Windows
Analysis Report
QT2Q1292.xla.xlsx
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w7x64
- EXCEL.EXE (PID: 3188 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\EXCEL. EXE" /auto mation -Em bedding MD5: D53B85E21886D2AF9815C377537BCAC3) - WINWORD.EXE (PID: 3496 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Offic e14\WINWOR D.EXE" -Em bedding MD5: 9EE74859D22DAE61F1750B3A1BACB6F5) - EQNEDT32.EXE (PID: 3860 cmdline:
"C:\Progra m Files\Co mmon Files \Microsoft Shared\EQ UATION\EQN EDT32.EXE" -Embeddin g MD5: A87236E214F6D42A65F5DEDAC816AEC8) - wscript.exe (PID: 3936 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Us ers\user\A ppData\Roa ming\seeth edifferent ofpicture. vbs" MD5: 979D74799EA6C8B8167869A68DF5204A) - temp_executable.exe (PID: 4016 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\temp_e xecutable. exe" MD5: 3E01AC27E853080CA5C92470DF3F738C) - aspnet_compiler.exe (PID: 3032 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\asp net_compil er.exe" MD5: A1CC6D0A95AA5C113FA52BEA08847010)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Formbook, Formbo | FormBook contains a unique crypter RunPE that has unique behavioral patterns subject to detection. It was initially called "Babushka Crypter" by Insidemalware. |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_RTF_MalVer_Objects | Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. | ditekSHen |
| |
INDICATOR_RTF_MalVer_Objects | Detects RTF documents with non-standard version and embeding one of the object mostly observed in exploit documents. | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
| |
JoeSecurity_FormBook_1 | Yara detected FormBook | Joe Security | ||
Windows_Trojan_Formbook_1112e116 | unknown | unknown |
|
Exploits |
---|
Source: | Author: Joe Security: |
Source: | Author: Joe Security: |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Markus Neis, FPT.EagleEye Team, Vadim Khrykov, Cyb3rEng, Michael Haag, Christopher Peacock @securepeacock, @scythe_io: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: frack113: |
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
Source: | Author: Michael Haag: |
Source: | Author: frack113: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:27:41.811382+0200 | 2019696 | 1 | A Network Trojan was detected | 192.168.2.22 | 49173 | 185.18.213.20 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:27:41.811382+0200 | 2019714 | 2 | Potentially Bad Traffic | 192.168.2.22 | 49173 | 185.18.213.20 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:27:44.294980+0200 | 2803305 | 3 | Unknown Traffic | 192.168.2.22 | 49174 | 185.18.213.20 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Exploits |
---|
Source: | Network connect: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Stream path '_1788916404/\x1CompObj' : | ||
Source: | Stream path '_1788916409/\x1CompObj' : | ||
Source: | Stream path '_1788916428/\x1CompObj' : | ||
Source: | Stream path '_1788916429/\x1CompObj' : |
Source: | Process created: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Software Vulnerabilities |
---|
Source: | Process created: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Networking |
---|
Source: | Suricata IDS: |
Source: | Dropped file: | Jump to dropped file | ||
Source: | Dropped file: | Jump to dropped file |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | File created: | Jump to behavior |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | OLE: | ||
Source: | OLE: | ||
Source: | OLE: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 13_2_0042BDA3 | |
Source: | Code function: | 13_2_007C07AC | |
Source: | Code function: | 13_2_007BF9F0 | |
Source: | Code function: | 13_2_007BFAE8 | |
Source: | Code function: | 13_2_007BFB68 | |
Source: | Code function: | 13_2_007BFDC0 | |
Source: | Code function: | 13_2_007C0078 | |
Source: | Code function: | 13_2_007C0060 | |
Source: | Code function: | 13_2_007C0048 | |
Source: | Code function: | 13_2_007C10D0 | |
Source: | Code function: | 13_2_007C00C4 | |
Source: | Code function: | 13_2_007C1148 | |
Source: | Code function: | 13_2_007C010C | |
Source: | Code function: | 13_2_007C01D4 | |
Source: | Code function: | 13_2_007BF8CC | |
Source: | Code function: | 13_2_007BF938 | |
Source: | Code function: | 13_2_007C1930 | |
Source: | Code function: | 13_2_007BF900 | |
Source: | Code function: | 13_2_007BFA50 | |
Source: | Code function: | 13_2_007BFA20 | |
Source: | Code function: | 13_2_007BFAD0 | |
Source: | Code function: | 13_2_007BFAB8 | |
Source: | Code function: | 13_2_007BFB50 | |
Source: | Code function: | 13_2_007BFBE8 | |
Source: | Code function: | 13_2_007BFBB8 | |
Source: | Code function: | 13_2_007BFC60 | |
Source: | Code function: | 13_2_007BFC48 | |
Source: | Code function: | 13_2_007C0C40 | |
Source: | Code function: | 13_2_007BFC30 | |
Source: | Code function: | 13_2_007BFC90 | |
Source: | Code function: | 13_2_007BFD5C | |
Source: | Code function: | 13_2_007BFD8C | |
Source: | Code function: | 13_2_007C1D80 | |
Source: | Code function: | 13_2_007BFE24 | |
Source: | Code function: | 13_2_007BFED0 | |
Source: | Code function: | 13_2_007BFEA0 | |
Source: | Code function: | 13_2_007BFF34 | |
Source: | Code function: | 13_2_007BFFFC | |
Source: | Code function: | 13_2_007BFFB4 |
Source: | Code function: | 12_2_001D7055 | |
Source: | Code function: | 12_2_001D28E0 | |
Source: | Code function: | 12_2_001D2108 | |
Source: | Code function: | 12_2_001D6721 | |
Source: | Code function: | 12_2_001D20F7 | |
Source: | Code function: | 12_2_001D0A78 | |
Source: | Code function: | 12_2_001D0A6A | |
Source: | Code function: | 13_2_00401000 | |
Source: | Code function: | 13_2_0040F803 | |
Source: | Code function: | 13_2_004160B3 | |
Source: | Code function: | 13_2_00401260 | |
Source: | Code function: | 13_2_0040FA23 | |
Source: | Code function: | 13_2_00402ADD | |
Source: | Code function: | 13_2_00402AE0 | |
Source: | Code function: | 13_2_0040DAA3 | |
Source: | Code function: | 13_2_00402340 | |
Source: | Code function: | 13_2_0042E333 | |
Source: | Code function: | 13_2_00402334 | |
Source: | Code function: | 13_2_00402E70 | |
Source: | Code function: | 13_2_0040F7FA | |
Source: | Code function: | 13_2_007E905A | |
Source: | Code function: | 13_2_007D3040 | |
Source: | Code function: | 13_2_007FD005 | |
Source: | Code function: | 13_2_007CE0C6 | |
Source: | Code function: | 13_2_0084D06D | |
Source: | Code function: | 13_2_0085D13F | |
Source: | Code function: | 13_2_007CE2E9 | |
Source: | Code function: | 13_2_00871238 | |
Source: | Code function: | 13_2_007D7353 | |
Source: | Code function: | 13_2_008763BF | |
Source: | Code function: | 13_2_007D2305 | |
Source: | Code function: | 13_2_007F63DB | |
Source: | Code function: | 13_2_007CF3CF | |
Source: | Code function: | 13_2_0081A37B | |
Source: | Code function: | 13_2_00805485 | |
Source: | Code function: | 13_2_0085443E | |
Source: | Code function: | 13_2_007E1489 | |
Source: | Code function: | 13_2_0080D47D | |
Source: | Code function: | 13_2_008735DA | |
Source: | Code function: | 13_2_007D351F | |
Source: | Code function: | 13_2_008505E3 | |
Source: | Code function: | 13_2_007EC5F0 | |
Source: | Code function: | 13_2_00816540 | |
Source: | Code function: | 13_2_00872622 | |
Source: | Code function: | 13_2_0081A634 | |
Source: | Code function: | 13_2_007DE6C1 | |
Source: | Code function: | 13_2_007D4680 | |
Source: | Code function: | 13_2_0085579A | |
Source: | Code function: | 13_2_008057C3 | |
Source: | Code function: | 13_2_0086771D | |
Source: | Code function: | 13_2_007DC7BC | |
Source: | Code function: | 13_2_007F286D | |
Source: | Code function: | 13_2_007DC85C | |
Source: | Code function: | 13_2_0084F8C4 | |
Source: | Code function: | 13_2_0086F8EE | |
Source: | Code function: | 13_2_0087098E | |
Source: | Code function: | 13_2_008649F5 | |
Source: | Code function: | 13_2_007E69FE | |
Source: | Code function: | 13_2_0085394B | |
Source: | Code function: | 13_2_007D29B2 | |
Source: | Code function: | 13_2_00855955 | |
Source: | Code function: | 13_2_00883A83 | |
Source: | Code function: | 13_2_0087CBA4 | |
Source: | Code function: | 13_2_00856BCB | |
Source: | Code function: | 13_2_0085DBDA | |
Source: | Code function: | 13_2_007F7B00 | |
Source: | Code function: | 13_2_007CFBD7 | |
Source: | Code function: | 13_2_00872C9C | |
Source: | Code function: | 13_2_0085AC5E | |
Source: | Code function: | 13_2_007DCD5B | |
Source: | Code function: | 13_2_0086FDDD | |
Source: | Code function: | 13_2_00800D3B | |
Source: | Code function: | 13_2_007EEE4C | |
Source: | Code function: | 13_2_00802E2F | |
Source: | Code function: | 13_2_007FDF7C | |
Source: | Code function: | 13_2_0086CFB1 | |
Source: | Code function: | 13_2_007E0F3F | |
Source: | Code function: | 13_2_00842FDC | |
Source: | Code function: | 13_2_0085BF14 |
Source: | OLE indicator, VBA macros: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: | ||
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: | ||
Source: | OLE indicator, Workbook stream: |
Source: | Process created: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Code function: | 10_2_002ED9C2 | |
Source: | Code function: | 13_2_00407042 | |
Source: | Code function: | 13_2_00417060 | |
Source: | Code function: | 13_2_004030F2 | |
Source: | Code function: | 13_2_0041C8C9 | |
Source: | Code function: | 13_2_0040194E | |
Source: | Code function: | 13_2_0040214E | |
Source: | Code function: | 13_2_0040210D | |
Source: | Code function: | 13_2_0040214A | |
Source: | Code function: | 13_2_0040214A | |
Source: | Code function: | 13_2_0041125E | |
Source: | Code function: | 13_2_00424330 | |
Source: | Code function: | 13_2_00424330 | |
Source: | Code function: | 13_2_00401AE3 | |
Source: | Code function: | 13_2_00413417 | |
Source: | Code function: | 13_2_0041ECDD | |
Source: | Code function: | 13_2_00401DB2 | |
Source: | Code function: | 13_2_00401DB2 | |
Source: | Code function: | 13_2_00416EAB | |
Source: | Code function: | 13_2_00401F19 | |
Source: | Code function: | 13_2_00401FEC | |
Source: | Code function: | 13_2_00411000 | |
Source: | Code function: | 13_2_00411000 | |
Source: | Code function: | 13_2_00401FAD | |
Source: | Code function: | 13_2_00401FC6 | |
Source: | Code function: | 13_2_007CDFB4 |
Persistence and Installation Behavior |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File dump: | Jump to dropped file | ||
Source: | File dump: | Jump to dropped file |
Source: | Section loaded: | Jump to behavior |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Stream path 'MBD00065630/Package' entropy: | ||
Source: | Stream path 'Workbook' entropy: | ||
Source: | Stream path 'Package' entropy: | ||
Source: | Stream path 'MBD00065630/Package' entropy: | ||
Source: | Stream path 'Workbook' entropy: |
Source: | Process created: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 13_2_00810101 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 13_2_00810101 |
Source: | Code function: | 13_2_007C07AC |
Source: | Code function: | 13_2_007D26F8 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 121 Scripting | Valid Accounts | 33 Exploitation for Client Execution | 121 Scripting | 311 Process Injection | 1 Masquerading | OS Credential Dumping | 12 Security Software Discovery | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 41 Virtualization/Sandbox Evasion | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 311 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 14 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Remote System Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 21 Obfuscated Files or Information | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 13 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
29% | ReversingLabs | Win32.Exploit.CVE-2017-0199 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | EXP/CVE-2017-11882.Gen | ||
100% | Joe Sandbox ML | |||
21% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
