Windows
Analysis Report
1HGXcC63iu.exe
Overview
General Information
Sample name: | 1HGXcC63iu.exerenamed because original name is a hash value |
Original sample name: | 8320df18fc9660f3a4dcaa29b3707847.exe |
Analysis ID: | 1532852 |
MD5: | 8320df18fc9660f3a4dcaa29b3707847 |
SHA1: | 1ec0afcceae9b6b0a771f28002b3617d45d5ab56 |
SHA256: | ce39271335727cb252102e59f53dedb8880fb3dca8f597bdf7e5d35c6d605de0 |
Tags: | exeStealcuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1HGXcC63iu.exe (PID: 7264 cmdline:
"C:\Users\ user\Deskt op\1HGXcC6 3iu.exe" MD5: 8320DF18FC9660F3A4DCAA29B3707847) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- scjabht (PID: 7684 cmdline:
C:\Users\u ser\AppDat a\Roaming\ scjabht MD5: 8320DF18FC9660F3A4DCAA29B3707847)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-14T01:52:27.352704+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:28.476787+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49737 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:29.578063+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:30.712318+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:31.846797+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:32.943368+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:34.066205+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49742 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:35.284563+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:36.394921+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49744 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:37.513650+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:38.616273+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:39.978543+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49747 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:41.229308+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:42.343624+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:43.461849+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49750 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:44.586287+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:45.701213+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:46.817207+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:47.922152+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:49.045985+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49755 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:50.193029+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:51.533325+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:52.671964+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49758 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:53.788983+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49759 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:54.895988+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49760 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:56.000150+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49761 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:57.098914+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49762 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:58.208548+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49763 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:59.308215+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49766 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:00.410405+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49772 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:01.541617+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49783 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:02.669552+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49789 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:03.768388+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49797 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:04.909931+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49806 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:06.098599+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49812 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:54:18.022227+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50037 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:25.117522+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50038 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:31.240510+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50039 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:37.062971+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50040 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:43.976866+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50041 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:50.199292+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50042 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:56.990013+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50043 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:03.109844+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50044 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:09.950050+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50045 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:17.944120+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50046 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:24.265967+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50047 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:30.261756+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50048 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:37.612387+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50049 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:44.030057+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50050 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:51.158024+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50051 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:56.961550+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50052 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:56:03.563735+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50053 | 58.151.148.90 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 5_2_00401514 | |
Source: | Code function: | 5_2_00402F97 | |
Source: | Code function: | 5_2_00401542 | |
Source: | Code function: | 5_2_00403247 | |
Source: | Code function: | 5_2_00401549 | |
Source: | Code function: | 5_2_0040324F | |
Source: | Code function: | 5_2_00403256 | |
Source: | Code function: | 5_2_00401557 | |
Source: | Code function: | 5_2_0040326C | |
Source: | Code function: | 5_2_00403277 | |
Source: | Code function: | 5_2_004014FE | |
Source: | Code function: | 5_2_00403290 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_02DD03D8 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_02D91550 | |
Source: | Code function: | 0_2_02DD220B | |
Source: | Code function: | 0_2_02DD2CD2 | |
Source: | Code function: | 0_2_02DD3E33 | |
Source: | Code function: | 5_2_004014E9 | |
Source: | Code function: | 5_2_004032AB | |
Source: | Code function: | 5_2_02B71550 | |
Source: | Code function: | 5_2_02DA478B | |
Source: | Code function: | 5_2_02DA362A | |
Source: | Code function: | 5_2_02DA2B63 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_02D90D90 | |
Source: | Code function: | 0_2_02D9092B | |
Source: | Code function: | 0_2_02DCFCB5 | |
Source: | Code function: | 5_2_02B70D90 | |
Source: | Code function: | 5_2_02B7092B | |
Source: | Code function: | 5_2_02DA060D |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00417620 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 411 Security Software Discovery | Remote Services | Data from Local System | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 12 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 3 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 113 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 12 Software Packing | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
34% | ReversingLabs | |||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
34% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
nwgrus.ru | 189.161.95.103 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
58.151.148.90 | unknown | Korea Republic of | 17858 | POWERVIS-AS-KRLGPOWERCOMMKR | true | |
189.161.95.103 | nwgrus.ru | Mexico | 8151 | UninetSAdeCVMX | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1532852 |
Start date and time: | 2024-10-14 01:51:07 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1HGXcC63iu.exerenamed because original name is a hash value |
Original Sample Name: | 8320df18fc9660f3a4dcaa29b3707847.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@2/2@3/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 1HGXcC63iu.exe
Time | Type | Description |
---|---|---|
00:52:26 | Task Scheduler | |
19:52:26 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
58.151.148.90 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | Babuk, Djvu | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
nwgrus.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
POWERVIS-AS-KRLGPOWERCOMMKR | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
UninetSAdeCVMX | Get hash | malicious | Mirai, Moobot | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Phorpiex, Xmrig | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 275456 |
Entropy (8bit): | 5.751648146553764 |
Encrypted: | false |
SSDEEP: | 3072:O9PTmSohCYWK7JSuGdngqp7U+L5ACyxF9Dav3xvZtWluUCIqzpjAqMi:gYhcOIuGdngq58/4JZoluVIqzpjAqh |
MD5: | 8320DF18FC9660F3A4DCAA29B3707847 |
SHA1: | 1EC0AFCCEAE9B6B0A771F28002B3617D45D5AB56 |
SHA-256: | CE39271335727CB252102E59F53DEDB8880FB3DCA8F597BDF7E5D35C6D605DE0 |
SHA-512: | A4A47B83FA644BB403CF2CF43CDA6357CE6149D874EE7549B6D0BA02E8BD31E3128F6546EA7ED1A225AC3DF70E3EB50848FDC859542C2F670F71F780A408017B |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.751648146553764 |
TrID: |
|
File name: | 1HGXcC63iu.exe |
File size: | 275'456 bytes |
MD5: | 8320df18fc9660f3a4dcaa29b3707847 |
SHA1: | 1ec0afcceae9b6b0a771f28002b3617d45d5ab56 |
SHA256: | ce39271335727cb252102e59f53dedb8880fb3dca8f597bdf7e5d35c6d605de0 |
SHA512: | a4a47b83fa644bb403cf2cf43cda6357ce6149d874ee7549b6d0ba02e8bd31e3128f6546ea7ed1a225ac3df70e3eb50848fdc859542c2f670f71f780a408017b |
SSDEEP: | 3072:O9PTmSohCYWK7JSuGdngqp7U+L5ACyxF9Dav3xvZtWluUCIqzpjAqMi:gYhcOIuGdngq58/4JZoluVIqzpjAqh |
TLSH: | 8444F68163A1AC13EFB64B324E39D9942A7EBC625E7572DFF104760F187B1A1E413B12 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................U.c.......q.......`.......v......E........................a.......d.....Rich....................PE..L.....Xe... |
