Edit tour
Windows
Analysis Report
file.exe
Overview
General Information
Detection
Credential Flusher
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Yara detected Credential Flusher
AI detected suspicious sample
Binary is likely a compiled AutoIt script file
Found API chain indicative of sandbox detection
Machine Learning detection for sample
Contains functionality for read data from the clipboard
Contains functionality to block mouse and keyboard input (often used to hinder debugging)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to communicate with device drivers
Contains functionality to dynamically determine API calls
Contains functionality to execute programs as a different user
Contains functionality to launch a process as a different user
Contains functionality to launch a program with higher privileges
Contains functionality to modify clipboard data
Contains functionality to open a port and listen for incoming connection (possibly a backdoor)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality to read the clipboard data
Contains functionality to retrieve information about pressed keystrokes
Contains functionality to shutdown / reboot the system
Contains functionality to simulate keystroke presses
Contains functionality to simulate mouse events
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected non-DNS traffic on DNS port
Detected potential crypto function
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
OS version to string mapping found (often used in BOTs)
Potential key logger detected (key state polling based)
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
- file.exe (PID: 7092 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 8A053C1EE0F0AD79E8CD1A0788741383) - chrome.exe (PID: 7132 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ap p="https:/ /youtube.c om/account ?=https:// accounts.g oogle.com/ v3/signin/ challenge/ pwd" --sta rt-fullscr een --no-f irst-run - -disable-s ession-cra shed-bubbl e --disabl e-features =CrashReco very MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 2996 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2096 --fi eld-trial- handle=201 2,i,173508 0414500895 824,739384 9833326395 272,262144 --disable -features= CrashRecov ery /prefe tch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialFlusher | Yara detected Credential Flusher | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00A9DBBE | |
Source: | Code function: | 0_2_00AA68EE | |
Source: | Code function: | 0_2_00AA698F | |
Source: | Code function: | 0_2_00A9D076 | |
Source: | Code function: | 0_2_00A9D3A9 | |
Source: | Code function: | 0_2_00AA9642 | |
Source: | Code function: | 0_2_00AA979D | |
Source: | Code function: | 0_2_00AA9B2B | |
Source: | Code function: | 0_2_00AA5C97 |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00AACE44 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00AAEAFF |
Source: | Code function: | 0_2_00AAED6A |
Source: | Code function: | 0_2_00AAEAFF |
Source: | Code function: | 0_2_00A9AA57 |
Source: | Code function: | 0_2_00AC9576 |
System Summary |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_1ba5fc97-3 | |
Source: | String found in binary or memory: | memstr_d6320fbb-f | |
Source: | String found in binary or memory: | memstr_b78d8275-d | |
Source: | String found in binary or memory: | memstr_e8eb5046-9 |
Source: | Code function: | 0_2_00A9D5EB |
Source: | Code function: | 0_2_00A91201 |
Source: | Code function: | 0_2_00A9E8F6 |
Source: | Code function: | 0_2_00A3BF40 | |
Source: | Code function: | 0_2_00A38060 | |
Source: | Code function: | 0_2_00AA2046 | |
Source: | Code function: | 0_2_00A98298 | |
Source: | Code function: | 0_2_00A6E4FF | |
Source: | Code function: | 0_2_00A6676B | |
Source: | Code function: | 0_2_00AC4873 | |
Source: | Code function: | 0_2_00A5CAA0 | |
Source: | Code function: | 0_2_00A3CAF0 | |
Source: | Code function: | 0_2_00A4CC39 | |
Source: | Code function: | 0_2_00A66DD9 | |
Source: | Code function: | 0_2_00A4D064 | |
Source: | Code function: | 0_2_00A391C0 | |
Source: | Code function: | 0_2_00A4B119 | |
Source: | Code function: | 0_2_00A51394 | |
Source: | Code function: | 0_2_00A51706 | |
Source: | Code function: | 0_2_00A5781B | |
Source: | Code function: | 0_2_00A519B0 | |
Source: | Code function: | 0_2_00A37920 | |
Source: | Code function: | 0_2_00A4997D | |
Source: | Code function: | 0_2_00A57A4A | |
Source: | Code function: | 0_2_00A57CA7 | |
Source: | Code function: | 0_2_00A51C77 | |
Source: | Code function: | 0_2_00A69EEE | |
Source: | Code function: | 0_2_00ABBE44 | |
Source: | Code function: | 0_2_00A51F32 |
Source: | Code function: | ||
Source: | Code function: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_00AA37B5 |
Source: | Code function: | 0_2_00A910BF | |
Source: | Code function: | 0_2_00A916C3 |
Source: | Code function: | 0_2_00AA51CD |
Source: | Code function: | 0_2_00A9D4DC |
Source: | Code function: | 0_2_00AA648E |
Source: | Code function: | 0_2_00A342A2 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Window detected: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00A342DE |
Source: | Code function: | 0_2_00A50A89 |
Source: | Code function: | 0_2_00A4F98E | |
Source: | Code function: | 0_2_00AC1C41 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Sandbox detection routine: | graph_0-95964 |
Source: | API coverage: |
Source: | Code function: | 0_2_00A9DBBE | |
Source: | Code function: | 0_2_00AA68EE | |
Source: | Code function: | 0_2_00AA698F | |
Source: | Code function: | 0_2_00A9D076 | |
Source: | Code function: | 0_2_00A9D3A9 | |
Source: | Code function: | 0_2_00AA9642 | |
Source: | Code function: | 0_2_00AA979D | |
Source: | Code function: | 0_2_00AA9B2B | |
Source: | Code function: | 0_2_00AA5C97 |
Source: | Code function: | 0_2_00A342DE |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00AAEAA2 |
Source: | Code function: | 0_2_00A62622 |
Source: | Code function: | 0_2_00A342DE |
