Windows
Analysis Report
50f86ebddd156619b173883981364d8955365d76d2c3a.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 50f86ebddd156619b173883981364d8955365d76d2c3a.exe (PID: 6364 cmdline:
"C:\Users\ user\Deskt op\50f86eb ddd156619b 1738839813 64d8955365 d76d2c3a.e xe" MD5: EA2E25EFD40CEBD5E9535B91D8E3F61F) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- vbirvce (PID: 736 cmdline:
C:\Users\u ser\AppDat a\Roaming\ vbirvce MD5: EA2E25EFD40CEBD5E9535B91D8E3F61F)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://nwgrus.ru/tmp/index.php", "http://tech-servers.in.net/tmp/index.php", "http://unicea.ws/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-19T06:42:26.094387+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:32.196942+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49926 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:33.757079+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49933 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:34.927963+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49938 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:36.072375+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49945 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:37.345716+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49951 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:38.468886+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49957 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:40.184673+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49968 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:41.372727+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49978 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:42.747992+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49985 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:44.436982+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49996 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:45.772403+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50005 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:46.960849+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50012 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:48.349030+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50015 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:49.520871+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50016 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:50.849583+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50017 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:52.112051+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50018 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:53.952245+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50019 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:55.523729+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50020 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:57.079166+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50021 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:58.583452+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50022 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:59.965280+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50023 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:01.281772+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50024 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:07.514716+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50025 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:12.945954+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50026 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:18.935052+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50027 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:25.042915+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50028 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:30.639250+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50029 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:36.825190+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50030 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:43.048365+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50031 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:48.684367+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50032 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:54.566603+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50033 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:45:00.323082+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50034 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:06.946810+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50035 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:13.109708+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50036 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:19.786287+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50037 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:26.127378+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50038 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:32.897718+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50039 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:39.218290+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50040 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:45.340212+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50041 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:52.202083+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 61684 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:58.797573+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 61685 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:46:06.755173+0200 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 61686 | 116.58.10.60 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401514 | |
Source: | Code function: | 0_2_00402F97 | |
Source: | Code function: | 0_2_00401542 | |
Source: | Code function: | 0_2_00403247 | |
Source: | Code function: | 0_2_00401549 | |
Source: | Code function: | 0_2_0040324F | |
Source: | Code function: | 0_2_00403256 | |
Source: | Code function: | 0_2_00401557 | |
Source: | Code function: | 0_2_0040326C | |
Source: | Code function: | 0_2_00403277 | |
Source: | Code function: | 0_2_004014FE | |
Source: | Code function: | 0_2_00403290 | |
Source: | Code function: | 5_2_00401514 | |
Source: | Code function: | 5_2_00402F97 | |
Source: | Code function: | 5_2_00401542 | |
Source: | Code function: | 5_2_00403247 | |
Source: | Code function: | 5_2_00401549 | |
Source: | Code function: | 5_2_0040324F | |
Source: | Code function: | 5_2_00403256 | |
Source: | Code function: | 5_2_00401557 | |
Source: | Code function: | 5_2_0040326C | |
Source: | Code function: | 5_2_00403277 | |
Source: | Code function: | 5_2_004032C7 | |
Source: | Code function: | 5_2_004014FE | |
Source: | Code function: | 5_2_00403290 |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_00514696 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004014E9 | |
Source: | Code function: | 0_2_004032AB | |
Source: | Code function: | 0_2_005180F1 | |
Source: | Code function: | 0_2_005164C9 | |
Source: | Code function: | 0_2_00516F90 | |
Source: | Code function: | 0_2_00621550 | |
Source: | Code function: | 5_2_004014E9 | |
Source: | Code function: | 5_2_004032AB | |
Source: | Code function: | 5_2_006C1550 | |
Source: | Code function: | 5_2_00716F19 | |
Source: | Code function: | 5_2_00715DB8 | |
Source: | Code function: | 5_2_007152F1 |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_00513F73 | |
Source: | Code function: | 0_2_0062092B | |
Source: | Code function: | 0_2_00620D90 | |
Source: | Code function: | 5_2_006C092B | |
Source: | Code function: | 5_2_006C0D90 | |
Source: | Code function: | 5_2_00712D9B |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 511 Security Software Discovery | Remote Services | Data from Local System | 2 Non-Application Layer Protocol | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 12 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 112 Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 3 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 12 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
74% | ReversingLabs | Win32.Trojan.Smokeloader | ||
60% | Virustotal | Browse | ||
100% | Avira | HEUR/AGEN.1310247 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1310247 | ||
100% | Joe Sandbox ML | |||
74% | ReversingLabs | Win32.Trojan.Smokeloader |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | Virustotal | Browse | ||
12% | Virustotal | Browse | ||
4% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
unicea.ws | 123.213.233.131 | true | true |
| unknown |
tech-servers.in.net | unknown | unknown | true |
| unknown |
nwgrus.ru | unknown | unknown | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
116.58.10.60 | unknown | Pakistan | 17563 | NEXLINX-AS-APAutonomousSystemNumberforNexlinxPK | true | |
123.213.233.131 | unicea.ws | Korea Republic of | 9318 | SKB-ASSKBroadbandCoLtdKR | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1537536 |
Start date and time: | 2024-10-19 06:41:04 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 50f86ebddd156619b173883981364d8955365d76d2c3a.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@2/2@61/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
00:42:23 | API Interceptor | |
05:42:22 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
116.58.10.60 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
123.213.233.131 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Babuk, Clipboard Hijacker, Djvu, Glupteba, LummaC Stealer, Mars Stealer | Browse |
| ||
Get hash | malicious | Glupteba, Petite Virus, Raccoon Stealer v2, RedLine, SmokeLoader, Socks5Systemz | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Glupteba, Petite Virus, RedLine, SmokeLoader, Socks5Systemz | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
unicea.ws | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NEXLINX-AS-APAutonomousSystemNumberforNexlinxPK | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Go Injector, SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | LummaC, SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, CryptOne, LummaC Stealer, SmokeLoader, Vidar | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
SKB-ASSKBroadbandCoLtdKR | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 454144 |
Entropy (8bit): | 6.357429709130068 |
Encrypted: | false |
SSDEEP: | 6144:HodLe5U3K0CfIvA2fLLRRjThRIDVNrEu+MykNso/0S2y6BbO42T8:6i5UafTsLbjTh2DzL+r2eNO4O |
MD5: | EA2E25EFD40CEBD5E9535B91D8E3F61F |
SHA1: | 85AFD5690C90716EB35FE57E78C1204EE7C6EB22 |
SHA-256: | 50F86EBDDD156619B173883981364D8955365D76D2C3AE9391EC911E65551BE9 |
SHA-512: | CF4BF97674BA99A43A81BD594AF91AE11B0FB32A1BF4224EFF39EEE56E7CA6C125CA88E073A0342E0AD8F844386ADB6C8406BA66050B8110E1B25194542F6997 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 6.357429709130068 |
TrID: |
|
File name: | 50f86ebddd156619b173883981364d8955365d76d2c3a.exe |
File size: | 454'144 bytes |
MD5: | ea2e25efd40cebd5e9535b91d8e3f61f |
SHA1: | 85afd5690c90716eb35fe57e78c1204ee7c6eb22 |
SHA256: | 50f86ebddd156619b173883981364d8955365d76d2c3ae9391ec911e65551be9 |
SHA512: | cf4bf97674ba99a43a81bd594af91ae11b0fb32a1bf4224eff39eee56e7ca6c125ca88e073a0342e0ad8f844386adb6c8406ba66050b8110e1b25194542f6997 |
SSDEEP: | 6144:HodLe5U3K0CfIvA2fLLRRjThRIDVNrEu+MykNso/0S2y6BbO42T8:6i5UafTsLbjTh2DzL+r2eNO4O |
TLSH: | 06A4C00262B5AEE0F7D64A338D1DE6E8A66DF851EE186777321E3B1F1B70571C222311 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........io..............~.......~.......~.......p..........3....~.......~.......~......Rich............PE..L...n..d................... |
Icon Hash: | 41294945514d610d |
Entrypoint: | 0x403bf9 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64B2FF6E [Sat Jul 15 20:19:58 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | cf2df69e8bb6acbf3b231da2c6f4bda2 |
Instruction |
---|
call 00007F436CF65CF9h |
jmp 00007F436CF62C4Eh |
push dword ptr [00451258h] |
call dword ptr [0040F12Ch] |
test eax, eax |
je 00007F436CF62DC4h |
call eax |
push 00000019h |
call 00007F436CF655DBh |
push 00000001h |
push 00000000h |
call 00007F436CF62580h |
add esp, 0Ch |
jmp 00007F436CF62545h |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 20h |
mov eax, dword ptr [ebp+08h] |
push esi |
push edi |
push 00000008h |
pop ecx |
mov esi, 0040F3C0h |
lea edi, dword ptr [ebp-20h] |
rep movsd |
mov dword ptr [ebp-08h], eax |
mov eax, dword ptr [ebp+0Ch] |
