Windows
Analysis Report
QT2hJT3Syn.exe
Overview
General Information
Sample name: | QT2hJT3Syn.exerenamed because original name is a hash value |
Original sample name: | 9bfd61a00155017d1a6768326549c65ea9bbe8884b92a7a013e97b507a9167ff.exe |
Analysis ID: | 1508523 |
MD5: | d19f3280851b5e9510a63fe7c80466ae |
SHA1: | 00e04653569a6d8244edff8765deec3d6ed9c15f |
SHA256: | 9bfd61a00155017d1a6768326549c65ea9bbe8884b92a7a013e97b507a9167ff |
Tags: | 116-198-231-169exe |
Infos: | |
Detection
Score: | 92 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- QT2hJT3Syn.exe (PID: 6588 cmdline:
"C:\Users\ user\Deskt op\QT2hJT3 Syn.exe" MD5: D19F3280851B5E9510A63FE7C80466AE) - WerFault.exe (PID: 6108 cmdline:
C:\Windows \system32\ WerFault.e xe -u -p 6 588 -s 138 8 MD5: FD27D9F6D02763BDE32511B5DF7FF7A0)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Cobalt Strike, CobaltStrike | Cobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit.The Beacon implant has become popular amongst targeted attackers and criminal users as it is well written, stable, and highly customizable. |
{"C2Server": "http://116.198.231.169:63222/jquery-3.7.2.min.js", "User Agent": "User-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko\r\n"}
{"Headers": "Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8\r\nAccept-Language: en-US,en;q=0.5\r\nReferer: http://www.microsoft.com/\r\nAccept-Encoding: gzip, deflate\r\nUser-Agent: Mozilla/5.0 (Windows NT 6.3; Trident/7.0; rv:11.0) like Gecko\r\n", "Type": "Metasploit Download", "URL": "http://116.198.231.169/jquery-3.7.2.min.js"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Metasploit_7bc0f998 | Identifies the API address lookup function leverage by metasploit shellcode | unknown |
| |
Windows_Trojan_Metasploit_c9773203 | Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_MetasploitPayload_3 | Yara detected Metasploit Payload | Joe Security | ||
JoeSecurity_CobaltStrike_3 | Yara detected CobaltStrike | Joe Security | ||
Windows_Trojan_Metasploit_7bc0f998 | Identifies the API address lookup function leverage by metasploit shellcode | unknown |
| |
Windows_Trojan_Metasploit_c9773203 | Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. | unknown |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-10T10:58:45.805295+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49730 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:49.904119+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49733 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:54.035146+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49736 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:58.765949+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49741 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:02.875405+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49748 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:06.930846+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49751 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:10.998546+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49754 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:15.034083+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49757 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:19.109811+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49760 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:23.134618+0200 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49763 | 116.198.231.169 | 63222 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Static PE information: |
Networking |
---|
Source: | URLs: | ||
Source: | URLs: |
Source: | TCP traffic: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FF7D9953EB0 | |
Source: | Code function: | 0_2_00007FF7D9952DC0 | |
Source: | Code function: | 0_2_00007FF7D99525E0 | |
Source: | Code function: | 0_2_00007FF7D9954360 | |
Source: | Code function: | 0_2_00007FF7D9952A60 | |
Source: | Code function: | 0_2_000000995739EB60 |
Source: | Process created: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_000000995739EDDB | |
Source: | Code function: | 0_2_000000995739EDDB |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00007FF7D9952038 |
Source: | Code function: | 0_2_00007FF7D9952038 | |
Source: | Code function: | 0_2_00007FF7D995221C |
Source: | Code function: | 0_2_00007FF7D995228C |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 1 Process Injection | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 1 DLL Side-Loading | LSASS Memory | 21 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | 2 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Win64.Backdoor.Cobeacon | ||
31% | Virustotal | Browse | ||
100% | Avira | TR/AD.PatchedWinSwrort.uidrr |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
116.198.231.169 | unknown | China | 137699 | CHINATELECOM-JIANGSU-SUQIAN-IDCCHINATELECOMJiangsuSuqian | true |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1508523 |
Start date and time: | 2024-09-10 10:57:41 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Run with higher sleep bypass |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | QT2hJT3Syn.exerenamed because original name is a hash value |
Original Sample Name: | 9bfd61a00155017d1a6768326549c65ea9bbe8884b92a7a013e97b507a9167ff.exe |
Detection: | MAL |
Classification: | mal92.troj.winEXE@2/5@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.168.117.173
- Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, ocsp.digicert.com, slscr.update.microsoft.com, login.live.com, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryValueKey calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
116.198.231.169 | Get hash | malicious | CobaltStrike, Metasploit | Browse | ||
Get hash | malicious | CobaltStrike, Metasploit | Browse | |||
Get hash | malicious | CobaltStrike, Metasploit | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CHINATELECOM-JIANGSU-SUQIAN-IDCCHINATELECOMJiangsuSuqian | Get hash | malicious | CobaltStrike, Metasploit | Browse |
| |
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_QT2hJT3Syn.exe_9773be4c1fb0eae18060de5a34e28b4a9399aa1_f3ab7727_a77f3ba9-fb32-4995-93cb-c27340063859\Report.wer
Download File
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.9839308801033855 |
Encrypted: | false |
SSDEEP: | 192:8eg4X6S50I3D8jfP+PzuiFr9Z24lO8TU:PXKSaI3D8jwzuiFr9Y4lO8TU |
MD5: | A33B898C59EC7EB478EF533F18A8023E |
SHA1: | 7667B449A892B9A1F10030B31A3697D2D3C17938 |
SHA-256: | C0FB1A4CA40558DAA9DEA896479ED2C97B0930F18DCEB149BC869A586B52A17C |
SHA-512: | 2B40290B5E3B5CDA6E63616BB51224D21984B7F0E7DEB12C7A3181F09AEE51A05446B0D95EC7C038735ED91289D6AAC6D163B40665DC7AB099B11155D77DB9B5 |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 154972 |
Entropy (8bit): | 1.4614159444920982 |
Encrypted: | false |
SSDEEP: | 384:TqodCVjVSIRA6iv+gebrQ4UbLp/4O8f80yStE/GYSFW2exnCPT:TqodCZep/4O8fzF8xCL |
MD5: | 391E934405B2E7B61E8B8DC4E21F7775 |
SHA1: | 91C5369017A2022CA8513F5F84F460F2C343BCDE |
SHA-256: | 988FEA3CE4F51007599A45D82064D4394E4B950A21E73D948463AEFA59F929FA |
SHA-512: | C4E989F32068B2EC9D018398456BBE029BB7F49DF86ED1E7B3612AB43295E86E2AB99D999D0879F1E007D5EA449006B4B31A16527537A2D4B326C73B45A7808C |
Malicious: | false |
Yara Hits: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10230 |
Entropy (8bit): | 3.7202987326664974 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJ8WC6Y9dRJc9gmfOTpDa89bkCVf0cgNsm:R6lXJNC6Y/RJc9gmfOVkofXC |
MD5: | DEA7C9252430F5455C9DEBF74C678AF4 |
SHA1: | 517A1B8EE134408400001D44DCD6A9E808CB0143 |
SHA-256: | F5F6C0B1B958216E20189890A5FA5772A3C35676BB1EAD6E91EE594DB5296576 |
SHA-512: | 86936902079B5E6B9E2065770A8A0BA9DEB2A9A677C84CBD5EEB03C55069DBE5B45341B5C9DEC63DED740F6DB478FF0B9414581510ABDF9B4F05696474F92882 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4693 |
Entropy (8bit): | 4.506143139180314 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsJJg771I9YDWpW8VYXYm8M4JYqQOKFEJyq85dpQOYlkFR/+d:uIjfbI7jy7VPJBQQJAQrlkFN+d |
MD5: | A0C5450FCCD1F696127AC8FF8257B812 |
SHA1: | 2B6ABEC9C569C41F8FC58ADCCEF10C63F8414B81 |
SHA-256: | 72E2A0F5769C553AE01165F819FF4261B64CCF331F44BDC90529A4873F9A0008 |
SHA-512: | 6768B7AC8394CBF3FA20C48CFE4753528C789DCA62C8DAA92B0299C7D117F415521BDD5C5233DBCF12CB354934546D8EF24BA1BB88C60622B79150A5B80B6390 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.465918874888848 |
Encrypted: | false |
SSDEEP: | 6144:8IXfpi67eLPU9skLmb0b48WSPKaJG8nAgejZMMhA2gX4WABl0uNrdwBCswSb5:BXD948WlLZMM6YFHB+5 |
MD5: | DB3FF01C4A73A5EBCB34B0CB83E90F52 |
SHA1: | 859E353862D6D2C94C0D5D585B8106742197B435 |
SHA-256: | 78B26CE99D43E6EDAE850A36BB3ECE413B2330B281BB70EB3F33385F459BBB19 |
SHA-512: | E6FF7F07FDEBD52B324EB2E52E8E59AA402804624322AC9D4B5E53383DAB1F8EC8D402591348C80BFFC32FB82F235F09DCB9A4E5D25FAFA916035D9999DB6A13 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.269430115749708 |
TrID: |
|
File name: | QT2hJT3Syn.exe |
File size: | 67'584 bytes |
MD5: | d19f3280851b5e9510a63fe7c80466ae |
SHA1: | 00e04653569a6d8244edff8765deec3d6ed9c15f |
SHA256: | 9bfd61a00155017d1a6768326549c65ea9bbe8884b92a7a013e97b507a9167ff |
SHA512: | 78650af411cfc8a1a1cf05a2538454fa5de7b3c6b6d80eef0193b1d3270389f69f998f1e80768f949167b6075aca1fd70be22b006e11fbd63a725c4097b3a99a |
SSDEEP: | 1536:mWHMTN/JJ86S4oqiEcpI6rAz/saT4c6WuC0J8:mWIJ8L1U/T4c6W70J8 |
TLSH: | D963BF9A7B428CFEE95613388123A49EF3F27C111B22ABFF47C601552D633D96C7A650 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Q...Q...Q...X.N.].......R.......X.......H.......W.......T...Q.......B...P...B...R...B...P...RichQ...................PE..d.. |
Icon Hash: | 0729494959591b1e |
Entrypoint: | 0x140001cf4 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66B5A165 [Fri Aug 9 04:56:05 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 6102f16ed129485447b57b8b35734f82 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F2414B207A4h |
dec eax |
add esp, 28h |
jmp 00007F2414B2008Fh |
int3 |
int3 |
jmp 00007F2414B209D6h |
int3 |
int3 |
int3 |
dec eax |
and dword ptr [ecx+10h], 00000000h |
dec eax |
lea eax, dword ptr [00004664h] |
dec eax |
mov dword ptr [ecx+08h], eax |
dec eax |
lea eax, dword ptr [00004649h] |
dec eax |
mov dword ptr [ecx], eax |
dec eax |
mov eax, ecx |
ret |
int3 |
int3 |
dec eax |
sub esp, 48h |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007F2414B201E7h |
dec eax |
lea edx, dword ptr [000091C3h] |
dec eax |
lea ecx, dword ptr [esp+20h] |
call 00007F2414B208F8h |
int3 |
dec eax |
mov dword ptr [esp+10h], ebx |
dec eax |
mov dword ptr [esp+18h], esi |
push ebp |
push edi |
inc ecx |
push esi |
dec eax |
mov ebp, esp |
dec eax |
sub esp, 10h |
xor eax, eax |
xor ecx, ecx |
cpuid |
inc esp |
mov eax, ecx |
inc esp |
mov edx, edx |
inc ecx |
xor edx, 49656E69h |
inc ecx |
xor eax, 6C65746Eh |
inc esp |
mov ecx, ebx |
inc esp |
mov esi, eax |
xor ecx, ecx |
mov eax, 00000001h |
cpuid |
inc ebp |
or edx, eax |
mov dword ptr [ebp-10h], eax |
inc ecx |
xor ecx, 756E6547h |
mov dword ptr [ebp-0Ch], ebx |
inc ebp |
or edx, ecx |
mov dword ptr [ebp-08h], ecx |
mov edi, ecx |