dl.zerotheme.ir | 185.18.213.20 | true | true | unknown | |
strmr.co | 104.21.64.88 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
false | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.235.137.223 | unknown | Iran (ISLAMIC Republic Of) | 202391 | AFRARASAIR | true | |
185.18.213.20 | dl.zerotheme.ir | Iran (ISLAMIC Republic Of) | 44285 | SEFROYEKPARDAZENG-ASAS42043-BertinaTechnologyCompanyIR | true | |
104.21.64.88 | strmr.co | United States | 13335 | CLOUDFLARENETUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1520386 |
Start date and time: | 2024-09-27 10:25:28 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 7 x64 SP1 with Office 2010 SP1 (IE 11, FF52, Chrome 57, Adobe Reader DC 15, Flash 25.0.0.127, Java 8 Update 121, .NET 4.6.2) |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 1 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | QT2Q1292.xla.xlsx |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winXLSX@9/24@9/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): mrxdav.sys, dllhost.exe, rundll32.exe, WMIADAP.exe
- Execution Graph export aborted for target EQNEDT32.EXE, PID 3860 because there are no executed function
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: QT2Q1292.xla.xlsx
Time | Type | Description |
---|---|---|
04:27:33 | API Interceptor | |
04:27:35 | API Interceptor | |
04:27:38 | API Interceptor | |
04:27:47 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.235.137.223 | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
104.21.64.88 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
strmr.co | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AFRARASAIR | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HtmlDropper | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
SEFROYEKPARDAZENG-ASAS42043-BertinaTechnologyCompanyIR | Get hash | malicious | Phisher | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
05af1f5ca1b87cc9cc9b25185115607d | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
7dcce5b76c8b17472d024758970a406b | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
36f7277af969a6947a61ae0b815907a1 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, RedLine | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
C:\Users\user\AppData\Local\Microsoft\Office\14.0\OfficeFileCache\LocalCacheFileEditManager\FSD-CNRY.FSD (copy)
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.02566653274851145 |
Encrypted: | false |
SSDEEP: | 6:I3DPc1i09hvxggLRzCip8sFRXv//4tfnRujlw//+GtluJ/eRuj:I3DPkiiNfrp9bvYg3J/ |
MD5: | 09CE1A9B707022FF6386E8EC1B8FDABF |
SHA1: | 2CAA2F3B7C000963DEF058CE14B870BCC5C66F23 |
SHA-256: | 267028E1CC86E8A7453245D68CD52DA98AAD39A03654DE09D01956D268690CA3 |
SHA-512: | F781F7D3EBC0FC1B8BBA4ED932773AAD1B4A4E13814EFC95372BE0C7AF706DA8EFEA699F6E24426DE718420D7D1A94FDF5AF9ED69A96C2A79852DD13D4A9607E |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\T4O403JZ\veryniceprojectwithgreatthingstobeonlineforentirenicewordwitheveryonetoetmenicethingstogetmebackwithnewpersontobegreat______seetheniceworldof[1].doc
Download File
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 108966 |
Entropy (8bit): | 2.8471901685936154 |
Encrypted: | false |
SSDEEP: | 768:DdO5Q5s3pz7p3S2b9dbk4bSI+GdepBlMNIbnq8dEK7wC5Sbcif4:DwaGj9BjjdepBCNIbnfEGMbn4 |
MD5: | D805F910E1756735E34523281088F2ED |
SHA1: | 243F7B70A0FDE02F3AFD3B7D2FE99A786CB505DB |
SHA-256: | D43CC5A3D193C33295A70F6861EE2D0DDBEEB165AB106018F06A38CC5297EB57 |
SHA-512: | 37C6EDC231148AF4C65C77412F7672D12EC8504B3FB35BF6581E7A3405242A21D302AF97C6B898312750D8938D8C4B83299DC746A284F5F90E2B8E5B7CBA807F |
Malicious: | false |
Yara Hits: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\XNHC0JWC\seethedifferentofpicture[1].vbs
Download File
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 92431 |
Entropy (8bit): | 4.8789339351328405 |
Encrypted: | false |
SSDEEP: | 1536:35VT1rG9XgL21xU47L2HiUYxd9jd4Qyxsyf4SgfAw2zXdcp2bF+Z:JPG9pxh7L2SxKsu4SU0u2bI |
MD5: | 7834CBAFCFAD72B1BDA091F3CCE8E997 |
SHA1: | 034AFCB22B254090084269FC8BCD68F64E4A85A8 |
SHA-256: | AAC62555CF55C081E503636CF2D696AB33A789B9D10DDC8A9EF2ED8014890913 |
SHA-512: | FA08EF7847F8F98A6E2442DB45935FBAA30D0C0CD26ABF457F8579FFDACE28D7851D5BBDC7630406C5FCFE74381241ACCD74B72E4DD79E194E1FD481BC06CFFF |
Malicious: | true |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\4B830AA2.doc
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 108966 |
Entropy (8bit): | 2.8471901685936154 |
Encrypted: | false |
SSDEEP: | 768:DdO5Q5s3pz7p3S2b9dbk4bSI+GdepBlMNIbnq8dEK7wC5Sbcif4:DwaGj9BjjdepBCNIbnfEGMbn4 |
MD5: | D805F910E1756735E34523281088F2ED |
SHA1: | 243F7B70A0FDE02F3AFD3B7D2FE99A786CB505DB |
SHA-256: | D43CC5A3D193C33295A70F6861EE2D0DDBEEB165AB106018F06A38CC5297EB57 |
SHA-512: | 37C6EDC231148AF4C65C77412F7672D12EC8504B3FB35BF6581E7A3405242A21D302AF97C6B898312750D8938D8C4B83299DC746A284F5F90E2B8E5B7CBA807F |
Malicious: | false |
Yara Hits: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\9097DE45.emf
Download File
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 3919640 |
Entropy (8bit): | 3.109586010517866 |
Encrypted: | false |
SSDEEP: | 12288:EHRgSGri2/oVyL00KH2sHliS4ri2/32h6001q:EHTGri2AVyLIH2sHR4ri2/2h6bq |
MD5: | AD5B063741C521880C04A4739CD29A12 |
SHA1: | 6634874A30DB4384B0EBF882261762FBF9B3212F |
SHA-256: | 257E06D8A62128C65F47C0185407AAB2144DC47B387AE986728DD3CEDEF33DF2 |
SHA-512: | CB6D041B561897B5107810C69E001977B9F168B4DFC734846794D9AB97B71BBD158025B690BF1F4ABB50E00EA7E23B4A57401EED30195F8852C47BFBA79EBE9B |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.MSO\DA53ED9B.emf
Download File
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 3237596 |
Entropy (8bit): | 2.941908215680894 |
Encrypted: | false |
SSDEEP: | 6144:JNpuoh+quNeNpVAZSedri2/OZGIuKO9l8J07uGOE68J0YHmDodYJhuRJiTeJa8Kd:xHniS4ri2/CGuIl00Rh600YHY3R |
MD5: | 886E5A977F3F446457EDB5D24FFD19A4 |
SHA1: | 4FA4E9045B1064F6FBE7171E8C2FEA86E650B338 |
SHA-256: | A28F8FB1CFFFEE037FCF67A7858B4CE3155FCD18C268BBC4EE73BDE44C8BC478 |
SHA-512: | B3B0815B234496BB7AFCDFD57750BEC9672886BD9B96E189F4662A100667EAF956158B36BF22370EAB86AD3E785FBD32A03A2565E83BF0C36F9DB8127E1DB840 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{081357E4-4C85-4436-B3DC-01EDA5DDF893}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 13312 |
Entropy (8bit): | 5.799722121763575 |
Encrypted: | false |
SSDEEP: | 192:fRxPtIr6jV2fP0Q9r6jV2UP05r6jV2UP99r6jV2:ZxPk60Phd6/PE6/Pb6 |
MD5: | A8C5FC488DE845011862CE10048F3AB4 |
SHA1: | DE2AAD47324A30BF2B86A4F1D5F41118BA7A0163 |
SHA-256: | 6A096AF87883E72F4E2DFA18313C3D96E5F90C18BB05B28CFF031CE0A9CA50AF |
SHA-512: | 85C6450C7AAB09C261E9C558DFB1845E9BBD84EE85AB35298711AEEC00613F280820150EECB18266A40AF314F4CE458745AC77C9BD40E69ACC160C75A240C3C6 |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{190CC976-8CEE-4CA6-B93D-6EB05B0D4ECE}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1024 |
Entropy (8bit): | 0.05390218305374581 |
Encrypted: | false |
SSDEEP: | 3:ol3lYdn:4Wn |
MD5: | 5D4D94EE7E06BBB0AF9584119797B23A |
SHA1: | DBB111419C704F116EFA8E72471DD83E86E49677 |
SHA-256: | 4826C0D860AF884D3343CA6460B0006A7A2CE7DBCCC4D743208585D997CC5FD1 |
SHA-512: | 95F83AE84CAFCCED5EAF504546725C34D5F9710E5CA2D11761486970F2FBECCB25F9CF50BBFC272BD75E1A66A18B7783F09E1C1454AFDA519624BC2BB2F28BA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{28E55565-B76A-44F2-9439-5AEC7371B4E8}.tmp
Download File
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16896 |
Entropy (8bit): | 3.5808522768349413 |
Encrypted: | false |
SSDEEP: | 384:Q/VXbEoRIdt1LMnoeC26GFYQuLJa18JRdZv8gk8J2+Dgrg:Q/VbIAnoeC26AUU18Fq58J2drg |
MD5: | 713B0001AD1DAFF84ACAD5592F784EDD |
SHA1: | BD5CBC19A7DE9F7E89A8E674D6CFF846EBAAA1D5 |
SHA-256: | 19CC03450F0AE47E79F3C3FABF5B4A556A2FA7B2AA90692B30C93977ACFC3ADE |
SHA-512: | A224DC3446D91666C634E45AF53CE058740200C630C633AB49E7F5E8E4573C86D2C7E5DECD8BB886F696A46A4B35A12FC455FFCF383C56EA04D8F63749E47AAD |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49152 |
Entropy (8bit): | 6.632984721949493 |
Encrypted: | false |
SSDEEP: | 768:Ua9FDkXneHCBXyDMLNe9rotBMx251CBXWZBiGRO4TjPZcVP+LWcwTQ1qsL8:Ua92XeiBCd9/o+XWgGRO4HPmN7TQ1tL8 |
MD5: | 3E01AC27E853080CA5C92470DF3F738C |
SHA1: | 41B6C3DF03856DDF7A5BA505900A9499A6ABADA1 |
SHA-256: | E350330729257731AC3E4CB80CFCB243F8FD629A2AB5BC11D7A1E89B3945C716 |
SHA-512: | 2D4A0A638274A2A3B1B5E6A48E7BFC9A96C8FC113E49A6D89BD4ED3B63B3B3A9410258AA47DE79741C55ADAF24DE417D474CA5971784684870FA469F7C017DFF |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.02566653274851145 |
Encrypted: | false |
SSDEEP: | 6:I3DPc1i09hvxggLRzCip8sFRXv//4tfnRujlw//+GtluJ/eRuj:I3DPkiiNfrp9bvYg3J/ |
MD5: | 09CE1A9B707022FF6386E8EC1B8FDABF |
SHA1: | 2CAA2F3B7C000963DEF058CE14B870BCC5C66F23 |
SHA-256: | 267028E1CC86E8A7453245D68CD52DA98AAD39A03654DE09D01956D268690CA3 |
SHA-512: | F781F7D3EBC0FC1B8BBA4ED932773AAD1B4A4E13814EFC95372BE0C7AF706DA8EFEA699F6E24426DE718420D7D1A94FDF5AF9ED69A96C2A79852DD13D4A9607E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.025564149139645997 |
Encrypted: | false |
SSDEEP: | 6:I3DPcD8xNHvxggLRFOX4TwPnN+RXv//4tfnRujlw//+GtluJ/eRuj:I3DPRgIM2vYg3J/ |
MD5: | 7F9B4590D8E68E372ECF4114EB9DE982 |
SHA1: | 4D6C1A2D3053A02BBEE7D9D2EC914D28439FC1C0 |
SHA-256: | 46F36F124155E25D2EFCF1934C1AF98F58345F5D9345A138646E6B083E27D6CE |
SHA-512: | 7780F8A736A2EE32D97D6E48AA2A2D5EA6BAF98585EB89F816AFB443FDF9A56EBA38A63702A051DAF30BAFAA2C0F96CA2CCCC10467EFC642D15B2ACF14EC1150 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 339968 |
Entropy (8bit): | 7.768246762015716 |
Encrypted: | false |
SSDEEP: | 6144:hTXU+xUOA8HH6InGM7HRgNbnFto8++wXbgcl0WDL4yQfL6fkAv5EE:hT5UOAsHFnd7HeT/o8gg8Rsfe8sEE |
MD5: | 996B56C8B888FAAE21647A151EED4D0F |
SHA1: | 0D6BA4DEE1DAB555F4476C755FDF2DAA5DC232E3 |
SHA-256: | 98B214BC85AA3ADF0BC9DFA05E5FE20B4F03C552F87801F1C79443DB4196BFDE |
SHA-512: | 85F2963AC7DF174002AF804E2D171A8F6E5C59F25F9094306CFB7EB098FD5187FB07C77A783ABB382954918D8DDD4CCA1E8883A520425C9BA2CD7BB898BCDF33 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 333824 |
Entropy (8bit): | 7.884335964134364 |
Encrypted: | false |
SSDEEP: | 6144:MTXU+xUOA8HH6InGM7HRgNbnFto8++wXbgcl0WDL4yQfL6fkAv5EE:MT5UOAsHFnd7HeT/o8gg8Rsfe8sEE |
MD5: | 06EB778904EA0E0EF73CB25AF9BE4AA0 |
SHA1: | 76E2DDB85910B2E2B7FB59B9D47621311678EAE2 |
SHA-256: | CA9A2973CB96D8C15C127C98F67EEAA8C3BF05AC42B3BABE1CD5813159A2BE0E |
SHA-512: | 91C545451A4C85EA096D76CB45A7E99419001059DDCD39125789B18E52B538DD63997E77F2D8EB87F257707E5826F500BE367FAD9C9FDC4067DDD10B16930CEC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 49 |
Entropy (8bit): | 4.586008375613847 |
Encrypted: | false |
SSDEEP: | 3:HRAbABGQYm2fk6ZeJd:HRYFVm4kX |
MD5: | 4DC6469FC624862123C3F2D65A18C9A1 |
SHA1: | C165E365AFDE22247A65BC455B979F1870420F1B |
SHA-256: | C1944E6DF93A2D0BEE05DFC64040A7C358833FA191A58AE4F3B25EBA44FDECDF |
SHA-512: | 4422DD33816CC5EBD6596EE11FCA435FD4196F4133DDB89AC4FC71AE08E51A480E0BF61430302884FE094D3908CAABBDAC374E060A519105B6A3128B22DC7297 |
Malicious: | true |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 41 |
Entropy (8bit): | 4.366596139176847 |
Encrypted: | false |
SSDEEP: | 3:bD+8OCy6ZW4y:b68OCy644y |
MD5: | 52F7D3157AFE59F49F093122645DD9B2 |
SHA1: | 4105CFAAF39513A775612FEC89B9EEBE0C83B8B1 |
SHA-256: | FE3D25CD09253E544498F160BE2C9869BA45F2319ECF2D6DB5A85D4D69823907 |
SHA-512: | AB7AF5DB816040D9087ED457FDE000E29D29A1A41A5906E040CD53C0FD0B8B3AE5C91F9258DD02B736DBF9E125591A9969B98BF611EF2D2B9CF9C66C3668CABD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 43 |
Entropy (8bit): | 4.300535174316826 |
Encrypted: | false |
SSDEEP: | 3:HRAbABGQYm2fk6ZD:HRYFVm4kE |
MD5: | 6B0CC25F2A1C5022663F9504B1978D43 |
SHA1: | 524A2AE756F4DB590A6F3981312C936F8B64B6D2 |
SHA-256: | 462CADC2A9625BB09682AAC27CD23FA484AE4638805E1ED16F0B82DDCD58EEB7 |
SHA-512: | 7DF469932CF64B9A65EE01878C68F16E56C4C1514D1A449754C73D5F840A0556CC7D2CE521F8444F0314B708C8EF3111C88AE272479077D7F341DA96DBFEAF13 |
