Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7640 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 6D42583DE8CB7222D51B9E5976AB2ED2) - InstallUtil.exe (PID: 7848 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Ins tallUtil.e xe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57)
- cmd.exe (PID: 6632 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\V olrhw1xPk7 ixUGFUQh9l CFk.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6768 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 604 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\L kpj4eLKYuR L6LrNltOgK 200.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 340 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 1372 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\V Kr8Efnr4Ph daHsuTmp4w B4v.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3832 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 2844 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\J G3bSh7wTLa 4W4VZ8WnUK E9x.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 2752 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 8144 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\J Wq659NA2Oq tOCxKRUrX3 Wvt.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 8152 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 6484 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\U MHO1eaoah7 nvsSNcEMZS aPH.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5160 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 3200 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\Y bsrj9OwOR4 A6LpqK3nX4 c7P.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1580 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cmd.exe (PID: 5920 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Roami ng\Microso ft\Windows \Start Men u\Programs \Startup\B 7apkUpVBoY MsvQw8GBJa P4b.bat" " MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4916 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DarkTortilla | DarkTortilla is a complex and highly configurable .NET-based crypter that has possibly been active since at least August 2015. It typically delivers popular information stealers and remote access trojans (RATs) such as AgentTesla, AsyncRat, NanoCore, and RedLine. While it appears to primarily deliver commodity malware, Secureworks Counter Threat Unit (CTU) researchers identified DarkTortilla samples delivering targeted payloads such as Cobalt Strike and Metasploit. It can also deliver "addon packages" such as additional malicious payloads, benign decoy documents, and executables. It features robust anti-analysis and anti-tamper controls that can make detection, analysis, and eradication challenging.From January 2021 through May 2022, an average of 93 unique DarkTortilla samples per week were uploaded to the VirusTotal analysis service. Code similarities suggest possible links between DarkTortilla and other malware: a crypter operated by the RATs Crew threat group, which was active between 2008 and 2012, and the Gameloader malware that emerged in 2021. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_AntiVM_3 | Yara detected AntiVM_3 | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
JoeSecurity_DarkTortilla | Yara detected DarkTortilla Crypter | Joe Security | ||
Click to see the 1 entries |
Data Obfuscation |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | DNS query: |
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: | ||
Source: | File created: |
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_07B4A478 |
Source: | Code function: | 0_2_012C29B0 | |
Source: | Code function: | 0_2_012C6C2D | |
Source: | Code function: | 0_2_012C3118 | |
Source: | Code function: | 0_2_012C366B | |
Source: | Code function: | 0_2_0575D16C | |
Source: | Code function: | 0_2_05811C00 | |
Source: | Code function: | 0_2_05811BD0 | |
Source: | Code function: | 0_2_05810013 | |
Source: | Code function: | 0_2_05810040 | |
Source: | Code function: | 0_2_05ED4E58 | |
Source: | Code function: | 0_2_05EDFA00 | |
Source: | Code function: | 0_2_05EDFA10 | |
Source: | Code function: | 0_2_076D3FB0 | |
Source: | Code function: | 0_2_076DFD68 | |
Source: | Code function: | 0_2_076DFD78 | |
Source: | Code function: | 0_2_076DFB40 | |
Source: | Code function: | 0_2_076DFB30 | |
Source: | Code function: | 0_2_076DF78A | |
Source: | Code function: | 0_2_076DF798 | |
Source: | Code function: | 0_2_076DF27D | |
Source: | Code function: | 0_2_076DF2AA | |
Source: | Code function: | 0_2_076DF2A4 | |
Source: | Code function: | 0_2_076DF498 | |
Source: | Code function: | 0_2_0778D7D8 | |
Source: | Code function: | 0_2_07783BBE | |
Source: | Code function: | 0_2_0778E678 | |
Source: | Code function: | 0_2_0778CE10 | |
Source: | Code function: | 0_2_0778B978 | |
Source: | Code function: | 0_2_07788558 | |
Source: | Code function: | 0_2_0778C588 | |
Source: | Code function: | 0_2_0778A8E0 | |
Source: | Code function: | 0_2_07782B20 | |
Source: | Code function: | 0_2_0778D7C8 | |
Source: | Code function: | 0_2_0778CE00 | |
Source: | Code function: | 0_2_0778B968 | |
Source: | Code function: | 0_2_0778F560 | |
Source: | Code function: | 0_2_0778C549 | |
Source: | Code function: | 0_2_0778D580 | |
Source: | Code function: | 0_2_0778A8D0 | |
Source: | Code function: | 0_2_07960040 | |
Source: | Code function: | 0_2_07B43370 | |
Source: | Code function: | 0_2_07B49378 | |
Source: | Code function: | 0_2_07B455A0 | |
Source: | Code function: | 0_2_07B44D88 | |
Source: | Code function: | 0_2_07B4A9F8 | |
Source: | Code function: | 0_2_07B4AD00 | |
Source: | Code function: | 0_2_07B40040 | |
Source: | Code function: | 0_2_07B40B9D | |
Source: | Code function: | 0_2_07B4B798 | |
Source: | Code function: | 0_2_07B44388 | |
Source: | Code function: | 0_2_07B40BF0 | |
Source: | Code function: | 0_2_07B47BE8 | |
Source: | Code function: | 0_2_07B44379 | |
Source: | Code function: | 0_2_07B4EF68 | |
Source: | Code function: | 0_2_07B47352 | |
Source: | Code function: | 0_2_07B4335F | |
Source: | Code function: | 0_2_07B47358 | |
Source: | Code function: | 0_2_07B45590 | |
Source: | Code function: | 0_2_07B485D0 | |
Source: | Code function: | 0_2_07B48D38 | |
Source: | Code function: | 0_2_07B44D79 | |
Source: | Code function: | 0_2_07B40006 | |
Source: | Code function: | 0_2_07B43C68 | |
Source: | Code function: | 0_2_076D3F85 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_012C249A | |
Source: | Code function: | 0_2_012C9B71 | |
Source: | Code function: | 0_2_012C9DA1 | |
Source: | Code function: | 0_2_0575AF3D | |
Source: | Code function: | 0_2_05754FEA | |
Source: | Code function: | 0_2_057597A9 | |
Source: | Code function: | 0_2_0575FCE9 | |
Source: | Code function: | 0_2_05EDD93A | |
Source: | Code function: | 0_2_076D9C12 | |
Source: | Code function: | 0_2_076DD9E6 | |
Source: | Code function: | 0_2_076DB88D | |
Source: | Code function: | 0_2_07789BDE | |
Source: | Code function: | 0_2_077874CE | |
Source: | Code function: | 0_2_0778750D | |
Source: | Code function: | 0_2_077808C4 |
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Boot Survival |
---|
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 11 Scripting | 1 Valid Accounts | Windows Management Instrumentation | 11 Scripting | 1 DLL Side-Loading | 1 Disable or Modify Tools | OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 Valid Accounts | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 12 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Valid Accounts | 1 Access Token Manipulation | 2 Obfuscated Files or Information | Security Account Manager | 11 Security Software Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 2 Registry Run Keys / Startup Folder | 311 Process Injection | 12 Software Packing | NTDS | 1 Process Discovery | Distributed Component Object Model | Input Capture | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 2 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | LSA Secrets | 31 Virtualization/Sandbox Evasion | SSH | Keylogging | 4 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Valid Accounts | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 Access Token Manipulation | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 31 Virtualization/Sandbox Evasion | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 311 Process Injection | Network Sniffing | Network Service Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
Network Security Appliances | Domains | Compromise Software Dependencies and Development Tools | AppleScript | Launchd | Launchd | 1 Hidden Files and Directories | Input Capture | System Network Connections Discovery | Software Deployment Tools | Remote Data Staging | Mail Protocols | Exfiltration Over Unencrypted Non-C2 Protocol | Firmware Corruption |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | ByteCode-MSIL.Trojan.AgentTesla | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
yip.su | 188.114.97.3 | true | false | unknown | |
pastebin.com | 104.20.3.235 | true | true | unknown | |
iplogger.com | 104.21.76.57 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.20.3.235 | pastebin.com | United States | 13335 | CLOUDFLARENETUS | true | |
188.114.97.3 | yip.su | European Union | 13335 | CLOUDFLARENETUS | false | |
104.21.76.57 | iplogger.com | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1508816 |
Start date and time: | 2024-09-10 18:19:12 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 24 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winEXE@29/8@3/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target InstallUtil.exe, PID 7848 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
12:20:57 | API Interceptor | |
12:20:58 | API Interceptor | |
18:21:03 | Autostart | |
18:21:16 | Autostart | |
18:21:24 | Autostart | |
18:21:37 | Autostart | |
18:21:45 | Autostart | |
18:21:53 | Autostart | |
18:22:01 | Autostart | |
18:22:14 | Autostart | |
18:22:23 | Autostart | |
18:22:31 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.20.3.235 | Get hash | malicious | VjW0rm, AsyncRAT, RATDispenser | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
Get hash | malicious | WSHRAT | Browse |
| ||
188.114.97.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
yip.su | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Djvu, Neoreklami, Stealc, Vidar, Xmrig | Browse |
| ||
Get hash | malicious | LummaC, Djvu, Go Injector, LummaC Stealer, Neoreklami, Stealc, SystemBC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Cryptbot | Browse |
| ||
iplogger.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DarkTortilla | Browse |
| ||
Get hash | malicious | DarkTortilla | Browse |
| ||
Get hash | malicious | Cryptbot, Vidar, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Metamorfo | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
pastebin.com | Get hash | malicious | MicroClip, RedLine | Browse |
| |
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
Get hash | malicious | MicroClip, RedLine | Browse |
| ||