pop edi |
mov dword ptr [ebp-04h], eax |
pop esi |
test eax, eax |
je 00007F436CF62DCEh |
test byte ptr [eax], 00000008h |
je 00007F436CF62DC9h |
mov dword ptr [ebp-0Ch], 01994000h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
push dword ptr [ebp-10h] |
push dword ptr [ebp-1Ch] |
push dword ptr [ebp-20h] |
call dword ptr [0040F160h] |
leave |
retn 0008h |
mov edi, edi |
push ebp |
mov ebp, esp |
push ecx |
push ebx |
mov eax, dword ptr [ebp+0Ch] |
add eax, 0Ch |
mov dword ptr [ebp-04h], eax |
mov ebx, dword ptr fs:[00000000h] |
mov eax, dword ptr [ebx] |
mov dword ptr fs:[00000000h], eax |
mov eax, dword ptr [ebp+08h] |
mov ebx, dword ptr [ebp+0Ch] |
mov ebp, dword ptr [ebp-04h] |
mov esp, dword ptr [ebx-04h] |
jmp eax |
pop ebx |
leave |
retn 0008h |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
pop eax |
pop ecx |
xchg dword ptr [esp], eax |
jmp eax |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x49b40 | 0x78 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x60000 | 0x1f108 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x49bb8 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x490c8 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xf000 | 0x1fc | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xd4dd | 0xd600 | 2039712dbf7a50bd45433c889e87fcc3 | False | 0.6018910630841121 | data | 6.671203412552697 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0xf000 | 0x3b6d2 | 0x3b800 | 2c06279e133be36d01ccfae1bcdf0cfb | False | 0.7520803243172269 | data | 6.870956222424823 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x4b000 | 0x11cc0 | 0x6000 | 648a35f029250a8b7b7d327c0ee5cba4 | False | 0.0838623046875 | data | 1.0912838539385947 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.guj | 0x5d000 | 0x400 | 0x400 | 0f343b0931126a20f133d67c2b018a3b | False | 0.0166015625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.ber | 0x5e000 | 0xd6 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.medajim | 0x5f000 | 0x400 | 0x400 | 0f343b0931126a20f133d67c2b018a3b | False | 0.0166015625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x60000 | 0x1f108 | 0x1f200 | af0679af61ade9ddd6c88c0067976997 | False | 0.4242124748995984 | data | 5.055365166130212 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x79b78 | 0x330 | Device independent bitmap graphic, 48 x 96 x 1, image size 0 | 0.1948529411764706 | ||
RT_CURSOR | 0x79ea8 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.33223684210526316 | ||
RT_CURSOR | 0x7a000 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.2953091684434968 | ||
RT_CURSOR | 0x7aea8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.46705776173285196 | ||
RT_CURSOR | 0x7b750 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5361271676300579 | ||
RT_CURSOR | 0x7bce8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | 0.30943496801705755 | ||
RT_CURSOR | 0x7cb90 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.427797833935018 | ||
RT_CURSOR | 0x7d438 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | 0.5469653179190751 | ||
RT_ICON | 0x60ac0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.3694029850746269 |
RT_ICON | 0x60ac0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.3694029850746269 |
RT_ICON | 0x61968 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.4553249097472924 |
RT_ICON | 0x61968 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.4553249097472924 |
RT_ICON | 0x62210 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.4619815668202765 |
RT_ICON | 0x62210 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.4619815668202765 |
RT_ICON | 0x628d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.4552023121387283 |
RT_ICON | 0x628d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.4552023121387283 |
RT_ICON | 0x62e40 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.2682572614107884 |
RT_ICON | 0x62e40 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.2682572614107884 |
RT_ICON | 0x653e8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.3074577861163227 |
RT_ICON | 0x653e8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.3074577861163227 |
RT_ICON | 0x66490 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.3599290780141844 |
RT_ICON | 0x66490 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.3599290780141844 |
RT_ICON | 0x66960 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.5660980810234542 |
RT_ICON | 0x66960 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.5660980810234542 |
RT_ICON | 0x67808 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.5464801444043321 |
RT_ICON | 0x67808 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.5464801444043321 |
RT_ICON | 0x680b0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.6177745664739884 |
RT_ICON | 0x680b0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.6177745664739884 |
RT_ICON | 0x68618 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.46182572614107886 |
RT_ICON | 0x68618 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.46182572614107886 |
RT_ICON | 0x6abc0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.4892120075046904 |
RT_ICON | 0x6abc0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.4892120075046904 |
RT_ICON | 0x6bc68 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.494672131147541 |
RT_ICON | 0x6bc68 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.494672131147541 |
RT_ICON | 0x6c5f0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.4512411347517731 |
RT_ICON | 0x6c5f0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.4512411347517731 |
RT_ICON | 0x6cac0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.3784648187633262 |
RT_ICON | 0x6cac0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.3784648187633262 |
RT_ICON | 0x6d968 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.5058664259927798 |
RT_ICON | 0x6d968 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.5058664259927798 |
RT_ICON | 0x6e210 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.5599078341013825 |
RT_ICON | 0x6e210 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.5599078341013825 |
RT_ICON | 0x6e8d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.583092485549133 |
RT_ICON | 0x6e8d8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.583092485549133 |
RT_ICON | 0x6ee40 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.37053941908713695 |
RT_ICON | 0x6ee40 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.37053941908713695 |
RT_ICON | 0x713e8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.41228893058161353 |
RT_ICON | 0x713e8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.41228893058161353 |
RT_ICON | 0x72490 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.40081967213114755 |
RT_ICON | 0x72490 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.40081967213114755 |
RT_ICON | 0x72e18 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.46897163120567376 |
RT_ICON | 0x72e18 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.46897163120567376 |
RT_ICON | 0x732f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | India | 0.3742004264392324 |
RT_ICON | 0x732f8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | Sri Lanka | 0.3742004264392324 |
RT_ICON | 0x741a0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | India | 0.5171480144404332 |
RT_ICON | 0x741a0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | Sri Lanka | 0.5171480144404332 |
RT_ICON | 0x74a48 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | India | 0.6059907834101382 |
RT_ICON | 0x74a48 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | Sri Lanka | 0.6059907834101382 |
RT_ICON | 0x75110 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | India | 0.6596820809248555 |
RT_ICON | 0x75110 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | Sri Lanka | 0.6596820809248555 |
RT_ICON | 0x75678 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | India | 0.487551867219917 |
RT_ICON | 0x75678 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | Sri Lanka | 0.487551867219917 |
RT_ICON | 0x77c20 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | India | 0.5060975609756098 |
RT_ICON | 0x77c20 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | Sri Lanka | 0.5060975609756098 |
RT_ICON | 0x78cc8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | India | 0.4860655737704918 |
RT_ICON | 0x78cc8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | Sri Lanka | 0.4860655737704918 |
RT_ICON | 0x79650 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | India | 0.5390070921985816 |
RT_ICON | 0x79650 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | Sri Lanka | 0.5390070921985816 |
RT_DIALOG | 0x7dc30 | 0x58 | data | 0.8977272727272727 | ||
RT_STRING | 0x7dc88 | 0x2c6 | data | Tamil | India | 0.4830985915492958 |
RT_STRING | 0x7dc88 | 0x2c6 | data | Tamil | Sri Lanka | 0.4830985915492958 |
RT_STRING | 0x7df50 | 0x6b4 | data | Tamil | India | 0.42657342657342656 |
RT_STRING | 0x7df50 | 0x6b4 | data | Tamil | Sri Lanka | 0.42657342657342656 |
RT_STRING | 0x7e608 | 0x242 | data | Tamil | India | 0.4982698961937716 |
RT_STRING | 0x7e608 | 0x242 | data | Tamil | Sri Lanka | 0.4982698961937716 |
RT_STRING | 0x7e850 | 0x620 | data | Tamil | India | 0.4343112244897959 |
RT_STRING | 0x7e850 | 0x620 | data | Tamil | Sri Lanka | 0.4343112244897959 |
RT_STRING | 0x7ee70 | 0x292 | data | Tamil | India | 0.4817629179331307 |
RT_STRING | 0x7ee70 | 0x292 | data | Tamil | Sri Lanka | 0.4817629179331307 |
RT_ACCELERATOR | 0x79b30 | 0x48 | data | Tamil | India | 0.8472222222222222 |
RT_ACCELERATOR | 0x79b30 | 0x48 | data | Tamil | Sri Lanka | 0.8472222222222222 |
RT_GROUP_CURSOR | 0x79fd8 | 0x22 | data | 1.0294117647058822 | ||
RT_GROUP_CURSOR | 0x7bcb8 | 0x30 | data | 0.9375 | ||
RT_GROUP_CURSOR | 0x7d9a0 | 0x30 | data | 0.9375 | ||
RT_GROUP_ICON | 0x6ca58 | 0x68 | data | Tamil | India | 0.7019230769230769 |
RT_GROUP_ICON | 0x6ca58 | 0x68 | data | Tamil | Sri Lanka | 0.7019230769230769 |
RT_GROUP_ICON | 0x668f8 | 0x68 | data | Tamil | India | 0.6826923076923077 |
RT_GROUP_ICON | 0x668f8 | 0x68 | data | Tamil | Sri Lanka | 0.6826923076923077 |
RT_GROUP_ICON | 0x73280 | 0x76 | data | Tamil | India | 0.6779661016949152 |
RT_GROUP_ICON | 0x73280 | 0x76 | data | Tamil | Sri Lanka | 0.6779661016949152 |
RT_GROUP_ICON | 0x79ab8 | 0x76 | data | Tamil | India | 0.6779661016949152 |
RT_GROUP_ICON | 0x79ab8 | 0x76 | data | Tamil | Sri Lanka | 0.6779661016949152 |
RT_VERSION | 0x7d9d0 | 0x25c | data | 0.5413907284768212 |
DLL | Import |
---|---|
KERNEL32.dll | InterlockedDecrement, SetEnvironmentVariableW, QueryDosDeviceA, SetVolumeMountPointW, GetComputerNameW, GetTimeFormatA, GetTickCount, CreateNamedPipeW, LocalFlags, GetNumberFormatA, SetFileTime, ClearCommBreak, TlsSetValue, GetEnvironmentStrings, SetFileShortNameW, LoadLibraryW, CopyFileW, _hread, GetCalendarInfoA, SetVolumeMountPointA, GetVersionExW, GetFileAttributesA, CreateProcessA, GetModuleFileNameW, CreateActCtxA, GetEnvironmentVariableA, GetShortPathNameA, CreateJobObjectA, EnumCalendarInfoW, InterlockedExchange, GetStdHandle, GetLogicalDriveStringsA, GetLastError, GetCurrentDirectoryW, GetProcAddress, EnumSystemCodePagesW, SetComputerNameA, SetFileAttributesA, GlobalFree, LoadLibraryA, LocalAlloc, CreateHardLinkW, GetNumberFormatW, CreateEventW, OpenEventA, FoldStringW, GlobalWire, EnumDateFormatsW, GetShortPathNameW, GetDiskFreeSpaceExA, ReadConsoleInputW, GetCurrentProcessId, DebugBreak, GetTempPathA, LCMapStringW, EnumCalendarInfoA, InterlockedIncrement, CommConfigDialogA, GetConsoleAliasExesA, GetLocaleInfoA, SetFilePointer, VerifyVersionInfoW, WriteConsoleW, CloseHandle, FlushFileBuffers, GetConsoleMode, GetConsoleCP, EncodePointer, DecodePointer, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapFree, HeapReAlloc, GetModuleHandleW, ExitProcess, GetCommandLineW, HeapSetInformation, GetStartupInfoW, RaiseException, RtlUnwind, HeapAlloc, WideCharToMultiByte, MultiByteToWideChar, GetCPInfo, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetCurrentProcess, HeapCreate, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, TlsAlloc, TlsGetValue, TlsFree, SetLastError, GetCurrentThreadId, WriteFile, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetSystemTimeAsFileTime, HeapSize, GetACP, GetOEMCP, IsValidCodePage, GetStringTypeW, SetStdHandle, CreateFileW |
GDI32.dll | GetCharWidthI, CreateDCA, CreateDCW, GetCharWidth32A |
ADVAPI32.dll | ReadEventLogW |
ole32.dll | CoSuspendClassObjects |
WINHTTP.dll | WinHttpOpen, WinHttpCheckPlatform |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Tamil | India | |