Icon Hash: | 17614cb2b24d2117 |
Entrypoint: | 0x401a22 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6558C78F [Sat Nov 18 14:17:51 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | dc51987737c4af4f71f5c3733cf2b1f2 |
Instruction |
---|
call 00007F8BAC8173D2h |
jmp 00007F8BAC813C4Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [0041C650h], eax |
mov dword ptr [0041C64Ch], ecx |
mov dword ptr [0041C648h], edx |
mov dword ptr [0041C644h], ebx |
mov dword ptr [0041C640h], esi |
mov dword ptr [0041C63Ch], edi |
mov word ptr [0041C668h], ss |
mov word ptr [0041C65Ch], cs |
mov word ptr [0041C638h], ds |
mov word ptr [0041C634h], es |
mov word ptr [0041C630h], fs |
mov word ptr [0041C62Ch], gs |
pushfd |
pop dword ptr [0041C660h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0041C654h], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [0041C658h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0041C664h], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [0041C5A0h], 00010001h |
mov eax, dword ptr [0041C658h] |
mov dword ptr [0041C554h], eax |
mov dword ptr [0041C548h], C0000409h |
mov dword ptr [0041C54Ch], 00000001h |
mov eax, dword ptr [0041B008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041B00Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000D8h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1985c | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x2725000 | 0x22dd0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x18000 | 0x19c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x169ef | 0x16a00 | 5017a637cc335af03a6ec36cca92aac4 | False | 0.8069319751381215 | data | 7.517270263050042 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x18000 | 0x21b0 | 0x2200 | 8f7390606cfa5526c62a62295eb9b3af | False | 0.37247242647058826 | data | 5.561090816497167 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x1b000 | 0x270121c | 0x1600 | 6d8a2d4cce703da056e9061551cb7a55 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.jekin | 0x271d000 | 0x4400 | 0x3800 | b211778b80f6d441b6cf61ada776fc6d | False | 0.0025809151785714285 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.zidisi | 0x2722000 | 0x2800 | 0x2800 | 1276481102f218c981e0324180bafd9f | False | 0.00322265625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x2725000 | 0x22dd0 | 0x22e00 | c0d08340b10908b7723d0d4308aa5d19 | False | 0.3799423163082437 | data | 4.837964295754695 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x273d678 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x273d7a8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_CURSOR | 0x273fd78 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7368421052631579 | ||
RT_CURSOR | 0x273fea8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | 0.06130705394190871 | ||
RT_ICON | 0x2725b50 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.5674307036247335 |
RT_ICON | 0x27269f8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.6376353790613718 |
RT_ICON | 0x27272a0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.6849078341013825 |
RT_ICON | 0x2727968 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.7456647398843931 |
RT_ICON | 0x2727ed0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkish | Turkey | 0.512863070539419 |
RT_ICON | 0x272a478 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkish | Turkey | 0.6137429643527205 |
RT_ICON | 0x272b520 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkish | Turkey | 0.6163934426229508 |
RT_ICON | 0x272bea8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkish | Turkey | 0.7553191489361702 |
RT_ICON | 0x272c388 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkish | Turkey | 0.39952025586353945 |
RT_ICON | 0x272d230 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkish | Turkey | 0.5 |
RT_ICON | 0x272dad8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkish | Turkey | 0.5155529953917051 |
RT_ICON | 0x272e1a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkish | Turkey | 0.5635838150289018 |
RT_ICON | 0x272e708 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Turkish | Turkey | 0.35477178423236516 |
RT_ICON | 0x2730cb0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Turkish | Turkey | 0.3820356472795497 |
RT_ICON | 0x2731d58 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Turkish | Turkey | 0.40614754098360656 |
RT_ICON | 0x27326e0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Turkish | Turkey | 0.42021276595744683 |
RT_ICON | 0x2732bc0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.39285714285714285 |
RT_ICON | 0x2733a68 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.5537003610108303 |
RT_ICON | 0x2734310 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.6226958525345622 |
RT_ICON | 0x27349d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.6372832369942196 |
RT_ICON | 0x2734f40 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.425422138836773 |
RT_ICON | 0x2735fe8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.4209016393442623 |
RT_ICON | 0x2736970 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.46187943262411346 |
RT_ICON | 0x2736e40 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkish | Turkey | 0.279317697228145 |
RT_ICON | 0x2737ce8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkish | Turkey | 0.3664259927797834 |
RT_ICON | 0x2738590 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkish | Turkey | 0.3773041474654378 |
RT_ICON | 0x2738c58 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkish | Turkey | 0.3764450867052023 |
RT_ICON | 0x27391c0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkish | Turkey | 0.2587136929460581 |
RT_ICON | 0x273b768 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkish | Turkey | 0.27345215759849906 |
RT_ICON | 0x273c810 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkish | Turkey | 0.28852459016393445 |
RT_ICON | 0x273d198 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkish | Turkey | 0.32180851063829785 |
RT_STRING | 0x2742630 | 0xaa | data | 0.5588235294117647 | ||
RT_STRING | 0x27426e0 | 0x600 | data | 0.4361979166666667 | ||
RT_STRING | 0x2742ce0 | 0x460 | data | 0.45 | ||
RT_STRING | 0x2743140 | 0x64a | data | 0.4360248447204969 | ||
RT_STRING | 0x2743790 | 0x7b4 | data | 0.417342799188641 | ||
RT_STRING | 0x2743f48 | 0x6d0 | data | 0.4294724770642202 | ||
RT_STRING | 0x2744618 | 0x76c | data | 0.42526315789473684 | ||
RT_STRING | 0x2744d88 | 0x606 | data | 0.4455252918287938 | ||
RT_STRING | 0x2745390 | 0x7c2 | data | 0.42245720040281975 | ||
RT_STRING | 0x2745b58 | 0x810 | data | 0.42102713178294576 | ||
RT_STRING | 0x2746368 | 0x584 | data | 0.4461756373937677 | ||
RT_STRING | 0x27468f0 | 0x74c | data | 0.4234475374732334 | ||
RT_STRING | 0x2747040 | 0x710 | data | 0.4303097345132743 | ||
RT_STRING | 0x2747750 | 0x5f6 | data | 0.4325032765399738 | ||
RT_STRING | 0x2747d48 | 0x88 | data | 0.625 | ||
RT_GROUP_CURSOR | 0x273fd50 | 0x22 | data | 1.0588235294117647 | ||
RT_GROUP_CURSOR | 0x2742450 | 0x22 | data | 1.088235294117647 | ||
RT_GROUP_ICON | 0x2732b48 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x273d600 | 0x76 | data | Turkish | Turkey | 0.6694915254237288 |
RT_GROUP_ICON | 0x272c310 | 0x76 | data | Turkish | Turkey | 0.6610169491525424 |
RT_GROUP_ICON | 0x2736dd8 | 0x68 | data | Turkish | Turkey | 0.7211538461538461 |
RT_VERSION | 0x2742478 | 0x1b4 | data | 0.5756880733944955 |
DLL | Import |
---|---|
KERNEL32.dll | OpenJobObjectA, ReadConsoleA, InterlockedDecrement, GlobalSize, SetDefaultCommConfigW, QueryDosDeviceA, GetComputerNameW, SetEvent, GetNumaAvailableMemoryNode, FreeEnvironmentStringsA, GetModuleHandleW, GetConsoleAliasesLengthA, SetCommState, GetConsoleWindow, ReadConsoleOutputW, GetVersionExW, GetStringTypeExW, HeapDestroy, GetFileAttributesA, DeleteVolumeMountPointA, DisconnectNamedPipe, LCMapStringA, GetLastError, GetProcAddress, MoveFileW, SetStdHandle, LoadLibraryA, InterlockedExchangeAdd, LocalAlloc, WritePrivateProfileStringA, GetModuleFileNameA, BuildCommDCBA, FatalAppExitA, GetShortPathNameW, SetCalendarInfoA, FindAtomW, SearchPathW, GetNumaProcessorNode, GetConsoleFontSize, PulseEvent, HeapAlloc, MultiByteToWideChar, Sleep, ExitProcess, GetCommandLineA, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, HeapFree, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, WriteFile, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, InitializeCriticalSectionAndSpinCount, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetFilePointer, GetConsoleCP, GetConsoleMode, FlushFileBuffers, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CloseHandle, CreateFileA |
GDI32.dll | GetBoundsRect |
ADVAPI32.dll | ClearEventLogW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-14T01:52:27.352704+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:28.476787+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49737 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:29.578063+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49738 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:30.712318+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49739 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:31.846797+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49740 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:32.943368+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49741 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:34.066205+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49742 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:35.284563+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49743 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:36.394921+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49744 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:37.513650+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49745 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:38.616273+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49746 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:39.978543+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49747 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:41.229308+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49748 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:42.343624+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49749 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:43.461849+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49750 