Source: | Code function: | 0_2_00A54CE8 |
Source: | Code function: | 0_2_00A90B62 |
Source: | Code function: | 0_2_00A62622 | |
Source: | Code function: | 0_2_00A5083F | |
Source: | Code function: | 0_2_00A509D5 | |
Source: | Code function: | 0_2_00A50C21 |
Source: | Code function: | 0_2_00A91201 |
Source: | Code function: | 0_2_00A72BA5 |
Source: | Code function: | 0_2_00A9B226 |
Source: | Code function: | 0_2_00AB22DA |
Source: | Code function: | 0_2_00A90B62 |
Source: | Code function: | 0_2_00A91663 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00A50698 |
Source: | Code function: | 0_2_00AA8195 |
Source: | Code function: | 0_2_00A8D27A |
Source: | Code function: | 0_2_00A6BB6F |
Source: | Code function: | 0_2_00A342DE |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | Code function: | 0_2_00AB1204 | |
Source: | Code function: | 0_2_00AB1806 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 1 Disable or Modify Tools | 21 Input Capture | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 2 Valid Accounts | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 1 Account Discovery | Remote Desktop Protocol | 21 Input Capture | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 2 Valid Accounts | 2 Obfuscated Files or Information | Security Account Manager | 1 File and Directory Discovery | SMB/Windows Admin Shares | 3 Clipboard Data | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 21 Access Token Manipulation | 1 DLL Side-Loading | NTDS | 15 System Information Discovery | Distributed Component Object Model | Input Capture | 3 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 2 Process Injection | 2 Valid Accounts | LSA Secrets | 12 Security Software Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 21 Access Token Manipulation | DCSync | 3 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 2 Process Injection | Proc Filesystem | 1 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
youtube-ui.l.google.com | 142.250.185.174 | true | false | unknown | |
www.google.com | 142.250.184.196 | true | false | unknown | |
youtube.com | 142.250.186.110 | true | false | unknown | |
www.youtube.com | unknown | unknown | false | unknown | |
86.23.85.13.in-addr.arpa | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.184.196 | www.google.com | United States | 15169 | GOOGLEUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
142.250.185.174 | youtube-ui.l.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.186.110 | youtube.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1523771 |
Start date and time: | 2024-10-02 01:38:06 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 26s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal64.troj.evad.winEXE@26/8@8/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.185.195, 172.217.16.206, 74.125.71.84, 34.104.35.123, 142.250.185.67, 172.217.18.3, 142.250.186.138, 142.250.185.202, 142.250.184.202, 216.58.206.42, 142.250.185.106, 142.250.181.234, 172.217.16.202, 216.58.206.74, 142.250.185.74, 142.250.185.234, 142.250.74.202, 142.250.184.234, 142.250.186.74, 142.250.185.170, 142.250.185.138, 172.217.23.106, 142.250.186.106, 172.217.16.138, 142.250.186.170, 172.217.18.10, 142.250.186.42, 93.184.221.240, 192.229.221.95, 172.217.16.195, 142.250.186.46, 142.250.184.206
- Excluded domains from analysis (whitelisted): clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, slscr.update.microsoft.com, fonts.gstatic.com, ctldl.windowsupdate.com, clientservices.googleapis.com, dns.msftncsi.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, update.googleapis.com, clients.l.google.com, www.gstatic.com, optimizationguide-pa.googleapis.com
- Not all processes where analyzed, report is missing behavior information
- VT rate limit hit for: file.exe
⊘No simulations
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HtmlDropper | Browse | |||
Get hash | malicious | Credential Flusher | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
⊘No context
⊘No context
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
28a2c9bd18a11de089ef85a160da29e4 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | Credential Flusher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | NetSupport RAT, Lsass Dumper, Mimikatz, Nukesped, Quasar, Trickbot, Xmrig | Browse |
|
⊘No context
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 706790 |
Entropy (8bit): | 5.792203668061935 |
Encrypted: | false |
SSDEEP: | 6144:HVXWBQkPdzg5pTX1ROv/duPzd8C3s891/v:gfd8j91/v |
MD5: | EC96CF2B9F4521835FDE7FAC7489AFBF |
SHA1: | E923628C8180BBAFE232BA92D1070F4C96BEF405 |
SHA-256: | 138B369B87F4B601584348DF97E778513A9AAA9B27ACC0941F551D77F519CDF9 |
SHA-512: | 48A00CF55E2760B26749DC6C4B4EF8591AFD58D1C8D11FF48F6A47F4293631F7CBC45AA53A6F691B49D082D2EDD7F7320C9802329AFB9835961A23DCEBAC7B3A |
Malicious: | false |
Reputation: | low |
URL: | "https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.AccountsSignInUi.en.RgRbaBHDctU.es5.O/am=xIFgKBimEQjEE54DekBRIOQAAAAAAAAAAKANAAB0DA/d=1/excm=_b,_tp,identifierview/ed=1/dg=0/wt=2/ujg=1/rs=AOaEmlFJRy1OqtUmLpt_G_DWG-oJaagYwQ/m=_b,_tp" |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 5430 |
Entropy (8bit): | 3.6534652184263736 |
Encrypted: | false |
SSDEEP: | 48:wIJct3xIAxG/7nvWDtZcdYLtX7B6QXL3aqG8Q:wIJct+A47v+rcqlBPG9B |
MD5: | F3418A443E7D841097C714D69EC4BCB8 |
SHA1: | 49263695F6B0CDD72F45CF1B775E660FDC36C606 |
SHA-256: | 6DA5620880159634213E197FAFCA1DDE0272153BE3E4590818533FAB8D040770 |
SHA-512: | 82D017C4B7EC8E0C46E8B75DA0CA6A52FD8BCE7FCF4E556CBDF16B49FC81BE9953FE7E25A05F63ECD41C7272E8BB0A9FD9AEDF0AC06CB6032330B096B3702563 |
Malicious: | false |
Reputation: | high, very likely benign file |
URL: | https://www.google.com/favicon.ico |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 52280 |
Entropy (8bit): | 7.995413196679271 |
Encrypted: | true |
SSDEEP: | 1536:1rvqtK8DZilXxwJ8mMwAZy7phqsFLdG3B4d:xytBZits8bw4wzbFxG3B4d |
MD5: | F61F0D4D0F968D5BBA39A84C76277E1A |