Get hash | malicious | VjW0rm, AsyncRAT, RATDispenser | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MinerDownloader, RedLine, Xmrig | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Phisher | Browse |
| ||
Get hash | malicious | NetSupport RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | GuLoader, Remcos | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLU84qpE4KlKDE4KhKiKhIE4Kx1qE4qXKIE4oKNzKoZAE4Kze0E4j:Mgv2HKlYHKh3oIHKx1qHitHo6hAHKzea |
MD5: | FB53815DEEC334028DBDE4E3660E26D0 |
SHA1: | 7F491359EC244406DFC8AA39FC9B727D677E4FDF |
SHA-256: | C3EC8D6C079B1940D82374A85E9DC41ED9FF683ADA338F89E375AA7AC777749D |
SHA-512: | 5CC466901D7911BE1E1731162CC01C371444AAFA9A504F1F22516F60C888048EB78B5C5A12215EE2B127BD67A19677E370686465E85E08BC14015F8FAB049E49 |
Malicious: | true |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Lkpj4eLKYuRL6LrNltOgK200.bat
Download File
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69 |
Entropy (8bit): | 4.811049276555988 |
Encrypted: | false |
SSDEEP: | 3:Ljn9m1s8pE2J5jkAUA0M0zCln:fE1sZ23nt0Q |
MD5: | BCBCE21828BA12B4E2D4089D6D56FB2C |
SHA1: | 7C299560545D1F37C7C2A544B8102CFA9F524B91 |
SHA-256: | 69FA8CAC49DCBAEF87C877D1B70CDBC489DAD2C65E4CD93B1F55954844522F83 |
SHA-512: | 3AD523DA9645E6465EBA47F7236A4E6860681E69B5E746B45FB593408BF5C6BCB33F4812182FE5A427B5C4E408D35B168FA221D4D7EFF3CB4554BD4A52A4087B |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Volrhw1xPk7ixUGFUQh9lCFk.bat
Download File
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69 |
Entropy (8bit): | 4.753684696555501 |
Encrypted: | false |
SSDEEP: | 3:Ljn9m1s8pE2J5qS+80oE28Q0s:fE1sZ23qS+lo7is |
MD5: | 92350C352FC278F9614A4AC0FB5D1ED7 |
SHA1: | 1C69CBB9CBD7FBC9ED39391E13E3DEFC6DA48351 |
SHA-256: | 841BB82F7C519D7E5F18385BAB831DA56F21128D8E2A8090DF587A2B1709D418 |
SHA-512: | 2B8B4EF4C02B1FDACD9B552B1B64E5D517F9C3AD9C3E471384B695C2AA4B70C4B402F8799FCCAE461AFA25E3D8B28ED4B72D597B0F0D84514A0C306218D1034C |
Malicious: | true |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7462 |
Entropy (8bit): | 5.420482116403958 |
Encrypted: | false |
SSDEEP: | 192:5LP+u+v13xV1cSHYu+zogDLIIUObDz5p7KoxSR1yz:5D+hv13T1FH0fHIIPD9xKu |
MD5: | 77F762F953163D7639DFF697104E1470 |
SHA1: | ADE9FFF9FFC2D587D50C636C28E4CD8DD99548D3 |
SHA-256: | D9E15BB8027FF52D6D8D4E294C0D690F4BBF9EF3ABC6001F69DCF08896FBD4EA |
SHA-512: | D9041D02AACA5F06A0F82111486DF1D58DF3BE7F42778C127CCC53B2E1804C57B42B263CC607D70E5240518280C7078E066C07DEC2EA32EC13FB86AA0D4CB499 |
Malicious: | false |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.29844567951361 |
Encrypted: | false |
SSDEEP: | 6144:oECqOEmWfd+WQFHy/9026ZTyaRsCDusBqD5dooi8lQSD6VJSR1o:NCsL6seqD5SZSWVARm |
MD5: | 4F772D99D75C62C410222EB93719C9DE |
SHA1: | 244874889CACA3029325786EDF11B0A781054558 |
SHA-256: | 6B0EEEE69CF0AFA817C65ECE8161D51B71FD940475E53F3061F880E73D7CD2BA |
SHA-512: | 916FF0F6C78504838C6E4DBDFFAA3BBBA022C4FD5BD9546BB6517F9815A341B86191D9C409EE4AFCED2C0BE97684BD643DE0BE9477893D22C31A327AC9D90E4F |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.505123268062248 |
TrID: |
|
File name: | file.exe |
File size: | 951'808 bytes |
MD5: | 6d42583de8cb7222d51b9e5976ab2ed2 |
SHA1: | 800f8bbcc6730f06f9bb9f2431b48ac7c0385fce |
SHA256: | 13de95a8a6ab504e0060485cc8eaab56531aa1b1a9e567d722774e15ea126640 |
SHA512: | 88252adbf63b1a76f18606008c23b96537f5d2f07d84df1b8d67dfa4a1bb110b2433038f5dbd0f9d915ea11e573d7135876b95cabddf8d3c6f78a4423a2fefb0 |
SSDEEP: | 12288:YIsRcP1Ai09bpspcAqHz+qLPOek+V5g/u4LHHMMjrxQo8LMsaEIux8U+lBkZOcm9:0Rc92psKAq6ITV5vGbao8LSEI28 |
TLSH: | 1E158C406BE81954F3FB2BB99FB998468A3BF8E15872C66E013055DE0632F81CD61737 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...pX.@.................~............... ........@.. ....................................`................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x4e9d0e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x40A05870 [Tue May 11 04:37:04 2004 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xe9cc0 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xea000 | 0x3f8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xec000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xe7d14 | 0xe7e00 | 4055e0f1aa58effafc62b0a836a97b23 | False | 0.7871820249326146 | data | 7.511723040802468 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xea000 | 0x3f8 | 0x400 | 7c38f3e1a963465f9aec4e4fb51fd88a | False | 0.4267578125 | data | 3.4719177119668405 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xec000 | 0xc | 0x200 | e89c9d12b0bcd9c6194cd5f085c4d57f | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xea058 | 0x3a0 | data | 0.4396551724137931 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 10, 2024 18:20:58.814404964 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:58.814450979 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:58.814515114 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:58.822427988 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:58.822448969 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.304081917 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.304160118 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.307420969 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.307429075 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.307674885 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.357901096 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.387020111 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.431416035 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495469093 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495501995 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495531082 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495567083 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.495596886 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495640039 CEST | 443 | 49711 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:20:59.495641947 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.495683908 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.562941074 CEST | 49711 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:20:59.810038090 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:20:59.810091972 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:20:59.810161114 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:20:59.810512066 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:20:59.810533047 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:00.283144951 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:00.283225060 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:00.285077095 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:00.285099983 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:00.285351992 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:00.287957907 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:00.331404924 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.413870096 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.413913012 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.413960934 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.414066076 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:01.414077997 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.414100885 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.414115906 CEST | 443 | 49712 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:01.414129019 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:01.414129019 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:01.414167881 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:01.415209055 CEST | 49712 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:04.827953100 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:04.827991962 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:04.828064919 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:04.828346014 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:04.828362942 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.289623022 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.292073011 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:05.292108059 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430504084 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430555105 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430592060 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430627108 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430660009 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:05.430681944 CEST | 443 | 49713 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:05.430686951 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:05.430743933 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:05.431406021 CEST | 49713 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:05.501121044 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:05.501149893 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:05.501348019 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:05.501554012 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:05.501566887 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:05.980034113 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:05.981666088 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:05.981681108 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433659077 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433706045 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433743000 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433758020 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:06.433772087 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433803082 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433814049 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:06.433819056 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433852911 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:06.433852911 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433864117 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433913946 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:06.433918953 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433950901 CEST | 443 | 49714 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:06.433986902 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:06.434389114 CEST | 49714 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:10.541148901 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:10.541191101 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:10.541271925 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:10.541770935 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:10.541799068 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.003037930 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.003112078 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.004883051 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.004899025 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.005150080 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.006480932 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.047444105 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152704954 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152776003 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152806997 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152843952 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152879953 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152887106 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.152921915 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152936935 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.152962923 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.152993917 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.153002977 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.153045893 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.153053999 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.153348923 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.153386116 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.153398037 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.201683998 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.225132942 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.225178957 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.225230932 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.225306988 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.225322962 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.225337029 CEST | 443 | 49715 | 104.21.76.57 | 192.168.2.11 |