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:44.586287+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49751 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:45.701213+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49752 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:46.817207+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49753 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:47.922152+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49754 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:49.045985+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49755 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:50.193029+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49756 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:51.533325+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49757 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:52.671964+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49758 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:53.788983+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49759 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:54.895988+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49760 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:56.000150+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49761 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:57.098914+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49762 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:58.208548+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49763 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:52:59.308215+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49766 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:00.410405+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49772 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:01.541617+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49783 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:02.669552+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49789 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:03.768388+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49797 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:04.909931+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49806 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:53:06.098599+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49812 | 189.161.95.103 | 80 | TCP |
2024-10-14T01:54:18.022227+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50037 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:25.117522+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50038 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:31.240510+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50039 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:37.062971+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50040 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:43.976866+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50041 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:50.199292+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50042 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:54:56.990013+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50043 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:03.109844+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50044 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:09.950050+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50045 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:17.944120+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50046 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:24.265967+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50047 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:30.261756+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50048 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:37.612387+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50049 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:44.030057+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50050 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:51.158024+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50051 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:55:56.961550+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50052 | 58.151.148.90 | 80 | TCP |
2024-10-14T01:56:03.563735+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50053 | 58.151.148.90 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 14, 2024 01:52:26.250921965 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:26.256372929 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:26.256572008 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:26.256912947 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:26.256913900 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:26.261977911 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:26.262103081 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.352427959 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.352530003 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.352704048 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.354927063 CEST | 49736 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.359307051 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.360255003 CEST | 80 | 49736 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.364826918 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.364927053 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.365040064 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.365065098 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:27.370734930 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:27.370774984 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.476666927 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.476717949 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.476787090 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.477004051 CEST | 49737 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.480262995 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.482255936 CEST | 80 | 49737 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.485543013 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.485601902 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.485728979 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.485752106 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:28.490801096 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:28.490998030 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.577939987 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.577999115 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.578063011 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.578174114 CEST | 49738 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.580718994 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.583134890 CEST | 80 | 49738 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.586182117 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.586394072 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.586394072 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.586394072 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:29.591716051 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:29.591753006 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.712194920 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.712241888 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.712317944 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.712481022 CEST | 49739 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.717324018 CEST | 80 | 49739 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.735101938 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.740581036 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.742223024 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.745536089 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.746463060 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:30.750751019 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:30.751739025 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.838764906 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.845276117 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.846796989 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.846844912 CEST | 49740 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.849359989 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.851830006 CEST | 80 | 49740 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.854748011 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.855186939 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.855186939 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.855186939 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:31.860682964 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:31.860724926 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.943216085 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.943268061 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.943367958 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.943514109 CEST | 49741 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.948695898 CEST | 80 | 49741 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.949100971 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.954121113 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.954205036 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.954488039 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.954519987 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:32.959379911 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:32.959428072 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.066059113 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.066123009 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.066205025 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.066339016 CEST | 49742 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.069298983 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.072515011 CEST | 80 | 49742 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.075131893 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.075226068 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.075334072 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.075371981 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:34.080177069 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:34.080348015 