SHA1: | AA3693EA140ECA418B4B2A30F6A68F6F43B4BEB2 |
SHA-256: | 57147F08949ABABE7DEEF611435AE418475A693E3823769A25C2A39B6EAD9CCC |
SHA-512: | 6C3BD90F709BCF9151C9ED9FFEA55C4F6883E7FDA2A4E26BF018C83FE1CFBE4F4AA0DB080D6D024070D53B2257472C399C8AC44EEFD38B9445640EFA85D5C487 |
Malicious: | false |
Reputation: | high, very likely benign file |
URL: | https://fonts.gstatic.com/s/googlesans/v58/4UaRrENHsxJlGDuGo1OIlJfC6l_24rlCK1Yo_Iq2vgCI.woff2 |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 84 |
Entropy (8bit): | 4.875266466142591 |
Encrypted: | false |
SSDEEP: | 3:DZFJu0+WVTBCq2Bjdw2KsJJuYHSKnZ:lFJuuVTBudw29nu4SKZ |
MD5: | 87B6333E98B7620EA1FF98D1A837A39E |
SHA1: | 105DE6815B0885357DE1414BFC0D77FCC9E924EF |
SHA-256: | DCD3C133C5C40BECD4100BBE6EDAE84C9735E778E4234A5E8395C56FF8A733BA |
SHA-512: | 867D7943D813685FAA76394E53199750C55817E836FD19C933F74D11E9657CE66719A6D6B2E39EE1DE62358BCE364E38A55F4E138DF92337DE6985DDCD5D0994 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISHgmA6QC9dWevzxIFDRkBE_oSBQ3oIX6GEgUN05ioBw==?alt=proto |
Preview: |
File type: | |
Entropy (8bit): | 6.581133758091637 |
TrID: |
|
File name: | file.exe |
File size: | 918'016 bytes |
MD5: | 8a053c1ee0f0ad79e8cd1a0788741383 |
SHA1: | b6e1e501874d798c8978e6e376be936386b87866 |
SHA256: | a1fb3e3bfa47fcb6a213addb2125c0971eccaba914830be8f9e2104c2edb2268 |
SHA512: | 94490fda5e002d24a4937a6be622848701ce4ce0b3c5e48bd76ea083bdd2f6fb66bf74c6403554ef98ecb8781c92b4005b02d5db64e2fc4d3bca19faeaad8c4f |
SSDEEP: | 12288:HqDEvFo+yo4DdbbMWu/jrQu4M9lBAlKhQcDGB3cuBNGE6iOrpfe4JdaDgaTTQ:HqDEvCTbMWu7rQYlBQcBiT6rprG8anQ |
TLSH: | 0B159E0273D1C062FFAB92334B5AF6515BBC69260123E61F13981DB9BE701B1563E7A3 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................j:......j:..C...j:......@.*...............................n.......~.............{.......{.......{.........z.... |
Icon Hash: | aaf3e3e3938382a0 |
Entrypoint: | 0x420577 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x66FC87B1 [Tue Oct 1 23:37:21 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 948cc502fe9226992dce9417f952fce3 |
Instruction |
---|
call 00007F34A8C2A043h |
jmp 00007F34A8C2994Fh |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007F34A8C29B2Dh |
mov dword ptr [esi], 0049FDF0h |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FDF8h |
mov dword ptr [ecx], 0049FDF0h |
ret |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007F34A8C29AFAh |
mov dword ptr [esi], 0049FE0Ch |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FE14h |
mov dword ptr [ecx], 0049FE0Ch |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
and dword ptr [eax], 00000000h |
and dword ptr [eax+04h], 00000000h |
push eax |
mov eax, dword ptr [ebp+08h] |
add eax, 04h |
push eax |
call 00007F34A8C2C6EDh |
pop ecx |
pop ecx |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
lea eax, dword ptr [ecx+04h] |
mov dword ptr [ecx], 0049FDD0h |
push eax |
call 00007F34A8C2C738h |
pop ecx |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
push eax |
call 00007F34A8C2C721h |
test byte ptr [ebp+08h], 00000001h |
pop ecx |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc8e64 | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xd4000 | 0x9750 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xde000 | 0x7594 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xb0ff0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0xc3400 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xb1010 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x9c000 | 0x894 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x9ab1d | 0x9ac00 | 0a1473f3064dcbc32ef93c5c8a90f3a6 | False | 0.565500681542811 | data | 6.668273581389308 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x9c000 | 0x2fb82 | 0x2fc00 | c9cf2468b60bf4f80f136ed54b3989fb | False | 0.35289185209424084 | data | 5.691811547483722 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xcc000 | 0x706c | 0x4800 | 53b9025d545d65e23295e30afdbd16d9 | False | 0.04356553819444445 | DOS executable (block device driver @\273\) | 0.5846666986982398 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xd4000 | 0x9750 | 0x9800 | f97dc394596efa6debd060cc0c00cadc | False | 0.29422800164473684 | data | 5.2263968035910775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xde000 | 0x7594 | 0x7600 | c68ee8931a32d45eb82dc450ee40efc3 | False | 0.7628111758474576 | data | 6.7972128181359786 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xd45a8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0xd46d0 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0xd47f8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0xd4920 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | Great Britain | 0.3333333333333333 |
RT_ICON | 0xd4c08 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | Great Britain | 0.5 |
RT_ICON | 0xd4d30 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | Great Britain | 0.2835820895522388 |
RT_ICON | 0xd5bd8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | Great Britain | 0.37906137184115524 |
RT_ICON | 0xd6480 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | Great Britain | 0.23699421965317918 |
RT_ICON | 0xd69e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | Great Britain | 0.13858921161825727 |
RT_ICON | 0xd8f90 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | Great Britain | 0.25070356472795496 |
RT_ICON | 0xda038 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | Great Britain | 0.3173758865248227 |
RT_MENU | 0xda4a0 | 0x50 | data | English | Great Britain | 0.9 |
RT_STRING | 0xda4f0 | 0x594 | data | English | Great Britain | 0.3333333333333333 |
RT_STRING | 0xdaa84 | 0x68a | data | English | Great Britain | 0.2735961768219833 |
RT_STRING | 0xdb110 | 0x490 | data | English | Great Britain | 0.3715753424657534 |
RT_STRING | 0xdb5a0 | 0x5fc | data | English | Great Britain | 0.3087467362924282 |
RT_STRING | 0xdbb9c | 0x65c | data | English | Great Britain | 0.34336609336609336 |
