Windows
Analysis Report
mGFoU1INUk.exe
Overview
General Information
Sample name: | mGFoU1INUk.exerenamed because original name is a hash value |
Original sample name: | 18daa2c6a6f6385895582d4e9954d851.exe |
Analysis ID: | 1532225 |
MD5: | 18daa2c6a6f6385895582d4e9954d851 |
SHA1: | 88f22a473df849c91e70a91a8376abff2b5b108f |
SHA256: | 346085fe3603fbc085f801241cccdc4d3765929a6cd5f9906cbcfcd6657065a3 |
Tags: | exeSocks5Systemzuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- mGFoU1INUk.exe (PID: 1976 cmdline:
"C:\Users\ user\Deskt op\mGFoU1I NUk.exe" MD5: 18DAA2C6A6F6385895582D4E9954D851) - explorer.exe (PID: 1028 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- ibjgueh (PID: 5960 cmdline:
C:\Users\u ser\AppDat a\Roaming\ ibjgueh MD5: 18DAA2C6A6F6385895582D4E9954D851)
- ibjgueh (PID: 2604 cmdline:
C:\Users\u ser\AppDat a\Roaming\ ibjgueh MD5: 18DAA2C6A6F6385895582D4E9954D851)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T20:07:29.848902+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49792 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:31.374913+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49799 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:32.891080+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49809 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:34.426343+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49820 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:35.946752+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49831 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:37.459108+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49841 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:38.958859+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49849 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:40.481991+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49861 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:41.972367+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49870 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:43.476100+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49881 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:44.967534+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49892 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:46.457451+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49903 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:47.959801+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49914 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:49.466916+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49925 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:50.949811+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49932 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:52.436567+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49943 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:53.920305+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49954 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:55.414257+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49964 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:56.903613+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49972 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:58.598972+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49983 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:00.089880+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49993 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:01.634818+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49998 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:03.281168+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49999 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:04.804921+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50000 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:08.140704+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50002 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:09.781553+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50003 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:11.264790+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50004 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:12.807847+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50005 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:15.107333+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50006 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:16.639263+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50007 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:18.120800+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50008 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:19.640221+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50009 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:21.135939+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50010 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:22.613113+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50011 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:23.941825+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50012 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:25.476955+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50013 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:34.491548+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50014 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:39.836652+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50015 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:45.207552+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50016 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:51.304176+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50017 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:57.203146+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50018 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:10:07.063551+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60089 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:11.870177+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60090 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:17.910339+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60091 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:23.702222+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60092 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:30.353244+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60093 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:36.229845+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60094 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:41.630767+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60095 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:46.361537+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60096 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:51.684157+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60097 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:56.903490+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60098 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:11:04.022959+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 60099 | 175.119.10.231 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 4_2_00401514 | |
Source: | Code function: | 4_2_00402F97 | |
Source: | Code function: | 4_2_00401542 | |
Source: | Code function: | 4_2_00403247 | |
Source: | Code function: | 4_2_00401549 | |
Source: | Code function: | 4_2_0040324F | |
Source: | Code function: | 4_2_00403256 | |
Source: | Code function: | 4_2_00401557 | |
Source: | Code function: | 4_2_0040326C | |
Source: | Code function: | 4_2_00403277 | |
Source: | Code function: | 4_2_004014FE | |
Source: | Code function: | 4_2_00403290 |
Source: | Code function: | 0_2_00415BA0 | |
Source: | Code function: | 4_2_00415BA0 |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02C4A58F |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02C4DFEA | |
Source: | Code function: | 0_2_02C4CE89 | |
Source: | Code function: | 0_2_02C4C3C2 | |
Source: | Code function: | 0_2_02C54A41 | |
Source: | Code function: | 0_2_02C54831 | |
Source: | Code function: | 0_2_02FC1550 | |
Source: | Code function: | 4_2_004014E9 | |
Source: | Code function: | 4_2_004032AB | |
Source: | Code function: | 4_2_02CC1550 | |
Source: | Code function: | 4_2_02D0E46A | |
Source: | Code function: | 4_2_02D0C842 | |
Source: | Code function: | 4_2_02D0D309 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_02C49E6C | |
Source: | Code function: | 0_2_02FC0D90 | |
Source: | Code function: | 0_2_02FC092B | |
Source: | Code function: | 4_2_02CC0D90 | |
Source: | Code function: | 4_2_02CC092B | |
Source: | Code function: | 4_2_02D0A2EC |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_00404E64 |
Source: | Code function: | 0_2_00415BA0 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 411 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 115 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 14 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
37% | ReversingLabs | |||
36% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
37% | ReversingLabs | |||
36% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
2% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
17% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 119.204.11.2 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
23.145.40.164 | unknown | Reserved | 22631 | SURFAIRWIRELESS-IN-01US | true | |
119.204.11.2 | nwgrus.ru | Korea Republic of | 4766 | KIXS-AS-KRKoreaTelecomKR | true | |
175.119.10.231 | unknown | Korea Republic of | 9318 | SKB-ASSKBroadbandCoLtdKR | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532225 |
Start date and time: | 2024-10-12 20:06:05 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 23s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | mGFoU1INUk.exerenamed because original name is a hash value |
Original Sample Name: | 18daa2c6a6f6385895582d4e9954d851.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@4/3@6/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target ibjgueh, PID 2604 because there are no executed function
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
14:07:13 | API Interceptor | |
20:07:24 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
23.145.40.164 | Get hash | malicious | SmokeLoader | Browse | ||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
119.204.11.2 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
175.119.10.231 | Get hash | malicious | CryptOne, SmokeLoader, Stealc | Browse |
| |
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu, Vidar | Browse |
| ||
Get hash | malicious | Babuk, Clipboard Hijacker, Djvu, Vidar | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
SKB-ASSKBroadbandCoLtdKR | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
KIXS-AS-KRKoreaTelecomKR | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
SURFAIRWIRELESS-IN-01US | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
72a589da586844d7f0818ce684948eea | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 167865 |
Entropy (8bit): | 6.197261972623414 |
Encrypted: | false |
SSDEEP: | 3072:GTAGy4uRrZA2NHJAgrOKePxcq55Q+CoNJk:GTAGyKurN+F4 |
MD5: | FB7D3959E02DD0DE0E7548C6F7CB2C5D |
SHA1: | 46CE9F287A834D1AC9970CD8463AB15F402CF51C |
SHA-256: | C741E33C801163A9CCBC88DEA39D63B4ECF1A3E533363C925B21EEEBF06576CF |
SHA-512: | 5D888B9E3289EE384655DBDB04ADF529DB1455A8BB35D3F3E24865BE4A518CC6D8116123304413369655835B4B32D4B2DDFAAC2C2BEF240A51778B3D7E4EB584 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243200 |
Entropy (8bit): | 5.891193199564729 |