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.284312010 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.284360886 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.284392118 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.284563065 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.284563065 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.284662962 CEST | 49743 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.287475109 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.289781094 CEST | 80 | 49743 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.292458057 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.292691946 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.292782068 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.292782068 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:35.298104048 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:35.298146009 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.394654036 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.394710064 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.394921064 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.395009041 CEST | 49744 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.400366068 CEST | 80 | 49744 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.402894020 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.408277988 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.408365011 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.408469915 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.408479929 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:36.413924932 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:36.414494038 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.513359070 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.513529062 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.513649940 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.513694048 CEST | 49745 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.517194986 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.519069910 CEST | 80 | 49745 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.522562981 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.522651911 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.522823095 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.522850037 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:37.528199911 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:37.528238058 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.610548973 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.616184950 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.616272926 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.616314888 CEST | 49746 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.619465113 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.621345043 CEST | 80 | 49746 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.624767065 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.624936104 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.624982119 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.624982119 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:38.630229950 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:38.630297899 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:39.978420019 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:39.978463888 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:39.978492022 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:39.978519917 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:39.978543043 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:39.978543997 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:39.978631973 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:39.982259989 CEST | 49747 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:39.987247944 CEST | 80 | 49747 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:40.118221998 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:40.123629093 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:40.123738050 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:40.123960972 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:40.124027014 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:40.129326105 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:40.129368067 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.223464966 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.229232073 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.229307890 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.229357004 CEST | 49748 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.232445955 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.234304905 CEST | 80 | 49748 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.237320900 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.237412930 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.237576008 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.237576008 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:41.242463112 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:41.242522001 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.343538046 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.343560934 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.343624115 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.343811989 CEST | 49749 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.347002029 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.348752022 CEST | 80 | 49749 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.352205992 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.352401018 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.352502108 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.352502108 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:42.357500076 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:42.357518911 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.461736917 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.461760044 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.461848974 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.468250036 CEST | 49750 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.473495960 CEST | 80 | 49750 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.482388973 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.487654924 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.487875938 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.505342960 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.505342960 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:43.510672092 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:43.511292934 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.583055019 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.586193085 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.586287022 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.586338043 CEST | 49751 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.589433908 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.591711044 CEST | 80 | 49751 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.594584942 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.594676018 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.594820976 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.594852924 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:44.600387096 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:44.600425005 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.700979948 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.701046944 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.701212883 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.701253891 CEST | 49752 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.704319000 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.706351995 CEST | 80 | 49752 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.709861040 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.710191011 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.710191965 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.710191965 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:45.715812922 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:45.716470957 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.816863060 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.816910028 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.817207098 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.817327976 CEST | 49753 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.820899010 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.823002100 CEST | 80 | 49753 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.826349020 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.826455116 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.826585054 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.826607943 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:46.831717968 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:46.831800938 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.921842098 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.921871901 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.922152042 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.922468901 CEST | 49754 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.925478935 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.927740097 CEST | 80 | 49754 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.930958033 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.931061029 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.931195021 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.931227922 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:47.936220884 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:47.936261892 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.045856953 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.045907021 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.045984983 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.046135902 CEST | 49755 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.049176931 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.051246881 CEST | 80 | 49755 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.054507971 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.054605007 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.054759026 