Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7400 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: F0342947877C844A5C82CB4BB5FDADAD) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5) - 565.exe (PID: 8020 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\565.exe MD5: F42E9B6758241070E7815B8BD1EB8335)
- trbwcit (PID: 7852 cmdline:
C:\Users\u ser\AppDat a\Roaming\ trbwcit MD5: F0342947877C844A5C82CB4BB5FDADAD)
- fgbwcit (PID: 6596 cmdline:
C:\Users\u ser\AppDat a\Roaming\ fgbwcit MD5: F42E9B6758241070E7815B8BD1EB8335)
- trbwcit (PID: 1432 cmdline:
C:\Users\u ser\AppDat a\Roaming\ trbwcit MD5: F0342947877C844A5C82CB4BB5FDADAD)
- fgbwcit (PID: 5356 cmdline:
C:\Users\u ser\AppDat a\Roaming\ fgbwcit MD5: F42E9B6758241070E7815B8BD1EB8335)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["https://ninjahallnews.com/search.php", "https://fallhandbat.com/search.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
Click to see the 19 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T22:28:34.855747+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:36.179777+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:37.301512+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:38.679060+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:39.768855+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49742 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:40.836305+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:42.152277+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49744 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:43.239304+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:44.333751+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:45.434201+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49747 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:46.545952+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:47.805965+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:48.888009+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49750 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:49.963152+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:51.038576+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:52.162158+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:53.210807+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:54.287233+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49755 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:55.393275+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:56.468350+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:57.586832+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49758 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:58.647677+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49760 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:59.810217+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49767 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:00.890699+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49773 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:03.439980+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49790 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:04.556178+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49796 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:06.138823+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49802 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:07.242035+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49808 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:08.323623+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49819 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:09.405245+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49825 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:10.496935+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49832 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:11.577113+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49841 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:12.665671+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49847 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:13.773014+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49853 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:15.061716+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49859 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:16.143581+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49870 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:26.260553+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50043 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:33.005730+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50044 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:42.007630+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50045 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:52.824767+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50046 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:31:06.258519+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50047 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:20.968526+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50048 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:36.114550+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50049 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:50.445964+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50050 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:32:05.414626+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50051 | 175.119.10.231 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 5_2_00401514 | |
Source: | Code function: | 5_2_00402F97 | |
Source: | Code function: | 5_2_00401542 | |
Source: | Code function: | 5_2_00403247 | |
Source: | Code function: | 5_2_00401549 | |
Source: | Code function: | 5_2_0040324F | |
Source: | Code function: | 5_2_00403256 | |
Source: | Code function: | 5_2_00401557 | |
Source: | Code function: | 5_2_0040326C | |
Source: | Code function: | 5_2_00403277 | |
Source: | Code function: | 5_2_004014FE | |
Source: | Code function: | 5_2_00403290 | |
Source: | Code function: | 6_2_00403103 | |
Source: | Code function: | 6_2_004014FB | |
Source: | Code function: | 6_2_00401641 | |
Source: | Code function: | 6_2_00403257 | |
Source: | Code function: | 6_2_00401606 | |
Source: | Code function: | 6_2_00401613 | |
Source: | Code function: | 6_2_00401627 | |
Source: | Code function: | 6_2_004015FB | |
Source: | Code function: | 8_2_00403103 | |
Source: | Code function: | 8_2_004014FB | |
Source: | Code function: | 8_2_00401641 | |
Source: | Code function: | 8_2_00403257 | |
Source: | Code function: | 8_2_00401606 | |
Source: | Code function: | 8_2_00401613 | |
Source: | Code function: | 8_2_00401627 | |
Source: | Code function: | 8_2_00403433 | |
Source: | Code function: | 8_2_004015FB |
Source: | Code function: | 0_2_00415B60 | |
Source: | Code function: | 5_2_00415B60 | |
Source: | Code function: | 6_2_00415840 | |
Source: | Code function: | 8_2_00415840 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02DBAE2E |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02D81550 | |
Source: | Code function: | 0_2_02DBE889 | |
Source: | Code function: | 0_2_02DBCC61 | |
Source: | Code function: | 0_2_02DBD728 | |
Source: | Code function: | 5_2_004014E9 | |
Source: | Code function: | 5_2_004032AB | |
Source: | Code function: | 5_2_02CC1550 | |
Source: | Code function: | 5_2_02D5DF71 | |
Source: | Code function: | 5_2_02D5C349 | |
Source: | Code function: | 5_2_02D5CE10 | |
Source: | Code function: | 6_2_004029D1 | |
Source: | Code function: | 6_2_0040106A | |
Source: | Code function: | 6_2_0040280A | |
Source: | Code function: | 6_2_00402523 | |
Source: | Code function: | 6_2_004033F3 | |
Source: | Code function: | 6_2_004035AB | |
Source: | Code function: | 6_2_0040118E | |
Source: | Code function: | 6_2_00402AAB | |
Source: | Code function: | 6_2_004012B8 | |
Source: | Code function: | 6_2_02BF11F5 | |
Source: | Code function: | 6_2_02BF10D1 | |
Source: | Code function: | 6_2_02BF131F | |
Source: | Code function: | 6_2_02BF2B12 | |
Source: | Code function: | 6_2_02BF258A | |
Source: | Code function: | 6_2_02BF2871 | |
Source: | Code function: | 8_2_004029D1 | |
Source: | Code function: | 8_2_0040106A | |
Source: | Code function: | 8_2_0040280A | |
Source: | Code function: | 8_2_00402523 |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_00401E65 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 6_2_00401E65 |
Source: | Code function: | 0_2_02D80D90 | |
Source: | Code function: | 0_2_02D8092B | |
Source: | Code function: | 0_2_02DBA70B | |
Source: | Code function: | 5_2_02CC0D90 | |
Source: | Code function: | 5_2_02CC092B | |
Source: | Code function: | 5_2_02D59DF3 | |
Source: | Code function: | 6_2_02BF0D90 | |
Source: | Code function: | 6_2_02BF092B | |
Source: | Code function: | 6_2_02C6A049 | |
Source: | Code function: | 8_2_02C39E19 | |
Source: | Code function: | 8_2_02E80D90 | |
Source: | Code function: | 8_2_02E8092B |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 9_2_00404E64 |
Source: | Code function: | 0_2_00415B60 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 521 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 115 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 14 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
37% | ReversingLabs | |||
40% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
37% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
12% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 190.147.128.172 | true | true |
| unknown |
fallhandbat.com | unknown | unknown | true | unknown | |
ninjahallnews.com | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
190.147.128.172 | nwgrus.ru | Colombia | 10620 | TelmexColombiaSACO | true | |
23.145.40.164 | unknown | Reserved | 22631 | SURFAIRWIRELESS-IN-01US | true | |
175.119.10.231 | unknown | Korea Republic of | 9318 | SKB-ASSKBroadbandCoLtdKR | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532238 |
Start date and time: | 2024-10-12 22:27:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@7/4@22/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 40.126.32.76, 20.190.160.14, 20.190.160.22, 40.126.32.134, 40.126.32.138, 40.126.32.72, 40.126.32.68, 40.126.32.136
- Excluded domains from analysis (whitelisted): prdv4a.aadg.msidentity.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, login.live.com, www.tm.v4.a.prd.aadg.akadns.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
- Execution Graph export aborted for target fgbwcit, PID 5356 because there are no executed function
- Execution Graph export aborted for target trbwcit, PID 1432 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
16:28:15 | API Interceptor | |
21:28:32 | Task Scheduler | |
21:29:28 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
190.147.128.172 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
23.145.40.164 | Get hash | malicious | SmokeLoader | Browse | ||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
Get hash | malicious | SmokeLoader | Browse | |||
175.119.10.231 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | CryptOne, SmokeLoader, Stealc | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, LummaC Stealer, SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu, Vidar | Browse |
| ||
Get hash | malicious | Babuk, Clipboard Hijacker, Djvu, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TelmexColombiaSACO | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
SKB-ASSKBroadbandCoLtdKR | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
SURFAIRWIRELESS-IN-01US | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
72a589da586844d7f0818ce684948eea | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 242688 |
Entropy (8bit): | 5.8793046064049905 |
Encrypted: | false |