Tamil | Sri Lanka |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-19T06:42:26.094387+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:32.196942+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49926 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:33.757079+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49933 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:34.927963+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49938 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:36.072375+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49945 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:37.345716+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49951 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:38.468886+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49957 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:40.184673+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49968 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:41.372727+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49978 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:42.747992+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49985 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:44.436982+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49996 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:45.772403+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50005 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:46.960849+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50012 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:48.349030+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50015 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:49.520871+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50016 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:50.849583+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50017 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:52.112051+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50018 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:53.952245+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50019 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:55.523729+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50020 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:57.079166+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50021 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:58.583452+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50022 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:43:59.965280+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50023 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:01.281772+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50024 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:07.514716+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50025 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:12.945954+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50026 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:18.935052+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50027 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:25.042915+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50028 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:30.639250+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50029 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:36.825190+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50030 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:43.048365+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50031 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:48.684367+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50032 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:44:54.566603+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50033 | 123.213.233.131 | 80 | TCP |
2024-10-19T06:45:00.323082+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50034 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:06.946810+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50035 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:13.109708+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50036 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:19.786287+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50037 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:26.127378+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50038 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:32.897718+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50039 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:39.218290+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50040 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:45.340212+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50041 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:52.202083+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 61684 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:45:58.797573+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 61685 | 116.58.10.60 | 80 | TCP |
2024-10-19T06:46:06.755173+0200 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 61686 | 116.58.10.60 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 19, 2024 06:42:25.008912086 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:25.013834000 CEST | 80 | 49736 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:42:25.013911963 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:25.014040947 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:25.014059067 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:25.018882990 CEST | 80 | 49736 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:42:25.018901110 CEST | 80 | 49736 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:42:26.094181061 CEST | 80 | 49736 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:42:26.094387054 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:26.095338106 CEST | 49736 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:42:26.100080013 CEST | 80 | 49736 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:31.087239027 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:31.092197895 CEST | 80 | 49926 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:31.092291117 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:31.092417955 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:31.092418909 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:31.097275972 CEST | 80 | 49926 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:31.097398996 CEST | 80 | 49926 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:32.193490982 CEST | 80 | 49926 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:32.196942091 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.197016001 CEST | 49926 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.201909065 CEST | 80 | 49926 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:32.642045021 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.647022009 CEST | 80 | 49933 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:32.647098064 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.647191048 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.647219896 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:32.652002096 CEST | 80 | 49933 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:32.652129889 CEST | 80 | 49933 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:33.752876043 CEST | 80 | 49933 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:33.757078886 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.759913921 CEST | 49933 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.764802933 CEST | 80 | 49933 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:33.785403967 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.790388107 CEST | 80 | 49938 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:33.790539026 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.790662050 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.790689945 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:33.795604944 CEST | 80 | 49938 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:33.795635939 CEST | 80 | 49938 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:34.927907944 CEST | 80 | 49938 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:34.927963018 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.928177118 CEST | 49938 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.932965040 CEST | 80 | 49938 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:34.978681087 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.983623028 CEST | 80 | 49945 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:34.983702898 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.983871937 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.983918905 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:34.988677979 CEST | 80 | 49945 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:34.988796949 CEST | 80 | 49945 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:36.072316885 CEST | 80 | 49945 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:36.072375059 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.075006008 CEST | 49945 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.079871893 CEST | 80 | 49945 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:36.203337908 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.208291054 CEST | 80 | 49951 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:36.208374977 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.208466053 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.208488941 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:36.213242054 CEST | 80 | 49951 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:36.213414907 CEST | 80 | 49951 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:37.343122005 CEST | 80 | 49951 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:37.345716000 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.345716000 CEST | 49951 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.350588083 CEST | 80 | 49951 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:37.380150080 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.385030985 CEST | 80 | 49957 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:37.387743950 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.387864113 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.387881994 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:37.392716885 CEST | 80 | 49957 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:37.392843962 CEST | 80 | 49957 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:38.468691111 CEST | 80 | 49957 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:38.468885899 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:38.468909979 CEST | 49957 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:38.473787069 CEST | 80 | 49957 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:39.074259043 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:39.079283953 CEST | 80 | 49968 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:39.079978943 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:39.080082893 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:39.080111027 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:39.084891081 CEST | 80 | 49968 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:39.085293055 CEST | 80 | 49968 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:40.184614897 CEST | 80 | 49968 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:40.184673071 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.184731960 CEST | 49968 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.189553022 CEST | 80 | 49968 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:40.266233921 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.271133900 CEST | 80 | 49978 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:40.273139000 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.273551941 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.273581982 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:40.278580904 CEST | 80 | 49978 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:40.278610945 CEST | 80 | 49978 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:41.372631073 CEST | 80 | 49978 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:41.372726917 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.372821093 