RT_STRING | 0xdc1f8 | 0x466 | data | English | Great Britain | 0.3605683836589698 |
RT_STRING | 0xdc660 | 0x158 | Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0 | English | Great Britain | 0.502906976744186 |
RT_RCDATA | 0xdc7b8 | 0xa18 | data | 1.0042569659442724 | ||
RT_GROUP_ICON | 0xdd1d0 | 0x76 | data | English | Great Britain | 0.6610169491525424 |
RT_GROUP_ICON | 0xdd248 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0xdd25c | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0xdd270 | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0xdd284 | 0xdc | data | English | Great Britain | 0.6181818181818182 |
RT_MANIFEST | 0xdd360 | 0x3ef | ASCII text, with CRLF line terminators | English | Great Britain | 0.5074478649453823 |
DLL | Import |
---|---|
WSOCK32.dll | gethostbyname, recv, send, socket, inet_ntoa, setsockopt, ntohs, WSACleanup, WSAStartup, sendto, htons, __WSAFDIsSet, select, accept, listen, bind, inet_addr, ioctlsocket, recvfrom, WSAGetLastError, closesocket, gethostname, connect |
VERSION.dll | GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW |
WINMM.dll | timeGetTime, waveOutSetVolume, mciSendStringW |
COMCTL32.dll | ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create |
MPR.dll | WNetGetConnectionW, WNetCancelConnection2W, WNetUseConnectionW, WNetAddConnection2W |
WININET.dll | HttpOpenRequestW, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, InternetConnectW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetQueryDataAvailable |
PSAPI.DLL | GetProcessMemoryInfo |
IPHLPAPI.DLL | IcmpSendEcho, IcmpCloseHandle, IcmpCreateFile |
USERENV.dll | DestroyEnvironmentBlock, LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile |
UxTheme.dll | IsThemeActive |
KERNEL32.dll | DuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, GetLongPathNameW, GetShortPathNameW, DeleteFileW, IsDebuggerPresent, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, LoadResource, LockResource, SizeofResource, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, LoadLibraryW, GetLocalTime, CompareStringW, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, VirtualAlloc, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, ResetEvent, WaitForSingleObjectEx, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, CloseHandle, GetFullPathNameW, GetStartupInfoW, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, ResumeThread, FreeLibraryAndExitThread, GetACP, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetStringTypeW, GetFileType, SetStdHandle, GetConsoleCP, GetConsoleMode, ReadConsoleW, GetTimeZoneInformation, FindFirstFileExW, IsValidCodePage, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, SetCurrentDirectoryW, FindNextFileW, WriteConsoleW |
USER32.dll | GetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, PeekMessageW, GetInputState, UnregisterHotKey, CharLowerBuffW, MonitorFromPoint, MonitorFromRect, LoadImageW, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, ClientToScreen, GetCursorPos, DeleteMenu, CheckMenuRadioItem, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, LockWindowUpdate, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, RegisterHotKey, GetCursorInfo, SetWindowPos, CopyImage, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, TrackPopupMenuEx, GetMessageW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, DispatchMessageW, keybd_event, TranslateMessage, ScreenToClient |
GDI32.dll | EndPath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, GetDeviceCaps, SetPixel, CloseFigure, LineTo, AngleArc, MoveToEx, Ellipse, CreateCompatibleBitmap, CreateCompatibleDC, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, SelectObject, StretchBlt, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, GetDIBits, StrokePath |
COMDLG32.dll | GetSaveFileNameW, GetOpenFileNameW |
ADVAPI32.dll | GetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, GetTokenInformation, RegCreateKeyExW, GetSecurityDescriptorDacl, GetAclInformation, GetUserNameW, AddAce, SetSecurityDescriptorDacl, InitiateSystemShutdownExW |
SHELL32.dll | DragFinish, DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW |
ole32.dll | CoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket |
OLEAUT32.dll | CreateStdDispatch, CreateDispTypeInfo, UnRegisterTypeLib, UnRegisterTypeLibForUser, RegisterTypeLibForUser, RegisterTypeLib, LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, VariantChangeType, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, SysStringLen, QueryPathOfRegTypeLib, SysAllocString, VariantInit, VariantClear, DispCallFunc, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, SafeArrayDestroyDescriptor, VariantCopy, OleLoadPicture |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 2, 2024 01:38:50.552994013 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 2, 2024 01:38:56.892304897 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:56.892333984 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:56.892402887 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:56.892987013 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:56.892999887 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.530097961 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.531186104 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.531200886 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.531554937 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.531622887 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.533052921 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.533127069 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.560220957 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.560264111 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.561835051 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.561841965 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.615026951 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.812259912 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.812311888 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.812385082 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.812418938 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.812454939 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.820195913 CEST | 50700 | 443 | 192.168.2.4 | 142.250.186.110 |