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.054791927 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:49.059986115 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:49.060026884 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.187657118 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.192949057 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.193028927 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.193067074 CEST | 49756 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.196022034 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.198364019 CEST | 80 | 49756 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.201195002 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.201419115 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.201419115 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.201419115 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:50.206924915 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:50.206953049 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.527635098 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.533226013 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.533324957 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.533411026 CEST | 49757 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.536586046 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.538320065 CEST | 80 | 49757 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.541495085 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.541585922 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.541734934 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.541734934 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:51.546936035 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:51.546967030 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.671621084 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.671694994 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.671963930 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.672009945 CEST | 49758 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.674043894 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.676868916 CEST | 80 | 49758 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.678994894 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.679081917 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.679179907 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.679209948 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:52.684351921 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:52.684380054 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.788449049 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.788889885 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.788983107 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.789098024 CEST | 49759 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.791578054 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.794078112 CEST | 80 | 49759 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.796813011 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.799993992 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.800121069 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.800148964 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:53.805656910 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:53.805697918 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.895823002 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.895917892 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.895987988 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.896083117 CEST | 49760 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.900985956 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.901808977 CEST | 80 | 49760 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.906548023 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.906769991 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.906866074 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.906898022 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:54.912614107 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:54.912653923 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:55.999577999 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:55.999865055 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:56.000149965 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.000149965 CEST | 49761 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.002588987 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.006042004 CEST | 80 | 49761 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:56.007834911 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:56.008057117 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.008057117 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.008057117 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:56.013331890 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:56.013417006 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.098568916 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.098784924 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.098913908 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.099947929 CEST | 49762 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.104788065 CEST | 80 | 49762 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.106440067 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.113982916 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.114072084 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.114233971 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.114264011 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:57.121006012 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:57.121057987 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.208302975 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.208472013 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.208548069 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.208636999 CEST | 49763 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.212496042 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.213665009 CEST | 80 | 49763 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.217425108 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.217502117 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.217596054 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.217612028 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:58.222853899 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:58.222867966 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.308052063 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.308142900 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.308214903 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.308512926 CEST | 49766 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.312824965 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.313508034 CEST | 80 | 49766 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.317754984 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.317873001 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.318584919 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.318584919 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:52:59.323476076 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:52:59.323489904 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.410244942 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.410334110 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.410404921 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.410528898 CEST | 49772 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.412744045 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.415455103 CEST | 80 | 49772 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.417757988 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.417833090 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.418123960 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.418123960 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:00.423209906 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:00.423501015 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.541305065 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.541534901 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.541616917 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.541697025 CEST | 49783 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.543881893 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.546633005 CEST | 80 | 49783 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.549751043 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.549827099 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.549936056 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.549978018 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:01.555916071 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:01.555946112 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.669269085 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.669487000 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.669552088 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.670196056 CEST | 49789 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.673273087 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.675467968 CEST | 80 | 49789 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.678237915 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.678303957 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.678565979 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.678565979 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:02.683708906 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:02.684586048 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.768182993 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.768251896 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.768388033 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.768560886 CEST | 49797 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.772875071 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.773360968 CEST | 80 | 49797 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.777806044 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.777878046 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.778011084 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.778024912 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:03.783148050 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:03.783263922 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.904217958 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.909857035 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.909930944 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.912894011 CEST | 49806 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.917814970 CEST | 80 | 49806 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.987200975 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.992111921 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.992206097 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.992335081 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.992361069 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:04.997240067 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:04.997422934 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:06.098270893 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:06.098501921 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:53:06.098598957 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:06.098675966 CEST | 49812 | 80 | 192.168.2.4 | 189.161.95.103 |