CEST | 49978 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.377758980 CEST | 80 | 49978 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:41.623692989 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.628592968 CEST | 80 | 49985 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:41.628681898 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.628854036 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.628884077 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:41.633668900 CEST | 80 | 49985 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:41.633833885 CEST | 80 | 49985 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:42.746006012 CEST | 80 | 49985 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:42.747992039 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:42.749577999 CEST | 49985 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:42.754412889 CEST | 80 | 49985 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:43.314146042 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:43.319139957 CEST | 80 | 49996 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:43.321079969 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:43.321141005 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:43.321171045 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:43.326056957 CEST | 80 | 49996 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:43.326107979 CEST | 80 | 49996 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:44.434215069 CEST | 80 | 49996 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:44.436981916 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.440747023 CEST | 49996 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.445622921 CEST | 80 | 49996 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:44.686404943 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.691359043 CEST | 80 | 50005 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:44.691440105 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.691551924 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.691591978 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:44.696341991 CEST | 80 | 50005 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:44.696510077 CEST | 80 | 50005 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:45.772242069 CEST | 80 | 50005 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:45.772403002 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.772403002 CEST | 50005 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.777296066 CEST | 80 | 50005 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:45.850749969 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.855727911 CEST | 80 | 50012 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:45.855833054 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.857701063 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.857701063 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:45.862543106 CEST | 80 | 50012 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:45.862642050 CEST | 80 | 50012 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:46.960751057 CEST | 80 | 50012 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:46.960849047 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:46.960849047 CEST | 50012 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:46.965742111 CEST | 80 | 50012 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:47.250878096 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:47.255811930 CEST | 80 | 50015 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:47.257005930 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:47.257234097 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:47.257234097 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:47.262096882 CEST | 80 | 50015 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:47.262111902 CEST | 80 | 50015 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:48.344830036 CEST | 80 | 50015 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:48.349030018 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.349107981 CEST | 50015 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.353975058 CEST | 80 | 50015 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:48.424591064 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.429557085 CEST | 80 | 50016 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:48.433029890 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.433176041 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.433207989 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:48.438055038 CEST | 80 | 50016 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:48.438122988 CEST | 80 | 50016 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:49.520750999 CEST | 80 | 50016 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:49.520870924 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.520956993 CEST | 50016 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.525943995 CEST | 80 | 50016 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:49.721970081 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.726937056 CEST | 80 | 50017 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:49.727020979 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.727139950 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.727173090 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:49.731945038 CEST | 80 | 50017 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:49.732050896 CEST | 80 | 50017 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:50.849469900 CEST | 80 | 50017 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:50.849582911 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:50.849636078 CEST | 50017 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:50.854505062 CEST | 80 | 50017 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:51.031574011 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:51.037013054 CEST | 80 | 50018 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:51.037092924 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:51.037252903 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:51.037280083 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:51.042521000 CEST | 80 | 50018 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:51.042537928 CEST | 80 | 50018 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:52.110703945 CEST | 80 | 50018 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:52.112051010 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.112152100 CEST | 50018 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.117105007 CEST | 80 | 50018 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:52.816726923 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.821708918 CEST | 80 | 50019 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:52.821815968 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.821947098 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.823015928 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:52.826947927 CEST | 80 | 50019 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:52.827867985 CEST | 80 | 50019 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:53.952177048 CEST | 80 | 50019 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:53.952244997 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:53.952305079 CEST | 50019 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:53.957182884 CEST | 80 | 50019 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:54.412265062 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:54.417241096 CEST | 80 | 50020 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:54.417332888 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:54.417454004 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:54.419017076 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:54.422204018 CEST | 80 | 50020 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:54.423758030 CEST | 80 | 50020 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:55.523525000 CEST | 80 | 50020 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:55.523729086 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.523770094 CEST | 50020 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.528590918 CEST | 80 | 50020 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:55.953875065 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.958820105 CEST | 80 | 50021 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:55.958914995 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.959076881 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.959129095 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:55.964027882 CEST | 80 | 50021 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:55.964036942 CEST | 80 | 50021 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:57.079065084 CEST | 80 | 50021 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:57.079165936 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.079245090 CEST | 50021 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.084207058 CEST | 80 | 50021 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:57.490047932 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.494955063 CEST | 80 | 50022 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:57.495136976 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.495244980 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.495289087 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:57.499986887 CEST | 80 | 50022 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:57.500143051 CEST | 80 | 50022 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:58.583332062 CEST | 80 | 50022 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:58.583451986 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.585477114 CEST | 50022 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.590246916 CEST | 80 | 50022 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:58.866991997 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.871927023 CEST | 80 | 50023 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:58.872003078 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.872142076 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.872153044 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:58.876857042 CEST | 80 | 50023 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:58.877078056 CEST | 80 | 50023 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:59.965219021 CEST | 80 | 50023 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:43:59.965280056 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:59.965312004 CEST | 50023 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:43:59.970129967 CEST | 80 | 50023 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:00.163891077 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:00.168879032 CEST | 80 | 50024 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:00.169087887 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:00.169258118 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:00.169302940 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:00.174067974 CEST | 80 | 50024 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:00.174206972 CEST | 80 | 50024 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:01.281676054 CEST | 80 | 50024 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:01.281771898 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:01.281771898 CEST | 50024 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:01.286753893 CEST | 80 | 50024 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:06.409543991 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:06.414447069 CEST | 80 | 50025 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:06.414510012 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:06.414633989 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:06.414633989 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:06.419445992 CEST | 80 | 50025 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:06.419497967 CEST | 80 | 50025 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:07.514636993 CEST | 80 | 50025 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:07.514715910 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:07.514786959 CEST | 50025 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:07.519659042 CEST | 80 | 50025 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:11.825265884 