Malicious: | true |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.503835550707525 |
Encrypted: | false |
SSDEEP: | 3:vrJlaCkWtVypil69oycWjUbtFJlln:vdsCkWtTl69oyjUvl |
MD5: | CB3D0F9D3F7204AF5670A294AB575B37 |
SHA1: | 5E792DFBAD5EDA9305FCF8F671F385130BB967D8 |
SHA-256: | 45968B9F50A9B4183FBF4987A106AB52EB3EF3279B2118F9AB01BA837DC3968A |
SHA-512: | BD116CAF3ACA40A5B90168A022C84923DB51630FA0E62E46020B71B8EB9613EAE776D476B0C6DE0D5F15642A74ED857765150F406937FBA5CB995E9FCDAC81AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 92431 |
Entropy (8bit): | 4.8789339351328405 |
Encrypted: | false |
SSDEEP: | 1536:35VT1rG9XgL21xU47L2HiUYxd9jd4Qyxsyf4SgfAw2zXdcp2bF+Z:JPG9pxh7L2SxKsu4SU0u2bI |
MD5: | 7834CBAFCFAD72B1BDA091F3CCE8E997 |
SHA1: | 034AFCB22B254090084269FC8BCD68F64E4A85A8 |
SHA-256: | AAC62555CF55C081E503636CF2D696AB33A789B9D10DDC8A9EF2ED8014890913 |
SHA-512: | FA08EF7847F8F98A6E2442DB45935FBAA30D0C0CD26ABF457F8579FFDACE28D7851D5BBDC7630406C5FCFE74381241ACCD74B72E4DD79E194E1FD481BC06CFFF |
Malicious: | true |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 725504 |
Entropy (8bit): | 7.97783459718104 |
Encrypted: | false |
SSDEEP: | 12288:KT5UOAsHFnd7HeT/o8gg8Rsfe8sEEn4ixnUNS2OdfMYwtgcRqIcKaq:qLpsAbg8RgEn1xnmMdfXwzdcU |
MD5: | A59A6D39E0AE0E415943EC229CA37287 |
SHA1: | C0FF4621D3545162848EF1E3EDDAEF823C65E6B2 |
SHA-256: | DFAD0A907D75A27DC0EDFE2954F2C78DD9C7B1471F854372E734B32FC38FCE2F |
SHA-512: | 5DF87F460E146B1C2918DE7B1CA3C740D009DB88BADAA436A326CEE867AD215128CB2BC65D2110E7A72B8F846D8AF0ABCC8DDF98A94696CD9648FA9F05CC6607 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 725504 |
Entropy (8bit): | 7.97783459718104 |
Encrypted: | false |
SSDEEP: | 12288:KT5UOAsHFnd7HeT/o8gg8Rsfe8sEEn4ixnUNS2OdfMYwtgcRqIcKaq:qLpsAbg8RgEn1xnmMdfXwzdcU |
MD5: | A59A6D39E0AE0E415943EC229CA37287 |
SHA1: | C0FF4621D3545162848EF1E3EDDAEF823C65E6B2 |
SHA-256: | DFAD0A907D75A27DC0EDFE2954F2C78DD9C7B1471F854372E734B32FC38FCE2F |
SHA-512: | 5DF87F460E146B1C2918DE7B1CA3C740D009DB88BADAA436A326CEE867AD215128CB2BC65D2110E7A72B8F846D8AF0ABCC8DDF98A94696CD9648FA9F05CC6607 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
File Type: | |
Category: | modified |
Size (bytes): | 165 |
Entropy (8bit): | 1.4377382811115937 |
Encrypted: | false |
SSDEEP: | 3:vZ/FFDJw2fV:vBFFGS |
MD5: | 797869BB881CFBCDAC2064F92B26E46F |
SHA1: | 61C1B8FBF505956A77E9A79CE74EF5E281B01F4B |
SHA-256: | D4E4008DD7DFB936F22D9EF3CC569C6F88804715EAB8101045BA1CD0B081F185 |
SHA-512: | 1B8350E1500F969107754045EB84EA9F72B53498B1DC05911D6C7E771316C632EA750FBCE8AD3A82D664E3C65CC5251D0E4A21F750911AE5DC2FC3653E49F58D |
Malicious: | true |
Preview: |
File type: | |
Entropy (8bit): | 7.967739609901458 |
TrID: |
|
File name: | QT2Q1292.xla.xlsx |
File size: | 723'456 bytes |
MD5: | 330b3a06df61fa152ea115447ea00c73 |
SHA1: | 99cf1cd78b14c95083c63c832f8edd3a90b047cc |
SHA256: | 17bc6d992ad4b0fd62bffda1ca6be76674837c2a15122b2547436db5ba827692 |
SHA512: | 16a284d19681f6609f935a5c58dbbaeb314fbbfb95bd5f83684ef5f16c7df7b074043f9897f789ffc84440f70967febf7fad7aeed7a1c4048047f1e95a72b9c5 |
SSDEEP: | 12288:2+UOAsHFnd7HeT/o8gg8Rsfe8vfOuaPIvtsxjzX5PV/RbkUf1Gj+wzggD:2epsAbg8RUfOu4IvMzpPRf4+8n |
TLSH: | 23F4122BF5D48611C0D2D83D17D85282156EFC054BEAAF033B457BFC3A7E5309A9629E |
File Content Preview: | ........................>...............................................................................c.......e.............................................................................................................................................. |
Icon Hash: | 2562ab89a7b7bfbf |
Document Type: | OLE |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | Microsoft Excel |
Encrypted Document: | True |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | True |
Code Page: | 1252 |
Author: | |
Last Saved By: | |
Create Time: | 2006-09-16 00:00:00 |
Last Saved Time: | 2024-09-26 06:06:02 |
Creating Application: | |
Security: | 1 |
Document Code Page: | 1252 |
Thumbnail Scaling Desired: | False |
Contains Dirty Links: | False |
Shared Document: | False |
Changed Hyperlinks: | False |
Application Version: | 786432 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet1 |
VBA File Name: | Sheet1.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % v . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - . |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 d5 25 76 a6 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet2 |
VBA File Name: | Sheet2.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % - y . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 d5 25 2d 79 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Sheet3 |
VBA File Name: | Sheet3.cls |
Stream Size: | 977 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % 6 + . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 2 . 0 . - |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 d5 25 36 2b 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/ThisWorkbook |
VBA File Name: | ThisWorkbook.cls |
Stream Size: | 985 |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . . # . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . S L . . . . S . . . . . S . . . . . < . . . . . . . . . . N . 0 . { . 0 . 0 . 0 . 2 . 0 . 8 . 1 . 9 . - . 0 |
Data Raw: | 01 16 01 00 00 f0 00 00 00 c4 02 00 00 d4 00 00 00 00 02 00 00 ff ff ff ff cb 02 00 00 1f 03 00 00 00 00 00 00 01 00 00 00 d5 25 ff 81 00 00 ff ff 23 01 00 00 88 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | \x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 114 |
Entropy: | 4.25248375192737 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F & . . . M i c r o s o f t O f f i c e E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 26 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | \x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 244 |
Entropy: | 2.889430592781307 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 2 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 c4 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 a1 00 00 00 02 00 00 00 e4 04 00 00 |
General | |
Stream Path: | \x5SummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 200 |
Entropy: | 3.250350317504982 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . T . . . . . . . ` . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . . | . # . @ . . . . . * . . . . . . . . . . |
Data Raw: | fe ff 00 00 06 02 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 98 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 54 00 00 00 12 00 00 00 60 00 00 00 0c 00 00 00 78 00 00 00 0d 00 00 00 84 00 00 00 13 00 00 00 90 00 00 00 02 00 00 00 e4 04 00 00 1e 00 00 00 04 00 00 00 |
General | |
Stream Path: | MBD00065630/\x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 99 |
Entropy: | 3.631242196770981 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . ! . . . M i c r o s o f t O f f i c e E x c e l W o r k s h e e t . . . . . E x c e l M L 1 2 . . . . . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 21 00 00 00 4d 69 63 72 6f 73 6f 66 74 20 4f 66 66 69 63 65 20 45 78 63 65 6c 20 57 6f 72 6b 73 68 65 65 74 00 0a 00 00 00 45 78 63 65 6c 4d 4c 31 32 00 00 00 00 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD00065630/Package |
CLSID: | |
File Type: | Microsoft Excel 2007+ |
Stream Size: | 323368 |
Entropy: | 7.985201154157948 |
Base64 Encoded: | True |
Data ASCII: | P K . . . . . . . . . . ! . . . . . . . . . . . [ C o n t e n t _ T y p e s ] . x m l . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 50 4b 03 04 14 00 06 00 08 00 00 00 21 00 94 ec d8 8a aa 01 00 00 c0 06 00 00 13 00 d6 01 5b 43 6f 6e 74 65 6e 74 5f 54 79 70 65 73 5d 2e 78 6d 6c 20 a2 d2 01 28 a0 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | MBD00065631/\x1Ole |
CLSID: | |
File Type: | data |
Stream Size: | 364 |
Entropy: | 6.491450646846212 |
Base64 Encoded: | False |
Data ASCII: | . . . . b x . . . . . . . . . . . . . . . . . y . . . K . . . . h . t . t . p . s . : . / . / . s . t . r . m . r . . . c . o . / . B . g . 7 . U . Y . E . . . G . . . h . Z B . M . ! . = N ~ 1 b D . w . R . | O % ( . . @ . 0 k . . . e K . . 0 < 8 ] t . ? v . a [ . l 5 F ` a r 1 P . , % F 5 W f m i T . Q . z } ` . . ( $ y L H . . v : p } . w W 9 { ? z D + . . . . . . . . . . . . . . . . . . . . a . K . 8 . e . o . T . d . S . p . . . C ' { . P O . ! & w . . H 7 |
Data Raw: | 01 00 00 02 a9 d4 62 78 c6 1a a7 10 00 00 00 00 00 00 00 00 00 00 00 00 f8 00 00 00 e0 c9 ea 79 f9 ba ce 11 8c 82 00 aa 00 4b a9 0b f4 00 00 00 68 00 74 00 74 00 70 00 73 00 3a 00 2f 00 2f 00 73 00 74 00 72 00 6d 00 72 00 2e 00 63 00 6f 00 2f 00 42 00 67 00 37 00 55 00 59 00 45 00 00 00 e4 9f 47 e8 0e 1e aa fe c0 c5 d2 08 68 9f de 1c a7 5a 42 92 91 8c 02 4d f2 eb fd eb 87 97 21 13 |
General | |
Stream Path: | Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 379917 |
Entropy: | 7.99897282082189 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . / . 6 . . . . . . . . _ . E Q . u n | . Z 3 . . . . z & f } ? 1 . \\ . ` ' . . . . . . . . . . 0 . . . \\ . p . p a . r 4 . % x . J . . b T @ C Q O 9 J r . . . . > . @ K . . e . M . H U _ q [ . m w ` 3 R h " N 0 Q A . | . \\ B . . . a . . . . . . . = . . . P S . . . . . . , ^ 3 . . # . & . . . . . . . h . . . . . . . . y . . . Q \\ . . . . J = . . . . ) . . . - . . 4 A 0 @ . . . . . . . . Z " . . . . . . . V . . . ] & . . . 1 . . . . . . . # M k : T + . 6 . 1 . u t m 1 . . . |
Data Raw: | 09 08 10 00 00 06 05 00 ab 1f cd 07 c1 00 01 00 06 04 00 00 2f 00 36 00 01 00 01 00 01 00 b4 04 5f fc 10 f5 45 51 c7 b3 75 6e b7 7c cc 81 c1 5a 33 0d a2 08 18 0d 8e a0 7a 26 66 e1 bc 7d fb ab 3f fa e5 31 11 5c c8 81 b9 8c fe 60 c7 27 87 00 00 00 e1 00 02 00 b0 04 c1 00 02 00 f1 30 e2 00 00 00 5c 00 70 00 c9 70 61 1a 72 34 d8 92 25 78 13 f1 4a 14 82 00 62 ab f0 54 82 40 bf 43 91 51 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECT |
CLSID: | |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 527 |
Entropy: | 5.269285940145925 |
Base64 Encoded: | True |
Data ASCII: | I D = " { 3 8 3 2 6 D A 8 - C 3 6 9 - 4 8 3 6 - B 4 3 E - A C A 0 2 1 A E F 2 C 7 } " . . D o c u m e n t = T h i s W o r k b o o k / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 1 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 2 / & H 0 0 0 0 0 0 0 0 . . D o c u m e n t = S h e e t 3 / & H 0 0 0 0 0 0 0 0 . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 5 C 5 E B B 4 7 B F 4 D C 3 4 D C |
Data Raw: | 49 44 3d 22 7b 33 38 33 32 36 44 41 38 2d 43 33 36 39 2d 34 38 33 36 2d 42 34 33 45 2d 41 43 41 30 32 31 41 45 46 32 43 37 7d 22 0d 0a 44 6f 63 75 6d 65 6e 74 3d 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 31 2f 26 48 30 30 30 30 30 30 30 30 0d 0a 44 6f 63 75 6d 65 6e 74 3d 53 68 65 65 74 32 2f 26 48 30 30 30 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECTwm |
CLSID: | |
File Type: | data |
Stream Size: | 104 |
Entropy: | 3.0488640812019017 |
Base64 Encoded: | False |
Data ASCII: | T h i s W o r k b o o k . T . h . i . s . W . o . r . k . b . o . o . k . . . S h e e t 1 . S . h . e . e . t . 1 . . . S h e e t 2 . S . h . e . e . t . 2 . . . S h e e t 3 . S . h . e . e . t . 3 . . . . . |
Data Raw: | 54 68 69 73 57 6f 72 6b 62 6f 6f 6b 00 54 00 68 00 69 00 73 00 57 00 6f 00 72 00 6b 00 62 00 6f 00 6f 00 6b 00 00 00 53 68 65 65 74 31 00 53 00 68 00 65 00 65 00 74 00 31 00 00 00 53 68 65 65 74 32 00 53 00 68 00 65 00 65 00 74 00 32 00 00 00 53 68 65 65 74 33 00 53 00 68 00 65 00 65 00 74 00 33 00 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/_VBA_PROJECT |
CLSID: | |
File Type: | data |
Stream Size: | 2644 |
Entropy: | 3.9802812936729834 |
Base64 Encoded: | True |
Data ASCII: | a . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 0 . # . 9 . # . C . : . \\ . P . R . O . G . R . A . ~ . 2 . \\ . C . O . M . M . O . N . ~ . 1 . \\ . M . I . C . R . O . S . ~ . 1 . \\ . V . B . A . \\ . V . B . A . 6 . \\ . V . B . E . 6 . . . D . L . L . # . V . i . s . u . a . l . . B . a . s . i . c . . F . o . r . |