Oct 2, 2024 01:38:57.820204973 CEST | 443 | 50700 | 142.250.186.110 | 192.168.2.4 |
Oct 2, 2024 01:38:57.830158949 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:57.830255985 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:57.830329895 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:57.831486940 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:57.831525087 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.461812019 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.462106943 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.462179899 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.462532997 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.462610006 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.463146925 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.463252068 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.464234114 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.464318991 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.464411974 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.464431047 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.504978895 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.761609077 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.761624098 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.761678934 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:38:58.761722088 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.761759996 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.764126062 CEST | 50705 | 443 | 192.168.2.4 | 142.250.185.174 |
Oct 2, 2024 01:38:58.764147043 CEST | 443 | 50705 | 142.250.185.174 | 192.168.2.4 |
Oct 2, 2024 01:39:00.160777092 CEST | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Oct 2, 2024 01:39:01.247437000 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.247464895 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.247539043 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.247772932 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.247780085 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.314867973 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:01.314924002 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:01.314996004 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:01.316641092 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:01.316648960 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:01.879631996 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.879853964 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.879865885 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.880711079 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.880770922 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.881793976 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.881839991 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.926398993 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:01.926408052 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:01.960185051 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:01.960272074 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:01.967274904 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:01.967291117 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:01.967530012 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:01.976629019 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:02.013775110 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.055425882 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.231800079 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.231843948 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.231918097 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.297707081 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.297744036 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.297759056 CEST | 50711 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.297766924 CEST | 443 | 50711 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.446005106 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.446053028 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:02.446116924 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.446398020 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:02.446412086 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.218298912 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.218385935 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.220328093 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.220340967 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.220561981 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.222524881 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.267404079 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.500682116 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.500735998 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.500895023 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.501419067 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.501434088 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:03.501442909 CEST | 50714 | 443 | 192.168.2.4 | 184.28.90.27 |
Oct 2, 2024 01:39:03.501449108 CEST | 443 | 50714 | 184.28.90.27 | 192.168.2.4 |