Encrypted: | false |
SSDEEP: | 3072:iTAAHnZJKzRKc6jdtPcTui/scq5vQ+CoNAMenJFBxqXYUGrG:iTAa7PCTd+FSMe/qI |
MD5: | 18DAA2C6A6F6385895582D4E9954D851 |
SHA1: | 88F22A473DF849C91E70A91A8376ABFF2B5B108F |
SHA-256: | 346085FE3603FBC085F801241CCCDC4D3765929A6CD5F9906CBCFCD6657065A3 |
SHA-512: | 552A9FFBB3A80495A523D7052E940677778AEED5A9569459029A71A4D45CF568CE447A4E79EFEA786CA4220B913F11CE1B4F8819AF48C7078430AEF2DA090F8F |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.891193199564729 |
TrID: |
|
File name: | mGFoU1INUk.exe |
File size: | 243'200 bytes |
MD5: | 18daa2c6a6f6385895582d4e9954d851 |
SHA1: | 88f22a473df849c91e70a91a8376abff2b5b108f |
SHA256: | 346085fe3603fbc085f801241cccdc4d3765929a6cd5f9906cbcfcd6657065a3 |
SHA512: | 552a9ffbb3a80495a523d7052e940677778aeed5a9569459029a71a4d45cf568ce447a4e79efea786ca4220b913f11ce1b4f8819af48c7078430aef2da090f8f |
SSDEEP: | 3072:iTAAHnZJKzRKc6jdtPcTui/scq5vQ+CoNAMenJFBxqXYUGrG:iTAa7PCTd+FSMe/qI |
TLSH: | D1342BC26EF17815F2B3CA31DE3992E4E52FF5D29E24725D21A4DA0F08F11A1D92B712 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........y...*...*...*...*...*...*...*...*...*.F.*...*...*...*...*...*...*...*...*...*Rich...*........................PE..L...Q..f... |
Icon Hash: | 738733b18ba383e4 |
Entrypoint: | 0x4018e4 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x661CE451 [Mon Apr 15 08:24:49 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | 636068238a0ab0df9c8e341eee8428d0 |
Instruction |
---|
call 00007FE54CFF8230h |
jmp 00007FE54CFF4B2Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041A3D0h], eax |
mov dword ptr [0041A3CCh], ecx |
mov dword ptr [0041A3C8h], edx |
mov dword ptr [0041A3C4h], ebx |
mov dword ptr [0041A3C0h], esi |
mov dword ptr [0041A3BCh], edi |
mov word ptr [0041A3E8h], ss |
mov word ptr [0041A3DCh], cs |
mov word ptr [0041A3B8h], ds |
mov word ptr [0041A3B4h], es |
mov word ptr [0041A3B0h], fs |
mov word ptr [0041A3ACh], gs |
pushfd |
pop dword ptr [0041A3E0h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041A3D4h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041A3D8h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041A3E4h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041A320h], 00010001h |
mov eax, dword ptr [0041A3D8h] |
mov dword ptr [0041A2D4h], eax |
mov dword ptr [0041A2C8h], C0000409h |
mov dword ptr [0041A2CCh], 00000001h |
mov eax, dword ptr [00419008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041900Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000DCh] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x17774 | 0x3c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2721000 | 0x1cac0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x16000 | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x14faf | 0x15000 | 6dc5e30b5d87861babcd358eb53f2106 | False | 0.8236374627976191 | data | 7.549565623085082 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x16000 | 0x2026 | 0x2200 | 6da4b7c2534b0027fef7635e158ee334 | False | 0.36247702205882354 | data | 5.4153798035975225 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x19000 | 0x26fff7c | 0x1400 | 3cba851d696b61283dc196131a3cd2a4 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.suhak | 0x2719000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.fofifuf | 0x271e000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2721000 | 0x1cac0 | 0x1cc00 | a27998791c525f409926d67585ed7489 | False | 0.4417119565217391 | data | 5.078965960078043 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x27219d0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5700959488272921 |
RT_ICON | 0x2722878 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6371841155234657 |
RT_ICON | 0x2723120 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6935483870967742 |
RT_ICON | 0x27237e8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2723d50 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.5137966804979253 |
RT_ICON | 0x27262f8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6128048780487805 |
RT_ICON | 0x27273a0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6180327868852459 |
RT_ICON | 0x2727d28 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7570921985815603 |
RT_ICON | 0x2728208 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.3342217484008529 |
RT_ICON | 0x27290b0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.526173285198556 |
RT_ICON | 0x2729958 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.5892857142857143 |
RT_ICON | 0x272a020 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6329479768786127 |
RT_ICON | 0x272a588 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.4270746887966805 |
RT_ICON | 0x272cb30 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.5057377049180328 |
RT_ICON | 0x272d4b8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.5044326241134752 |
RT_ICON | 0x272d988 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39498933901918976 |
RT_ICON | 0x272e830 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5546028880866426 |
RT_ICON | 0x272f0d8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6169354838709677 |
RT_ICON | 0x272f7a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6423410404624278 |
RT_ICON | 0x272fd08 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.42706378986866794 |
RT_ICON | 0x2730db0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4245901639344262 |
RT_ICON | 0x2731738 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.4645390070921986 |
RT_ICON | 0x2731c08 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.28331556503198296 |
RT_ICON | 0x2732ab0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.36913357400722024 |
RT_ICON | 0x2733358 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.37672811059907835 |
RT_ICON | 0x2733a20 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3786127167630058 |
RT_ICON | 0x2733f88 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.25778008298755184 |
RT_ICON | 0x2736530 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.275328330206379 |
RT_ICON | 0x27375d8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28647540983606556 |
RT_ICON | 0x2737f60 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32358156028368795 |
RT_STRING | 0x27385f8 | 0xcc | data | 0.553921568627451 | ||
RT_STRING | 0x27386c8 | 0x50c | data | 0.4473684210526316 | ||
RT_STRING | 0x2738bd8 | 0x3aa | data | 0.4616204690831556 | ||
RT_STRING | 0x2738f88 | 0x52c | data | 0.4516616314199396 | ||
RT_STRING | 0x27394b8 | 0x652 | data | 0.4338689740420272 | ||
RT_STRING | 0x2739b10 | 0x798 | data | 0.41975308641975306 | ||
RT_STRING | 0x273a2a8 | 0x84c | data | 0.4129001883239171 | ||
RT_STRING | 0x273aaf8 | 0x666 | data | 0.4340659340659341 | ||
RT_STRING | 0x273b160 | 0x7f6 | data | 0.4210009813542689 | ||
RT_STRING | 0x273b958 | 0x758 | data | 0.41914893617021276 | ||
RT_STRING | 0x273c0b0 | 0x78c | data | 0.4254658385093168 | ||
RT_STRING | 0x273c840 | 0x666 | data | 0.4340659340659341 | ||
RT_STRING | 0x273cea8 | 0x69e | data | 0.4268004722550177 | ||
RT_STRING | 0x273d548 | 0x54c | data | 0.44026548672566373 | ||
RT_STRING | 0x273da98 | 0x26 | data | 0.5526315789473685 | ||
RT_GROUP_ICON | 0x272d920 | 0x68 | data | Turkish | Turkey | 0.7019230769230769 |
RT_GROUP_ICON | 0x27383c8 | 0x76 | data | Turkish | Turkey | 0.6779661016949152 |
RT_GROUP_ICON | 0x2728190 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2731ba0 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2738440 | 0x1b4 | data | 0.5848623853211009 |
DLL | Import |
---|---|
KERNEL32.dll | GetConsoleAliasExesLengthA, DeleteVolumeMountPointA, OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, InterlockedCompareExchange, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, SetCommState, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, GetTimeFormatW, SearchPathW, GetBinaryTypeA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, GetNumaHighestNodeNumber, LoadLibraryA, LocalAlloc, WritePrivateProfileStringA, QueryDosDeviceW, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SetConsoleMode, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, GetCPInfo, InterlockedIncrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, HeapSize |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T20:07:29.848902+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49792 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:31.374913+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49799 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:32.891080+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49809 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:34.426343+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49820 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:35.946752+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49831 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:37.459108+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49841 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:38.958859+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49849 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:40.481991+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49861 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:41.972367+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49870 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:43.476100+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49881 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:44.967534+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49892 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:46.457451+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49903 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:47.959801+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49914 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:49.466916+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49925 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:50.949811+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49932 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:52.436567+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49943 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:53.920305+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49954 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:55.414257+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49964 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:56.903613+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49972 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:07:58.598972+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49983 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:00.089880+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49993 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:01.634818+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49998 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:03.281168+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49999 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:04.804921+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50000 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:08.140704+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50002 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:09.781553+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50003 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:11.264790+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50004 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:12.807847+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50005 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:15.107333+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50006 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:16.639263+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50007 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:18.120800+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50008 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:19.640221+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50009 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:21.135939+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50010 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:22.613113+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50011 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:23.941825+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50012 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:08:25.476955+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50013 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:34.491548+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50014 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:39.836652+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50015 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:45.207552+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50016 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:51.304176+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50017 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:09:57.203146+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50018 | 119.204.11.2 | 80 | TCP |