Sep 10, 2024 18:21:11.225367069 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.225399017 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.230171919 CEST | 49715 | 443 | 192.168.2.11 | 104.21.76.57 |
Sep 10, 2024 18:21:11.343319893 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.343368053 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.343460083 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.343744040 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.343755960 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.813936949 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.815779924 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.815809011 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946139097 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946270943 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946358919 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946443081 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946547031 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.946583033 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.946603060 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.946614027 CEST | 443 | 49716 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:11.947149992 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.947170019 CEST | 49716 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:11.997988939 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:11.998053074 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:11.998172998 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:11.998419046 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:11.998435974 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.462142944 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.463958025 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:12.463993073 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605215073 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605338097 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605415106 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605448961 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:12.605479956 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605547905 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605621099 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605638981 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:12.605648041 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605690002 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:12.605856895 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:12.605917931 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:12.606328011 CEST | 49717 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:17.109013081 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.109060049 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.109194994 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.109483004 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.109494925 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.593208075 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.595238924 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.595263004 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743149996 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743268967 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743329048 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.743349075 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743377924 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743417978 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.743474007 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743655920 CEST | 443 | 49719 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:17.743712902 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.744002104 CEST | 49719 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:17.797308922 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:17.797358990 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:17.797451019 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:17.797689915 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:17.797709942 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.313957930 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.315660954 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:18.315687895 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.467911005 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.467962027 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.467993021 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468039989 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468077898 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:18.468096018 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468108892 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:18.468187094 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468235016 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:18.468240976 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468452930 CEST | 443 | 49720 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:18.468504906 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:18.468786955 CEST | 49720 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:22.922434092 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:22.922504902 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:22.922565937 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:22.922885895 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:22.922899008 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.402514935 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.404536009 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:23.404566050 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.540967941 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541109085 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541187048 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:23.541198015 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541666985 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541733980 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:23.541739941 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541862965 CEST | 443 | 49721 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:23.541923046 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:23.542206049 CEST | 49721 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:23.621315002 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:23.621364117 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:23.621546030 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:23.621726990 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:23.621736050 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.107377052 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.111202955 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:24.111221075 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.269545078 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.269578934 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.269628048 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.269721985 CEST | 443 | 49722 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:24.269778013 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:24.269778013 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:24.269834995 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:24.270123005 CEST | 49722 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:28.751900911 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:28.751966953 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:28.752069950 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:28.752551079 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:28.752563953 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.220369101 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.222312927 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:29.222342014 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350421906 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350548029 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350630045 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350662947 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:29.350725889 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350795984 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:29.350812912 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.350915909 CEST | 443 | 49723 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:29.351001978 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:29.351377010 CEST | 49723 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:29.373291969 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.373351097 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.373454094 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.373752117 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.373769045 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.846100092 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.847841978 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.847857952 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999366045 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999419928 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999459028 