Oct 14, 2024 01:53:06.103533983 CEST | 80 | 49812 | 189.161.95.103 | 192.168.2.4 |
Oct 14, 2024 01:54:15.448882103 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:15.453952074 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:15.454190016 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:15.511869907 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:15.511869907 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:15.516829014 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:15.517102003 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:18.021929979 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:18.022150040 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:18.022227049 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:18.022279024 CEST | 50037 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:18.027142048 CEST | 80 | 50037 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:22.517494917 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:22.522993088 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:22.523197889 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:22.523246050 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:22.523262978 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:22.528127909 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:22.528563976 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:25.117286921 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:25.117326975 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:25.117522001 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:25.117578983 CEST | 50038 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:25.122562885 CEST | 80 | 50038 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:29.624329090 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:29.629518986 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:29.629622936 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:29.629760027 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:29.629771948 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:29.634715080 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:29.634879112 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:31.239456892 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:31.240447044 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:31.240509987 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:31.240546942 CEST | 50039 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:31.246912956 CEST | 80 | 50039 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:35.417798042 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:35.423034906 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:35.423322916 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:35.423472881 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:35.423472881 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:35.429430962 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:35.429456949 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:37.062496901 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:37.062875032 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:37.062971115 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:37.063061953 CEST | 50040 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:37.068008900 CEST | 80 | 50040 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:42.296602011 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:42.301887989 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:42.302007914 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:42.302177906 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:42.302210093 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:42.307053089 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:42.307451963 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:43.975779057 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:43.976774931 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:43.976866007 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:43.979399920 CEST | 50041 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:43.984313011 CEST | 80 | 50041 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:48.575867891 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:48.581134081 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:48.581258059 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:48.581429005 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:48.581461906 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:48.586329937 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:48.586361885 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:50.179156065 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:50.199232101 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:50.199291945 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:50.199413061 CEST | 50042 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:50.204415083 CEST | 80 | 50042 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:55.391624928 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:55.412868023 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:55.413130999 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:55.413235903 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:55.413260937 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:55.420443058 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:55.420490026 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:56.987704039 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:56.989906073 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:54:56.990012884 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:56.990103960 CEST | 50043 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:54:56.995096922 CEST | 80 | 50043 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:01.430545092 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:01.435676098 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:01.435777903 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:01.435952902 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:01.435983896 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:01.440944910 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:01.440984964 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:03.107470036 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:03.109678030 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:03.109843969 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:03.109844923 CEST | 50044 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:03.115145922 CEST | 80 | 50044 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:08.434984922 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:08.440068007 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:08.440363884 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:08.440407991 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:08.440407991 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:08.445372105 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:08.445383072 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:09.949276924 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:09.949969053 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:09.950050116 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:09.950143099 CEST | 50045 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:09.955471992 CEST | 80 | 50045 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:15.610415936 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:15.615705013 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:15.615817070 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:15.616013050 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:15.616063118 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:15.621125937 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:15.621169090 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:17.943950891 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:17.944026947 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:17.944119930 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:17.945818901 CEST | 50046 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:17.950668097 CEST | 80 | 50046 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:22.605346918 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:22.610667944 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:22.610780001 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:22.610935926 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:22.610937119 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:22.616003990 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:22.616033077 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:24.219738007 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:24.265830994 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:24.265966892 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:24.266062975 CEST | 50047 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:24.271219969 CEST | 80 | 50047 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:28.579772949 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:28.585165024 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:28.585268974 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:28.585405111 