SSDEEP: | 3072:9TA7cae5AP1XfHJ2IQg4cq5FQ+CoNmp8FBxqXYUGrG:9TA7cjOP1vJ28+FwwqI |
MD5: | F42E9B6758241070E7815B8BD1EB8335 |
SHA1: | E9C8CBE1D1BF1B47A913C0900EA86ADB1F553631 |
SHA-256: | 07C4DB8CD40625B3BA63A1DB74432EA62A8ADC5ABECDF32166BC25AB75AD79D5 |
SHA-512: | 35DD401427C3FE5C03A7B363545B93E4E5C09EF7EFA0D55F109A25460E21CBB04D5539A54C0BB001AF74D13936ECC3DF7FD7C7919B3906BA32BE830459941C0E |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 242688 |
Entropy (8bit): | 5.8793046064049905 |
Encrypted: | false |
SSDEEP: | 3072:9TA7cae5AP1XfHJ2IQg4cq5FQ+CoNmp8FBxqXYUGrG:9TA7cjOP1vJ28+FwwqI |
MD5: | F42E9B6758241070E7815B8BD1EB8335 |
SHA1: | E9C8CBE1D1BF1B47A913C0900EA86ADB1F553631 |
SHA-256: | 07C4DB8CD40625B3BA63A1DB74432EA62A8ADC5ABECDF32166BC25AB75AD79D5 |
SHA-512: | 35DD401427C3FE5C03A7B363545B93E4E5C09EF7EFA0D55F109A25460E21CBB04D5539A54C0BB001AF74D13936ECC3DF7FD7C7919B3906BA32BE830459941C0E |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243200 |
Entropy (8bit): | 5.896612954245981 |
Encrypted: | false |
SSDEEP: | 3072:tTA5IqRZn1qS6GF3Sv3zscq5SQ+CoNep0FBxqXYUGrG:tTAuqRZ7ndw3y+FBqI |
MD5: | F0342947877C844A5C82CB4BB5FDADAD |
SHA1: | C460F35ED9F2B3FD6172F38C70B6073FFFE70F17 |
SHA-256: | E93BC7594D1FC8CA1EFF0E522B8547E74B3AC33840C55B4F50F69278E4CD8242 |
SHA-512: | 3B6657DE56FE6EBBE964512091638596D41962B1C7E531A81BC85003F4A194232C1083904E0817E6E6F969567517131FE12D11BA0065EA804362DE5EF709B2F7 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.896612954245981 |
TrID: |
|
File name: | file.exe |
File size: | 243'200 bytes |
MD5: | f0342947877c844a5c82cb4bb5fdadad |
SHA1: | c460f35ed9f2b3fd6172f38c70b6073fffe70f17 |
SHA256: | e93bc7594d1fc8ca1eff0e522b8547e74b3ac33840c55b4f50f69278e4cd8242 |
SHA512: | 3b6657de56fe6ebbe964512091638596d41962b1c7e531a81bc85003f4a194232c1083904e0817e6e6f969567517131fe12d11ba0065ea804362de5ef709b2f7 |
SSDEEP: | 3072:tTA5IqRZn1qS6GF3Sv3zscq5SQ+CoNep0FBxqXYUGrG:tTAuqRZ7ndw3y+FBqI |
TLSH: | 1E342A41EEF13C14F673DA31DE3992E8A62FF9E25E20625E11A45A0F08F1291C57B736 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........y...*...*...*...*...*...*...*...*...*.F.*...*...*...*...*...*...*...*...*...*Rich...*........................PE..L....,.e... |
Icon Hash: | 738733b18b8b8be4 |
Entrypoint: | 0x4018e4 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x657F2CA1 [Sun Dec 17 17:15:13 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | 636068238a0ab0df9c8e341eee8428d0 |
Instruction |
---|
call 00007FAAD08C7390h |
jmp 00007FAAD08C3C8Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041A3D0h], eax |
mov dword ptr [0041A3CCh], ecx |
mov dword ptr [0041A3C8h], edx |
mov dword ptr [0041A3C4h], ebx |
mov dword ptr [0041A3C0h], esi |
mov dword ptr [0041A3BCh], edi |
mov word ptr [0041A3E8h], ss |
mov word ptr [0041A3DCh], cs |
mov word ptr [0041A3B8h], ds |
mov word ptr [0041A3B4h], es |
mov word ptr [0041A3B0h], fs |
mov word ptr [0041A3ACh], gs |
pushfd |
pop dword ptr [0041A3E0h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041A3D4h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041A3D8h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041A3E4h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041A320h], 00010001h |
mov eax, dword ptr [0041A3D8h] |
mov dword ptr [0041A2D4h], eax |
mov dword ptr [0041A2C8h], C0000409h |
mov dword ptr [0041A2CCh], 00000001h |
mov eax, dword ptr [00419008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041900Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000DCh] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x17774 | 0x3c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2721000 | 0x1cac0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x16000 | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x14f6f | 0x15000 | f8d0a9d4becd8846b657e5f44f1141fd | False | 0.8229747953869048 | data | 7.548546960257042 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x16000 | 0x2026 | 0x2200 | 6da4b7c2534b0027fef7635e158ee334 | False | 0.36247702205882354 | data | 5.4153798035975225 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x19000 | 0x26fff7c | 0x1400 | 50c0dd9d406b2697a593034cdc3cf287 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.vugud | 0x2719000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.fay | 0x271e000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2721000 | 0x1cac0 | 0x1cc00 | 0267d5c30b13ca618b1ccdaa9189f178 | False | 0.4420091711956522 | data | 5.0953748346714445 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x27219d0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5700959488272921 |
RT_ICON | 0x2722878 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6371841155234657 |
RT_ICON | 0x2723120 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6935483870967742 |
RT_ICON | 0x27237e8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2723d50 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.5137966804979253 |
RT_ICON | 0x27262f8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6128048780487805 |
RT_ICON | 0x27273a0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6180327868852459 |
RT_ICON | 0x2727d28 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7570921985815603 |
RT_ICON | 0x2728208 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.3368869936034115 |
RT_ICON | 0x27290b0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5252707581227437 |
RT_ICON | 0x2729958 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.5858294930875576 |
RT_ICON | 0x272a020 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6372832369942196 |
RT_ICON | 0x272a588 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.4263485477178423 |
RT_ICON | 0x272cb30 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.49959016393442623 |
RT_ICON | 0x272d4b8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.5062056737588653 |
RT_ICON | 0x272d988 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39498933901918976 |
RT_ICON | 0x272e830 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5546028880866426 |
RT_ICON | 0x272f0d8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6169354838709677 |
RT_ICON | 0x272f7a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6423410404624278 |
RT_ICON | 0x272fd08 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.42706378986866794 |
RT_ICON | 0x2730db0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4245901639344262 |
RT_ICON | 0x2731738 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.4645390070921986 |
RT_ICON | 0x2731c08 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.28331556503198296 |
RT_ICON | 0x2732ab0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.36913357400722024 |
RT_ICON | 0x2733358 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.37672811059907835 |
RT_ICON | 0x2733a20 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3786127167630058 |
RT_ICON | 0x2733f88 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.25778008298755184 |
RT_ICON | 0x2736530 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.275328330206379 |
RT_ICON | 0x27375d8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28647540983606556 |
RT_ICON | 0x2737f60 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32358156028368795 |
RT_STRING | 0x27385f8 | 0xcc | data | 0.553921568627451 | ||
RT_STRING | 0x27386c8 | 0x50c | data | 0.4473684210526316 | ||
RT_STRING | 0x2738bd8 | 0x3aa | data | 0.4616204690831556 | ||
RT_STRING | 0x2738f88 | 0x52c | data | 0.4516616314199396 | ||
RT_STRING | 0x27394b8 | 0x652 | data | 0.4338689740420272 | ||
RT_STRING | 0x2739b10 | 0x798 | data | 0.41975308641975306 | ||
RT_STRING | 0x273a2a8 | 0x84c | data | 0.4129001883239171 | ||
RT_STRING | 0x273aaf8 | 0x666 | data | 0.4340659340659341 | ||
RT_STRING | 0x273b160 | 0x7f6 | data | 0.4210009813542689 | ||
RT_STRING | 0x273b958 | 0x758 | data | 0.41914893617021276 | ||
RT_STRING | 0x273c0b0 | 0x78c | data | 0.4254658385093168 | ||
RT_STRING | 0x273c840 | 0x666 | data | 0.4340659340659341 | ||
RT_STRING | 0x273cea8 | 0x69e | data | 0.4268004722550177 | ||
RT_STRING | 0x273d548 | 0x54c | data | 0.44026548672566373 | ||
RT_STRING | 0x273da98 | 0x26 | data | 0.5526315789473685 | ||
RT_GROUP_ICON | 0x272d920 | 0x68 | data | Turkish | Turkey | 0.7019230769230769 |
RT_GROUP_ICON | 0x27383c8 | 0x76 | data | Turkish | Turkey | 0.6779661016949152 |
RT_GROUP_ICON | 0x2728190 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2731ba0 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2738440 | 0x1b4 | data | 0.5848623853211009 |
DLL | Import |
---|---|
KERNEL32.dll | GetConsoleAliasExesLengthA, DeleteVolumeMountPointA, OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, InterlockedCompareExchange, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, SetCommState, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, GetTimeFormatW, SearchPathW, GetBinaryTypeA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, GetNumaHighestNodeNumber, LoadLibraryA, LocalAlloc, WritePrivateProfileStringA, QueryDosDeviceW, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SetConsoleMode, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, GetCPInfo, InterlockedIncrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, HeapSize |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-12T22:28:34.855747+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49738 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:36.179777+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49739 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:37.301512+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49740 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:38.679060+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49741 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:39.768855+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49742 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:40.836305+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49743 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:42.152277+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49744 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:43.239304+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49745 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:44.333751+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49746 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:45.434201+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49747 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:46.545952+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49748 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:47.805965+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49749 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:48.888009+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49750 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:49.963152+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49751 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:51.038576+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49752 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:52.162158+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49753 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:53.210807+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49754 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:54.287233+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49755 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:55.393275+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49756 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:56.468350+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49757 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:57.586832+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49758 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:58.647677+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49760 