mov dword ptr [ebp-04h], edx |
jne 00007F2414B2026Dh |
dec eax |
or dword ptr [0000A26Dh], FFFFFFFFh |
and eax, 0FFF3FF0h |
dec eax |
mov dword ptr [00000055h], 00000000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xaff4 | 0xf0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xf000 | 0x56ec | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0xd000 | 0x438 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0x70 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xa3b0 | 0x38 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xa270 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x6000 | 0x290 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4584 | 0x4600 | d031826de6e0e6fb9ccc321e78e11d07 | False | 0.5434151785714286 | data | 6.374369452326817 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x6000 | 0x5bc4 | 0x5c00 | d9c437122c60c894b2f54adf5a7e1a71 | False | 0.6548488451086957 | data | 7.210114059723916 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xc000 | 0x200 | 0x200 | 59db9f2a508b239ec802e9d0119966a6 | False | 0.26171875 | DOS executable (block device driver \377\377\377\377\377\377) | 2.224911641545331 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0xd000 | 0x438 | 0x600 | 221a3fb74e87cf68c7ec77be366c615c | False | 0.3580729166666667 | data | 3.1722964215356337 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0x70 | 0x200 | 81c0371bb37172bdb766a9f4233486e2 | False | 0.224609375 | data | 1.3216181203289816 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.rsrc | 0xf000 | 0x56ec | 0x5800 | 568a6f175845f6ba67d1ccd2ac08b100 | False | 0.9483753551136364 | data | 7.839562838980695 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xf2a8 | 0x2ec | PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced | 1.0147058823529411 | ||
RT_ICON | 0xf594 | 0x592 | PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced | 1.0077138849929874 | ||
RT_ICON | 0xfb28 | 0x8f4 | PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced | 1.0047993019197208 | ||
RT_ICON | 0x1041c | 0x156d | PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced | 1.0020054694621696 | ||
RT_ICON | 0x1198c | 0x324 | PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced | 1.013681592039801 | ||
RT_ICON | 0x11cb0 | 0x60c | PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced | 1.0071059431524547 | ||
RT_ICON | 0x122bc | 0x998 | PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced | 1.0044788273615635 | ||
RT_ICON | 0x12c54 | 0x16b3 | PNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced | 1.0018929616245051 | ||
RT_GROUP_ICON | 0x14308 | 0x3e | data | 0.8709677419354839 | ||
RT_GROUP_ICON | 0x14348 | 0x3e | data | 0.8870967741935484 | ||
RT_VERSION | 0x14388 | 0x364 | data | English | United States | 0.5483870967741935 |
DLL | Import |
---|---|
KERNEL32.dll | HeapCreate, WaitForSingleObject, Sleep, LoadLibraryA, CreateThread, HeapAlloc, GetModuleHandleW, IsProcessorFeaturePresent, GetStartupInfoW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, IsDebuggerPresent, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, QueryPerformanceCounter |
USER32.dll | MessageBoxW |
MSVCP140.dll | ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAV01@AEAV01@@Z@Z, ?good@ios_base@std@@QEBA_NXZ, ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ, ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z, ?uncaught_exception@std@@YA_NXZ, ?cout@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A, ?_Xlength_error@std@@YAXPEBD@Z, ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ?put@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@D@Z, ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ, ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z |
VCRUNTIME140_1.dll | __CxxFrameHandler4 |
VCRUNTIME140.dll | __current_exception, _CxxThrowException, __current_exception_context, memcpy, __C_specific_handler, __std_exception_copy, __std_exception_destroy, __std_terminate, memset, memchr |
api-ms-win-crt-string-l1-1-0.dll | isalnum, strcmp |
api-ms-win-crt-runtime-l1-1-0.dll | _initterm_e, _initterm, _register_thread_local_exe_atexit_callback, terminate, _c_exit, _set_app_type, exit, _exit, _seh_filter_exe, _get_narrow_winmain_command_line, _crt_atexit, _register_onexit_function, _initialize_onexit_table, _initialize_narrow_environment, _configure_narrow_argv, _invalid_parameter_noinfo_noreturn, _cexit |
api-ms-win-crt-heap-l1-1-0.dll | free, _set_new_mode, malloc, _callnewh |
api-ms-win-crt-math-l1-1-0.dll | __setusermatherr |
api-ms-win-crt-stdio-l1-1-0.dll | _set_fmode, __p__commode |
api-ms-win-crt-locale-l1-1-0.dll | _configthreadlocale |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-10T10:58:45.805295+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49730 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:49.904119+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49733 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:54.035146+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49736 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:58:58.765949+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49741 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:02.875405+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49748 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:06.930846+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49751 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:10.998546+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49754 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:15.034083+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49757 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:19.109811+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49760 | 116.198.231.169 | 63222 | TCP |