Data Raw: | cc 61 88 00 00 01 00 ff 09 40 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 fa 00 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 30 00 23 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/dir |
CLSID: | |
File Type: | data |
Stream Size: | 553 |
Entropy: | 6.356862187459324 |
Base64 Encoded: | True |
Data ASCII: | . % . . . . . . . . 0 * . . . . p . . H . . . . d . . . . . . . V B A P r o j e c t . . 4 . . @ . . j . . . = . . . . r . . . . . . . . . s . i . . . . J < . . . . . r s t d o l e > . . . s . t . d . o . l . e . . . h . % . ^ . . * \\ G { 0 0 0 2 0 4 3 0 - . . . . . C . . . . . . 0 0 4 . 6 } # 2 . 0 # 0 . # C : \\ W i n d . o w s \\ S y s W O W 6 4 \\ . e 2 . . t l b # O L E . A u t o m a t i . o n . ` . . E O f f D i c E O . f . i . c E . . E . 2 D F 8 D 0 4 C . - 5 B F A - 1 0 1 B - B D E 5 E A A C 4 . 2 |
Data Raw: | 01 25 b2 80 01 00 04 00 00 00 01 00 30 2a 02 02 90 09 00 70 14 06 48 03 00 82 02 00 64 e4 04 04 00 0a 00 1c 00 56 42 41 50 72 6f 6a 65 88 63 74 05 00 34 00 00 40 02 14 6a 06 02 0a 3d 02 0a 07 02 72 01 14 08 05 06 12 09 02 12 73 f0 05 69 08 94 00 0c 02 4a 3c 02 0a 16 00 01 72 80 73 74 64 6f 6c 65 3e 02 19 00 73 00 74 00 64 00 6f 00 80 6c 00 65 00 0d 00 68 00 25 02 5e 00 03 2a 5c 47 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-09-27T10:27:41.811382+0200 | 2019696 | ET MALWARE Possible MalDoc Payload Download Nov 11 2014 | 1 | 192.168.2.22 | 49173 | 185.18.213.20 | 443 | TCP |
2024-09-27T10:27:41.811382+0200 | 2019714 | ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile | 2 | 192.168.2.22 | 49173 | 185.18.213.20 | 443 | TCP |
2024-09-27T10:27:44.294980+0200 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.22 | 49174 | 185.18.213.20 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 10:27:13.866991997 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:13.867090940 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:13.867196083 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:13.888407946 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:13.888454914 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.356899977 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.357033968 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.371049881 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.371104956 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.371584892 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.371654034 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.537800074 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.579436064 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.984955072 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.985029936 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.985145092 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.985413074 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.989981890 CEST | 49163 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:14.990039110 CEST | 443 | 49163 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:14.999330997 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.004426003 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.004538059 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.004591942 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.009439945 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639127970 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639174938 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639204979 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639235973 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639287949 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639323950 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639347076 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639348030 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639373064 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639373064 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639421940 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639456034 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639487982 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639488935 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639508009 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639523029 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.639523983 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.639573097 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.644385099 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.644419909 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.644454002 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.644479036 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.644511938 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.729780912 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.729831934 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.729850054 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.729867935 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.729882002 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.729917049 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730010986 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730010986 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730108023 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730178118 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730249882 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730295897 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730313063 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730334044 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730349064 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730360031 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730365038 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.730387926 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730387926 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.730417967 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731131077 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731158972 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731173038 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731187105 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731194019 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731232882 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731232882 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731232882 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731700897 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731733084 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731755018 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731761932 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731769085 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731784105 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.731785059 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731805086 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.731820107 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.732136011 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.732548952 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.732563972 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.732578993 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.732595921 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.732637882 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.810914040 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.810990095 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.811151028 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.811181068 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.811208010 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.811213017 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.811237097 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.811252117 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820288897 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820363998 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820408106 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820437908 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820472002 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820496082 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820550919 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820584059 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820616007 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820616961 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.820641041 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.820689917 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821098089 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821131945 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821163893 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821178913 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821178913 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821196079 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821217060 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821228027 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821252108 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821259975 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821284056 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821295023 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821321964 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821338892 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821340084 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821400881 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821592093 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821654081 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821733952 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821765900 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821790934 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821798086 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821813107 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821850061 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821855068 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821885109 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821907997 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821916103 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821924925 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821950912 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.821976900 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.821995974 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822597980 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822649956 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822660923 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822683096 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822707891 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822715998 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822750092 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822781086 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822812080 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822839022 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822844982 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.822854996 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822875977 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.822894096 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823672056 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823704004 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823841095 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823872089 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823872089 