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:28:59.810217+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49767 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:00.890699+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49773 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:03.439980+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49790 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:04.556178+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49796 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:06.138823+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49802 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:07.242035+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49808 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:08.323623+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49819 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:09.405245+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49825 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:10.496935+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49832 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:11.577113+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49841 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:12.665671+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49847 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:13.773014+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49853 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:15.061716+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49859 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:29:16.143581+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49870 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:26.260553+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50043 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:33.005730+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50044 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:42.007630+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50045 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:30:52.824767+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50046 | 190.147.128.172 | 80 | TCP |
2024-10-12T22:31:06.258519+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50047 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:20.968526+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50048 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:36.114550+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50049 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:31:50.445964+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50050 | 175.119.10.231 | 80 | TCP |
2024-10-12T22:32:05.414626+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50051 | 175.119.10.231 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 22:28:33.770670891 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:33.775965929 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:33.779050112 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:33.779191971 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:33.779207945 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:33.784885883 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:33.784929991 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.853705883 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.855674028 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.855746984 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.858443022 CEST | 49738 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.863708019 CEST | 80 | 49738 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.865556002 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.871479034 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.871782064 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.871783018 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.872253895 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:34.878262043 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:34.878304958 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.179528952 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.179589987 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.179776907 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.187469006 CEST | 49739 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.193149090 CEST | 80 | 49739 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.195935965 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.201766014 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.201921940 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.202023029 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.202045918 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:36.207376957 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:36.207436085 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.289573908 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.299576998 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.301512003 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.310858965 CEST | 49740 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.316076994 CEST | 80 | 49740 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.414208889 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.419828892 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.421583891 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.424860954 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.424860954 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:37.430412054 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:37.430454969 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.672749996 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.678963900 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.679059982 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.679151058 CEST | 49741 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.681971073 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.684175014 CEST | 80 | 49741 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.686997890 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.687088966 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.687381029 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.687443972 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:38.692604065 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:38.692692995 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.768317938 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.768364906 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.768855095 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.768949032 CEST | 49742 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.771872997 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.774502039 CEST | 80 | 49742 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.777617931 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.777806044 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.777894974 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.777895927 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:39.783144951 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:39.783581018 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:40.835685968 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:40.836146116 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:40.836304903 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:40.838768959 CEST | 49743 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:40.844115973 CEST | 80 | 49743 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:41.079164982 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:41.084857941 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:41.085087061 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:41.085225105 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:41.085225105 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:41.090698957 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:41.090740919 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.151626110 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.152110100 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.152276993 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.152277946 CEST | 49744 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.156593084 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.158034086 CEST | 80 | 49744 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.162166119 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.162252903 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.162394047 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.162415981 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:42.167875051 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:42.167963982 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.233310938 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.239176035 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.239304066 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.239417076 CEST | 49745 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.241761923 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.244939089 CEST | 80 | 49745 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.247461081 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.247555971 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.247734070 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.247759104 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:43.253447056 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:43.253489017 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.333525896 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.333573103 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.333750963 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.333848000 CEST | 49746 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.337908983 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.339143991 CEST | 80 | 49746 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.343411922 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.343616962 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.343616962 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.343703032 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:44.349200964 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:44.349242926 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.426671982 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.434111118 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.434201002 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.434283018 CEST | 49747 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.437298059 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.441237926 CEST | 80 | 49747 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.445086002 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.445662022 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.445760965 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.445760965 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:45.455094099 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:45.455600023 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.545255899 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.545748949 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.545952082 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.546099901 CEST | 49748 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.548844099 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.551568985 CEST | 80 | 49748 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.554313898 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.554399967 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.554502964 