2024-09-10T10:59:23.134618+0200 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49763 | 116.198.231.169 | 63222 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 10, 2024 10:58:43.758131981 CEST | 49730 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:43.764611006 CEST | 63222 | 49730 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:43.764699936 CEST | 49730 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:43.794102907 CEST | 49730 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:43.799022913 CEST | 63222 | 49730 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:45.805049896 CEST | 63222 | 49730 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:45.805294991 CEST | 49730 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:45.805345058 CEST | 49730 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:45.808933020 CEST | 49731 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:45.810237885 CEST | 63222 | 49730 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:45.813857079 CEST | 63222 | 49731 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:45.813951969 CEST | 49731 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:45.814260006 CEST | 49731 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:45.819109917 CEST | 63222 | 49731 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.872833014 CEST | 63222 | 49731 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.873039007 CEST | 49731 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.873867989 CEST | 49731 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.876543999 CEST | 49732 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.879692078 CEST | 63222 | 49731 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.882460117 CEST | 63222 | 49732 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.882554054 CEST | 49732 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.882685900 CEST | 49732 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.888441086 CEST | 49733 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.889218092 CEST | 63222 | 49732 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.889324903 CEST | 49732 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.894175053 CEST | 63222 | 49733 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:47.894270897 CEST | 49733 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.894575119 CEST | 49733 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:47.900820017 CEST | 63222 | 49733 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:49.902786016 CEST | 63222 | 49733 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:49.904119015 CEST | 49733 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:49.904270887 CEST | 49733 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:49.909096956 CEST | 63222 | 49733 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:49.911626101 CEST | 49734 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:49.916635036 CEST | 63222 | 49734 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:49.916728973 CEST | 49734 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:49.917155027 CEST | 49734 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:49.921955109 CEST | 63222 | 49734 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.932179928 CEST | 63222 | 49734 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.932280064 CEST | 49734 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.932456017 CEST | 49734 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.935085058 CEST | 49735 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.938368082 CEST | 63222 | 49734 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.940850019 CEST | 63222 | 49735 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.940932989 CEST | 49735 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.941056967 CEST | 49735 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.944641113 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.946450949 CEST | 63222 | 49735 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.946517944 CEST | 49735 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.949587107 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:51.949978113 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.949978113 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:51.955117941 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.035084009 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.035145998 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.035249949 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.039737940 CEST | 49737 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.337465048 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.361259937 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.361304998 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.683594942 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.683643103 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.691303015 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.691422939 CEST | 63222 | 49737 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.691497087 CEST | 49737 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.691737890 