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:11.830065966 CEST | 80 | 50026 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:11.830152035 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:11.830302000 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:11.830326080 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:11.835066080 CEST | 80 | 50026 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:11.835083961 CEST | 80 | 50026 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:12.945704937 CEST | 80 | 50026 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:12.945954084 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:12.945954084 CEST | 50026 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:12.950871944 CEST | 80 | 50026 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:17.791687965 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:17.796751976 CEST | 80 | 50027 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:17.796837091 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:17.796960115 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:17.796978951 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:17.801753998 CEST | 80 | 50027 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:17.801858902 CEST | 80 | 50027 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:18.934892893 CEST | 80 | 50027 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:18.935051918 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:18.935137033 CEST | 50027 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:18.939996958 CEST | 80 | 50027 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:23.948446035 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:23.953391075 CEST | 80 | 50028 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:23.953454971 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:23.953608990 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:23.953627110 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:23.958453894 CEST | 80 | 50028 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:23.958482981 CEST | 80 | 50028 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:25.042648077 CEST | 80 | 50028 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:25.042915106 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:25.043178082 CEST | 50028 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:25.047956944 CEST | 80 | 50028 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:29.524445057 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:29.529319048 CEST | 80 | 50029 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:29.529397011 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:29.529582977 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:29.529627085 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:29.534497023 CEST | 80 | 50029 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:29.534626961 CEST | 80 | 50029 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:30.639116049 CEST | 80 | 50029 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:30.639250040 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:30.663470030 CEST | 50029 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:30.668329000 CEST | 80 | 50029 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:35.725434065 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:35.730365038 CEST | 80 | 50030 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:35.730431080 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:35.730554104 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:35.730586052 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:35.735404968 CEST | 80 | 50030 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:35.735547066 CEST | 80 | 50030 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:36.825098038 CEST | 80 | 50030 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:36.825190067 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:36.825268984 CEST | 50030 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:36.830105066 CEST | 80 | 50030 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:41.920255899 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:41.925215006 CEST | 80 | 50031 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:41.925297976 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:41.925421953 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:41.925450087 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:41.930213928 CEST | 80 | 50031 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:41.930355072 CEST | 80 | 50031 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:43.048300028 CEST | 80 | 50031 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:43.048365116 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:43.048397064 CEST | 50031 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:43.053646088 CEST | 80 | 50031 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:47.590974092 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:47.595793009 CEST | 80 | 50032 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:47.595860958 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:47.595964909 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:47.596019030 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:47.600755930 CEST | 80 | 50032 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:47.600913048 CEST | 80 | 50032 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:48.684273005 CEST | 80 | 50032 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:48.684366941 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:48.684442997 CEST | 50032 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:48.689416885 CEST | 80 | 50032 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:53.429882050 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:53.434947014 CEST | 80 | 50033 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:53.435044050 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:53.435223103 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:53.435261965 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:53.440068007 CEST | 80 | 50033 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:53.440223932 CEST | 80 | 50033 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:54.566488028 CEST | 80 | 50033 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:54.566602945 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:54.566672087 CEST | 50033 | 80 | 192.168.2.4 | 123.213.233.131 |
Oct 19, 2024 06:44:54.571535110 CEST | 80 | 50033 | 123.213.233.131 | 192.168.2.4 |
Oct 19, 2024 06:44:58.968638897 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:44:58.973572016 CEST | 80 | 50034 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:44:58.973670959 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:44:58.973855972 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:44:58.973910093 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:44:58.978718996 CEST | 80 | 50034 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:44:58.978852034 CEST | 80 | 50034 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:00.322999001 CEST | 80 | 50034 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:00.323081970 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:00.323163986 CEST | 50034 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:00.328069925 CEST | 80 | 50034 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:05.619326115 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:05.624557018 CEST | 80 | 50035 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:05.624726057 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:05.624799967 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:05.624835014 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:05.629607916 CEST | 80 | 50035 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:05.629853010 CEST | 80 | 50035 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:06.946711063 CEST | 80 | 50035 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:06.946810007 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:06.946845055 CEST | 50035 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:06.951733112 CEST | 80 | 50035 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:11.774388075 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:11.779227972 CEST | 80 | 50036 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:11.779335022 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:11.779484987 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:11.779517889 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:11.784290075 CEST | 80 | 50036 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:11.784306049 CEST | 80 | 50036 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:13.109616041 CEST | 80 | 50036 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:13.109708071 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:13.109790087 CEST | 50036 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:13.114765882 CEST | 80 | 50036 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:18.422658920 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:18.431857109 CEST | 80 | 50037 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:18.431950092 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:18.432126045 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:18.432161093 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:18.441935062 CEST | 80 | 50037 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:18.446175098 CEST | 80 | 50037 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:19.786210060 CEST | 80 | 50037 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:19.786287069 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:19.786952972 CEST | 50037 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:19.795475006 CEST | 80 | 50037 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:24.736581087 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:24.746570110 CEST | 80 | 50038 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:24.746635914 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:24.746797085 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:24.746833086 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:24.756546974 CEST | 80 | 50038 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:24.760447025 CEST | 80 | 50038 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:26.127265930 CEST | 80 | 50038 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:26.127377987 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:26.127485037 CEST | 50038 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:26.133923054 CEST | 80 | 50038 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:31.540827036 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:31.551846027 CEST | 80 | 50039 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:31.551944017 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:31.552082062 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:31.552139997 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:31.562463045 CEST | 80 | 50039 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:31.562493086 CEST | 80 | 50039 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:32.897641897 CEST | 80 | 50039 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:32.897717953 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:32.897763968 CEST | 50039 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:32.905973911 CEST | 80 | 50039 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:37.859927893 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:37.867314100 CEST | 80 | 50040 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:37.867393970 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:37.867525101 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:37.867558002 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:37.875444889 CEST | 80 | 50040 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:37.875475883 CEST | 80 | 50040 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:39.218147039 CEST | 80 | 50040 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:39.218290091 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:39.218333960 CEST | 50040 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:39.228147984 CEST | 80 | 50040 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:43.991055965 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:43.996644974 CEST | 