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.554517031 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:46.559757948 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:46.560254097 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.805634022 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.805665970 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.805692911 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.805964947 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.806013107 CEST | 49749 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.809058905 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.811342955 CEST | 80 | 49749 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.814418077 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.814587116 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.814610004 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.814631939 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:47.819936991 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:47.820000887 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.887799025 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.887852907 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.888009071 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.888355970 CEST | 49750 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.891052008 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.893260956 CEST | 80 | 49750 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.895977974 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.896080017 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.896249056 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.896281004 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:48.901341915 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:48.901372910 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.962893009 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.962938070 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.963151932 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.963242054 CEST | 49751 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.966161013 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.968807936 CEST | 80 | 49751 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.971616983 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.971728086 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.971869946 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.971894026 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:49.977370977 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:49.977413893 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.038444996 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.038501978 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.038575888 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.038806915 CEST | 49752 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.041127920 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.043999910 CEST | 80 | 49752 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.046570063 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.046684027 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.046792984 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.046792984 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:51.052293062 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:51.052330017 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.156235933 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.161973000 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.162158012 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.162158966 CEST | 49753 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.164845943 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.167463064 CEST | 80 | 49753 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.170300961 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.170399904 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.170543909 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.170579910 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:52.175702095 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:52.175743103 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.208653927 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.210635900 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.210807085 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.210807085 CEST | 49754 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.213532925 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.216123104 CEST | 80 | 49754 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.218782902 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.218873978 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.219034910 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.219077110 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:53.224292994 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:53.224337101 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.279781103 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.286978006 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.287233114 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.287331104 CEST | 49755 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.289580107 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.292366982 CEST | 80 | 49755 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.294853926 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.295131922 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.295329094 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.295380116 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:54.300625086 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:54.300667048 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.387770891 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.393183947 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.393275023 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.393313885 CEST | 49756 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.395605087 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.398699045 CEST | 80 | 49756 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.401074886 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.401216984 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.401335001 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.401361942 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:55.406569958 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:55.406610012 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.467653990 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.468162060 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.468349934 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.468349934 CEST | 49757 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.473654032 CEST | 80 | 49757 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.494889021 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.500446081 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.500699043 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.500699043 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.500699997 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:56.506357908 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:56.506402016 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.586148977 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.586626053 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.586832047 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.586832047 CEST | 49758 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.588846922 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.592365980 CEST | 80 | 49758 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.594033003 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.594113111 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.594208956 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.594225883 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:57.599651098 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:57.599693060 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.647370100 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.647612095 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.647676945 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.647727013 CEST | 49760 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.649568081 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.653172970 CEST | 80 | 49760 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.654737949 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.654814005 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.654917002 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.654952049 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:58.660334110 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:58.660366058 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.809421062 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.810144901 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.810216904 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.810305119 CEST | 49767 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.815531015 CEST | 80 | 49767 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.815695047 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.821042061 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.821125031 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.821225882 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.821257114 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:28:59.826600075 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:28:59.826642036 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:00.882107973 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:00.889564037 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:00.890698910 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:00.890754938 CEST | 49773 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:00.892493963 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:00.892544985 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:00.892626047 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:00.892898083 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:00.892925024 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:00.896018982 CEST | 80 | 49773 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:01.505800962 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.505886078 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.507594109 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.507621050 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.507911921 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.517083883 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.559418917 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.731127024 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.731144905 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.731266022 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.731298923 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.778923988 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.819884062 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.819891930 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.820008993 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.820020914 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.820029974 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.820090055 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.820961952 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.820967913 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.821017981 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.822050095 