Oct 2, 2024 01:39:04.217605114 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:04.263403893 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.483880997 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.483921051 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.483957052 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.483983994 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.484082937 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:04.484095097 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:04.484095097 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:04.484128952 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:04.484960079 CEST | 50710 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:39:04.484968901 CEST | 443 | 50710 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:39:12.860697031 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:12.860728979 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:12.860801935 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:12.861803055 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:12.861814022 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:13.443660021 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:13.443747997 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:13.447345018 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:13.447351933 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:13.447602034 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:13.489237070 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.700639009 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.747400045 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.893954992 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.893986940 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.893996954 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894041061 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894074917 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894076109 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.894102097 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894119978 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.894119978 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.894130945 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894156933 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.894180059 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:14.894238949 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894273043 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:14.894840956 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:15.809967041 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:15.809988022 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:15.809999943 CEST | 50722 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:15.810004950 CEST | 443 | 50722 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:20.028713942 CEST | 56667 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:20.033500910 CEST | 53 | 56667 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:20.033588886 CEST | 56667 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:20.038363934 CEST | 53 | 56667 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:20.496834993 CEST | 56667 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:20.502175093 CEST | 53 | 56667 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:20.502228022 CEST | 56667 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:22.512214899 CEST | 58615 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:22.516997099 CEST | 53 | 58615 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:22.519331932 CEST | 58615 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:22.524164915 CEST | 53 | 58615 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:22.983652115 CEST | 58615 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:22.984283924 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:22.984328032 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:22.984402895 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:22.984819889 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:22.984833002 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:22.989461899 CEST | 53 | 58615 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:22.989516020 CEST | 58615 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:23.762379885 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:23.762437105 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:23.765954971 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:23.765964985 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:23.766164064 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:23.774647951 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:23.819408894 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:24.220995903 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:24.221060038 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:24.221110106 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:24.221195936 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:24.221214056 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:24.221224070 CEST | 58616 | 443 | 192.168.2.4 | 13.85.23.206 |
Oct 2, 2024 01:39:24.221229076 CEST | 443 | 58616 | 13.85.23.206 | 192.168.2.4 |
Oct 2, 2024 01:39:24.242065907 CEST | 58617 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:24.242094040 CEST | 443 | 58617 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:24.242182970 CEST | 58617 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:24.242433071 CEST | 58617 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:24.242445946 CEST | 443 | 58617 | 20.12.23.50 | 192.168.2.4 |
Oct 2, 2024 01:39:24.832715034 CEST | 58617 | 443 | 192.168.2.4 | 20.12.23.50 |