CEST | 63222 | 49736 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:54.691773891 CEST | 49736 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.691962957 CEST | 49737 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:54.696837902 CEST | 63222 | 49737 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.699539900 CEST | 63222 | 49737 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.699625015 CEST | 49737 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.699693918 CEST | 49737 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.702323914 CEST | 49740 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.704504013 CEST | 63222 | 49737 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.707171917 CEST | 63222 | 49740 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.707237959 CEST | 49740 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.707395077 CEST | 49740 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.712131023 CEST | 49741 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.712840080 CEST | 63222 | 49740 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.712881088 CEST | 49740 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.716969967 CEST | 63222 | 49741 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:56.717044115 CEST | 49741 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.717350006 CEST | 49741 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:56.722222090 CEST | 63222 | 49741 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:58.765882015 CEST | 63222 | 49741 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:58.765949011 CEST | 49741 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:58.766026974 CEST | 49741 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:58.766525030 CEST | 49745 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:58.770963907 CEST | 63222 | 49741 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:58.771466017 CEST | 63222 | 49745 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:58:58.771534920 CEST | 49745 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:58.771795034 CEST | 49745 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:58:58.776650906 CEST | 63222 | 49745 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.832192898 CEST | 63222 | 49745 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.832271099 CEST | 49745 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.832365036 CEST | 49745 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.833012104 CEST | 49747 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.837419033 CEST | 63222 | 49745 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.838108063 CEST | 63222 | 49747 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.838538885 CEST | 49747 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.838646889 CEST | 49747 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.840727091 CEST | 49748 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.843666077 CEST | 63222 | 49747 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.843720913 CEST | 49747 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.845738888 CEST | 63222 | 49748 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:00.845798969 CEST | 49748 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.846127033 CEST | 49748 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:00.851494074 CEST | 63222 | 49748 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:02.875322104 CEST | 63222 | 49748 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:02.875405073 CEST | 49748 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:02.875494003 CEST | 49748 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:02.876707077 CEST | 49749 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:02.880296946 CEST | 63222 | 49748 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:02.882599115 CEST | 63222 | 49749 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:02.882678032 CEST | 49749 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:02.882960081 CEST | 49749 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:02.887773037 CEST | 63222 | 49749 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.886533976 CEST | 63222 | 49749 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.886703968 CEST | 49749 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.886807919 CEST | 49749 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.887306929 CEST | 49750 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.891625881 CEST | 63222 | 49749 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.892127037 CEST | 63222 | 49750 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.892210007 CEST | 49750 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.892318010 CEST | 49750 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.894712925 CEST | 49751 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.897375107 CEST | 63222 | 49750 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.897455931 CEST | 49750 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.899703979 CEST | 63222 | 49751 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:04.899806976 CEST | 49751 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.900156021 CEST | 49751 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:04.905044079 CEST | 63222 | 49751 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:06.930447102 CEST | 63222 | 49751 