80 | 50041 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:43.996730089 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:43.996870041 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:43.996893883 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:44.002635956 CEST | 80 | 50041 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:44.003681898 CEST | 80 | 50041 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:45.340089083 CEST | 80 | 50041 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:45.340212107 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:45.341804981 CEST | 50041 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:45.353017092 CEST | 80 | 50041 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:50.862325907 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:50.869719028 CEST | 80 | 61684 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:50.869800091 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:50.869941950 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:50.869941950 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:50.877536058 CEST | 80 | 61684 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:50.879879951 CEST | 80 | 61684 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:52.201960087 CEST | 80 | 61684 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:52.202083111 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:52.202169895 CEST | 61684 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:52.210602045 CEST | 80 | 61684 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:57.431236982 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:57.441242933 CEST | 80 | 61685 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:57.441338062 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:57.441528082 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:57.441571951 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:57.451409101 CEST | 80 | 61685 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:57.456542015 CEST | 80 | 61685 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:58.797473907 CEST | 80 | 61685 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:45:58.797573090 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:58.797662973 CEST | 61685 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:45:58.803745985 CEST | 80 | 61685 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:46:05.405811071 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:05.412285089 CEST | 80 | 61686 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:46:05.412379026 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:05.412533998 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:05.412570000 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:05.420882940 CEST | 80 | 61686 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:46:05.424128056 CEST | 80 | 61686 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:46:06.755083084 CEST | 80 | 61686 | 116.58.10.60 | 192.168.2.4 |
Oct 19, 2024 06:46:06.755172968 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:06.755274057 CEST | 61686 | 80 | 192.168.2.4 | 116.58.10.60 |
Oct 19, 2024 06:46:06.760132074 CEST | 80 | 61686 | 116.58.10.60 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 19, 2024 06:42:22.519059896 CEST | 49190 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:42:22.786690950 CEST | 53 | 49190 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:42:22.789664030 CEST | 51985 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:42:22.798180103 CEST | 53 | 51985 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:42:22.800153017 CEST | 62230 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:42:23.805304050 CEST | 62230 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:42:24.803971052 CEST | 62230 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:42:25.007183075 CEST | 53 | 62230 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:42:25.007201910 CEST | 53 | 62230 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:42:25.007211924 CEST | 53 | 62230 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:30.912147045 CEST | 49311 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:31.060017109 CEST | 53 | 49311 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:31.062853098 CEST | 60996 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:31.071732044 CEST | 53 | 60996 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:36.125165939 CEST | 59978 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:36.173964024 CEST | 53 | 59978 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:36.176858902 CEST | 61559 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:36.195174932 CEST | 53 | 61559 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:41.562773943 CEST | 49342 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:41.609564066 CEST | 53 | 49342 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:41.612140894 CEST | 58048 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:41.620878935 CEST | 53 | 58048 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:47.169883966 CEST | 55779 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:47.218054056 CEST | 53 | 55779 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:47.236016989 CEST | 51451 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:47.245474100 CEST | 53 | 51451 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:52.408652067 CEST | 64073 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:52.678066969 CEST | 53 | 64073 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:52.685308933 CEST | 51110 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:52.813299894 CEST | 53 | 51110 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:57.318674088 CEST | 64212 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:57.465337038 CEST | 53 | 64212 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:43:57.471810102 CEST | 65096 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:43:57.480257034 CEST | 53 | 65096 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:06.329474926 CEST | 50729 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:06.378844023 CEST | 53 | 50729 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:06.387263060 CEST | 52581 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:06.399254084 CEST | 53 | 52581 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:11.747459888 CEST | 52438 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:11.795420885 CEST | 53 | 52438 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:11.804964066 CEST | 52479 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:11.812458992 CEST | 53 | 52479 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:17.713236094 CEST | 61402 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:17.761531115 CEST | 53 | 61402 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:17.770863056 CEST | 56095 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:17.780821085 CEST | 53 | 56095 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:23.772494078 CEST | 63320 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:23.920578003 CEST | 53 | 63320 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:23.927993059 CEST | 63004 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:23.941919088 CEST | 53 | 63004 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:29.448184013 CEST | 64396 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:29.496779919 CEST | 53 | 64396 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:29.502087116 CEST | 55163 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:29.511501074 CEST | 53 | 55163 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:35.522624969 CEST | 53637 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:35.670763969 CEST | 53 | 53637 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:35.679120064 CEST | 62891 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:35.692931890 CEST | 53 | 62891 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:41.658227921 CEST | 57923 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:41.894262075 CEST | 53 | 57923 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:41.903820992 CEST | 63870 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:41.916258097 CEST | 53 | 63870 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:47.520014048 CEST | 64959 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:47.568840027 CEST | 53 | 64959 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:47.579088926 CEST | 57125 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:47.588046074 CEST | 53 | 57125 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:53.154050112 CEST | 55077 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:53.407582998 CEST | 53 | 55077 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:53.415479898 CEST | 55342 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:53.424381018 CEST | 53 | 55342 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:58.602396011 CEST | 59444 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:58.652081966 CEST | 53 | 59444 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:58.660918951 CEST | 61099 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:58.670176983 CEST | 53 | 61099 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:44:58.675455093 CEST | 50176 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:44:58.967871904 CEST | 53 | 50176 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:05.364461899 CEST | 58841 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:05.594314098 CEST | 53 | 58841 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:05.602200031 CEST | 63412 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:05.609821081 CEST | 53 | 63412 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:11.606097937 CEST | 63029 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:11.752604008 CEST | 53 | 63029 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:11.758584976 CEST | 51324 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:11.765506029 CEST | 53 | 51324 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:18.213108063 CEST | 59897 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:18.366010904 CEST | 53 | 59897 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:18.385843992 CEST | 63030 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:18.409480095 CEST | 53 | 63030 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:24.590960979 CEST | 58504 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:24.701432943 CEST | 53 | 58504 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:24.712013006 CEST | 63350 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:24.723958015 CEST | 53 | 63350 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:30.832644939 CEST | 54143 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:31.514403105 CEST | 53 | 54143 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:31.520375967 CEST | 57033 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:31.534745932 CEST | 53 | 57033 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:37.829662085 CEST | 55607 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:37.840265036 CEST | 53 | 55607 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:37.843049049 CEST | 62821 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:37.855453968 CEST | 53 | 62821 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:43.706187963 CEST | 49857 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:43.883142948 CEST | 49857 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:43.967185974 CEST | 53 | 49857 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:43.967202902 CEST | 53 | 49857 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:43.975368977 CEST | 64927 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:43.985213995 CEST | 53 | 64927 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:49.836412907 CEST | 65473 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:50.024265051 CEST | 65473 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:50.036670923 CEST | 53 | 65473 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:50.083595991 CEST | 53 | 65473 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:50.840441942 CEST | 61393 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:50.850619078 CEST | 53 | 61393 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:57.132236004 CEST | 59953 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:57.305071115 CEST | 59953 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:57.396687984 CEST | 53 | 59953 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:57.396701097 CEST | 53 | 59953 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:45:57.401525974 CEST | 49860 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:45:57.421417952 CEST | 53 | 49860 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:46:05.335688114 CEST | 59598 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:46:05.385740995 CEST | 53 | 59598 | 1.1.1.1 | 192.168.2.4 |