Oct 2, 2024 01:39:24.853506088 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:24.853528023 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:24.853589058 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:24.854052067 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:24.854063034 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.568166971 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.568229914 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:25.570014000 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:25.570019960 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.570266962 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.571146011 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:25.615410089 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.755577087 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.755649090 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:25.755700111 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:25.758471966 CEST | 58618 | 443 | 192.168.2.4 | 13.85.23.86 |
Oct 2, 2024 01:39:25.758481026 CEST | 443 | 58618 | 13.85.23.86 | 192.168.2.4 |
Oct 2, 2024 01:39:27.634809971 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:27.634875059 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:27.634963036 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:27.635447025 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:27.635473013 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:28.607852936 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:28.607918024 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:28.609350920 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:28.609373093 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:28.609622955 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:28.610610962 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:28.655400991 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.903435946 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.903461933 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.903479099 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.903539896 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:29.903587103 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.903656960 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:29.904124975 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.904175997 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.904216051 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:29.908556938 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:29.908595085 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:29.908611059 CEST | 58619 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:29.908621073 CEST | 443 | 58619 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.034097910 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.034179926 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.034337997 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.034648895 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.034698963 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.842525005 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.842639923 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.871256113 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.871309996 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.871637106 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:30.872577906 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:30.919409990 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.172852993 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.172873974 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.172888994 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.172939062 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.172979116 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.173010111 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.173032045 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.174124956 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.174161911 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.174199104 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.174206972 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.174218893 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.174259901 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.176246881 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.176278114 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:39:31.176309109 CEST | 58620 | 443 | 192.168.2.4 | 20.114.59.183 |
Oct 2, 2024 01:39:31.176322937 CEST | 443 | 58620 | 20.114.59.183 | 192.168.2.4 |
Oct 2, 2024 01:40:01.389844894 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:01.389873981 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:01.389960051 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:01.390228987 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:01.390239954 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:02.024976969 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:02.025279999 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:02.025298119 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:02.025770903 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:02.026063919 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:02.026143074 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:02.070966005 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:11.925801039 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:11.925889969 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:40:11.925949097 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:38.521982908 CEST | 58622 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:40:38.522003889 CEST | 443 | 58622 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.366132021 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:41:01.366170883 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.366275072 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:41:01.366600037 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:41:01.366612911 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.998116970 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.998501062 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:41:01.998523951 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.999648094 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:01.999989986 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Oct 2, 2024 01:41:02.000164986 CEST | 443 | 58624 | 142.250.184.196 | 192.168.2.4 |