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:28.585429907 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:28.591015100 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:28.591054916 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:30.260673046 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:30.261689901 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:30.261755943 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:30.261805058 CEST | 50048 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:30.266617060 CEST | 80 | 50048 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:35.112736940 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:35.118083000 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:35.118192911 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:35.118352890 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:35.118386984 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:35.123316050 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:35.123713970 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:37.592566013 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:37.612277985 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:37.612386942 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:37.612437963 CEST | 50049 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:37.617403030 CEST | 80 | 50049 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:42.377270937 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:42.383109093 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:42.383168936 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:42.383274078 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:42.383285999 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:42.389940023 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:42.389952898 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:44.025274038 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:44.029972076 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:44.030056953 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:44.030113935 CEST | 50050 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:44.036514044 CEST | 80 | 50050 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:48.551573038 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:48.556894064 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:48.557096958 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:48.557193041 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:48.557193041 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:48.562792063 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:48.562820911 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:51.157521009 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:51.157830954 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:51.158024073 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:51.160254002 CEST | 50051 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:51.165204048 CEST | 80 | 50051 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:55.317894936 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:55.323106050 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:55.323280096 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:55.323379040 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:55.323379040 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:55.328490019 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:55.328653097 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:56.957978010 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:56.961333036 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:55:56.961549997 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:56.961550951 CEST | 50052 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:55:56.966809034 CEST | 80 | 50052 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:01.906378984 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:01.911695004 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:01.911793947 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:01.911906958 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:01.911933899 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:01.917319059 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:01.917346954 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:03.562711000 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:03.563688040 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Oct 14, 2024 01:56:03.563735008 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:03.563791990 CEST | 50053 | 80 | 192.168.2.4 | 58.151.148.90 |
Oct 14, 2024 01:56:03.568773985 CEST | 80 | 50053 | 58.151.148.90 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 14, 2024 01:52:26.241811037 CEST | 53554 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 14, 2024 01:52:26.249304056 CEST | 53 | 53554 | 1.1.1.1 | 192.168.2.4 |
Oct 14, 2024 01:54:14.237809896 CEST | 63940 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 14, 2024 01:54:15.225946903 CEST | 63940 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 14, 2024 01:54:15.434916019 CEST | 53 | 63940 | 1.1.1.1 | 192.168.2.4 |
Oct 14, 2024 01:54:15.434993982 CEST | 53 | 63940 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 14, 2024 01:52:26.241811037 CEST | 192.168.2.4 | 1.1.1.1 | 0x3d83 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 01:54:14.237809896 CEST | 192.168.2.4 | 1.1.1.1 | 0x1a3b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 14, 2024 01:54:15.225946903 CEST | 192.168.2.4 | 1.1.1.1 | 0x1a3b | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 181.123.219.23 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 187.209.194.244 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 180.75.11.133 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 183.100.39.16 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 189.163.31.73 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 189.61.54.32 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:52:26.249304056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3d83 | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 190.13.174.94 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434916019 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 190.13.174.94 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 189.181.56.137 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 95.86.30.3 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 190.147.128.172 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 154.144.253.197 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 109.175.29.39 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 189.161.95.103 | A (IP address) | IN (0x0001) | false | ||
Oct 14, 2024 01:54:15.434993982 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a3b | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:26.256912947 CEST | 281 | OUT | |
Oct 14, 2024 01:52:26.256913900 CEST | 114 | OUT | |
Oct 14, 2024 01:52:27.352427959 CEST | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:27.365040064 CEST | 283 | OUT | |
Oct 14, 2024 01:52:27.365065098 CEST | 273 | OUT | |
Oct 14, 2024 01:52:28.476666927 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:28.485728979 CEST | 280 | OUT | |
Oct 14, 2024 01:52:28.485752106 CEST | 133 | OUT | |
Oct 14, 2024 01:52:29.577939987 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:29.586394072 CEST | 279 | OUT | |
Oct 14, 2024 01:52:29.586394072 CEST | 304 | OUT | |
Oct 14, 2024 01:52:30.712194920 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:30.745536089 CEST | 283 | OUT | |
Oct 14, 2024 01:52:30.746463060 CEST | 159 | OUT | |
Oct 14, 2024 01:52:31.838764906 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:31.855186939 CEST | 283 | OUT | |
Oct 14, 2024 01:52:31.855186939 CEST | 343 | OUT | |
Oct 14, 2024 01:52:32.943216085 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49742 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:32.954488039 CEST | 283 | OUT | |
Oct 14, 2024 01:52:32.954519987 CEST | 360 | OUT | |
Oct 14, 2024 01:52:34.066059113 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49743 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:34.075334072 CEST | 278 | OUT | |
Oct 14, 2024 01:52:34.075371981 CEST | 192 | OUT | |
Oct 14, 2024 01:52:35.284312010 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49744 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:35.292782068 CEST | 280 | OUT | |
Oct 14, 2024 01:52:35.292782068 CEST | 361 | OUT | |
Oct 14, 2024 01:52:36.394654036 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49745 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:36.408469915 CEST | 283 | OUT | |
Oct 14, 2024 01:52:36.408479929 CEST | 283 | OUT | |
Oct 14, 2024 01:52:37.513359070 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49746 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:37.522823095 CEST | 282 | OUT | |
Oct 14, 2024 01:52:37.522850037 CEST | 310 | OUT | |
Oct 14, 2024 01:52:38.610548973 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49747 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:38.624982119 CEST | 280 | OUT | |
Oct 14, 2024 01:52:38.624982119 CEST | 261 | OUT | |
Oct 14, 2024 01:52:39.978420019 CEST | 484 | IN | |
Oct 14, 2024 01:52:39.978519917 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49748 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:40.123960972 CEST | 280 | OUT | |
Oct 14, 2024 01:52:40.124027014 CEST | 325 | OUT | |
Oct 14, 2024 01:52:41.223464966 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49749 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:41.237576008 CEST | 280 | OUT | |
Oct 14, 2024 01:52:41.237576008 CEST | 216 | OUT | |
Oct 14, 2024 01:52:42.343538046 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49750 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:42.352502108 CEST | 278 | OUT | |
Oct 14, 2024 01:52:42.352502108 CEST | 114 | OUT | |
Oct 14, 2024 01:52:43.461736917 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49751 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:43.505342960 CEST | 281 | OUT | |
Oct 14, 2024 01:52:43.505342960 CEST | 237 | OUT | |
Oct 14, 2024 01:52:44.583055019 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49752 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:44.594820976 CEST | 283 | OUT | |
Oct 14, 2024 01:52:44.594852924 CEST | 125 | OUT | |
Oct 14, 2024 01:52:45.700979948 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49753 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:45.710191965 CEST | 281 | OUT | |