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823874950 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823901892 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823906898 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823939085 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.823961973 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823961973 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.823988914 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897070885 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897161961 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897196054 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897209883 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897244930 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897279978 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897311926 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897342920 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897373915 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897407055 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897440910 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.897542000 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542000 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542000 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542000 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542000 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542953 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542953 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897542953 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.897592068 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.902291059 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.902338982 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.902373075 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.902383089 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.902383089 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.902405024 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.902429104 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.902441025 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.902519941 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.902519941 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.911073923 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.911093950 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.911112070 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:15.911170959 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:15.911170959 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:16.127083063 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:16.127171040 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:16.567028046 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:16.567250013 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:17.430974007 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:17.431091070 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:19.131848097 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:19.132033110 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:19.330555916 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:19.335747957 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:19.335779905 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:19.335788012 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:19.335797071 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:19.335896015 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:19.932028055 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:19.932080030 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:19.932127953 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:19.936619043 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:19.936635971 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.210227013 CEST | 80 | 49164 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:21.210361958 CEST | 49164 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:21.211630106 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.211728096 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.216597080 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.216605902 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.216900110 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.216960907 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.337107897 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.383404016 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.719439030 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.719543934 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.719651937 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.765043974 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.765080929 CEST | 443 | 49165 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:21.765130043 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:21.765180111 CEST | 49165 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.403121948 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.403217077 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:23.403306961 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.403765917 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.403788090 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:23.870840073 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:23.870995045 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.876765966 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.876791000 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:23.877151966 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:23.885555029 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:23.931406975 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:24.273339987 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:24.273497105 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:24.273665905 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:24.273780107 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:24.273808956 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:24.273869991 CEST | 49166 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:24.273885012 CEST | 443 | 49166 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:27.840054035 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:27.840099096 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:27.840181112 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:27.840970039 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:27.840984106 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.328521013 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.328588009 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:28.333545923 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:28.333568096 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.333854914 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.349226952 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:28.395405054 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.763758898 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.763853073 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:28.763909101 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:28.770952940 CEST | 49167 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:28.770976067 CEST | 443 | 49167 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.164953947 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.164984941 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.165047884 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.165322065 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.165333033 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.626796007 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.626940966 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.633075953 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.633083105 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.633363962 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:29.638083935 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:29.683404922 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.043447971 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.043553114 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.043710947 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.050807953 CEST | 49168 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.050831079 CEST | 443 | 49168 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.070013046 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.070086956 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.070180893 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.070363045 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.070378065 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.537594080 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.538654089 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.538666964 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.539597034 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.539602041 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.956741095 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.956841946 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:30.956984997 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.957096100 CEST | 49169 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:30.957118988 CEST | 443 | 49169 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:31.577064991 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:31.577131033 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:31.577214956 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:31.577687025 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:31.577701092 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.041213989 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.041301012 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.043427944 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.043445110 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.045429945 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.045439005 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.474348068 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.474416971 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.474422932 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.474479914 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.474554062 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.474580050 CEST | 443 | 49170 | 104.21.64.88 | 192.168.2.22 |
Sep 27, 2024 10:27:32.474592924 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.474637985 CEST | 49170 | 443 | 192.168.2.22 | 104.21.64.88 |