Oct 2, 2024 01:41:02.049834013 CEST | 58624 | 443 | 192.168.2.4 | 142.250.184.196 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 2, 2024 01:38:56.878489971 CEST | 49472 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:38:56.878639936 CEST | 55410 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:38:56.885113001 CEST | 53 | 49472 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:56.886234045 CEST | 53 | 51149 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:56.889461040 CEST | 53 | 55410 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:56.903215885 CEST | 53 | 61876 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:57.822614908 CEST | 59651 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:38:57.822870016 CEST | 49407 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:38:57.829503059 CEST | 53 | 59651 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:57.829581022 CEST | 53 | 49407 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:38:57.895142078 CEST | 53 | 49358 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:01.239876986 CEST | 52175 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:01.240008116 CEST | 55676 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:01.246588945 CEST | 53 | 55676 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:01.246602058 CEST | 53 | 52175 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:03.274925947 CEST | 53 | 54811 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:08.997390032 CEST | 53 | 50790 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:14.935261011 CEST | 53 | 58307 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:19.354760885 CEST | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Oct 2, 2024 01:39:20.028331041 CEST | 53 | 55094 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:22.511749029 CEST | 53 | 59500 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:39:24.844906092 CEST | 58482 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:39:24.851932049 CEST | 53 | 58482 | 1.1.1.1 | 192.168.2.4 |
Oct 2, 2024 01:40:01.303844929 CEST | 59036 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 2, 2024 01:40:01.388524055 CEST | 53 | 59036 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 2, 2024 01:38:56.878489971 CEST | 192.168.2.4 | 1.1.1.1 | 0x6a86 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 01:38:56.878639936 CEST | 192.168.2.4 | 1.1.1.1 | 0x905 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 01:38:57.822614908 CEST | 192.168.2.4 | 1.1.1.1 | 0xce18 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 01:38:57.822870016 CEST | 192.168.2.4 | 1.1.1.1 | 0x5375 | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 01:39:01.239876986 CEST | 192.168.2.4 | 1.1.1.1 | 0xb125 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 2, 2024 01:39:01.240008116 CEST | 192.168.2.4 | 1.1.1.1 | 0xfd4b | Standard query (0) | 65 | IN (0x0001) | false | |
Oct 2, 2024 01:39:24.844906092 CEST | 192.168.2.4 | 1.1.1.1 | 0x6d86 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Oct 2, 2024 01:40:01.303844929 CEST | 192.168.2.4 | 1.1.1.1 | 0x7018 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 2, 2024 01:38:56.885113001 CEST | 1.1.1.1 | 192.168.2.4 | 0x6a86 | No error (0) | 142.250.186.110 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:56.889461040 CEST | 1.1.1.1 | 192.168.2.4 | 0x905 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | youtube-ui.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.174 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 216.58.212.142 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.184.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 172.217.23.110 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 172.217.16.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.74.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 216.58.206.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.186.142 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.181.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 172.217.18.110 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.184.206 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.142 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.238 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.78 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829503059 CEST | 1.1.1.1 | 192.168.2.4 | 0xce18 | No error (0) | 142.250.185.110 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829581022 CEST | 1.1.1.1 | 192.168.2.4 | 0x5375 | No error (0) | youtube-ui.l.google.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 2, 2024 01:38:57.829581022 CEST | 1.1.1.1 | 192.168.2.4 | 0x5375 | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 01:39:01.246588945 CEST | 1.1.1.1 | 192.168.2.4 | 0xfd4b | No error (0) | 65 | IN (0x0001) | false | |||
Oct 2, 2024 01:39:01.246602058 CEST | 1.1.1.1 | 192.168.2.4 | 0xb125 | No error (0) | 142.250.184.196 | A (IP address) | IN (0x0001) | false | ||
Oct 2, 2024 01:39:24.851932049 CEST | 1.1.1.1 | 192.168.2.4 | 0x6d86 | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Oct 2, 2024 01:40:01.388524055 CEST | 1.1.1.1 | 192.168.2.4 | 0x7018 | No error (0) | 142.250.184.196 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 50700 | 142.250.186.110 | 443 | 2996 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 23:38:57 UTC | 851 | OUT | |
2024-10-01 23:38:57 UTC | 1726 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 50705 | 142.250.185.174 | 443 | 2996 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-01 23:38:58 UTC | 869 | OUT | |
2024-10-01 23:38:58 UTC | 2634 | IN |