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999500036 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.999511003 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999524117 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999562979 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999579906 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.999587059 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999598026 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.999660969 CEST | 443 | 49724 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:29.999716997 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:29.999998093 CEST | 49724 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:34.485701084 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:34.485729933 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:34.485862970 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:34.486160994 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:34.486172915 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.005991936 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.008131027 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:35.008145094 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.161577940 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.161640882 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.161672115 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.161880970 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:35.161907911 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.162229061 CEST | 443 | 49725 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:35.162305117 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:35.162305117 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:35.162936926 CEST | 49725 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:35.181663990 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.181706905 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.181919098 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.182075024 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.182096004 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.675890923 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.679281950 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.679305077 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827059984 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827143908 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827178955 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827214956 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827230930 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.827263117 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827282906 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.827507019 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827539921 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827586889 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.827605009 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827634096 CEST | 443 | 49726 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:35.827682972 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.827682972 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:35.828095913 CEST | 49726 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:40.296667099 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.296711922 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.296798944 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.297116995 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.297132969 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.762664080 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.764508009 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.764523029 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896297932 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896351099 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896384954 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896413088 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896450996 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.896465063 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896476030 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.896486044 CEST | 443 | 49727 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:40.896543980 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.896996975 CEST | 49727 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:40.915070057 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:40.915111065 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:40.915215969 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:40.915468931 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:40.915488005 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.381573915 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.383138895 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:41.383178949 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620851040 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620887995 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620908022 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620934963 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620959044 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.620989084 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:41.621015072 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.621032000 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:41.621092081 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:41.621509075 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.622071981 CEST | 443 | 49728 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:41.622138023 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:41.622476101 CEST | 49728 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:46.031068087 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.031121969 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.031420946 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.031527042 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.031542063 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.507222891 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.508868933 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.508888006 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665107965 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665160894 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665194988 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665218115 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665250063 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.665278912 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665296078 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.665299892 CEST | 443 | 49729 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:46.665344000 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.670063972 CEST | 49729 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:46.787560940 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:46.787612915 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:46.787681103 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:46.787930965 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:46.787944078 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.272569895 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.274125099 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.274144888 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.494560957 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.494606972 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.494642019 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.494648933 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.494663000 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.494693041 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.494699001 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495223045 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495250940 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495265961 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.495274067 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495307922 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.495313883 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495326996 CEST | 443 | 49730 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:47.495359898 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:47.495599031 CEST | 49730 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:51.906022072 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:51.906100988 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:51.906213999 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:51.906497002 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:51.906533957 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.383263111 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.385077953 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:52.385164022 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508644104 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508688927 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508716106 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508749008 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508800030 CEST | 443 | 49731 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:52.508852959 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:52.508882046 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:52.509504080 CEST | 49731 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:52.536259890 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:52.536317110 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:52.536559105 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:52.536843061 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:52.536858082 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.001904964 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.003463030 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:53.003492117 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226181984 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226227045 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226264000 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226291895 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226310015 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:53.226322889 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226334095 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226377964 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:53.226377964 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:53.226686954 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.226793051 CEST | 443 | 49732 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:53.227919102 