2024-10-12T20:10:07.063551+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60089 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:11.870177+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60090 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:17.910339+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60091 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:23.702222+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60092 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:30.353244+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60093 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:36.229845+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60094 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:41.630767+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60095 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:46.361537+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60096 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:51.684157+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60097 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:10:56.903490+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60098 | 175.119.10.231 | 80 | TCP |
2024-10-12T20:11:04.022959+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 60099 | 175.119.10.231 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 20:07:28.075416088 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:28.080332041 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:28.084074974 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:28.084242105 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:28.084254980 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:28.089385986 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:28.089456081 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.848795891 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.848814964 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.848819017 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.848901987 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.849989891 CEST | 49792 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.855135918 CEST | 80 | 49792 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.856249094 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.861108065 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.861186028 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.861692905 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.861723900 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:29.866565943 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:29.866575003 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.374404907 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.374792099 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.374912977 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.375153065 CEST | 49799 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.378616095 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.379995108 CEST | 80 | 49799 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.383480072 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.385885000 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.386056900 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.386091948 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:31.390966892 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:31.391489029 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.890898943 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.890948057 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.891079903 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.891319990 CEST | 49809 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.894352913 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.896089077 CEST | 80 | 49809 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.899163961 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.899247885 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.899426937 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.899456024 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:32.904236078 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:32.904414892 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.426244020 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.426287889 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.426342964 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.426495075 CEST | 49820 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.429492950 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.431477070 CEST | 80 | 49820 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.434863091 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.434946060 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.435060024 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.435089111 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:34.440107107 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:34.440135956 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.946641922 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.946676016 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.946752071 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.946875095 CEST | 49831 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.949459076 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.951684952 CEST | 80 | 49831 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.954246998 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.955926895 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.956039906 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.956039906 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:35.960818052 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:35.961082935 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.458920956 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.459052086 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.459108114 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.459192038 CEST | 49841 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.462085962 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.464039087 CEST | 80 | 49841 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.466983080 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.467063904 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.467190981 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.467225075 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:37.471970081 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:37.472177982 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.958609104 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.958801985 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.958858967 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.958924055 CEST | 49849 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.961695910 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.963689089 CEST | 80 | 49849 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.966685057 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.966808081 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.966912031 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.967140913 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:38.971641064 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:38.971852064 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.481789112 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.481942892 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.481991053 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.483067989 CEST | 49861 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.485280037 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.487932920 CEST | 80 | 49861 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.490185976 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.490252018 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.490367889 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.490377903 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:40.495178938 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:40.495187044 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.972019911 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.972307920 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.972367048 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.972440958 CEST | 49870 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.976982117 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.977267981 CEST | 80 | 49870 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.981909037 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.982019901 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.982127905 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.982155085 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:41.986932039 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:41.987041950 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.473678112 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.474653006 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.476099968 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.476146936 CEST | 49881 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.478612900 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.481029034 CEST | 80 | 49881 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.483577967 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.483639956 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.483773947 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.483793020 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:43.488534927 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:43.488544941 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.967206001 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.967457056 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.967534065 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.967576981 CEST | 49892 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.969868898 