Sep 27, 2024 10:27:32.478142023 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:32.483020067 CEST | 80 | 49171 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:32.483097076 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:32.483186007 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:32.488017082 CEST | 80 | 49171 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:33.100713015 CEST | 80 | 49171 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:33.100934029 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.062602043 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.067424059 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.067526102 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.068087101 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.072824001 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691303015 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691323042 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691334963 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691342115 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691346884 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691359043 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691370964 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691390991 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.691406965 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.691421032 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.691426992 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691438913 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691452026 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.691473961 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.691497087 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.696389914 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.696444035 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.696456909 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.696485996 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.696499109 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.696515083 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.696542978 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.696576118 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.777359962 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.777457952 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.779649019 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779663086 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779675007 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779686928 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779714108 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.779735088 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.779870987 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779908895 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.779927969 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779939890 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.779988050 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.780006886 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780016899 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780029058 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780051947 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.780070066 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.780900955 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780911922 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780922890 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.780951023 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.780966997 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781044006 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781054974 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781065941 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781089067 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781105995 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781852961 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781863928 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781876087 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781886101 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781908989 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781919003 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781929970 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781940937 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.781955957 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.781975985 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.784501076 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.784563065 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.784580946 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.784619093 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868129015 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868145943 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868163109 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868175030 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868187904 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868201971 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868212938 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868227005 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868238926 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868249893 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868258953 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868268967 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868279934 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868290901 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868303061 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868321896 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868670940 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868688107 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868699074 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868712902 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868719101 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868733883 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868762970 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.868951082 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.868994951 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869015932 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869031906 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869044065 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869055033 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869062901 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869080067 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869093895 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869293928 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869338036 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869405031 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869421959 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869431973 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869442940 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869452000 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869460106 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869472027 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869477034 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869488001 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869501114 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869505882 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869514942 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869522095 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:35.869540930 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:35.869556904 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.056010008 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.060983896 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061006069 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061016083 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061033010 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061043024 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061057091 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061065912 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061065912 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061078072 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061094999 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061125040 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061132908 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061141968 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061150074 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061161041 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061167002 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061176062 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061183929 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061192989 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061202049 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061211109 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061218023 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061235905 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061254978 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061383009 CEST | 80 | 49172 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:36.061424971 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.061502934 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:36.910851955 CEST | 49172 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:38.611455917 CEST | 80 | 49171 | 185.235.137.223 | 192.168.2.22 |
Sep 27, 2024 10:27:38.611617088 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Sep 27, 2024 10:27:40.526741982 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:40.526804924 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:40.526943922 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:40.531084061 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:40.531104088 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.341744900 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.341870070 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.347063065 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.347079992 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.347496986 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.443116903 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.487441063 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.811449051 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981520891 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981533051 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981575966 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981589079 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981595993 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981695890 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.981695890 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.981743097 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981771946 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.981794119 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.983562946 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983571053 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983596087 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983616114 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983623028 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983634949 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.983660936 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983686924 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:41.983690977 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:41.983720064 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.014476061 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.151030064 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151045084 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151088953 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151106119 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151113033 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151128054 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151180983 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.151180983 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.151180983 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.151221037 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.151259899 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.152870893 