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:53.228203058 CEST | 49732 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:57.655752897 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:57.655802011 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:57.655870914 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:57.656193972 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:57.656208038 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.349838972 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.353530884 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:58.353566885 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547355890 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547382116 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547414064 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547468901 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547538042 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:58.547557116 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547575951 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:58.547590017 CEST | 443 | 49733 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:21:58.547640085 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:58.548053980 CEST | 49733 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:21:58.570266962 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:58.570319891 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:58.570610046 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:58.570724010 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:58.570735931 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.029046059 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.030742884 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.030764103 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267100096 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267148972 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267179966 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267184973 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.267246962 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267297983 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.267309904 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267339945 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267368078 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267416000 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.267424107 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267494917 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.267501116 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267513037 CEST | 443 | 49734 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:21:59.267584085 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:21:59.267975092 CEST | 49734 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:03.687416077 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:03.687463045 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:03.687536955 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:03.687868118 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:03.687880039 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.151442051 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.153757095 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:04.153793097 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.268919945 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.268970013 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.269006014 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.269040108 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.269049883 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:04.269074917 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.269095898 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:04.269148111 CEST | 443 | 49735 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:04.271867037 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:04.272243977 CEST | 49735 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:04.293560982 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.293612003 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.293739080 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.294008970 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.294023037 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.778997898 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.781770945 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.781795979 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926103115 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926156044 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926201105 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926214933 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.926240921 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926274061 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926275015 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.926284075 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926323891 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926328897 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.926337957 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926382065 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.926386118 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926419973 CEST | 443 | 49736 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:04.926454067 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:04.926899910 CEST | 49736 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:09.406039000 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:09.406075001 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:09.406157017 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:09.406377077 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:09.406388044 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:09.890500069 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:09.892380953 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:09.892414093 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039738894 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039782047 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039805889 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039829016 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:10.039832115 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039839983 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.039877892 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:10.039963961 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.040002108 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:10.040014029 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.040029049 CEST | 443 | 49737 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:10.040067911 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:10.040575981 CEST | 49737 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:10.060981989 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.061032057 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.061126947 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.061502934 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.061522007 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.532507896 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.534143925 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.534172058 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.771991014 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772063971 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772099018 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772109032 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.772142887 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772186041 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.772187948 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772201061 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772255898 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772255898 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.772264957 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772310019 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.772319078 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772356987 CEST | 443 | 49738 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:10.772399902 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:10.772826910 CEST | 49738 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:15.171495914 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.171535015 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.171644926 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.171864033 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.171875954 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.649744034 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.651283979 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.651315928 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.807862997 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.807946920 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.807980061 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.808017969 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.808044910 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.808115005 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.808152914 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.808193922 CEST | 443 | 49739 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:15.808248043 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.808598995 CEST | 49739 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:15.834161043 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:15.834206104 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:15.834301949 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:15.834630966 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:15.834644079 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.312047958 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.313647032 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.313663960 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.539865017 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.539917946 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.539947987 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.539985895 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.539983988 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.540019989 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540098906 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.540121078 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540153027 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540164948 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.540179014 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540224075 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.540236950 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540258884 CEST | 443 | 49740 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:16.540303946 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:16.540640116 CEST | 49740 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:20.952930927 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:20.952970028 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:20.953183889 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:20.953368902 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:20.953378916 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.412739992 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.416457891 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:21.416474104 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.538897038 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.539033890 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.539118052 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.539167881 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:21.539181948 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.539413929 CEST | 443 | 49741 | 104.20.3.235 | 192.168.2.11 |