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.972446918 CEST | 80 | 49892 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.974981070 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.975231886 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.975231886 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.975404024 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:44.980185032 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:44.980211020 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.457277060 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.457314014 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.457451105 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.457617998 CEST | 49903 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.460134983 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.462490082 CEST | 80 | 49903 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.465078115 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.465184927 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.465318918 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.465373039 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:46.470110893 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:46.470233917 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.959476948 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.959691048 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.959800959 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.959800959 CEST | 49914 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.962589025 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.964683056 CEST | 80 | 49914 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.967750072 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.967833996 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.967969894 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.968004942 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:47.972826958 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:47.972942114 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.466757059 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.466795921 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.466916084 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.467063904 CEST | 49925 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.469439983 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.471947908 CEST | 80 | 49925 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.474510908 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.474600077 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.474919081 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.474951029 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:49.479720116 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:49.479937077 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.949657917 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.949701071 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.949810982 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.949930906 CEST | 49932 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.952074051 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.954751968 CEST | 80 | 49932 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.956986904 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.957077980 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.957179070 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.957180023 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:50.962038040 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:50.962068081 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.436352968 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.436495066 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.436567068 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.436619043 CEST | 49943 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.439568996 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.441471100 CEST | 80 | 49943 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.444452047 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.444534063 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.444674969 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.444685936 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:52.449487925 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:52.449601889 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.920020103 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.920252085 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.920305014 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.920347929 CEST | 49954 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.924154043 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.925143957 CEST | 80 | 49954 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.929255009 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.929353952 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.929517984 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.929550886 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:53.934362888 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:53.934515953 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.414083958 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.414165974 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.414257050 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.414398909 CEST | 49964 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.417716980 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.419969082 CEST | 80 | 49964 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.422612906 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.423331022 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.423439026 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.423453093 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:55.428386927 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:55.428638935 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.903420925 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.903554916 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.903613091 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.903645992 CEST | 49972 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.905852079 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.908566952 CEST | 80 | 49972 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.910773993 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.910845041 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.910952091 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.910976887 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:56.915836096 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:56.916021109 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.598740101 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.598787069 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.598871946 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.598972082 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.599797010 CEST | 49983 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.602504969 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.604635000 CEST | 80 | 49983 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.607451916 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.610280037 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.610378981 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.610402107 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:07:58.618027925 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:07:58.618057013 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.089637995 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.089792013 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.089879990 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.089879990 CEST | 49993 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.092329979 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.094861031 CEST | 80 | 49993 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.097347975 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.097444057 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.097592115 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.097647905 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:00.102510929 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:00.102543116 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.634527922 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.634624004 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.634818077 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.665533066 CEST | 49998 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.671596050 CEST | 80 | 49998 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.765675068 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.770747900 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.770827055 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.771761894 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.771790028 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:01.776616096 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:01.776768923 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.280970097 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.281069994 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.281167984 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.281323910 CEST | 49999 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.283809900 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.286107063 CEST | 80 | 49999 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.288744926 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.288834095 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.293900013 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.293936014 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:03.298789024 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:03.298892021 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:04.804044962 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:04.804840088 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:04.804920912 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:04.805011034 CEST | 50000 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:04.807180882 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:04.807272911 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:04.807414055 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:04.807898045 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:04.807936907 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:04.809922934 CEST | 80 | 50000 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:05.426835060 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:05.426939011 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:05.428956985 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:05.429012060 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:05.429435968 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:05.437896967 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:05.483407974 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.616775990 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.616842031 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.616977930 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.617043018 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.622133017 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.622239113 