Oct 14, 2024 01:52:45.710191965 CEST | 177 | OUT | |
Oct 14, 2024 01:52:46.816863060 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49754 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:46.826585054 CEST | 279 | OUT | |
Oct 14, 2024 01:52:46.826607943 CEST | 199 | OUT | |
Oct 14, 2024 01:52:47.921842098 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49755 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:47.931195021 CEST | 282 | OUT | |
Oct 14, 2024 01:52:47.931227922 CEST | 345 | OUT | |
Oct 14, 2024 01:52:49.045856953 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49756 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:49.054759026 CEST | 281 | OUT | |
Oct 14, 2024 01:52:49.054791927 CEST | 268 | OUT | |
Oct 14, 2024 01:52:50.187657118 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49757 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:50.201419115 CEST | 278 | OUT | |
Oct 14, 2024 01:52:50.201419115 CEST | 116 | OUT | |
Oct 14, 2024 01:52:51.527635098 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49758 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:51.541734934 CEST | 280 | OUT | |
Oct 14, 2024 01:52:51.541734934 CEST | 135 | OUT | |
Oct 14, 2024 01:52:52.671621084 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49759 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:52.679179907 CEST | 282 | OUT | |
Oct 14, 2024 01:52:52.679209948 CEST | 324 | OUT | |
Oct 14, 2024 01:52:53.788449049 CEST | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49760 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:53.800121069 CEST | 278 | OUT | |
Oct 14, 2024 01:52:53.800148964 CEST | 166 | OUT | |
Oct 14, 2024 01:52:54.895823002 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49761 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:54.906866074 CEST | 282 | OUT | |
Oct 14, 2024 01:52:54.906898022 CEST | 255 | OUT | |
Oct 14, 2024 01:52:55.999577999 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49762 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:56.008057117 CEST | 282 | OUT | |
Oct 14, 2024 01:52:56.008057117 CEST | 276 | OUT | |
Oct 14, 2024 01:52:57.098568916 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49763 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:57.114233971 CEST | 278 | OUT | |
Oct 14, 2024 01:52:57.114264011 CEST | 330 | OUT | |
Oct 14, 2024 01:52:58.208302975 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49766 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:58.217596054 CEST | 281 | OUT | |
Oct 14, 2024 01:52:58.217612028 CEST | 172 | OUT | |
Oct 14, 2024 01:52:59.308052063 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49772 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:52:59.318584919 CEST | 282 | OUT | |
Oct 14, 2024 01:52:59.318584919 CEST | 316 | OUT | |
Oct 14, 2024 01:53:00.410244942 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49783 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:53:00.418123960 CEST | 282 | OUT | |
Oct 14, 2024 01:53:00.418123960 CEST | 124 | OUT | |
Oct 14, 2024 01:53:01.541305065 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49789 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:53:01.549936056 CEST | 283 | OUT | |
Oct 14, 2024 01:53:01.549978018 CEST | 338 | OUT | |
Oct 14, 2024 01:53:02.669269085 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49797 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:53:02.678565979 CEST | 280 | OUT | |
Oct 14, 2024 01:53:02.678565979 CEST | 222 | OUT | |
Oct 14, 2024 01:53:03.768182993 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49806 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:53:03.778011084 CEST | 280 | OUT | |
Oct 14, 2024 01:53:03.778024912 CEST | 273 | OUT | |
Oct 14, 2024 01:53:04.904217958 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49812 | 189.161.95.103 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:53:04.992335081 CEST | 279 | OUT | |
Oct 14, 2024 01:53:04.992361069 CEST | 156 | OUT | |
Oct 14, 2024 01:53:06.098270893 CEST | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 50037 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:15.511869907 CEST | 278 | OUT | |
Oct 14, 2024 01:54:15.511869907 CEST | 204 | OUT | |
Oct 14, 2024 01:54:18.021929979 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 50038 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:22.523246050 CEST | 281 | OUT | |
Oct 14, 2024 01:54:22.523262978 CEST | 162 | OUT | |
Oct 14, 2024 01:54:25.117286921 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 50039 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:29.629760027 CEST | 278 | OUT | |
Oct 14, 2024 01:54:29.629771948 CEST | 165 | OUT | |
Oct 14, 2024 01:54:31.239456892 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 50040 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:35.423472881 CEST | 279 | OUT | |
Oct 14, 2024 01:54:35.423472881 CEST | 122 | OUT | |
Oct 14, 2024 01:54:37.062496901 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 50041 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:42.302177906 CEST | 283 | OUT | |
Oct 14, 2024 01:54:42.302210093 CEST | 311 | OUT | |
Oct 14, 2024 01:54:43.975779057 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 50042 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:48.581429005 CEST | 283 | OUT | |
Oct 14, 2024 01:54:48.581461906 CEST | 311 | OUT | |
Oct 14, 2024 01:54:50.179156065 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 50043 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:54:55.413235903 CEST | 282 | OUT | |
Oct 14, 2024 01:54:55.413260937 CEST | 332 | OUT | |
Oct 14, 2024 01:54:56.987704039 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 50044 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:01.435952902 CEST | 278 | OUT | |
Oct 14, 2024 01:55:01.435983896 CEST | 285 | OUT | |
Oct 14, 2024 01:55:03.107470036 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 50045 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:08.440407991 CEST | 283 | OUT | |
Oct 14, 2024 01:55:08.440407991 CEST | 217 | OUT | |
Oct 14, 2024 01:55:09.949276924 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 50046 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:15.616013050 CEST | 283 | OUT | |
Oct 14, 2024 01:55:15.616063118 CEST | 326 | OUT | |
Oct 14, 2024 01:55:17.943950891 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 50047 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:22.610935926 CEST | 279 | OUT | |
Oct 14, 2024 01:55:22.610937119 CEST | 157 | OUT | |
Oct 14, 2024 01:55:24.219738007 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 50048 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:28.585405111 CEST | 280 | OUT | |
Oct 14, 2024 01:55:28.585429907 CEST | 369 | OUT | |
Oct 14, 2024 01:55:30.260673046 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 50049 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:35.118352890 CEST | 278 | OUT | |
Oct 14, 2024 01:55:35.118386984 CEST | 241 | OUT | |
Oct 14, 2024 01:55:37.592566013 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 50050 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:42.383274078 CEST | 278 | OUT | |
Oct 14, 2024 01:55:42.383285999 CEST | 174 | OUT | |
Oct 14, 2024 01:55:44.025274038 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 50051 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:48.557193041 CEST | 281 | OUT | |
Oct 14, 2024 01:55:48.557193041 CEST | 362 | OUT | |
Oct 14, 2024 01:55:51.157521009 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 50052 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:55:55.323379040 CEST | 283 | OUT | |
Oct 14, 2024 01:55:55.323379040 CEST | 273 | OUT | |
Oct 14, 2024 01:55:56.957978010 CEST | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 50053 | 58.151.148.90 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 14, 2024 01:56:01.911906958 CEST | 283 | OUT | |
Oct 14, 2024 01:56:01.911933899 CEST | 263 | OUT | |
Oct 14, 2024 01:56:03.562711000 CEST | 151 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:51:58 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\Desktop\1HGXcC63iu.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 275'456 bytes |
MD5 hash: | 8320DF18FC9660F3A4DCAA29B3707847 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 19:52:07 |
Start date: | 13/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 19:52:26 |
Start date: | 13/10/2024 |
Path: | C:\Users\user\AppData\Roaming\scjabht |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 275'456 bytes |
MD5 hash: | 8320DF18FC9660F3A4DCAA29B3707847 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 28.7% |
Signature Coverage: | 41.5% |
Total number of Nodes: | 171 |
Total number of Limit Nodes: | 5 |
Graph
Function 00417620 Relevance: 38.8, APIs: 20, Strings: 2, Instructions: 269filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DD03D8 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02D9003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004178E3 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417290 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D90E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DD0097 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417260 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D9092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02DCFCB5 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D90D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417580 Relevance: 6.0, APIs: 4, Instructions: 43memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.5% |
Dynamic/Decrypted Code Coverage: | 28.7% |
Signature Coverage: | 0% |
Total number of Nodes: | 171 |
Total number of Limit Nodes: | 5 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417620 Relevance: 38.8, APIs: 20, Strings: 2, Instructions: 269filelibrarypipeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02B7003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004178E3 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417290 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 63librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DA0D30 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02B70E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02DA09EF Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417260 Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417580 Relevance: 6.0, APIs: 4, Instructions: 43memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|