Sep 10, 2024 18:22:21.539496899 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:21.539899111 CEST | 49741 | 443 | 192.168.2.11 | 104.20.3.235 |
Sep 10, 2024 18:22:21.557220936 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:21.557276964 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:21.557363987 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:21.557595968 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:21.557620049 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.029640913 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.032217026 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.032232046 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246392012 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246443987 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246474981 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246494055 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.246506929 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246520042 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246550083 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.246565104 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246597052 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246604919 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.246611118 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246654987 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.246660948 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246680021 CEST | 443 | 49742 | 188.114.97.3 | 192.168.2.11 |
Sep 10, 2024 18:22:22.246726990 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Sep 10, 2024 18:22:22.247016907 CEST | 49742 | 443 | 192.168.2.11 | 188.114.97.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 10, 2024 18:20:58.796513081 CEST | 49589 | 53 | 192.168.2.11 | 1.1.1.1 |
Sep 10, 2024 18:20:58.805022955 CEST | 53 | 49589 | 1.1.1.1 | 192.168.2.11 |
Sep 10, 2024 18:20:59.713452101 CEST | 59562 | 53 | 192.168.2.11 | 1.1.1.1 |
Sep 10, 2024 18:20:59.809323072 CEST | 53 | 59562 | 1.1.1.1 | 192.168.2.11 |
Sep 10, 2024 18:21:10.532569885 CEST | 64019 | 53 | 192.168.2.11 | 1.1.1.1 |
Sep 10, 2024 18:21:10.540421963 CEST | 53 | 64019 | 1.1.1.1 | 192.168.2.11 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 10, 2024 18:20:58.796513081 CEST | 192.168.2.11 | 1.1.1.1 | 0x7270 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 10, 2024 18:20:59.713452101 CEST | 192.168.2.11 | 1.1.1.1 | 0xf34a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 10, 2024 18:21:10.532569885 CEST | 192.168.2.11 | 1.1.1.1 | 0xcefa | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 10, 2024 18:20:58.805022955 CEST | 1.1.1.1 | 192.168.2.11 | 0x7270 | No error (0) | 104.20.3.235 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:20:58.805022955 CEST | 1.1.1.1 | 192.168.2.11 | 0x7270 | No error (0) | 172.67.19.24 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:20:58.805022955 CEST | 1.1.1.1 | 192.168.2.11 | 0x7270 | No error (0) | 104.20.4.235 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:20:59.809323072 CEST | 1.1.1.1 | 192.168.2.11 | 0xf34a | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:20:59.809323072 CEST | 1.1.1.1 | 192.168.2.11 | 0xf34a | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:21:10.540421963 CEST | 1.1.1.1 | 192.168.2.11 | 0xcefa | No error (0) | 104.21.76.57 | A (IP address) | IN (0x0001) | false | ||
Sep 10, 2024 18:21:10.540421963 CEST | 1.1.1.1 | 192.168.2.11 | 0xcefa | No error (0) | 172.67.188.178 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.11 | 49711 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:20:59 UTC | 74 | OUT | |
2024-09-10 16:20:59 UTC | 222 | IN | |
2024-09-10 16:20:59 UTC | 1147 | IN | |
2024-09-10 16:20:59 UTC | 1369 | IN | |
2024-09-10 16:20:59 UTC | 1369 | IN | |
2024-09-10 16:20:59 UTC | 529 | IN | |
2024-09-10 16:20:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.11 | 49712 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:00 UTC | 65 | OUT | |
2024-09-10 16:21:01 UTC | 899 | IN | |
2024-09-10 16:21:01 UTC | 470 | IN | |
2024-09-10 16:21:01 UTC | 1369 | IN | |
2024-09-10 16:21:01 UTC | 1369 | IN | |
2024-09-10 16:21:01 UTC | 1369 | IN | |
2024-09-10 16:21:01 UTC | 1369 | IN | |
2024-09-10 16:21:01 UTC | 1369 | IN | |
2024-09-10 16:21:01 UTC | 155 | IN | |
2024-09-10 16:21:01 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.11 | 49713 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:05 UTC | 74 | OUT | |
2024-09-10 16:21:05 UTC | 222 | IN | |
2024-09-10 16:21:05 UTC | 1147 | IN | |
2024-09-10 16:21:05 UTC | 1369 | IN | |
2024-09-10 16:21:05 UTC | 1369 | IN | |
2024-09-10 16:21:05 UTC | 529 | IN | |
2024-09-10 16:21:05 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.11 | 49714 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:05 UTC | 65 | OUT | |
2024-09-10 16:21:06 UTC | 898 | IN | |
2024-09-10 16:21:06 UTC | 471 | IN | |
2024-09-10 16:21:06 UTC | 1369 | IN | |
2024-09-10 16:21:06 UTC | 1369 | IN | |
2024-09-10 16:21:06 UTC | 1369 | IN | |
2024-09-10 16:21:06 UTC | 1369 | IN | |
2024-09-10 16:21:06 UTC | 1369 | IN | |
2024-09-10 16:21:06 UTC | 154 | IN | |
2024-09-10 16:21:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.11 | 49715 | 104.21.76.57 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:11 UTC | 68 | OUT | |
2024-09-10 16:21:11 UTC | 1285 | IN | |
2024-09-10 16:21:11 UTC | 693 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.11 | 49716 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:11 UTC | 74 | OUT | |
2024-09-10 16:21:11 UTC | 222 | IN | |
2024-09-10 16:21:11 UTC | 1147 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 1369 | IN | |
2024-09-10 16:21:11 UTC | 529 | IN | |
2024-09-10 16:21:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.11 | 49717 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:12 UTC | 65 | OUT | |
2024-09-10 16:21:12 UTC | 898 | IN | |
2024-09-10 16:21:12 UTC | 471 | IN | |
2024-09-10 16:21:12 UTC | 1369 | IN | |
2024-09-10 16:21:12 UTC | 1369 | IN | |
2024-09-10 16:21:12 UTC | 1369 | IN | |
2024-09-10 16:21:12 UTC | 1369 | IN | |
2024-09-10 16:21:12 UTC | 1369 | IN | |
2024-09-10 16:21:12 UTC | 154 | IN | |
2024-09-10 16:21:12 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.11 | 49719 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:17 UTC | 74 | OUT | |
2024-09-10 16:21:17 UTC | 222 | IN | |
2024-09-10 16:21:17 UTC | 1147 | IN | |
2024-09-10 16:21:17 UTC | 1369 | IN | |
2024-09-10 16:21:17 UTC | 1369 | IN | |
2024-09-10 16:21:17 UTC | 529 | IN | |
2024-09-10 16:21:17 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.11 | 49720 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:18 UTC | 65 | OUT | |
2024-09-10 16:21:18 UTC | 902 | IN | |
2024-09-10 16:21:18 UTC | 467 | IN | |
2024-09-10 16:21:18 UTC | 1369 | IN | |
2024-09-10 16:21:18 UTC | 1369 | IN | |
2024-09-10 16:21:18 UTC | 1369 | IN | |
2024-09-10 16:21:18 UTC | 1369 | IN | |
2024-09-10 16:21:18 UTC | 1369 | IN | |
2024-09-10 16:21:18 UTC | 158 | IN | |
2024-09-10 16:21:18 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.11 | 49721 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:23 UTC | 74 | OUT | |
2024-09-10 16:21:23 UTC | 222 | IN | |
2024-09-10 16:21:23 UTC | 1147 | IN | |
2024-09-10 16:21:23 UTC | 1369 | IN | |
2024-09-10 16:21:23 UTC | 1369 | IN | |
2024-09-10 16:21:23 UTC | 529 | IN | |
2024-09-10 16:21:23 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.11 | 49722 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:24 UTC | 65 | OUT | |
2024-09-10 16:21:24 UTC | 902 | IN | |
2024-09-10 16:21:24 UTC | 467 | IN | |
2024-09-10 16:21:24 UTC | 1369 | IN | |
2024-09-10 16:21:24 UTC | 1369 | IN | |
2024-09-10 16:21:24 UTC | 1369 | IN | |
2024-09-10 16:21:24 UTC | 1369 | IN | |
2024-09-10 16:21:24 UTC | 1369 | IN | |
2024-09-10 16:21:24 UTC | 158 | IN | |
2024-09-10 16:21:24 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.11 | 49723 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:29 UTC | 74 | OUT | |
2024-09-10 16:21:29 UTC | 222 | IN | |
2024-09-10 16:21:29 UTC | 1147 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 529 | IN | |
2024-09-10 16:21:29 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.11 | 49724 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:29 UTC | 65 | OUT | |
2024-09-10 16:21:29 UTC | 906 | IN | |
2024-09-10 16:21:29 UTC | 463 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 1369 | IN | |
2024-09-10 16:21:29 UTC | 162 | IN | |
2024-09-10 16:21:29 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.11 | 49725 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:35 UTC | 74 | OUT | |
2024-09-10 16:21:35 UTC | 222 | IN | |
2024-09-10 16:21:35 UTC | 1147 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 529 | IN | |
2024-09-10 16:21:35 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.11 | 49726 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:35 UTC | 65 | OUT | |
2024-09-10 16:21:35 UTC | 900 | IN | |
2024-09-10 16:21:35 UTC | 469 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 1369 | IN | |
2024-09-10 16:21:35 UTC | 156 | IN | |
2024-09-10 16:21:35 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.11 | 49727 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:40 UTC | 74 | OUT | |
2024-09-10 16:21:40 UTC | 222 | IN | |
2024-09-10 16:21:40 UTC | 1147 | IN | |
2024-09-10 16:21:40 UTC | 1369 | IN | |
2024-09-10 16:21:40 UTC | 1369 | IN | |
2024-09-10 16:21:40 UTC | 529 | IN | |
2024-09-10 16:21:40 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.11 | 49728 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:41 UTC | 65 | OUT | |
2024-09-10 16:21:41 UTC | 904 | IN | |
2024-09-10 16:21:41 UTC | 465 | IN | |
2024-09-10 16:21:41 UTC | 1369 | IN | |