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.152885914 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.152935028 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.152941942 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.152951002 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.152967930 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.153002024 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.153058052 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.154803038 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.154814005 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.154851913 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.154875994 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.154896021 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.154927969 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.154927969 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.154999971 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.157130003 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.157180071 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.157222033 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.157222033 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.157236099 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321037054 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321095943 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321249008 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.321273088 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321463108 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321472883 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321512938 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321531057 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321537018 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321552038 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.321578979 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321610928 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.321610928 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.321613073 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.321676970 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.322012901 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322021008 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322057009 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322062969 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322082996 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.322098970 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322125912 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.322782040 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322805882 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322829962 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322838068 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322869062 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.322887897 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.322913885 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.326395035 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.326483965 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367059946 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367099047 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.367137909 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.367182016 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.367225885 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367225885 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367252111 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367856979 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.367970943 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.409480095 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.409529924 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.409588099 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.409605980 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.409646034 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.410496950 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.619411945 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.619473934 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905045033 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905102015 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905128956 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905145884 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905155897 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905213118 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905241966 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905247927 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905258894 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905272007 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905313015 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905319929 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905371904 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905422926 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905424118 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905437946 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905467987 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905503035 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905543089 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905549049 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905555010 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905586004 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905667067 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905709028 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905716896 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.905721903 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905752897 CEST | 443 | 49173 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.905791998 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.906630039 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.909661055 CEST | 49173 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.913577080 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.913605928 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:42.913656950 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.914235115 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:42.914247990 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:43.812000990 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:43.854341984 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:43.854377985 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.295017958 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.467958927 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.467977047 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.468018055 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.468054056 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.468076944 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.468092918 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.468102932 CEST | 443 | 49174 | 185.18.213.20 | 192.168.2.22 |
Sep 27, 2024 10:27:44.468121052 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.468166113 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.468185902 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.468321085 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:27:44.469122887 CEST | 49174 | 443 | 192.168.2.22 | 185.18.213.20 |
Sep 27, 2024 10:28:18.215395927 CEST | 49171 | 80 | 192.168.2.22 | 185.235.137.223 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 27, 2024 10:27:13.844804049 CEST | 54562 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:13.859518051 CEST | 53 | 54562 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:19.913589001 CEST | 52917 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:19.927918911 CEST | 53 | 52917 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:23.380498886 CEST | 62751 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:23.387986898 CEST | 53 | 62751 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:23.390081882 CEST | 57893 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:23.402549982 CEST | 53 | 57893 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:27.821894884 CEST | 54821 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:27.829379082 CEST | 53 | 54821 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:27.831527948 CEST | 54719 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:27.839637041 CEST | 53 | 54719 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:29.149490118 CEST | 49881 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:29.156718016 CEST | 53 | 49881 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:29.157960892 CEST | 54998 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:29.164592028 CEST | 53 | 54998 | 8.8.8.8 | 192.168.2.22 |
Sep 27, 2024 10:27:40.323401928 CEST | 52781 | 53 | 192.168.2.22 | 8.8.8.8 |
Sep 27, 2024 10:27:40.520168066 CEST | 53 | 52781 | 8.8.8.8 | 192.168.2.22 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 27, 2024 10:27:13.844804049 CEST | 192.168.2.22 | 8.8.8.8 | 0xaec7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:19.913589001 CEST | 192.168.2.22 | 8.8.8.8 | 0x2c63 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:23.380498886 CEST | 192.168.2.22 | 8.8.8.8 | 0x9d7d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:23.390081882 CEST | 192.168.2.22 | 8.8.8.8 | 0x8d70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:27.821894884 CEST | 192.168.2.22 | 8.8.8.8 | 0x1100 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:27.831527948 CEST | 192.168.2.22 | 8.8.8.8 | 0x2664 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:29.149490118 CEST | 192.168.2.22 | 8.8.8.8 | 0xb6ec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:29.157960892 CEST | 192.168.2.22 | 8.8.8.8 | 0xd97e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 27, 2024 10:27:40.323401928 CEST | 192.168.2.22 | 8.8.8.8 | 0x6f98 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 27, 2024 10:27:13.859518051 CEST | 8.8.8.8 | 192.168.2.22 | 0xaec7 | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:13.859518051 CEST | 8.8.8.8 | 192.168.2.22 | 0xaec7 | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:19.927918911 CEST | 8.8.8.8 | 192.168.2.22 | 0x2c63 | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:19.927918911 CEST | 8.8.8.8 | 192.168.2.22 | 0x2c63 | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:23.387986898 CEST | 8.8.8.8 | 192.168.2.22 | 0x9d7d | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:23.387986898 CEST | 8.8.8.8 | 192.168.2.22 | 0x9d7d | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:23.402549982 CEST | 8.8.8.8 | 192.168.2.22 | 0x8d70 | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:23.402549982 CEST | 8.8.8.8 | 192.168.2.22 | 0x8d70 | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:27.829379082 CEST | 8.8.8.8 | 192.168.2.22 | 0x1100 | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:27.829379082 CEST | 8.8.8.8 | 192.168.2.22 | 0x1100 | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:27.839637041 CEST | 8.8.8.8 | 192.168.2.22 | 0x2664 | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:27.839637041 CEST | 8.8.8.8 | 192.168.2.22 | 0x2664 | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:29.156718016 CEST | 8.8.8.8 | 192.168.2.22 | 0xb6ec | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:29.156718016 CEST | 8.8.8.8 | 192.168.2.22 | 0xb6ec | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:29.164592028 CEST | 8.8.8.8 | 192.168.2.22 | 0xd97e | No error (0) | 104.21.64.88 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:29.164592028 CEST | 8.8.8.8 | 192.168.2.22 | 0xd97e | No error (0) | 172.67.179.215 | A (IP address) | IN (0x0001) | false | ||