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.622257948 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.622472048 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.622565985 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.622579098 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.624172926 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.624260902 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.624294996 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.625029087 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.625108957 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.625122070 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.627831936 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.627927065 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.627939939 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.628914118 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.629034042 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.629048109 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.632078886 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.632169962 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.632183075 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.632850885 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.632932901 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.632945061 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.633457899 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.633536100 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.633548021 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.634052038 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.634131908 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.634144068 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.634490013 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.634566069 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.634577036 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.635035038 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.635113001 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.635123968 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.637525082 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.637603998 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.637615919 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.637645960 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.637726068 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.637737036 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.638093948 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.638169050 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.638180017 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.638259888 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.638333082 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.638344049 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.639022112 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.639111042 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.639127016 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.639166117 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.639214039 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.639239073 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.640044928 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.640146971 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.640208006 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.640290022 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.640300989 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.640396118 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.640458107 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.640499115 CEST | 50001 | 443 | 192.168.2.5 | 23.145.40.164 |
Oct 12, 2024 20:08:06.640527964 CEST | 443 | 50001 | 23.145.40.164 | 192.168.2.5 |
Oct 12, 2024 20:08:06.661393881 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:06.666320086 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:06.666403055 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:06.666564941 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:06.666588068 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:06.671478987 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:06.671494961 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.140535116 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.140613079 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.140703917 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.140955925 CEST | 50002 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.143580914 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.147577047 CEST | 80 | 50002 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.149363995 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.149441004 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.149559021 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.149594069 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:08.155446053 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:08.155453920 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.781217098 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.781232119 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.781234980 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.781553030 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.781666994 CEST | 50003 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.785038948 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.786573887 CEST | 80 | 50003 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.790123940 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.790216923 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.790385008 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.790419102 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:09.795181990 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:09.795357943 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.264607906 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.264705896 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.264790058 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.265103102 CEST | 50004 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.268346071 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.270302057 CEST | 80 | 50004 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.274672985 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.274806023 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.274945021 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.274966955 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:11.281177044 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:11.281214952 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.806922913 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.807482958 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.807847023 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.807847023 CEST | 50005 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.811254978 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.813213110 CEST | 80 | 50005 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.816379070 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.816540003 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.816751003 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.816786051 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:12.821635962 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:12.821752071 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.107202053 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.107248068 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.107276917 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.107314110 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.107332945 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.107332945 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.107453108 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.107614040 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.108445883 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.108505011 CEST | 50006 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.111119032 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.113223076 CEST | 80 | 50006 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.116086960 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.116169930 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.116512060 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.116561890 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:15.121419907 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:15.121510029 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.638910055 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.639003038 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.639262915 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.639586926 CEST | 50007 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.642072916 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.644808054 CEST | 80 | 50007 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.647351027 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.647474051 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.650084019 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.650121927 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:16.655230999 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:16.655271053 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.120666981 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.120716095 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.120800018 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.120954990 CEST | 50008 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.126095057 CEST | 80 | 50008 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.135024071 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.140064955 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.140151978 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.140367031 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.140367031 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:18.145693064 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:18.145724058 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.640125990 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.640150070 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.640221119 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.640378952 CEST | 50009 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.643846035 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.645279884 CEST | 80 | 50009 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.648659945 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.648749113 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.650695086 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.650719881 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:19.655569077 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:19.655596018 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.135768890 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.135833025 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.135938883 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.136056900 CEST | 50010 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.139151096 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.140896082 CEST | 80 | 50010 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.144131899 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.144331932 