Oct 19, 2024 06:46:05.390922070 CEST | 61069 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 19, 2024 06:46:05.401643991 CEST | 53 | 61069 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 19, 2024 06:42:22.519059896 CEST | 192.168.2.4 | 1.1.1.1 | 0xa325 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:22.789664030 CEST | 192.168.2.4 | 1.1.1.1 | 0xa58f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:22.800153017 CEST | 192.168.2.4 | 1.1.1.1 | 0xec8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:23.805304050 CEST | 192.168.2.4 | 1.1.1.1 | 0xec8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:24.803971052 CEST | 192.168.2.4 | 1.1.1.1 | 0xec8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:30.912147045 CEST | 192.168.2.4 | 1.1.1.1 | 0xb757 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:31.062853098 CEST | 192.168.2.4 | 1.1.1.1 | 0x1739 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:36.125165939 CEST | 192.168.2.4 | 1.1.1.1 | 0x5d4d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:36.176858902 CEST | 192.168.2.4 | 1.1.1.1 | 0xc493 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:41.562773943 CEST | 192.168.2.4 | 1.1.1.1 | 0x55ca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:41.612140894 CEST | 192.168.2.4 | 1.1.1.1 | 0xcd0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:47.169883966 CEST | 192.168.2.4 | 1.1.1.1 | 0x3f60 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:47.236016989 CEST | 192.168.2.4 | 1.1.1.1 | 0x8ebc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:52.408652067 CEST | 192.168.2.4 | 1.1.1.1 | 0xfabf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:52.685308933 CEST | 192.168.2.4 | 1.1.1.1 | 0x8d77 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:57.318674088 CEST | 192.168.2.4 | 1.1.1.1 | 0x15cc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:57.471810102 CEST | 192.168.2.4 | 1.1.1.1 | 0x299 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:06.329474926 CEST | 192.168.2.4 | 1.1.1.1 | 0xbf51 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:06.387263060 CEST | 192.168.2.4 | 1.1.1.1 | 0x56af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:11.747459888 CEST | 192.168.2.4 | 1.1.1.1 | 0x4202 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:11.804964066 CEST | 192.168.2.4 | 1.1.1.1 | 0x6ebd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:17.713236094 CEST | 192.168.2.4 | 1.1.1.1 | 0xe53 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:17.770863056 CEST | 192.168.2.4 | 1.1.1.1 | 0x1a0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:23.772494078 CEST | 192.168.2.4 | 1.1.1.1 | 0xd03f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:23.927993059 CEST | 192.168.2.4 | 1.1.1.1 | 0xa5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:29.448184013 CEST | 192.168.2.4 | 1.1.1.1 | 0x28f4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:29.502087116 CEST | 192.168.2.4 | 1.1.1.1 | 0x2c92 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:35.522624969 CEST | 192.168.2.4 | 1.1.1.1 | 0x5a75 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:35.679120064 CEST | 192.168.2.4 | 1.1.1.1 | 0x43fe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:41.658227921 CEST | 192.168.2.4 | 1.1.1.1 | 0x4604 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:41.903820992 CEST | 192.168.2.4 | 1.1.1.1 | 0x84e3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:47.520014048 CEST | 192.168.2.4 | 1.1.1.1 | 0xab35 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:47.579088926 CEST | 192.168.2.4 | 1.1.1.1 | 0x9c3a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:53.154050112 CEST | 192.168.2.4 | 1.1.1.1 | 0x84e9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:53.415479898 CEST | 192.168.2.4 | 1.1.1.1 | 0x1446 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.602396011 CEST | 192.168.2.4 | 1.1.1.1 | 0x7985 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.660918951 CEST | 192.168.2.4 | 1.1.1.1 | 0x277d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.675455093 CEST | 192.168.2.4 | 1.1.1.1 | 0x4733 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:05.364461899 CEST | 192.168.2.4 | 1.1.1.1 | 0xd741 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:05.602200031 CEST | 192.168.2.4 | 1.1.1.1 | 0x40e3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:11.606097937 CEST | 192.168.2.4 | 1.1.1.1 | 0x84d7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:11.758584976 CEST | 192.168.2.4 | 1.1.1.1 | 0x457d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:18.213108063 CEST | 192.168.2.4 | 1.1.1.1 | 0x24f9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:18.385843992 CEST | 192.168.2.4 | 1.1.1.1 | 0x3e84 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:24.590960979 CEST | 192.168.2.4 | 1.1.1.1 | 0xd2c5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:24.712013006 CEST | 192.168.2.4 | 1.1.1.1 | 0x34ae | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:30.832644939 CEST | 192.168.2.4 | 1.1.1.1 | 0x9ad2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:31.520375967 CEST | 192.168.2.4 | 1.1.1.1 | 0x1344 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:37.829662085 CEST | 192.168.2.4 | 1.1.1.1 | 0xa13 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:37.843049049 CEST | 192.168.2.4 | 1.1.1.1 | 0xde4a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.706187963 CEST | 192.168.2.4 | 1.1.1.1 | 0xc819 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.883142948 CEST | 192.168.2.4 | 1.1.1.1 | 0xc819 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.975368977 CEST | 192.168.2.4 | 1.1.1.1 | 0xc5be | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:49.836412907 CEST | 192.168.2.4 | 1.1.1.1 | 0xe383 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:50.024265051 CEST | 192.168.2.4 | 1.1.1.1 | 0xe383 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:50.840441942 CEST | 192.168.2.4 | 1.1.1.1 | 0x2892 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.132236004 CEST | 192.168.2.4 | 1.1.1.1 | 0xfde9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.305071115 CEST | 192.168.2.4 | 1.1.1.1 | 0xfde9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.401525974 CEST | 192.168.2.4 | 1.1.1.1 | 0x5711 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:46:05.335688114 CEST | 192.168.2.4 | 1.1.1.1 | 0x78b4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:46:05.390922070 CEST | 192.168.2.4 | 1.1.1.1 | 0xac92 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 19, 2024 06:42:22.786690950 CEST | 1.1.1.1 | 192.168.2.4 | 0xa325 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:22.798180103 CEST | 1.1.1.1 | 192.168.2.4 | 0xa58f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.146.112.188 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007183075 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 218.111.151.79 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.146.112.188 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007201910 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 218.111.151.79 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 109.98.58.98 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.146.112.188 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 190.147.2.86 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 211.171.233.129 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:42:25.007211924 CEST | 1.1.1.1 | 192.168.2.4 | 0xec8 | No error (0) | 218.111.151.79 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:43:31.060017109 CEST | 1.1.1.1 | 192.168.2.4 | 0xb757 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:31.071732044 CEST | 1.1.1.1 | 192.168.2.4 | 0x1739 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:36.173964024 CEST | 1.1.1.1 | 192.168.2.4 | 0x5d4d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:36.195174932 CEST | 1.1.1.1 | 192.168.2.4 | 0xc493 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:41.609564066 CEST | 1.1.1.1 | 192.168.2.4 | 0x55ca | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:41.620878935 CEST | 1.1.1.1 | 192.168.2.4 | 0xcd0e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:47.218054056 CEST | 1.1.1.1 | 192.168.2.4 | 0x3f60 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:47.245474100 CEST | 1.1.1.1 | 192.168.2.4 | 0x8ebc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:52.678066969 CEST | 1.1.1.1 | 192.168.2.4 | 0xfabf | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:52.813299894 CEST | 1.1.1.1 | 192.168.2.4 | 0x8d77 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:57.465337038 CEST | 1.1.1.1 | 192.168.2.4 | 0x15cc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:43:57.480257034 CEST | 1.1.1.1 | 192.168.2.4 | 0x299 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:06.378844023 CEST | 1.1.1.1 | 192.168.2.4 | 0xbf51 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:06.399254084 CEST | 1.1.1.1 | 192.168.2.4 | 0x56af | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:11.795420885 CEST | 1.1.1.1 | 192.168.2.4 | 0x4202 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:11.812458992 CEST | 1.1.1.1 | 192.168.2.4 | 0x6ebd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:17.761531115 CEST | 1.1.1.1 | 192.168.2.4 | 0xe53 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:17.780821085 CEST | 1.1.1.1 | 192.168.2.4 | 0x1a0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:23.920578003 CEST | 1.1.1.1 | 192.168.2.4 | 0xd03f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:23.941919088 CEST | 1.1.1.1 | 192.168.2.4 | 0xa5e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:29.496779919 CEST | 1.1.1.1 | 192.168.2.4 | 0x28f4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:29.511501074 CEST | 1.1.1.1 | 192.168.2.4 | 0x2c92 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:35.670763969 CEST | 1.1.1.1 | 192.168.2.4 | 0x5a75 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:35.692931890 CEST | 1.1.1.1 | 192.168.2.4 | 0x43fe | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:41.894262075 CEST | 1.1.1.1 | 192.168.2.4 | 0x4604 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:41.916258097 CEST | 1.1.1.1 | 192.168.2.4 | 0x84e3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:47.568840027 CEST | 1.1.1.1 | 192.168.2.4 | 0xab35 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:47.588046074 CEST | 1.1.1.1 | 192.168.2.4 | 0x9c3a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:53.407582998 CEST | 1.1.1.1 | 192.168.2.4 | 0x84e9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:53.424381018 CEST | 1.1.1.1 | 192.168.2.4 | 0x1446 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.652081966 CEST | 1.1.1.1 | 192.168.2.4 | 0x7985 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.670176983 CEST | 1.1.1.1 | 192.168.2.4 | 0x277d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 116.58.10.60 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 190.218.17.143 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 190.220.21.28 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 196.189.156.245 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 2.185.214.11 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 187.199.203.72 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 201.110.253.191 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 46.100.50.5 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:44:58.967871904 CEST | 1.1.1.1 | 192.168.2.4 | 0x4733 | No error (0) | 105.197.97.247 | A (IP address) | IN (0x0001) | false | ||