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:06.930845976 CEST | 49751 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:06.931231022 CEST | 49751 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:06.934432983 CEST | 49752 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:06.936003923 CEST | 63222 | 49751 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:06.939294100 CEST | 63222 | 49752 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:06.939366102 CEST | 49752 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:06.939646006 CEST | 49752 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:06.946193933 CEST | 63222 | 49752 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.965465069 CEST | 63222 | 49752 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.965533972 CEST | 49752 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.965632915 CEST | 49752 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.968099117 CEST | 49753 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.971379995 CEST | 63222 | 49752 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.974172115 CEST | 63222 | 49753 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.974338055 CEST | 49753 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.974338055 CEST | 49753 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.978257895 CEST | 49754 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.979873896 CEST | 63222 | 49753 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.980103016 CEST | 63222 | 49753 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.980156898 CEST | 49753 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.983679056 CEST | 63222 | 49754 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:08.983751059 CEST | 49754 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.984019041 CEST | 49754 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:08.989511013 CEST | 63222 | 49754 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:10.997436047 CEST | 63222 | 49754 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:10.998545885 CEST | 49754 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:10.998631954 CEST | 49754 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:10.999223948 CEST | 49755 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:11.003457069 CEST | 63222 | 49754 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:11.004076958 CEST | 63222 | 49755 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:11.004259109 CEST | 49755 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:11.004523039 CEST | 49755 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:11.009325981 CEST | 63222 | 49755 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.006623030 CEST | 63222 | 49755 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.009548903 CEST | 49755 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.009629965 CEST | 49755 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.014522076 CEST | 63222 | 49755 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.022764921 CEST | 49756 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.028240919 CEST | 63222 | 49756 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.028322935 CEST | 49756 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.028503895 CEST | 49756 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.030687094 CEST | 49757 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.034523964 CEST | 63222 | 49756 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.034580946 CEST | 49756 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.035706997 CEST | 63222 | 49757 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:13.035763979 CEST | 49757 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.036000013 CEST | 49757 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:13.041086912 CEST | 63222 | 49757 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:15.033972979 CEST | 63222 | 49757 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:15.034082890 CEST | 49757 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:15.034157991 CEST | 49757 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:15.036770105 CEST | 49758 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:15.039926052 CEST | 63222 | 49757 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:15.044568062 CEST | 63222 | 49758 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:15.044646978 CEST | 49758 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:15.044976950 CEST | 49758 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:15.049789906 CEST | 63222 | 49758 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.057945013 CEST | 63222 | 49758 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.058547974 CEST | 49758 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.063710928 CEST | 49758 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.068033934 CEST | 49759 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.069633961 CEST | 63222 | 49758 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.072936058 CEST | 63222 | 49759 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.074572086 CEST | 49759 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.074695110 CEST | 49759 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.076956034 CEST | 49760 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.079726934 CEST | 63222 | 49759 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.081867933 