-08-09 21:01:31 UTC | 1369 | IN | |
2024-08-09 21:01:31 UTC | 1369 | IN | |
2024-08-09 21:01:31 UTC | 1369 | IN | |
2024-08-09 21:01:31 UTC | 154 | IN | |
2024-08-09 21:01:31 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.6 | 49739 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:36 UTC | 74 | OUT | |
2024-08-09 21:01:36 UTC | 222 | IN | |
2024-08-09 21:01:36 UTC | 1147 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 529 | IN | |
2024-08-09 21:01:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.6 | 49740 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:36 UTC | 65 | OUT | |
2024-08-09 21:01:36 UTC | 904 | IN | |
2024-08-09 21:01:36 UTC | 465 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 1369 | IN | |
2024-08-09 21:01:36 UTC | 160 | IN | |
2024-08-09 21:01:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.6 | 49741 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:41 UTC | 74 | OUT | |
2024-08-09 21:01:41 UTC | 222 | IN | |
2024-08-09 21:01:41 UTC | 1147 | IN | |
2024-08-09 21:01:41 UTC | 1369 | IN | |
2024-08-09 21:01:41 UTC | 1369 | IN | |
2024-08-09 21:01:41 UTC | 529 | IN | |
2024-08-09 21:01:41 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.6 | 49742 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:42 UTC | 65 | OUT | |
2024-08-09 21:01:42 UTC | 906 | IN | |
2024-08-09 21:01:42 UTC | 463 | IN | |
2024-08-09 21:01:42 UTC | 1369 | IN | |
2024-08-09 21:01:42 UTC | 1369 | IN | |
2024-08-09 21:01:42 UTC | 1369 | IN | |
2024-08-09 21:01:42 UTC | 1369 | IN | |
2024-08-09 21:01:42 UTC | 1369 | IN | |
2024-08-09 21:01:42 UTC | 162 | IN | |
2024-08-09 21:01:42 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.6 | 49743 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:47 UTC | 74 | OUT | |
2024-08-09 21:01:47 UTC | 222 | IN | |
2024-08-09 21:01:47 UTC | 1147 | IN | |
2024-08-09 21:01:47 UTC | 1369 | IN | |
2024-08-09 21:01:47 UTC | 1369 | IN | |
2024-08-09 21:01:47 UTC | 529 | IN | |
2024-08-09 21:01:47 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.6 | 49744 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:48 UTC | 65 | OUT | |
2024-08-09 21:01:48 UTC | 896 | IN | |
2024-08-09 21:01:48 UTC | 473 | IN | |
2024-08-09 21:01:48 UTC | 1369 | IN | |
2024-08-09 21:01:48 UTC | 1369 | IN | |
2024-08-09 21:01:48 UTC | 1369 | IN | |
2024-08-09 21:01:48 UTC | 1369 | IN | |
2024-08-09 21:01:48 UTC | 1369 | IN | |
2024-08-09 21:01:48 UTC | 152 | IN | |
2024-08-09 21:01:48 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.6 | 49745 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:54 UTC | 74 | OUT | |
2024-08-09 21:01:54 UTC | 222 | IN | |
2024-08-09 21:01:54 UTC | 1147 | IN | |
2024-08-09 21:01:54 UTC | 1369 | IN | |
2024-08-09 21:01:54 UTC | 1369 | IN | |
2024-08-09 21:01:54 UTC | 529 | IN | |
2024-08-09 21:01:54 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.6 | 49746 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:54 UTC | 65 | OUT | |
2024-08-09 21:01:55 UTC | 898 | IN | |
2024-08-09 21:01:55 UTC | 471 | IN | |
2024-08-09 21:01:55 UTC | 1369 | IN | |
2024-08-09 21:01:55 UTC | 1369 | IN | |
2024-08-09 21:01:55 UTC | 1369 | IN | |
2024-08-09 21:01:55 UTC | 1369 | IN | |
2024-08-09 21:01:55 UTC | 1369 | IN | |
2024-08-09 21:01:55 UTC | 154 | IN | |
2024-08-09 21:01:55 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.6 | 49747 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:01:59 UTC | 74 | OUT | |
2024-08-09 21:01:59 UTC | 222 | IN | |
2024-08-09 21:01:59 UTC | 1147 | IN | |
2024-08-09 21:01:59 UTC | 1369 | IN | |
2024-08-09 21:01:59 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 529 | IN | |
2024-08-09 21:02:00 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.6 | 49748 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:00 UTC | 65 | OUT | |
2024-08-09 21:02:00 UTC | 906 | IN | |
2024-08-09 21:02:00 UTC | 463 | IN | |
2024-08-09 21:02:00 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 1369 | IN | |
2024-08-09 21:02:00 UTC | 162 | IN | |
2024-08-09 21:02:00 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.6 | 49749 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:05 UTC | 74 | OUT | |
2024-08-09 21:02:05 UTC | 222 | IN | |
2024-08-09 21:02:05 UTC | 1147 | IN | |
2024-08-09 21:02:05 UTC | 1369 | IN | |
2024-08-09 21:02:05 UTC | 1369 | IN | |
2024-08-09 21:02:05 UTC | 529 | IN | |
2024-08-09 21:02:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.6 | 49750 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:06 UTC | 65 | OUT | |
2024-08-09 21:02:06 UTC | 900 | IN | |
2024-08-09 21:02:06 UTC | 469 | IN | |
2024-08-09 21:02:06 UTC | 1369 | IN | |
2024-08-09 21:02:06 UTC | 1369 | IN | |
2024-08-09 21:02:06 UTC | 1369 | IN | |
2024-08-09 21:02:06 UTC | 1369 | IN | |
2024-08-09 21:02:06 UTC | 1369 | IN | |
2024-08-09 21:02:06 UTC | 156 | IN | |
2024-08-09 21:02:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.6 | 49751 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:11 UTC | 74 | OUT | |
2024-08-09 21:02:11 UTC | 222 | IN | |
2024-08-09 21:02:11 UTC | 1147 | IN | |
2024-08-09 21:02:11 UTC | 1369 | IN | |
2024-08-09 21:02:11 UTC | 1369 | IN | |
2024-08-09 21:02:11 UTC | 529 | IN | |
2024-08-09 21:02:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.6 | 49752 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:12 UTC | 65 | OUT | |
2024-08-09 21:02:12 UTC | 920 | IN | |
2024-08-09 21:02:12 UTC | 449 | IN | |
2024-08-09 21:02:12 UTC | 1369 | IN | |
2024-08-09 21:02:12 UTC | 1369 | IN | |
2024-08-09 21:02:12 UTC | 1369 | IN | |
2024-08-09 21:02:12 UTC | 1369 | IN | |
2024-08-09 21:02:12 UTC | 1369 | IN | |
2024-08-09 21:02:12 UTC | 176 | IN | |
2024-08-09 21:02:12 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.6 | 49753 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:17 UTC | 74 | OUT | |
2024-08-09 21:02:17 UTC | 222 | IN | |
2024-08-09 21:02:17 UTC | 1147 | IN | |
2024-08-09 21:02:17 UTC | 1369 | IN | |
2024-08-09 21:02:17 UTC | 1369 | IN | |
2024-08-09 21:02:17 UTC | 529 | IN | |
2024-08-09 21:02:17 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.6 | 49754 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:17 UTC | 65 | OUT | |
2024-08-09 21:02:18 UTC | 906 | IN | |
2024-08-09 21:02:18 UTC | 463 | IN | |
2024-08-09 21:02:18 UTC | 1369 | IN | |
2024-08-09 21:02:18 UTC | 1369 | IN | |
2024-08-09 21:02:18 UTC | 1369 | IN | |
2024-08-09 21:02:18 UTC | 1369 | IN | |
2024-08-09 21:02:18 UTC | 1369 | IN | |
2024-08-09 21:02:18 UTC | 162 | IN | |
2024-08-09 21:02:18 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.6 | 49755 | 172.67.19.24 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:22 UTC | 74 | OUT | |
2024-08-09 21:02:23 UTC | 222 | IN | |
2024-08-09 21:02:23 UTC | 1147 | IN | |