Oct 19, 2024 06:45:05.594314098 CEST | 1.1.1.1 | 192.168.2.4 | 0xd741 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:05.609821081 CEST | 1.1.1.1 | 192.168.2.4 | 0x40e3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:11.752604008 CEST | 1.1.1.1 | 192.168.2.4 | 0x84d7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:11.765506029 CEST | 1.1.1.1 | 192.168.2.4 | 0x457d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:18.366010904 CEST | 1.1.1.1 | 192.168.2.4 | 0x24f9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:18.409480095 CEST | 1.1.1.1 | 192.168.2.4 | 0x3e84 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:24.701432943 CEST | 1.1.1.1 | 192.168.2.4 | 0xd2c5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:24.723958015 CEST | 1.1.1.1 | 192.168.2.4 | 0x34ae | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:31.514403105 CEST | 1.1.1.1 | 192.168.2.4 | 0x9ad2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:31.534745932 CEST | 1.1.1.1 | 192.168.2.4 | 0x1344 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:37.840265036 CEST | 1.1.1.1 | 192.168.2.4 | 0xa13 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:37.855453968 CEST | 1.1.1.1 | 192.168.2.4 | 0xde4a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.967185974 CEST | 1.1.1.1 | 192.168.2.4 | 0xc819 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.967202902 CEST | 1.1.1.1 | 192.168.2.4 | 0xc819 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:43.985213995 CEST | 1.1.1.1 | 192.168.2.4 | 0xc5be | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:50.083595991 CEST | 1.1.1.1 | 192.168.2.4 | 0xe383 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:50.850619078 CEST | 1.1.1.1 | 192.168.2.4 | 0x2892 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.396687984 CEST | 1.1.1.1 | 192.168.2.4 | 0xfde9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.396701097 CEST | 1.1.1.1 | 192.168.2.4 | 0xfde9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:45:57.421417952 CEST | 1.1.1.1 | 192.168.2.4 | 0x5711 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:46:05.385740995 CEST | 1.1.1.1 | 192.168.2.4 | 0x78b4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Oct 19, 2024 06:46:05.401643991 CEST | 1.1.1.1 | 192.168.2.4 | 0xac92 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:42:25.014040947 CEST | 282 | OUT | |
Oct 19, 2024 06:42:25.014059067 CEST | 314 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49926 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:31.092417955 CEST | 278 | OUT | |
Oct 19, 2024 06:43:31.092418909 CEST | 211 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49933 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:32.647191048 CEST | 278 | OUT | |
Oct 19, 2024 06:43:32.647219896 CEST | 119 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49938 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:33.790662050 CEST | 280 | OUT | |
Oct 19, 2024 06:43:33.790689945 CEST | 128 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49945 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:34.983871937 CEST | 279 | OUT | |
Oct 19, 2024 06:43:34.983918905 CEST | 279 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49951 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:36.208466053 CEST | 279 | OUT | |
Oct 19, 2024 06:43:36.208488941 CEST | 256 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49957 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:37.387864113 CEST | 279 | OUT | |
Oct 19, 2024 06:43:37.387881994 CEST | 264 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49968 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:39.080082893 CEST | 281 | OUT | |
Oct 19, 2024 06:43:39.080111027 CEST | 127 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49978 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:40.273551941 CEST | 279 | OUT | |
Oct 19, 2024 06:43:40.273581982 CEST | 323 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49985 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:41.628854036 CEST | 280 | OUT | |
Oct 19, 2024 06:43:41.628884077 CEST | 270 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49996 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:43.321141005 CEST | 283 | OUT | |
Oct 19, 2024 06:43:43.321171045 CEST | 299 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 50005 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:44.691551924 CEST | 281 | OUT | |
Oct 19, 2024 06:43:44.691591978 CEST | 173 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 50012 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:45.857701063 CEST | 278 | OUT | |
Oct 19, 2024 06:43:45.857701063 CEST | 188 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 50015 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:47.257234097 CEST | 279 | OUT | |
Oct 19, 2024 06:43:47.257234097 CEST | 369 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 50016 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:48.433176041 CEST | 279 | OUT | |
Oct 19, 2024 06:43:48.433207989 CEST | 350 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 50017 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:49.727139950 CEST | 280 | OUT | |
Oct 19, 2024 06:43:49.727173090 CEST | 270 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 50018 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:51.037252903 CEST | 278 | OUT | |
Oct 19, 2024 06:43:51.037280083 CEST | 299 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 50019 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:52.821947098 CEST | 282 | OUT | |
Oct 19, 2024 06:43:52.823015928 CEST | 345 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 50020 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:54.417454004 CEST | 282 | OUT | |
Oct 19, 2024 06:43:54.419017076 CEST | 210 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 50021 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:55.959076881 CEST | 278 | OUT | |
Oct 19, 2024 06:43:55.959129095 CEST | 116 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 50022 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:57.495244980 CEST | 281 | OUT | |
Oct 19, 2024 06:43:57.495289087 CEST | 188 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 50023 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:43:58.872142076 CEST | 278 | OUT | |
Oct 19, 2024 06:43:58.872153044 CEST | 205 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 50024 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:00.169258118 CEST | 282 | OUT | |
Oct 19, 2024 06:44:00.169302940 CEST | 260 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 50025 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:06.414633989 CEST | 282 | OUT | |
Oct 19, 2024 06:44:06.414633989 CEST | 291 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 50026 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:11.830302000 CEST | 281 | OUT | |
Oct 19, 2024 06:44:11.830326080 CEST | 356 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 50027 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:17.796960115 CEST | 281 | OUT | |
Oct 19, 2024 06:44:17.796978951 CEST | 126 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 50028 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:23.953608990 CEST | 283 | OUT | |
Oct 19, 2024 06:44:23.953627110 CEST | 335 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 50029 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:29.529582977 CEST | 283 | OUT | |
Oct 19, 2024 06:44:29.529627085 CEST | 176 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 50030 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:35.730554104 CEST | 280 | OUT | |
Oct 19, 2024 06:44:35.730586052 CEST | 131 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 50031 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:41.925421953 CEST | 278 | OUT | |
Oct 19, 2024 06:44:41.925450087 CEST | 165 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 50032 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:47.595964909 CEST | 278 | OUT | |
Oct 19, 2024 06:44:47.596019030 CEST | 190 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 50033 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:53.435223103 CEST | 280 | OUT | |
Oct 19, 2024 06:44:53.435261965 CEST | 254 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 50034 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:44:58.973855972 CEST | 283 | OUT | |
Oct 19, 2024 06:44:58.973910093 CEST | 137 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 50035 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:05.624799967 CEST | 282 | OUT | |
Oct 19, 2024 06:45:05.624835014 CEST | 220 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 50036 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:11.779484987 CEST | 283 | OUT | |
Oct 19, 2024 06:45:11.779517889 CEST | 331 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 50037 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:18.432126045 CEST | 282 | OUT | |
Oct 19, 2024 06:45:18.432161093 CEST | 178 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 50038 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:24.746797085 CEST | 281 | OUT | |
Oct 19, 2024 06:45:24.746833086 CEST | 117 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 50039 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:31.552082062 CEST | 279 | OUT | |
Oct 19, 2024 06:45:31.552139997 CEST | 317 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 50040 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:37.867525101 CEST | 282 | OUT | |
Oct 19, 2024 06:45:37.867558002 CEST | 359 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 50041 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:43.996870041 CEST | 283 | OUT | |
Oct 19, 2024 06:45:43.996893883 CEST | 273 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 61684 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:50.869941950 CEST | 280 | OUT | |
Oct 19, 2024 06:45:50.869941950 CEST | 237 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 61685 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:45:57.441528082 CEST | 278 | OUT | |
Oct 19, 2024 06:45:57.441571951 CEST | 154 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 61686 | 116.58.10.60 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 19, 2024 06:46:05.412533998 CEST | 282 | OUT | |
Oct 19, 2024 06:46:05.412570000 CEST | 189 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 00:41:58 |
Start date: | 19/10/2024 |
Path: | C:\Users\user\Desktop\50f86ebddd156619b173883981364d8955365d76d2c3a.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 454'144 bytes |
MD5 hash: | EA2E25EFD40CEBD5E9535B91D8E3F61F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 00:42:03 |
Start date: | 19/10/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 00:42:22 |
Start date: | 19/10/2024 |
Path: | C:\Users\user\AppData\Roaming\vbirvce |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 454'144 bytes |
MD5 hash: | EA2E25EFD40CEBD5E9535B91D8E3F61F |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Analysis Process: 50f86ebddd156619b173883981364d8955365d76d2c3a.exePID: 6364, Parent PID: 2580COMMON
Execution Graph
Execution Coverage: | 8.7% |
Dynamic/Decrypted Code Coverage: | 40.7% |
Signature Coverage: | 44.9% |
Total number of Nodes: | 118 |
Total number of Limit Nodes: | 4 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00514696 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0062003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00620E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00514355 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0062092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00513F73 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403277 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00620D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040324F Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403256 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403247 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040326C Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403290 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 8.7% |
Dynamic/Decrypted Code Coverage: | 40.7% |
Signature Coverage: | 0% |
Total number of Nodes: | 118 |
Total number of Limit Nodes: | 4 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 006C003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 007134BE Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 006C0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018E6 Relevance: 1.3, APIs: 1, Instructions: 63sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401915 Relevance: 1.3, APIs: 1, Instructions: 59sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F1 Relevance: 1.3, APIs: 1, Instructions: 55sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401912 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0071317D Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401925 Relevance: 1.3, APIs: 1, Instructions: 46sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|