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.822118044 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.908531904 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.908631086 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.908756018 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.908828020 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.909353018 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.909405947 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.910263062 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.910317898 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.910970926 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.911025047 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.911758900 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.911820889 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.911979914 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.912036896 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.979561090 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.979651928 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.997404099 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.997493029 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.997551918 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.997618914 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.997862101 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.997931957 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.998405933 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.998470068 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.998559952 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.998619080 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.999363899 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.999428988 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:01.999603033 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:01.999656916 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.000592947 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.000658035 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.000755072 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.000818014 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.002063990 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.002176046 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.002223015 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.002295971 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.026463032 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.026562929 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.068217039 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.068320036 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.086375952 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.086462021 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.086590052 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.086649895 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.086826086 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.086885929 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087016106 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087079048 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087102890 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087148905 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087167978 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087189913 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087213039 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087260008 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087289095 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087289095 CEST | 49779 | 443 | 192.168.2.4 | 23.145.40.164 |
Oct 12, 2024 22:29:02.087311029 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.087328911 CEST | 443 | 49779 | 23.145.40.164 | 192.168.2.4 |
Oct 12, 2024 22:29:02.370021105 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:02.376630068 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:02.376837969 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:02.376838923 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:02.376929045 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:02.382256985 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:02.382299900 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.439204931 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.439730883 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.439980030 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.439980030 CEST | 49790 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.445301056 CEST | 80 | 49790 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.468022108 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.472986937 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.473063946 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.473176003 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.473217010 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:03.478657007 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:03.478703976 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:04.555243969 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:04.556098938 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:04.556178093 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:04.558222055 CEST | 49796 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:04.563371897 CEST | 80 | 49796 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:05.041482925 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:05.047158003 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:05.047312021 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:05.088399887 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:05.088399887 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:05.095603943 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:05.095640898 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.138050079 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.138746023 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.138823032 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.139019966 CEST | 49802 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.142816067 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.144479036 CEST | 80 | 49802 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.148385048 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.148590088 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.148591042 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.148591042 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:06.153795004 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:06.153947115 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.234761000 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.241862059 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.242034912 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.242034912 CEST | 49808 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.245758057 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.247637033 CEST | 80 | 49808 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.251243114 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.251317024 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.251553059 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.251590967 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:07.256794930 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:07.256833076 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.323353052 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.323421001 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.323622942 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.324081898 CEST | 49819 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.329366922 CEST | 80 | 49819 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.331887007 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.337357998 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.337567091 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.337567091 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.337567091 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:08.342834949 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:08.343105078 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.404885054 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.405164003 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.405245066 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.405328989 CEST | 49825 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.410476923 CEST | 80 | 49825 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.413985968 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.419420004 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.419581890 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.419826984 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.419826984 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:09.424931049 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:09.424968004 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.496790886 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.496826887 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.496934891 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.498910904 CEST | 49832 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.503926992 CEST | 80 | 49832 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.505112886 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.510168076 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.510255098 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.510524988 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.510557890 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:10.515578985 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:10.515610933 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.566257000 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.577018976 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.577112913 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.577178955 CEST | 49841 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.582381010 CEST | 80 | 49841 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.587343931 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.593336105 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.593549013 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.593549013 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.593636990 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:11.599046946 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:11.599451065 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.657061100 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.665472031 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.665671110 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.665671110 CEST | 49847 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.668271065 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.671094894 CEST | 80 | 49847 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.673388958 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.673463106 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.673738956 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.673738956 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:12.680645943 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:12.680685997 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.772727013 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.772773027 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.773014069 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.779894114 CEST | 49853 