2024-08-09 21:02:23 UTC | 1369 | IN | |
2024-08-09 21:02:23 UTC | 1369 | IN | |
2024-08-09 21:02:23 UTC | 529 | IN | |
2024-08-09 21:02:23 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.6 | 49756 | 188.114.96.3 | 443 | 4876 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-08-09 21:02:24 UTC | 65 | OUT | |
2024-08-09 21:02:24 UTC | 898 | IN | |
2024-08-09 21:02:24 UTC | 471 | IN | |
2024-08-09 21:02:24 UTC | 1369 | IN | |
2024-08-09 21:02:24 UTC | 1369 | IN | |
2024-08-09 21:02:24 UTC | 1369 | IN | |
2024-08-09 21:02:24 UTC | 1369 | IN | |
2024-08-09 21:02:24 UTC | 1369 | IN | |
2024-08-09 21:02:24 UTC | 154 | IN | |
2024-08-09 21:02:24 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:00:16 |
Start date: | 09/08/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfb0000 |
File size: | 9'643'376 bytes |
MD5 hash: | A7F1B43BB75327181BF5535F6EAB329D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 17:00:18 |
Start date: | 09/08/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xed0000 |
File size: | 42'064 bytes |
MD5 hash: | 5D4073B2EB6D217C19F2B22F21BF8D57 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 8 |
Start time: | 17:01:02 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 17:01:02 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 17:01:16 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 17:01:16 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 17:01:24 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 17:01:24 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 17:01:37 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 15 |
Start time: | 17:01:37 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 16 |
Start time: | 17:01:45 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 17 |
Start time: | 17:01:45 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 18 |
Start time: | 17:01:53 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 19 |
Start time: | 17:01:53 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 17:02:07 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 17:02:07 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 17:02:15 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d1ec0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 17:02:15 |
Start date: | 09/08/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 18.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 9.4% |
Total number of Nodes: | 96 |
Total number of Limit Nodes: | 6 |
Graph
Function 07311C57 Relevance: 5.6, Instructions: 5643COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07311C70 Relevance: 5.6, Instructions: 5633COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07221D58 Relevance: 5.2, Instructions: 5170COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073210ED Relevance: 3.2, Instructions: 3173COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918BA60 Relevance: 2.7, Strings: 2, Instructions: 182COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09184100 Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732BEA0 Relevance: 1.7, APIs: 1, Instructions: 153memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091840F0 Relevance: 1.4, Strings: 1, Instructions: 171COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732B048 Relevance: 1.4, Strings: 1, Instructions: 150COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2A3C8 Relevance: 1.0, Instructions: 1003COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05E7A794 Relevance: 1.0, Instructions: 1001COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D29778 Relevance: .9, Instructions: 895COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05E72488 Relevance: .6, Instructions: 596COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05E72479 Relevance: .6, Instructions: 585COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0722B6F5 Relevance: .3, Instructions: 339COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918F338 Relevance: .3, Instructions: 336COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732EBAA Relevance: .3, Instructions: 314COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091867EC Relevance: .3, Instructions: 293COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732EC4A Relevance: .3, Instructions: 280COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732EC60 Relevance: .3, Instructions: 278COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732CC49 Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732CC58 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09185B70 Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732D380 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09185858 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09185868 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732DD50 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731A6E8 Relevance: 1.7, Strings: 1, Instructions: 446COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918E160 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918CF98 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918DED8 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09183FF0 Relevance: 1.6, APIs: 1, Instructions: 57memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07229660 Relevance: 1.6, APIs: 1, Instructions: 56fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732BF68 Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09183FF8 Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918D668 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA09C9 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09186733 Relevance: 1.5, APIs: 1, Instructions: 49windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0918E3E8 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA09D0 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091866B8 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D29268 Relevance: 1.5, Strings: 1, Instructions: 230COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B480 Relevance: 1.3, Strings: 1, Instructions: 91COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D290BF Relevance: 1.3, Strings: 1, Instructions: 78COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B5A0 Relevance: .8, Instructions: 787COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07310007 Relevance: .6, Instructions: 593COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07310040 Relevance: .6, Instructions: 561COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07319F96 Relevance: .5, Instructions: 452COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731AC51 Relevance: .4, Instructions: 434COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07319380 Relevance: .4, Instructions: 366COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731A6D7 Relevance: .3, Instructions: 345COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731A004 Relevance: .3, Instructions: 331COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731A047 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07319337 Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2A4C9 Relevance: .3, Instructions: 273COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07319370 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C948 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26068 Relevance: .3, Instructions: 262COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26057 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C60C Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D28E70 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B211 Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D28CF9 Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24778 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B050 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073109FF Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C4D3 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D278C0 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07310A18 Relevance: .1, Instructions: 92COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D278D0 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24D70 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2B398 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C50F Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C520 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24F20 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D267F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C9D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C9D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24D5F Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D267E8 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24F30 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26A68 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C9D005 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731C4CF Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D29D90 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D25EF0 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26A5A Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D25EF8 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26B34 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C9D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D28878 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D27A28 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D20838 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A7D7CD Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D28868 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D26980 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D20848 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A7D7CC Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D24610 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 073191F0 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731FEB1 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D245BA Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D245C8 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D2C1D5 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D29509 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0731FEC8 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D29518 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732FAF8 Relevance: 1.5, Strings: 1, Instructions: 205COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732FB08 Relevance: 1.5, Strings: 1, Instructions: 202COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07320040 Relevance: .7, Instructions: 724COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07320006 Relevance: .6, Instructions: 574COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05E7C368 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DA0368 Relevance: .3, Instructions: 298COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0722CC8B Relevance: .3, Instructions: 275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0722CC88 Relevance: .3, Instructions: 273COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0722CC98 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091896C8 Relevance: .2, Instructions: 250COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0722CCE3 Relevance: .2, Instructions: 245COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091808D8 Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091808E8 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09180012 Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09180330 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09180040 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09181805 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091806A0 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09180D08 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091806B0 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09180D18 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09181860 Relevance: .1, Instructions: 106COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0732C018 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09184A30 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09188508 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091843A0 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09189DF8 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09185098 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09184390 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 091884F8 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018425D4 Relevance: .5, Instructions: 513COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841648 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841658 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018408DD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018408E6 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841C90 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018408F9 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018414F0 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01840848 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841CC0 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841752 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01840957 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018429F8 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 018417E8 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01841C50 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|