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.144534111 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.144654989 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:21.149337053 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:21.149452925 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.612827063 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.612874985 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.613112926 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.613535881 CEST | 50011 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.618426085 CEST | 80 | 50011 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.619102955 CEST | 50012 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.624028921 CEST | 80 | 50012 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.624248028 CEST | 50012 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.624696970 CEST | 50012 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.624831915 CEST | 50012 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:22.629547119 CEST | 80 | 50012 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:22.629637003 CEST | 80 | 50012 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:23.941824913 CEST | 50012 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:23.954070091 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:23.959233999 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:23.959373951 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:23.959450006 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:23.959471941 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:23.964519978 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:23.964550018 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:25.476564884 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:25.476701975 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:08:25.476954937 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:25.478574991 CEST | 50013 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:08:25.483500957 CEST | 80 | 50013 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:32.645432949 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:32.650964975 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:32.651062012 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:32.651304007 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:32.651304007 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:32.656173944 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:32.656270027 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:34.491059065 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:34.491348028 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:34.491364956 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:34.491380930 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:34.491548061 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:34.491548061 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:34.491548061 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:34.492841959 CEST | 50014 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:34.497596979 CEST | 80 | 50014 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:38.294967890 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:38.300112009 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:38.300205946 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:38.300371885 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:38.300395012 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:38.305162907 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:38.305314064 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:39.836384058 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:39.836433887 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:39.836652040 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:39.836746931 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.144743919 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.754304886 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.892271996 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.892357111 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.892951012 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.893089056 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.893574953 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.893639088 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.896163940 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.896193027 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.896220922 CEST | 80 | 50015 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:40.896253109 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:40.896269083 CEST | 50015 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:43.700503111 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:43.706607103 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:43.706904888 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:43.706906080 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:43.706906080 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:43.712658882 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:43.712709904 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:45.206844091 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:45.207338095 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:45.207551956 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:45.207551956 CEST | 50016 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:45.213047981 CEST | 80 | 50016 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:49.800120115 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:49.811477900 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:49.811592102 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:49.811738968 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:49.811764956 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:49.817473888 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:49.817487955 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:51.303992987 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:51.304086924 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:51.304176092 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:51.304306030 CEST | 50017 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:51.309189081 CEST | 80 | 50017 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:55.725019932 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:55.730482101 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:55.730611086 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:55.730739117 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:55.730772018 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:55.735733986 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:55.735764980 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:57.202977896 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:57.203066111 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:09:57.203145981 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:57.203242064 CEST | 50018 | 80 | 192.168.2.5 | 119.204.11.2 |
Oct 12, 2024 20:09:57.208129883 CEST | 80 | 50018 | 119.204.11.2 | 192.168.2.5 |
Oct 12, 2024 20:10:05.618999004 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:05.623936892 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:05.624042988 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:05.624172926 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:05.624182940 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:05.630160093 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:05.631269932 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:07.063302040 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:07.063460112 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:07.063550949 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:07.063620090 CEST | 60089 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:07.069400072 CEST | 80 | 60089 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:10.426723003 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:10.431813002 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:10.431971073 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:10.432107925 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:10.432109118 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:10.438182116 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:10.438211918 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:11.869925022 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:11.870115042 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:11.870177031 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:11.870220900 CEST | 60090 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:11.875686884 CEST | 80 | 60090 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:16.228486061 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:16.442487955 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:16.442619085 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:16.442836046 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:16.442836046 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:16.447645903 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:16.447864056 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:17.906589985 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:17.910243034 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:17.910339117 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:17.917098045 CEST | 60091 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:17.922075987 CEST | 80 | 60091 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:22.248954058 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:22.254139900 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:22.254244089 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:22.254404068 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:22.254436016 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:22.259356022 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:22.259516001 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:23.702090025 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:23.702141047 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:23.702222109 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:23.702428102 CEST | 60092 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:23.707254887 CEST | 80 | 60092 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:28.951699972 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:28.956794977 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:28.956896067 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:28.957082033 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:28.957132101 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:28.962270021 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:28.962451935 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:30.352883101 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:30.353166103 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:30.353244066 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:30.353348970 CEST | 60093 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:30.358401060 CEST | 80 | 60093 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:34.681212902 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:34.773701906 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:34.773796082 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:34.773941040 