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.785394907 CEST | 80 | 49853 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.982450962 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.987763882 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.987854004 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.987952948 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.987977982 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:13.993138075 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:13.993180037 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.061553955 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.061604023 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.061716080 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.061873913 CEST | 49859 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.064712048 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.067174911 CEST | 80 | 49859 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.070250034 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.070327044 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.070422888 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.070442915 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:15.075679064 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:15.075717926 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:16.143505096 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:16.143526077 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:29:16.143580914 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:16.143764973 CEST | 49870 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:29:16.149138927 CEST | 80 | 49870 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:25.190335989 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:25.196372986 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:25.196475029 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:25.196594954 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:25.196616888 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:25.201997995 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:25.202029943 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:26.260431051 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:26.260479927 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:26.260552883 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:26.260684013 CEST | 50043 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:26.265918016 CEST | 80 | 50043 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:31.919907093 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:31.925132990 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:31.925231934 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:31.925354004 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:31.925384998 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:31.930289984 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:31.930435896 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:33.004900932 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:33.005628109 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:33.005729914 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:33.005783081 CEST | 50044 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:33.011173964 CEST | 80 | 50044 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:40.932591915 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:40.937622070 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:40.937760115 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:40.937889099 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:40.937935114 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:40.942701101 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:40.942784071 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:42.007350922 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:42.007540941 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:42.007630110 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:42.007716894 CEST | 50045 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:42.012484074 CEST | 80 | 50045 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:51.645098925 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:51.742556095 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:51.742657900 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:51.742774963 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:51.742810011 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:51.747577906 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:51.747736931 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:52.824522018 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:52.824682951 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:30:52.824767113 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:52.824846983 CEST | 50046 | 80 | 192.168.2.4 | 190.147.128.172 |
Oct 12, 2024 22:30:52.829699039 CEST | 80 | 50046 | 190.147.128.172 | 192.168.2.4 |
Oct 12, 2024 22:31:04.780033112 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:04.785052061 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:04.785155058 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:04.785314083 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:04.785346985 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:04.790196896 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:04.790226936 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:06.258120060 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:06.258173943 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:06.258518934 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:06.263987064 CEST | 50047 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:06.269501925 CEST | 80 | 50047 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:19.243087053 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:19.248999119 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:19.249105930 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:19.249269009 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:19.249310017 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:19.255212069 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:19.255588055 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:20.968141079 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:20.968288898 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:20.968525887 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:20.970817089 CEST | 50048 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:20.975636959 CEST | 80 | 50048 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:34.606482029 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:34.612118006 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:34.612279892 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:34.612454891 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:34.612473011 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:34.617397070 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:34.617502928 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:36.113661051 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:36.114489079 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:36.114550114 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:36.114582062 CEST | 50049 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:36.119816065 CEST | 80 | 50049 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:48.989573956 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:48.995209932 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:48.995419025 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:48.995564938 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:48.995596886 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:49.001049995 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:49.001091003 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:50.445827961 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:50.445909977 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:31:50.445964098 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:50.446098089 CEST | 50050 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:31:50.451061964 CEST | 80 | 50050 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:03.959069967 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:03.964113951 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:03.964227915 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:03.964360952 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:03.964402914 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:03.969360113 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:03.969388962 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:05.414036036 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:05.414531946 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Oct 12, 2024 22:32:05.414625883 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:05.414675951 CEST | 50051 | 80 | 192.168.2.4 | 175.119.10.231 |
Oct 12, 2024 22:32:05.419831038 CEST | 80 | 50051 | 175.119.10.231 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 12, 2024 22:28:31.494110107 CEST | 62995 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:28:32.499870062 CEST | 62995 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:28:33.513564110 CEST | 62995 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:28:33.769710064 CEST | 53 | 62995 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:28:33.769759893 CEST | 53 | 62995 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:28:33.769789934 CEST | 53 | 62995 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:29:27.878504038 CEST | 50265 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:29:27.911137104 CEST | 53 | 50265 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:29:27.917161942 CEST | 52678 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:29:27.948661089 CEST | 53 | 52678 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:38.213104963 CEST | 58069 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:38.223284960 CEST | 53 | 58069 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:38.243469954 CEST | 58843 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:38.313920021 CEST | 53 | 58843 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:45.817096949 CEST | 51352 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:45.987010002 CEST | 53 | 51352 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:45.996114969 CEST | 54642 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:46.374330997 CEST | 53 | 54642 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:56.804435015 CEST | 51463 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:56.814508915 CEST | 53 | 51463 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:30:56.821585894 CEST | 59563 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:30:56.831568956 CEST | 53 | 59563 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:04.636575937 CEST | 62672 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:04.768667936 CEST | 53 | 62672 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:09.740458012 CEST | 59684 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:09.751693010 CEST | 53 | 59684 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:09.777600050 CEST | 52183 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:09.808649063 CEST | 53 | 52183 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:22.764609098 CEST | 52766 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:22.798492908 CEST | 53 | 52766 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:22.810658932 CEST | 61010 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:22.972979069 CEST | 53 | 61010 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:36.510673046 CEST | 51216 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:36.521195889 CEST | 53 | 51216 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:36.534760952 CEST | 49176 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:36.548430920 CEST | 53 | 49176 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:49.461226940 CEST | 51223 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:49.494296074 CEST | 53 | 51223 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:31:49.568062067 CEST | 51059 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:31:49.579103947 CEST | 53 | 51059 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:32:03.359817028 CEST | 60814 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:32:03.369863987 CEST | 53 | 60814 | 1.1.1.1 | 192.168.2.4 |