Sep 27, 2024 10:27:40.520168066 CEST | 8.8.8.8 | 192.168.2.22 | 0x6f98 | No error (0) | 185.18.213.20 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.22 | 49164 | 185.235.137.223 | 80 | 3188 | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 27, 2024 10:27:15.004591942 CEST | 473 | OUT | |
Sep 27, 2024 10:27:15.639127970 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639174938 CEST | 224 | IN | |
Sep 27, 2024 10:27:15.639204979 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639235973 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639323950 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639373064 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639421940 CEST | 896 | IN | |
Sep 27, 2024 10:27:15.639456034 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639488935 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.639523029 CEST | 1236 | IN | |
Sep 27, 2024 10:27:15.644385099 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.22 | 49171 | 185.235.137.223 | 80 | 3496 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 27, 2024 10:27:32.483186007 CEST | 286 | OUT | |
Sep 27, 2024 10:27:33.100713015 CEST | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.22 | 49172 | 185.235.137.223 | 80 | 3860 | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 27, 2024 10:27:35.068087101 CEST | 333 | OUT | |
Sep 27, 2024 10:27:35.691303015 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691323042 CEST | 224 | IN | |
Sep 27, 2024 10:27:35.691334963 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691342115 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691346884 CEST | 448 | IN | |
Sep 27, 2024 10:27:35.691359043 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691370964 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691426992 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691438913 CEST | 1236 | IN | |
Sep 27, 2024 10:27:35.691452026 CEST | 896 | IN | |
Sep 27, 2024 10:27:35.696389914 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.22 | 49163 | 104.21.64.88 | 443 | 3188 | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:14 UTC | 321 | OUT | |
2024-09-27 08:27:14 UTC | 970 | IN | |
2024-09-27 08:27:14 UTC | 196 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.22 | 49165 | 104.21.64.88 | 443 | 3496 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:21 UTC | 130 | OUT | |
2024-09-27 08:27:21 UTC | 792 | IN | |
2024-09-27 08:27:21 UTC | 13 | IN | |
2024-09-27 08:27:21 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.22 | 49166 | 104.21.64.88 | 443 | 3496 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:23 UTC | 115 | OUT | |
2024-09-27 08:27:24 UTC | 974 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.22 | 49167 | 104.21.64.88 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:28 UTC | 125 | OUT | |
2024-09-27 08:27:28 UTC | 792 | IN | |
2024-09-27 08:27:28 UTC | 13 | IN | |
2024-09-27 08:27:28 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.22 | 49168 | 104.21.64.88 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:29 UTC | 155 | OUT | |
2024-09-27 08:27:30 UTC | 825 | IN | |
2024-09-27 08:27:30 UTC | 150 | IN | |
2024-09-27 08:27:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.22 | 49169 | 104.21.64.88 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:30 UTC | 155 | OUT | |
2024-09-27 08:27:30 UTC | 827 | IN | |
2024-09-27 08:27:30 UTC | 150 | IN | |
2024-09-27 08:27:30 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.22 | 49170 | 104.21.64.88 | 443 | 3496 | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:32 UTC | 134 | OUT | |
2024-09-27 08:27:32 UTC | 976 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.22 | 49173 | 185.18.213.20 | 443 | 4016 | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:41 UTC | 89 | OUT | |
2024-09-27 08:27:41 UTC | 207 | IN | |
2024-09-27 08:27:41 UTC | 16384 | IN | |
2024-09-27 08:27:41 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN | |
2024-09-27 08:27:42 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.22 | 49174 | 185.18.213.20 | 443 | 4016 | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-27 08:27:43 UTC | 66 | OUT | |
2024-09-27 08:27:44 UTC | 206 | IN | |
2024-09-27 08:27:44 UTC | 1162 | IN | |
2024-09-27 08:27:44 UTC | 14198 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:26:22 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Microsoft Office\Office14\EXCEL.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13f260000 |
File size: | 28'253'536 bytes |
MD5 hash: | D53B85E21886D2AF9815C377537BCAC3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 4 |
Start time: | 04:27:15 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x13f5c0000 |
File size: | 1'423'704 bytes |
MD5 hash: | 9EE74859D22DAE61F1750B3A1BACB6F5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 04:27:33 |
Start date: | 27/09/2024 |
Path: | C:\Program Files\Common Files\Microsoft Shared\EQUATION\EQNEDT32.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 543'304 bytes |
MD5 hash: | A87236E214F6D42A65F5DEDAC816AEC8 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 04:27:35 |
Start date: | 27/09/2024 |
Path: | C:\Windows\SysWOW64\wscript.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x40000 |
File size: | 141'824 bytes |
MD5 hash: | 979D74799EA6C8B8167869A68DF5204A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 04:27:37 |
Start date: | 27/09/2024 |
Path: | C:\Users\user\AppData\Local\Temp\temp_executable.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbe0000 |
File size: | 49'152 bytes |
MD5 hash: | 3E01AC27E853080CA5C92470DF3F738C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 13 |
Start time: | 04:27:44 |
Start date: | 27/09/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\aspnet_compiler.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xac0000 |
File size: | 55'384 bytes |
MD5 hash: | A1CC6D0A95AA5C113FA52BEA08847010 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | true |
Call Graph
Graph
- Entrypoint
- Decryption Function
- Executed
- Not Executed
- Show Help
Module: Sheet1
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet1" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: Sheet2
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet2" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: Sheet3
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "Sheet3" |
2 | Attribute VB_Base = "0{00020820-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Module: ThisWorkbook
Declaration
Line | Content |
---|---|
1 | Attribute VB_Name = "ThisWorkbook" |
2 | Attribute VB_Base = "0{00020819-0000-0000-C000-000000000046}" |
3 | Attribute VB_GlobalNameSpace = False |
4 | Attribute VB_Creatable = False |
5 | Attribute VB_PredeclaredId = True |
6 | Attribute VB_Exposed = True |
7 | Attribute VB_TemplateDerived = False |
8 | Attribute VB_Customizable = True |
Execution Graph
Execution Coverage: | 21.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 2 |
Graph
Function 001D7055 Relevance: 1.8, Instructions: 1847COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D2108 Relevance: 1.6, Strings: 1, Instructions: 377COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D6721 Relevance: .6, Instructions: 570COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D28E0 Relevance: .5, Instructions: 513COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8D48 Relevance: 1.6, APIs: 1, Instructions: 105COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8D50 Relevance: 1.6, APIs: 1, Instructions: 100COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8E61 Relevance: 1.6, APIs: 1, Instructions: 98memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8E68 Relevance: 1.6, APIs: 1, Instructions: 95memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8C38 Relevance: 1.6, APIs: 1, Instructions: 92threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D8C40 Relevance: 1.6, APIs: 1, Instructions: 88threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D90A9 Relevance: 1.6, APIs: 1, Instructions: 67threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D90B0 Relevance: 1.6, APIs: 1, Instructions: 66threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00200430 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00200B68 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00200A20 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00200238 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00200580 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 002003E0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 002009D0 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D0A78 Relevance: 1.8, Strings: 1, Instructions: 521COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D20F7 Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 001D0A6A Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 1.1% |
Dynamic/Decrypted Code Coverage: | 4.4% |
Signature Coverage: | 7% |
Total number of Nodes: | 114 |
Total number of Limit Nodes: | 11 |
Graph
Function 0042BDA3 Relevance: 1.5, APIs: 1, Instructions: 25nativeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 007C07AC Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BF9F0 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFAE8 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFB68 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFDC0 Relevance: 1.5, APIs: 1, Instructions: 6libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042C0E3 Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C0A3 Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C123 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 007D26F8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00810101 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C0078 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C0060 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C0048 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C10D0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C00C4 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C1148 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C010C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C01D4 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BF8CC Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BF938 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C1930 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BF900 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFA50 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFA20 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFAD0 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFAB8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFB50 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFBE8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFBB8 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFC60 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFC48 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C0C40 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFC30 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFC90 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFD5C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFD8C Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007C1D80 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFE24 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFED0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFEA0 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFF34 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFFFC Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007BFFB4 Relevance: .0, Instructions: 6COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 007FFCC9 Relevance: 6.3, APIs: 4, Instructions: 257COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|