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:34.773976088 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:34.778983116 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:34.779014111 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:36.229604006 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:36.229760885 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:36.229845047 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:36.231537104 CEST | 60094 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:36.236427069 CEST | 80 | 60094 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:40.189896107 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:40.195266962 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:40.195369005 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:40.195491076 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:40.195527077 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:40.200292110 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:40.200536013 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:41.630479097 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:41.630572081 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:41.630767107 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:41.630870104 CEST | 60095 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:41.637284994 CEST | 80 | 60095 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:44.928771019 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:44.934091091 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:44.934236050 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:44.934335947 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:44.934374094 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:44.939558029 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:44.939589977 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:46.361423016 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:46.361453056 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:46.361536980 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:46.361769915 CEST | 60096 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:46.366588116 CEST | 80 | 60096 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:50.236258030 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:50.241606951 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:50.241720915 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:50.241883039 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:50.241919041 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:50.247287035 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:50.247317076 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:51.683959961 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:51.684092999 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:51.684156895 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:51.684351921 CEST | 60097 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:51.689147949 CEST | 80 | 60097 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:55.437047005 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:55.442363977 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:55.442465067 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:55.442645073 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:55.442673922 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:55.447571993 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:55.447900057 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:56.903294086 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:56.903348923 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:10:56.903490067 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:56.903590918 CEST | 60098 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:10:56.908699989 CEST | 80 | 60098 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:01.748743057 CEST | 60099 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:11:02.606597900 CEST | 80 | 60099 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:02.607084036 CEST | 60099 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:11:02.607198000 CEST | 60099 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:11:02.607198000 CEST | 60099 | 80 | 192.168.2.5 | 175.119.10.231 |
Oct 12, 2024 20:11:02.612180948 CEST | 80 | 60099 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:02.612289906 CEST | 80 | 60099 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:04.022588015 CEST | 80 | 60099 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:04.022815943 CEST | 80 | 60099 | 175.119.10.231 | 192.168.2.5 |
Oct 12, 2024 20:11:04.022958994 CEST | 60099 | 80 | 192.168.2.5 | 175.119.10.231 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 20:07:23.962045908 CEST | 57496 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:07:24.957123041 CEST | 57496 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:07:25.972798109 CEST | 57496 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:07:27.988540888 CEST | 57496 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:07:28.073901892 CEST | 53 | 57496 | 1.1.1.1 | 192.168.2.5 |
Oct 12, 2024 20:07:28.073935986 CEST | 53 | 57496 | 1.1.1.1 | 192.168.2.5 |
Oct 12, 2024 20:07:28.073944092 CEST | 53 | 57496 | 1.1.1.1 | 192.168.2.5 |
Oct 12, 2024 20:07:28.073951960 CEST | 53 | 57496 | 1.1.1.1 | 192.168.2.5 |
Oct 12, 2024 20:10:01.575406075 CEST | 57718 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:10:02.566796064 CEST | 57718 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 12, 2024 20:10:02.574071884 CEST | 53 | 57718 | 1.1.1.1 | 192.168.2.5 |
Oct 12, 2024 20:10:03.638221025 CEST | 53 | 57718 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 12, 2024 20:07:23.962045908 CEST | 192.168.2.5 | 1.1.1.1 | 0xc35e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 20:07:24.957123041 CEST | 192.168.2.5 | 1.1.1.1 | 0xc35e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 20:07:25.972798109 CEST | 192.168.2.5 | 1.1.1.1 | 0xc35e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 20:07:27.988540888 CEST | 192.168.2.5 | 1.1.1.1 | 0xc35e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 20:10:01.575406075 CEST | 192.168.2.5 | 1.1.1.1 | 0x37fc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 20:10:02.566796064 CEST | 192.168.2.5 | 1.1.1.1 | 0x37fc | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 119.204.11.2 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 93.118.137.82 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 187.199.203.72 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073901892 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 119.204.11.2 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 93.118.137.82 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 187.199.203.72 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073935986 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 119.204.11.2 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 93.118.137.82 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 187.199.203.72 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073944092 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 119.204.11.2 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.187.52.42 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 93.118.137.82 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.164.127.217 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 187.199.203.72 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:07:28.073951960 CEST | 1.1.1.1 | 192.168.2.5 | 0xc35e | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 177.129.90.106 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 201.233.78.169 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 190.146.112.188 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 185.12.79.25 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 175.119.10.231 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 186.233.231.45 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 20:10:03.638221025 CEST | 1.1.1.1 | 192.168.2.5 | 0x37fc | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49792 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:28.084242105 CEST | 278 | OUT | |
Oct 12, 2024 20:07:28.084254980 CEST | 353 | OUT | |
Oct 12, 2024 20:07:29.848795891 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49799 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:29.861692905 CEST | 278 | OUT | |
Oct 12, 2024 20:07:29.861723900 CEST | 328 | OUT | |
Oct 12, 2024 20:07:31.374404907 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49809 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:31.386056900 CEST | 280 | OUT | |
Oct 12, 2024 20:07:31.386091948 CEST | 331 | OUT | |
Oct 12, 2024 20:07:32.890898943 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49820 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:32.899426937 CEST | 280 | OUT | |
Oct 12, 2024 20:07:32.899456024 CEST | 221 | OUT | |
Oct 12, 2024 20:07:34.426244020 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49831 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:34.435060024 CEST | 280 | OUT | |
Oct 12, 2024 20:07:34.435089111 CEST | 185 | OUT | |
Oct 12, 2024 20:07:35.946641922 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49841 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:35.956039906 CEST | 282 | OUT | |
Oct 12, 2024 20:07:35.956039906 CEST | 129 | OUT | |
Oct 12, 2024 20:07:37.458920956 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49849 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:37.467190981 CEST | 283 | OUT | |
Oct 12, 2024 20:07:37.467225075 CEST | 227 | OUT | |
Oct 12, 2024 20:07:38.958609104 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49861 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:38.966912031 CEST | 281 | OUT | |
Oct 12, 2024 20:07:38.967140913 CEST | 141 | OUT | |
Oct 12, 2024 20:07:40.481789112 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49870 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:40.490367889 CEST | 280 | OUT | |
Oct 12, 2024 20:07:40.490377903 CEST | 303 | OUT | |
Oct 12, 2024 20:07:41.972019911 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49881 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:41.982127905 CEST | 282 | OUT | |
Oct 12, 2024 20:07:41.982155085 CEST | 140 | OUT | |
Oct 12, 2024 20:07:43.473678112 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.5 | 49892 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:43.483773947 CEST | 283 | OUT | |
Oct 12, 2024 20:07:43.483793020 CEST | 338 | OUT | |
Oct 12, 2024 20:07:44.967206001 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.5 | 49903 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:44.975231886 CEST | 278 | OUT | |
Oct 12, 2024 20:07:44.975404024 CEST | 137 | OUT | |
Oct 12, 2024 20:07:46.457277060 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.5 | 49914 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:46.465318918 CEST | 279 | OUT | |
Oct 12, 2024 20:07:46.465373039 CEST | 236 | OUT | |
Oct 12, 2024 20:07:47.959476948 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.5 | 49925 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:47.967969894 CEST | 282 | OUT | |
Oct 12, 2024 20:07:47.968004942 CEST | 210 | OUT | |
Oct 12, 2024 20:07:49.466757059 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.5 | 49932 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:49.474919081 CEST | 283 | OUT | |
Oct 12, 2024 20:07:49.474951029 CEST | 121 | OUT | |
Oct 12, 2024 20:07:50.949657917 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.5 | 49943 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:50.957179070 CEST | 282 | OUT | |