2024-09-10 16:21:41 UTC | 1369 | IN | |
2024-09-10 16:21:41 UTC | 1369 | IN | |
2024-09-10 16:21:41 UTC | 1369 | IN | |
2024-09-10 16:21:41 UTC | 1369 | IN | |
2024-09-10 16:21:41 UTC | 160 | IN | |
2024-09-10 16:21:41 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.11 | 49729 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:46 UTC | 74 | OUT | |
2024-09-10 16:21:46 UTC | 222 | IN | |
2024-09-10 16:21:46 UTC | 1147 | IN | |
2024-09-10 16:21:46 UTC | 1369 | IN | |
2024-09-10 16:21:46 UTC | 1369 | IN | |
2024-09-10 16:21:46 UTC | 529 | IN | |
2024-09-10 16:21:46 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.11 | 49730 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:47 UTC | 65 | OUT | |
2024-09-10 16:21:47 UTC | 906 | IN | |
2024-09-10 16:21:47 UTC | 463 | IN | |
2024-09-10 16:21:47 UTC | 1369 | IN | |
2024-09-10 16:21:47 UTC | 1369 | IN | |
2024-09-10 16:21:47 UTC | 1369 | IN | |
2024-09-10 16:21:47 UTC | 1369 | IN | |
2024-09-10 16:21:47 UTC | 1369 | IN | |
2024-09-10 16:21:47 UTC | 162 | IN | |
2024-09-10 16:21:47 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.11 | 49731 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:52 UTC | 74 | OUT | |
2024-09-10 16:21:52 UTC | 222 | IN | |
2024-09-10 16:21:52 UTC | 1147 | IN | |
2024-09-10 16:21:52 UTC | 1369 | IN | |
2024-09-10 16:21:52 UTC | 1369 | IN | |
2024-09-10 16:21:52 UTC | 529 | IN | |
2024-09-10 16:21:52 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.11 | 49732 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:53 UTC | 65 | OUT | |
2024-09-10 16:21:53 UTC | 898 | IN | |
2024-09-10 16:21:53 UTC | 471 | IN | |
2024-09-10 16:21:53 UTC | 1369 | IN | |
2024-09-10 16:21:53 UTC | 1369 | IN | |
2024-09-10 16:21:53 UTC | 1369 | IN | |
2024-09-10 16:21:53 UTC | 1369 | IN | |
2024-09-10 16:21:53 UTC | 1369 | IN | |
2024-09-10 16:21:53 UTC | 154 | IN | |
2024-09-10 16:21:53 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.11 | 49733 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:58 UTC | 74 | OUT | |
2024-09-10 16:21:58 UTC | 222 | IN | |
2024-09-10 16:21:58 UTC | 1147 | IN | |
2024-09-10 16:21:58 UTC | 1369 | IN | |
2024-09-10 16:21:58 UTC | 1369 | IN | |
2024-09-10 16:21:58 UTC | 529 | IN | |
2024-09-10 16:21:58 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.11 | 49734 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:21:59 UTC | 65 | OUT | |
2024-09-10 16:21:59 UTC | 896 | IN | |
2024-09-10 16:21:59 UTC | 473 | IN | |
2024-09-10 16:21:59 UTC | 1369 | IN | |
2024-09-10 16:21:59 UTC | 1369 | IN | |
2024-09-10 16:21:59 UTC | 1369 | IN | |
2024-09-10 16:21:59 UTC | 1369 | IN | |
2024-09-10 16:21:59 UTC | 1369 | IN | |
2024-09-10 16:21:59 UTC | 152 | IN | |
2024-09-10 16:21:59 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.11 | 49735 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:04 UTC | 74 | OUT | |
2024-09-10 16:22:04 UTC | 222 | IN | |
2024-09-10 16:22:04 UTC | 1147 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 529 | IN | |
2024-09-10 16:22:04 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.11 | 49736 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:04 UTC | 65 | OUT | |
2024-09-10 16:22:04 UTC | 900 | IN | |
2024-09-10 16:22:04 UTC | 469 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 1369 | IN | |
2024-09-10 16:22:04 UTC | 156 | IN | |
2024-09-10 16:22:04 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.11 | 49737 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:09 UTC | 74 | OUT | |
2024-09-10 16:22:10 UTC | 222 | IN | |
2024-09-10 16:22:10 UTC | 1147 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 529 | IN | |
2024-09-10 16:22:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.11 | 49738 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:10 UTC | 65 | OUT | |
2024-09-10 16:22:10 UTC | 898 | IN | |
2024-09-10 16:22:10 UTC | 471 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 1369 | IN | |
2024-09-10 16:22:10 UTC | 154 | IN | |
2024-09-10 16:22:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.11 | 49739 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:15 UTC | 74 | OUT | |
2024-09-10 16:22:15 UTC | 222 | IN | |
2024-09-10 16:22:15 UTC | 1147 | IN | |
2024-09-10 16:22:15 UTC | 1369 | IN | |
2024-09-10 16:22:15 UTC | 1369 | IN | |
2024-09-10 16:22:15 UTC | 529 | IN | |
2024-09-10 16:22:15 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.11 | 49740 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:16 UTC | 65 | OUT | |
2024-09-10 16:22:16 UTC | 900 | IN | |
2024-09-10 16:22:16 UTC | 469 | IN | |
2024-09-10 16:22:16 UTC | 1369 | IN | |
2024-09-10 16:22:16 UTC | 1369 | IN | |
2024-09-10 16:22:16 UTC | 1369 | IN | |
2024-09-10 16:22:16 UTC | 1369 | IN | |
2024-09-10 16:22:16 UTC | 1369 | IN | |
2024-09-10 16:22:16 UTC | 156 | IN | |
2024-09-10 16:22:16 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.11 | 49741 | 104.20.3.235 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:21 UTC | 74 | OUT | |
2024-09-10 16:22:21 UTC | 222 | IN | |
2024-09-10 16:22:21 UTC | 1147 | IN | |
2024-09-10 16:22:21 UTC | 1369 | IN | |
2024-09-10 16:22:21 UTC | 1369 | IN | |
2024-09-10 16:22:21 UTC | 529 | IN | |
2024-09-10 16:22:21 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.11 | 49742 | 188.114.97.3 | 443 | 7848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-10 16:22:22 UTC | 65 | OUT | |
2024-09-10 16:22:22 UTC | 910 | IN | |
2024-09-10 16:22:22 UTC | 459 | IN | |
2024-09-10 16:22:22 UTC | 1369 | IN | |
2024-09-10 16:22:22 UTC | 1369 | IN | |
2024-09-10 16:22:22 UTC | 1369 | IN | |
2024-09-10 16:22:22 UTC | 1369 | IN | |
2024-09-10 16:22:22 UTC | 1369 | IN | |
2024-09-10 16:22:22 UTC | 166 | IN | |
2024-09-10 16:22:22 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:20:19 |
Start date: | 10/09/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe0000 |
File size: | 951'808 bytes |
MD5 hash: | 6D42583DE8CB7222D51B9E5976AB2ED2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 12:20:25 |
Start date: | 10/09/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb30000 |
File size: | 42'064 bytes |
MD5 hash: | 5D4073B2EB6D217C19F2B22F21BF8D57 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 7 |
Start time: | 12:21:11 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 12:21:11 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 12:21:24 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 12:21:24 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 12:21:32 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 12:21:32 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 12:21:45 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 12:21:45 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 15 |
Start time: | 12:21:53 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 16 |
Start time: | 12:21:53 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 17 |
Start time: | 12:22:01 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 18 |
Start time: | 12:22:01 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 20 |
Start time: | 12:22:09 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 12:22:09 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 12:22:22 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bace0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 12:22:23 |
Start date: | 10/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 20.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 3.9% |
Total number of Nodes: | 228 |
Total number of Limit Nodes: | 10 |
Graph
Function 012C366B Relevance: 12.2, Strings: 9, Instructions: 900COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07783BBE Relevance: 7.1, Strings: 3, Instructions: 3324COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D3F85 Relevance: 5.5, Instructions: 5514COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D3FB0 Relevance: 5.5, Instructions: 5499COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C3118 Relevance: 5.3, Strings: 4, Instructions: 328COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05ED4E58 Relevance: 5.2, Instructions: 5237COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4A9F8 Relevance: 5.2, Strings: 4, Instructions: 190COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B43370 Relevance: 3.9, Strings: 3, Instructions: 167COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C29B0 Relevance: 2.9, Strings: 2, Instructions: 448COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B47BE8 Relevance: 2.8, Strings: 2, Instructions: 251COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778C549 Relevance: 2.7, Strings: 2, Instructions: 234COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4AD00 Relevance: 2.7, Strings: 2, Instructions: 232COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778C588 Relevance: 2.7, Strings: 2, Instructions: 207COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4335F Relevance: 2.7, Strings: 2, Instructions: 170COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C6C2D Relevance: 1.5, Strings: 1, Instructions: 293COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778E678 Relevance: 1.5, Strings: 1, Instructions: 266COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778CE10 Relevance: 1.4, Strings: 1, Instructions: 143COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07788558 Relevance: 1.4, Instructions: 1392COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778CE00 Relevance: 1.4, Strings: 1, Instructions: 142COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778A8E0 Relevance: 1.4, Strings: 1, Instructions: 121COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778A8D0 Relevance: 1.4, Strings: 1, Instructions: 119COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778B978 Relevance: 1.3, Strings: 1, Instructions: 84COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B455A0 Relevance: .3, Instructions: 319COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B45590 Relevance: .3, Instructions: 282COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05811C00 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05811BD0 Relevance: .2, Instructions: 236COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B44D88 Relevance: .2, Instructions: 159COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B44D79 Relevance: .2, Instructions: 155COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778D7D8 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778D7C8 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B49378 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B40040 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575D328 Relevance: 6.1, APIs: 4, Instructions: 134threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575D338 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1660 Relevance: 4.0, Strings: 3, Instructions: 246COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D2C94 Relevance: 3.9, Strings: 3, Instructions: 118COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1C40 Relevance: 2.9, Strings: 2, Instructions: 390COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CB088 Relevance: 2.8, Strings: 2, Instructions: 287COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C1FE3 Relevance: 2.7, Strings: 2, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C26D8 Relevance: 2.7, Strings: 2, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C0DA0 Relevance: 2.6, Strings: 2, Instructions: 109COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C7FF0 Relevance: 2.6, Strings: 2, Instructions: 101COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D2DA0 Relevance: 2.5, Strings: 2, Instructions: 43COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D0196 Relevance: 2.0, Strings: 1, Instructions: 762COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05811793 Relevance: 1.8, APIs: 1, Instructions: 345COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D3510 Relevance: 1.7, Strings: 1, Instructions: 497COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778B88F Relevance: 1.7, APIs: 1, Instructions: 207memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575ACA8 Relevance: 1.7, APIs: 1, Instructions: 199COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D3500 Relevance: 1.7, Strings: 1, Instructions: 416COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 058118F0 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05813EDE Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DEBEC Relevance: 1.6, Strings: 1, Instructions: 320COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575D578 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575B690 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4C438 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4D850 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4D5B0 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B43262 Relevance: 1.6, APIs: 1, Instructions: 56memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05EDC978 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B43268 Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778B8B8 Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4CB20 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575A004 Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4DAB8 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4B2F8 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C6D43 Relevance: 1.4, Strings: 1, Instructions: 139COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C6CD8 Relevance: 1.4, Strings: 1, Instructions: 135COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CAC38 Relevance: 1.4, Strings: 1, Instructions: 116COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C997B Relevance: 1.4, Strings: 1, Instructions: 111COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 079606A0 Relevance: 1.3, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 079606A8 Relevance: 1.3, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D0F38 Relevance: 1.3, Strings: 1, Instructions: 34COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C0EE0 Relevance: 1.3, Strings: 1, Instructions: 27COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DCDEC Relevance: .6, Instructions: 552COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D2E18 Relevance: .5, Instructions: 528COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DBF41 Relevance: .4, Instructions: 430COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DB288 Relevance: .4, Instructions: 413COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CC200 Relevance: .3, Instructions: 330COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C43F9 Relevance: .3, Instructions: 306COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C4518 Relevance: .2, Instructions: 243COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CB59D Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C71D0 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DE9AD Relevance: .2, Instructions: 191COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DE9E8 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C9650 Relevance: .2, Instructions: 151COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C2FC3 Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CB6A0 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C22E0 Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C49E8 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1650 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DB0EC Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CC06D Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C4250 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1050 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DE894 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C67DB Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C13A8 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C7468 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C7478 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C9883 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C9DDB Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CC0B6 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C252F Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CBA10 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DB834 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011FD01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011FD1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C8B60 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D18C0 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C08D9 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C13A3 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C08E8 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011FD006 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C424B Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C2540 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DE7C8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D0FA0 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011FD1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C8B54 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D0F93 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1C30 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C49E3 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011DD7D9 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFEE0 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C9AC8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFE48 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFED3 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C964B Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFE58 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011DD7D8 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFF60 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D0F28 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076D1047 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CFF70 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C9ABB Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C7FE3 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DB0DD Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C61C3 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C61C8 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF798 Relevance: 3.9, Strings: 3, Instructions: 153COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF78A Relevance: 3.9, Strings: 3, Instructions: 151COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07960040 Relevance: 2.8, Strings: 2, Instructions: 298COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4B798 Relevance: 2.7, Strings: 2, Instructions: 185COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DFD68 Relevance: 2.7, Strings: 2, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DFD78 Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DFB30 Relevance: 2.6, Strings: 2, Instructions: 114COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DFB40 Relevance: 2.6, Strings: 2, Instructions: 113COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07782B20 Relevance: 2.1, Strings: 1, Instructions: 804COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF2A4 Relevance: 1.6, Strings: 1, Instructions: 394COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF2AA Relevance: 1.6, Strings: 1, Instructions: 392COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF27D Relevance: 1.6, Strings: 1, Instructions: 362COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 076DF498 Relevance: 1.4, Strings: 1, Instructions: 160COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B4EF68 Relevance: .4, Instructions: 363COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05810040 Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05EDFA00 Relevance: .3, Instructions: 270COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B485D0 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05EDFA10 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0575D16C Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05810013 Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B48D38 Relevance: .2, Instructions: 215COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B47358 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778D580 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778F560 Relevance: .2, Instructions: 174COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B47352 Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B40B9D Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B44388 Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B44379 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B40BF0 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B40006 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07B43C68 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0778B968 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012C70E8 Relevance: 5.0, Strings: 4, Instructions: 49COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A25D4 Relevance: .5, Instructions: 510COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A0808 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1648 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1658 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A08DD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A08E6 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A08F9 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A14F7 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1CB0 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A0848 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A155A Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1CC0 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1752 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A0957 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A17E8 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A29F8 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1C30 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 011A1C50 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|