Oct 12, 2024 22:32:03.403362989 CEST | 61696 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 12, 2024 22:32:03.414715052 CEST | 53 | 61696 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 12, 2024 22:28:31.494110107 CEST | 192.168.2.4 | 1.1.1.1 | 0x98b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:28:32.499870062 CEST | 192.168.2.4 | 1.1.1.1 | 0x98b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:28:33.513564110 CEST | 192.168.2.4 | 1.1.1.1 | 0x98b1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:29:27.878504038 CEST | 192.168.2.4 | 1.1.1.1 | 0xbaca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:29:27.917161942 CEST | 192.168.2.4 | 1.1.1.1 | 0xc63a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:38.213104963 CEST | 192.168.2.4 | 1.1.1.1 | 0x1c9b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:38.243469954 CEST | 192.168.2.4 | 1.1.1.1 | 0xbdee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:45.817096949 CEST | 192.168.2.4 | 1.1.1.1 | 0x9961 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:45.996114969 CEST | 192.168.2.4 | 1.1.1.1 | 0x2e21 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:56.804435015 CEST | 192.168.2.4 | 1.1.1.1 | 0x22b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:56.821585894 CEST | 192.168.2.4 | 1.1.1.1 | 0xa3b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:04.636575937 CEST | 192.168.2.4 | 1.1.1.1 | 0xd28c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:09.740458012 CEST | 192.168.2.4 | 1.1.1.1 | 0xeafd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:09.777600050 CEST | 192.168.2.4 | 1.1.1.1 | 0x7268 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:22.764609098 CEST | 192.168.2.4 | 1.1.1.1 | 0xddd9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:22.810658932 CEST | 192.168.2.4 | 1.1.1.1 | 0x1aab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:36.510673046 CEST | 192.168.2.4 | 1.1.1.1 | 0x6900 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:36.534760952 CEST | 192.168.2.4 | 1.1.1.1 | 0x8181 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:49.461226940 CEST | 192.168.2.4 | 1.1.1.1 | 0x182b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:49.568062067 CEST | 192.168.2.4 | 1.1.1.1 | 0xf9a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:32:03.359817028 CEST | 192.168.2.4 | 1.1.1.1 | 0x6dd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:32:03.403362989 CEST | 192.168.2.4 | 1.1.1.1 | 0x72ed | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 187.211.161.52 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 185.18.245.58 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769710064 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.191.99.134 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 187.211.161.52 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 185.18.245.58 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769759893 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.191.99.134 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 187.211.161.52 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.212.52.197 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 220.125.3.190 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 185.18.245.58 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:28:33.769789934 CEST | 1.1.1.1 | 192.168.2.4 | 0x98b1 | No error (0) | 201.191.99.134 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:29:27.911137104 CEST | 1.1.1.1 | 192.168.2.4 | 0xbaca | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:29:27.948661089 CEST | 1.1.1.1 | 192.168.2.4 | 0xc63a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:38.223284960 CEST | 1.1.1.1 | 192.168.2.4 | 0x1c9b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:38.313920021 CEST | 1.1.1.1 | 192.168.2.4 | 0xbdee | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:45.987010002 CEST | 1.1.1.1 | 192.168.2.4 | 0x9961 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:46.374330997 CEST | 1.1.1.1 | 192.168.2.4 | 0x2e21 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:56.814508915 CEST | 1.1.1.1 | 192.168.2.4 | 0x22b4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:30:56.831568956 CEST | 1.1.1.1 | 192.168.2.4 | 0xa3b6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 175.119.10.231 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 190.220.21.28 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 187.211.161.52 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 212.112.110.243 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 190.224.203.37 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 186.233.231.45 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 211.171.233.126 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:04.768667936 CEST | 1.1.1.1 | 192.168.2.4 | 0xd28c | No error (0) | 177.222.41.236 | A (IP address) | IN (0x0001) | false | ||
Oct 12, 2024 22:31:09.751693010 CEST | 1.1.1.1 | 192.168.2.4 | 0xeafd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:09.808649063 CEST | 1.1.1.1 | 192.168.2.4 | 0x7268 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:22.798492908 CEST | 1.1.1.1 | 192.168.2.4 | 0xddd9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:22.972979069 CEST | 1.1.1.1 | 192.168.2.4 | 0x1aab | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:36.521195889 CEST | 1.1.1.1 | 192.168.2.4 | 0x6900 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:36.548430920 CEST | 1.1.1.1 | 192.168.2.4 | 0x8181 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:49.494296074 CEST | 1.1.1.1 | 192.168.2.4 | 0x182b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:31:49.579103947 CEST | 1.1.1.1 | 192.168.2.4 | 0xf9a6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:32:03.369863987 CEST | 1.1.1.1 | 192.168.2.4 | 0x6dd3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 12, 2024 22:32:03.414715052 CEST | 1.1.1.1 | 192.168.2.4 | 0x72ed | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49738 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:33.779191971 CEST | 282 | OUT | |
Oct 12, 2024 22:28:33.779207945 CEST | 287 | OUT | |
Oct 12, 2024 22:28:34.853705883 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49739 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:34.871783018 CEST | 280 | OUT | |
Oct 12, 2024 22:28:34.872253895 CEST | 148 | OUT | |
Oct 12, 2024 22:28:36.179528952 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49740 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:36.202023029 CEST | 283 | OUT | |
Oct 12, 2024 22:28:36.202045918 CEST | 238 | OUT | |
Oct 12, 2024 22:28:37.289573908 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49741 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:37.424860954 CEST | 280 | OUT | |
Oct 12, 2024 22:28:37.424860954 CEST | 173 | OUT | |
Oct 12, 2024 22:28:38.672749996 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49742 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:38.687381029 CEST | 278 | OUT | |
Oct 12, 2024 22:28:38.687443972 CEST | 128 | OUT | |
Oct 12, 2024 22:28:39.768317938 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49743 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:39.777894974 CEST | 283 | OUT | |
Oct 12, 2024 22:28:39.777895927 CEST | 250 | OUT | |
Oct 12, 2024 22:28:40.835685968 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49744 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:41.085225105 CEST | 278 | OUT | |
Oct 12, 2024 22:28:41.085225105 CEST | 285 | OUT | |
Oct 12, 2024 22:28:42.151626110 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49745 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:42.162394047 CEST | 278 | OUT | |
Oct 12, 2024 22:28:42.162415981 CEST | 262 | OUT | |
Oct 12, 2024 22:28:43.233310938 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49746 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:43.247734070 CEST | 281 | OUT | |
Oct 12, 2024 22:28:43.247759104 CEST | 246 | OUT | |
Oct 12, 2024 22:28:44.333525896 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49747 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:44.343616962 CEST | 282 | OUT | |
Oct 12, 2024 22:28:44.343703032 CEST | 322 | OUT | |
Oct 12, 2024 22:28:45.426671982 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49748 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:45.445760965 CEST | 283 | OUT | |
Oct 12, 2024 22:28:45.445760965 CEST | 218 | OUT | |
Oct 12, 2024 22:28:46.545255899 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49749 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:46.554502964 CEST | 283 | OUT | |
Oct 12, 2024 22:28:46.554517031 CEST | 287 | OUT | |
Oct 12, 2024 22:28:47.805634022 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49750 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:47.814610004 CEST | 278 | OUT | |
Oct 12, 2024 22:28:47.814631939 CEST | 120 | OUT | |
Oct 12, 2024 22:28:48.887799025 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49751 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:48.896249056 CEST | 279 | OUT | |
Oct 12, 2024 22:28:48.896281004 CEST | 121 | OUT | |
Oct 12, 2024 22:28:49.962893009 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49752 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:49.971869946 CEST | 278 | OUT | |
Oct 12, 2024 22:28:49.971894026 CEST | 329 | OUT | |
Oct 12, 2024 22:28:51.038444996 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49753 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:51.046792984 CEST | 278 | OUT | |
Oct 12, 2024 22:28:51.046792984 CEST | 164 | OUT | |
Oct 12, 2024 22:28:52.156235933 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49754 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:52.170543909 CEST | 283 | OUT | |
Oct 12, 2024 22:28:52.170579910 CEST | 329 | OUT | |
Oct 12, 2024 22:28:53.208653927 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49755 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:53.219034910 CEST | 278 | OUT | |
Oct 12, 2024 22:28:53.219077110 CEST | 341 | OUT | |
Oct 12, 2024 22:28:54.279781103 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49756 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:54.295329094 CEST | 280 | OUT | |
Oct 12, 2024 22:28:54.295380116 CEST | 195 | OUT | |
Oct 12, 2024 22:28:55.387770891 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49757 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:55.401335001 CEST | 282 | OUT | |
Oct 12, 2024 22:28:55.401361942 CEST | 325 | OUT | |
Oct 12, 2024 22:28:56.467653990 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49758 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:56.500699043 CEST | 283 | OUT | |
Oct 12, 2024 22:28:56.500699997 CEST | 160 | OUT | |
Oct 12, 2024 22:28:57.586148977 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49760 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:57.594208956 CEST | 283 | OUT | |
Oct 12, 2024 22:28:57.594225883 CEST | 135 | OUT | |
Oct 12, 2024 22:28:58.647370100 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49767 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:58.654917002 CEST | 279 | OUT | |