CEST | 63222 | 49760 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:17.081948996 CEST | 49759 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.081984043 CEST | 49760 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.082261086 CEST | 49760 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:17.087032080 CEST | 63222 | 49760 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:19.104685068 CEST | 63222 | 49760 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:19.109811068 CEST | 49760 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:19.109885931 CEST | 49760 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:19.112216949 CEST | 49761 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:19.114890099 CEST | 63222 | 49760 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:19.117077112 CEST | 63222 | 49761 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:19.122566938 CEST | 49761 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:19.122898102 CEST | 49761 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:19.127803087 CEST | 63222 | 49761 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.112323046 CEST | 63222 | 49761 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.112386942 CEST | 49761 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.112624884 CEST | 49761 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.114809036 CEST | 49762 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.117465019 CEST | 63222 | 49761 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.119664907 CEST | 63222 | 49762 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.119745016 CEST | 49762 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.119862080 CEST | 49762 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.124620914 CEST | 49763 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.125508070 CEST | 63222 | 49762 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.125562906 CEST | 49762 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.129520893 CEST | 63222 | 49763 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:21.129592896 CEST | 49763 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.129798889 CEST | 49763 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:21.134906054 CEST | 63222 | 49763 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:23.134493113 CEST | 63222 | 49763 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:23.134618044 CEST | 49763 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:23.134712934 CEST | 49763 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:23.137036085 CEST | 49764 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:23.140155077 CEST | 63222 | 49763 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:23.142083883 CEST | 63222 | 49764 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:23.142164946 CEST | 49764 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:23.142474890 CEST | 49764 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:23.147934914 CEST | 63222 | 49764 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:25.155025959 CEST | 63222 | 49764 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:25.156979084 CEST | 49764 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:25.157080889 CEST | 49764 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:25.159776926 CEST | 49765 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:25.161973000 CEST | 63222 | 49764 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:25.164700985 CEST | 63222 | 49765 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:25.164808989 CEST | 49765 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:25.164947033 CEST | 49765 | 63222 | 192.168.2.4 | 116.198.231.169 |
Sep 10, 2024 10:59:25.170629978 CEST | 63222 | 49765 | 116.198.231.169 | 192.168.2.4 |
Sep 10, 2024 10:59:25.172998905 CEST | 49765 | 63222 | 192.168.2.4 | 116.198.231.169 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:58:37 |
Start date: | 10/09/2024 |
Path: | C:\Users\user\Desktop\QT2hJT3Syn.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d9950000 |
File size: | 67'584 bytes |
MD5 hash: | D19F3280851B5E9510A63FE7C80466AE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 04:59:24 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\WerFault.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff753dc0000 |
File size: | 570'736 bytes |
MD5 hash: | FD27D9F6D02763BDE32511B5DF7FF7A0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 13.4% |
Dynamic/Decrypted Code Coverage: | 8.3% |
Signature Coverage: | 30.8% |
Total number of Nodes: | 266 |
Total number of Limit Nodes: | 6 |
Graph
Callgraph
Function 00007FF7D9953EB0 Relevance: 37.1, APIs: 17, Strings: 4, Instructions: 302memorysleeplibraryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000000995739EB7F Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 99networkCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 000000995739EB26 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 56librarynetworkCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7D995228C Relevance: 6.0, APIs: 4, Instructions: 39timethreadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7D99525E0 Relevance: 4.8, APIs: 2, Strings: 1, Instructions: 294COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7D995221C Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7D9951260 Relevance: 16.0, APIs: 8, Strings: 1, Instructions: 217COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|