Oct 12, 2024 20:07:50.957180023 CEST | 326 | OUT | |
Oct 12, 2024 20:07:52.436352968 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.5 | 49954 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:52.444674969 CEST | 280 | OUT | |
Oct 12, 2024 20:07:52.444685936 CEST | 120 | OUT | |
Oct 12, 2024 20:07:53.920020103 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.5 | 49964 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:53.929517984 CEST | 283 | OUT | |
Oct 12, 2024 20:07:53.929550886 CEST | 274 | OUT | |
Oct 12, 2024 20:07:55.414083958 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.5 | 49972 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:55.423439026 CEST | 280 | OUT | |
Oct 12, 2024 20:07:55.423453093 CEST | 124 | OUT | |
Oct 12, 2024 20:07:56.903420925 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.5 | 49983 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:56.910952091 CEST | 278 | OUT | |
Oct 12, 2024 20:07:56.910976887 CEST | 224 | OUT | |
Oct 12, 2024 20:07:58.598740101 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.5 | 49993 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:07:58.610378981 CEST | 279 | OUT | |
Oct 12, 2024 20:07:58.610402107 CEST | 262 | OUT | |
Oct 12, 2024 20:08:00.089637995 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.5 | 49998 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:00.097592115 CEST | 282 | OUT | |
Oct 12, 2024 20:08:00.097647905 CEST | 207 | OUT | |
Oct 12, 2024 20:08:01.634527922 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.5 | 49999 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:01.771761894 CEST | 278 | OUT | |
Oct 12, 2024 20:08:01.771790028 CEST | 259 | OUT | |
Oct 12, 2024 20:08:03.280970097 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.5 | 50000 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:03.293900013 CEST | 283 | OUT | |
Oct 12, 2024 20:08:03.293936014 CEST | 140 | OUT | |
Oct 12, 2024 20:08:04.804044962 CEST | 189 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.5 | 50002 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:06.666564941 CEST | 282 | OUT | |
Oct 12, 2024 20:08:06.666588068 CEST | 319 | OUT | |
Oct 12, 2024 20:08:08.140535116 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.5 | 50003 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:08.149559021 CEST | 281 | OUT | |
Oct 12, 2024 20:08:08.149594069 CEST | 210 | OUT | |
Oct 12, 2024 20:08:09.781217098 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.5 | 50004 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:09.790385008 CEST | 280 | OUT | |
Oct 12, 2024 20:08:09.790419102 CEST | 173 | OUT | |
Oct 12, 2024 20:08:11.264607906 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.5 | 50005 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:11.274945021 CEST | 280 | OUT | |
Oct 12, 2024 20:08:11.274966955 CEST | 308 | OUT | |
Oct 12, 2024 20:08:12.806922913 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.5 | 50006 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:12.816751003 CEST | 279 | OUT | |
Oct 12, 2024 20:08:12.816786051 CEST | 117 | OUT | |
Oct 12, 2024 20:08:15.107202053 CEST | 484 | IN | |
Oct 12, 2024 20:08:15.107314110 CEST | 484 | IN | |
Oct 12, 2024 20:08:15.108445883 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.5 | 50007 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:15.116512060 CEST | 278 | OUT | |
Oct 12, 2024 20:08:15.116561890 CEST | 278 | OUT | |
Oct 12, 2024 20:08:16.638910055 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.5 | 50008 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:16.650084019 CEST | 278 | OUT | |
Oct 12, 2024 20:08:16.650121927 CEST | 359 | OUT | |
Oct 12, 2024 20:08:18.120666981 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.5 | 50009 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:18.140367031 CEST | 278 | OUT | |
Oct 12, 2024 20:08:18.140367031 CEST | 186 | OUT | |
Oct 12, 2024 20:08:19.640125990 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.5 | 50010 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:19.650695086 CEST | 281 | OUT | |
Oct 12, 2024 20:08:19.650719881 CEST | 156 | OUT | |
Oct 12, 2024 20:08:21.135768890 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.5 | 50011 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:21.144534111 CEST | 279 | OUT | |
Oct 12, 2024 20:08:21.144654989 CEST | 267 | OUT | |
Oct 12, 2024 20:08:22.612827063 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.5 | 50012 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:22.624696970 CEST | 280 | OUT | |
Oct 12, 2024 20:08:22.624831915 CEST | 305 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.5 | 50013 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:08:23.959450006 CEST | 283 | OUT | |
Oct 12, 2024 20:08:23.959471941 CEST | 261 | OUT | |
Oct 12, 2024 20:08:25.476564884 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.5 | 50014 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:09:32.651304007 CEST | 279 | OUT | |
Oct 12, 2024 20:09:32.651304007 CEST | 319 | OUT | |
Oct 12, 2024 20:09:34.491059065 CEST | 151 | IN | |
Oct 12, 2024 20:09:34.491380930 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.5 | 50015 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:09:38.300371885 CEST | 281 | OUT | |
Oct 12, 2024 20:09:38.300395012 CEST | 236 | OUT | |
Oct 12, 2024 20:09:39.836384058 CEST | 151 | IN | |
Oct 12, 2024 20:09:40.892951012 CEST | 151 | IN | |
Oct 12, 2024 20:09:40.893574953 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.5 | 50016 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:09:43.706906080 CEST | 278 | OUT | |
Oct 12, 2024 20:09:43.706906080 CEST | 359 | OUT | |
Oct 12, 2024 20:09:45.206844091 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.5 | 50017 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:09:49.811738968 CEST | 279 | OUT | |
Oct 12, 2024 20:09:49.811764956 CEST | 368 | OUT | |
Oct 12, 2024 20:09:51.303992987 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.5 | 50018 | 119.204.11.2 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:09:55.730739117 CEST | 283 | OUT | |
Oct 12, 2024 20:09:55.730772018 CEST | 333 | OUT | |
Oct 12, 2024 20:09:57.202977896 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.5 | 60089 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:05.624172926 CEST | 278 | OUT | |
Oct 12, 2024 20:10:05.624182940 CEST | 123 | OUT | |
Oct 12, 2024 20:10:07.063302040 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.5 | 60090 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:10.432107925 CEST | 283 | OUT | |
Oct 12, 2024 20:10:10.432109118 CEST | 194 | OUT | |
Oct 12, 2024 20:10:11.869925022 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.5 | 60091 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:16.442836046 CEST | 279 | OUT | |
Oct 12, 2024 20:10:16.442836046 CEST | 173 | OUT | |
Oct 12, 2024 20:10:17.906589985 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.5 | 60092 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:22.254404068 CEST | 281 | OUT | |
Oct 12, 2024 20:10:22.254436016 CEST | 231 | OUT | |
Oct 12, 2024 20:10:23.702090025 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.5 | 60093 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:28.957082033 CEST | 283 | OUT | |
Oct 12, 2024 20:10:28.957132101 CEST | 200 | OUT | |
Oct 12, 2024 20:10:30.352883101 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.5 | 60094 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:34.773941040 CEST | 278 | OUT | |
Oct 12, 2024 20:10:34.773976088 CEST | 239 | OUT | |
Oct 12, 2024 20:10:36.229604006 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.5 | 60095 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:40.195491076 CEST | 282 | OUT | |
Oct 12, 2024 20:10:40.195527077 CEST | 273 | OUT | |
Oct 12, 2024 20:10:41.630479097 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.5 | 60096 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:44.934335947 CEST | 278 | OUT | |
Oct 12, 2024 20:10:44.934374094 CEST | 264 | OUT | |
Oct 12, 2024 20:10:46.361423016 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.5 | 60097 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:50.241883039 CEST | 281 | OUT | |
Oct 12, 2024 20:10:50.241919041 CEST | 318 | OUT | |
Oct 12, 2024 20:10:51.683959961 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.5 | 60098 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:10:55.442645073 CEST | 278 | OUT | |
Oct 12, 2024 20:10:55.442673922 CEST | 290 | OUT | |
Oct 12, 2024 20:10:56.903294086 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.5 | 60099 | 175.119.10.231 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 20:11:02.607198000 CEST | 279 | OUT | |
Oct 12, 2024 20:11:02.607198000 CEST | 164 | OUT | |
Oct 12, 2024 20:11:04.022588015 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 50001 | 23.145.40.164 | 443 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-12 18:08:05 UTC | 162 | OUT | |
2024-10-12 18:08:06 UTC | 327 | IN | |
2024-10-12 18:08:06 UTC | 7865 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN | |
2024-10-12 18:08:06 UTC | 8000 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 14:06:55 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\Desktop\mGFoU1INUk.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | 18DAA2C6A6F6385895582D4E9954D851 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 14:07:04 |
Start date: | 12/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff674740000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 4 |
Start time: | 14:07:24 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\ibjgueh |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | 18DAA2C6A6F6385895582D4E9954D851 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 14:10:02 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\ibjgueh |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | 18DAA2C6A6F6385895582D4E9954D851 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 8.8% |
Dynamic/Decrypted Code Coverage: | 30.2% |
Signature Coverage: | 43.2% |
Total number of Nodes: | 162 |
Total number of Limit Nodes: | 6 |
Graph
Function 00415BA0 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C4A58F Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02FC003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415820 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02FC0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C4A24E Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157F0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02FC092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040324F Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403256 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C49E6C Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403290 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02FC0D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415B10 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.6% |
Dynamic/Decrypted Code Coverage: | 30.2% |
Signature Coverage: | 0% |
Total number of Nodes: | 162 |
Total number of Limit Nodes: | 6 |
Graph
Function 00415BA0 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CC003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415820 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D0AA0F Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02CC0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D0A6CE Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157F0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415B10 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|