Oct 12, 2024 22:28:58.654952049 CEST | 223 | OUT | |
Oct 12, 2024 22:28:59.809421062 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49773 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:28:59.821225882 CEST | 279 | OUT | |
Oct 12, 2024 22:28:59.821257114 CEST | 308 | OUT | |
Oct 12, 2024 22:29:00.882107973 CEST | 189 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49790 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:02.376838923 CEST | 278 | OUT | |
Oct 12, 2024 22:29:02.376929045 CEST | 247 | OUT | |
Oct 12, 2024 22:29:03.439204931 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49796 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:03.473176003 CEST | 282 | OUT | |
Oct 12, 2024 22:29:03.473217010 CEST | 241 | OUT | |
Oct 12, 2024 22:29:04.555243969 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49802 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:05.088399887 CEST | 280 | OUT | |
Oct 12, 2024 22:29:05.088399887 CEST | 333 | OUT | |
Oct 12, 2024 22:29:06.138050079 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49808 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:06.148591042 CEST | 282 | OUT | |
Oct 12, 2024 22:29:06.148591042 CEST | 164 | OUT | |
Oct 12, 2024 22:29:07.234761000 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49819 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:07.251553059 CEST | 283 | OUT | |
Oct 12, 2024 22:29:07.251590967 CEST | 294 | OUT | |
Oct 12, 2024 22:29:08.323353052 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49825 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:08.337567091 CEST | 283 | OUT | |
Oct 12, 2024 22:29:08.337567091 CEST | 130 | OUT | |
Oct 12, 2024 22:29:09.404885054 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49832 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:09.419826984 CEST | 283 | OUT | |
Oct 12, 2024 22:29:09.419826984 CEST | 322 | OUT | |
Oct 12, 2024 22:29:10.496790886 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49841 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:10.510524988 CEST | 283 | OUT | |
Oct 12, 2024 22:29:10.510557890 CEST | 258 | OUT | |
Oct 12, 2024 22:29:11.566257000 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49847 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:11.593549013 CEST | 280 | OUT | |
Oct 12, 2024 22:29:11.593636990 CEST | 308 | OUT | |
Oct 12, 2024 22:29:12.657061100 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49853 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:12.673738956 CEST | 280 | OUT | |
Oct 12, 2024 22:29:12.673738956 CEST | 213 | OUT | |
Oct 12, 2024 22:29:13.772727013 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49859 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:13.987952948 CEST | 279 | OUT | |
Oct 12, 2024 22:29:13.987977982 CEST | 202 | OUT | |
Oct 12, 2024 22:29:15.061553955 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49870 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:29:15.070422888 CEST | 278 | OUT | |
Oct 12, 2024 22:29:15.070442915 CEST | 356 | OUT | |
Oct 12, 2024 22:29:16.143505096 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 50043 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:30:25.196594954 CEST | 279 | OUT | |
Oct 12, 2024 22:30:25.196616888 CEST | 227 | OUT | |
Oct 12, 2024 22:30:26.260431051 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 50044 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:30:31.925354004 CEST | 281 | OUT | |
Oct 12, 2024 22:30:31.925384998 CEST | 173 | OUT | |
Oct 12, 2024 22:30:33.004900932 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 50045 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:30:40.937889099 CEST | 280 | OUT | |
Oct 12, 2024 22:30:40.937935114 CEST | 292 | OUT | |
Oct 12, 2024 22:30:42.007350922 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 50046 | 190.147.128.172 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:30:51.742774963 CEST | 278 | OUT | |
Oct 12, 2024 22:30:51.742810011 CEST | 208 | OUT | |
Oct 12, 2024 22:30:52.824522018 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 50047 | 175.119.10.231 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:31:04.785314083 CEST | 281 | OUT | |
Oct 12, 2024 22:31:04.785346985 CEST | 338 | OUT | |
Oct 12, 2024 22:31:06.258120060 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 50048 | 175.119.10.231 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:31:19.249269009 CEST | 278 | OUT | |
Oct 12, 2024 22:31:19.249310017 CEST | 229 | OUT | |
Oct 12, 2024 22:31:20.968141079 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 50049 | 175.119.10.231 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:31:34.612454891 CEST | 280 | OUT | |
Oct 12, 2024 22:31:34.612473011 CEST | 137 | OUT | |
Oct 12, 2024 22:31:36.113661051 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 50050 | 175.119.10.231 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:31:48.995564938 CEST | 278 | OUT | |
Oct 12, 2024 22:31:48.995596886 CEST | 261 | OUT | |
Oct 12, 2024 22:31:50.445827961 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 50051 | 175.119.10.231 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 12, 2024 22:32:03.964360952 CEST | 279 | OUT | |
Oct 12, 2024 22:32:03.964402914 CEST | 301 | OUT | |
Oct 12, 2024 22:32:05.414036036 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49779 | 23.145.40.164 | 443 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-12 20:29:01 UTC | 162 | OUT | |
2024-10-12 20:29:01 UTC | 327 | IN | |
2024-10-12 20:29:01 UTC | 7865 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN | |
2024-10-12 20:29:01 UTC | 8000 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:28:02 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | F0342947877C844A5C82CB4BB5FDADAD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 16:28:12 |
Start date: | 12/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 16:28:32 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\trbwcit |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | F0342947877C844A5C82CB4BB5FDADAD |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 16:29:01 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Local\Temp\565.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 242'688 bytes |
MD5 hash: | F42E9B6758241070E7815B8BD1EB8335 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 16:29:28 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\fgbwcit |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 242'688 bytes |
MD5 hash: | F42E9B6758241070E7815B8BD1EB8335 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 16:30:01 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\trbwcit |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 243'200 bytes |
MD5 hash: | F0342947877C844A5C82CB4BB5FDADAD |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 10 |
Start time: | 16:30:02 |
Start date: | 12/10/2024 |
Path: | C:\Users\user\AppData\Roaming\fgbwcit |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 242'688 bytes |
MD5 hash: | F42E9B6758241070E7815B8BD1EB8335 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 9.4% |
Dynamic/Decrypted Code Coverage: | 29.4% |
Signature Coverage: | 42.9% |
Total number of Nodes: | 163 |
Total number of Limit Nodes: | 7 |
Graph
Function 00415B60 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DBAE2E Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02D8003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415792 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 73librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157E0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D80E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DBAAED Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157B0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D8092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02DBA70B Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D80D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415AD0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.4% |
Dynamic/Decrypted Code Coverage: | 29.4% |
Signature Coverage: | 0% |
Total number of Nodes: | 163 |
Total number of Limit Nodes: | 7 |
Graph
Function 00415B60 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02CC003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415792 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 73librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157E0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D5A516 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02CC0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D5A1D5 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157B0 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415AD0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.5% |
Dynamic/Decrypted Code Coverage: | 16.5% |
Signature Coverage: | 0% |
Total number of Nodes: | 170 |
Total number of Limit Nodes: | 9 |
Graph
Function 00415840 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004014FB Relevance: 10.8, APIs: 7, Instructions: 316COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02BF003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004154C0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C6A76C Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02BF0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004019C0 Relevance: 1.3, APIs: 1, Instructions: 68sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019E0 Relevance: 1.3, APIs: 1, Instructions: 60sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019EB Relevance: 1.3, APIs: 1, Instructions: 54sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A04 Relevance: 1.3, APIs: 1, Instructions: 50sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019FD Relevance: 1.3, APIs: 1, Instructions: 49sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C6A42B Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401A15 Relevance: 1.3, APIs: 1, Instructions: 42sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A20 Relevance: 1.3, APIs: 1, Instructions: 42sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415490 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401E65 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157B0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.1% |
Dynamic/Decrypted Code Coverage: | 16.5% |
Signature Coverage: | 0% |
Total number of Nodes: | 170 |
Total number of Limit Nodes: | 9 |
Graph
Function 00415840 Relevance: 44.0, APIs: 23, Strings: 2, Instructions: 283filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004014FB Relevance: 10.8, APIs: 7, Instructions: 316COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02E8003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004154C0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C3A53C Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02E80E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004019C0 Relevance: 1.3, APIs: 1, Instructions: 68sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019E0 Relevance: 1.3, APIs: 1, Instructions: 60sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019EB Relevance: 1.3, APIs: 1, Instructions: 54sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A04 Relevance: 1.3, APIs: 1, Instructions: 50sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004019FD Relevance: 1.3, APIs: 1, Instructions: 49sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02C3A1FB Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401A15 Relevance: 1.3, APIs: 1, Instructions: 42sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A20 Relevance: 1.3, APIs: 1, Instructions: 42sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415490 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004157B0 Relevance: 6.0, APIs: 4, Instructions: 41memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|