Windows
Analysis Report
Ref#150689.vbe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6200 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\Ref#1 50689.vbe" MD5: A47CBE969EA935BDD3AB568BB126BC80)
- wscript.exe (PID: 6580 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\App Data\Roami ng\dirDChD JoZeRjid.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 6804 cmdline:
"C:\Window s\system32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 6800 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - RegSvcs.exe (PID: 6176 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Reg Svcs.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - wermgr.exe (PID: 2764 cmdline:
"C:\Window s\system32 \wermgr.ex e" "-outpr oc" "0" "6 804" "2876 " "2568" " 2880" "0" "0" "2884" "0" "0" " 0" "0" "0" MD5: 74A0194782E039ACE1F7349544DC1CF4) - powershell.exe (PID: 4676 cmdline:
"C:\Window s\system32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7164 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - wermgr.exe (PID: 1436 cmdline:
"C:\Window s\system32 \wermgr.ex e" "-outpr oc" "0" "4 676" "1988 " "2556" " 2192" "0" "0" "2124" "0" "0" " 0" "0" "0" MD5: 74A0194782E039ACE1F7349544DC1CF4)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "SMTP", "Port": "587", "Host": "162.254.34.31", "Username": "sendxambro@educt.shop", "Password": "ABwuRZS5Mjh5"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
|
System Summary |
---|
Source: | Author: frack113, Florian Roth: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Tim Shelton: |
Source: | Author: frack113: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-22T14:45:59.281919+0200 | 2030171 | 1 | A Network Trojan was detected | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-22T14:46:31.537759+0200 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-22T14:46:31.537759+0200 | 2855245 | 1 | A Network Trojan was detected | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-22T14:45:59.281919+0200 | 2840032 | 1 | A Network Trojan was detected | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Integrated Neural Analysis Model: |
Source: | HTTPS traffic detected: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Software Vulnerabilities |
---|
Source: | Child: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 8_2_0097E270 | |
Source: | Code function: | 8_2_00974A98 | |
Source: | Code function: | 8_2_0097AA12 | |
Source: | Code function: | 8_2_00973E80 | |
Source: | Code function: | 8_2_009741C8 | |
Source: | Code function: | 8_2_0604A178 | |
Source: | Code function: | 8_2_06055640 | |
Source: | Code function: | 8_2_06056668 | |
Source: | Code function: | 8_2_0605C200 | |
Source: | Code function: | 8_2_0605B2A2 | |
Source: | Code function: | 8_2_06053100 | |
Source: | Code function: | 8_2_06057DF0 | |
Source: | Code function: | 8_2_06057710 | |
Source: | Code function: | 8_2_06052409 | |
Source: | Code function: | 8_2_0605E418 | |
Source: | Code function: | 8_2_06050040 | |
Source: | Code function: | 8_2_06055D5F | |
Source: | Code function: | 8_2_06050006 |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 8_2_00970712 | |
Source: | Code function: | 8_2_00970722 | |
Source: | Code function: | 8_2_00970702 | |
Source: | Code function: | 8_2_00970712 | |
Source: | Code function: | 8_2_00970722 | |
Source: | Code function: | 8_2_00970712 | |
Source: | Code function: | 8_2_00970732 | |
Source: | Code function: | 8_2_0604FBDC |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Dropped file: | Jump to dropped file |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior | ||
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 311 Scripting | Valid Accounts | 121 Windows Management Instrumentation | 311 Scripting | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 311 Process Injection | 1 Obfuscated Files or Information | 1 Credentials in Registry | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Masquerading | NTDS | 1 Process Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 131 Virtualization/Sandbox Evasion | LSA Secrets | 131 Virtualization/Sandbox Evasion | SSH | Keylogging | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 311 Process Injection | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | ReversingLabs | Script-WScript.Trojan.GuLoader |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.13.205 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
144.91.79.54 | unknown | Germany | 51167 | CONTABODE | true | |
104.26.13.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false | |
162.254.34.31 | unknown | United States | 64200 | VIVIDHOSTINGUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1539284 |
Start date and time: | 2024-10-22 14:45:10 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Ref#150689.vbe |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winVBE@14/19@1/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 13.89.179.12
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, login.live.com, blobcollector.events.data.trafficmanager.net, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, onedsblobprdcus17.centralus.cloudapp.azure.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: Ref#150689.vbe
Time | Type | Description |
---|---|---|
08:46:03 | API Interceptor | |
08:46:12 | API Interceptor | |
08:46:28 | API Interceptor | |
08:46:44 | API Interceptor | |
14:46:06 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
144.91.79.54 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
104.26.13.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Node Stealer | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | AgentTesla, PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
| |
Get hash | malicious | Babadeda | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | HtmlDropper | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
| ||
VIVIDHOSTINGUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
CONTABODE | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Remcos, GuLoader | Browse |
| |
Get hash | malicious | Babadeda | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_powershell.exe_6dcd90a0cfadcd56d98897fd4ad3469a57ab5cb_00000000_25500876-a34d-47e4-bb20-4e5a6be1c385\Report.wer
Download File
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.5201198159915306 |
Encrypted: | false |
SSDEEP: | 96:soF7cp0nj2rxYid67nRH3Uje0e3e/3hosM1QXIGZAX/d5FMT2SlPkpXmTA2f/VX7:hNj2mG67nR30hHxAzuiFsZ24lO8r |
MD5: | B2770F2F1F7D08A2D9AE6581C5034AAC |
SHA1: | DD956BE9E2BCB699FBB265C44EAFC993E29005D8 |
SHA-256: | DA5456695CB1E363568C289630AF46E208BD5312E0E86D6B2AC556A7F0CC58E7 |
SHA-512: | D50A2FFF2EA237619378FC0DEF7A2A05B7B25B57B7DAD15430CDEF9FF3479E8BC2221F782FF909AA722F7440C2DC58CFBD7E6E7714533523D6B4AEBF9B898CF4 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_powershell.exe_b4b21b9272f0623778607a435112f88140f556cc_00000000_bcb8d328-dfa3-4531-aae7-c2ccd8044f2a\Report.wer
Download File
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.5345553664920891 |
Encrypted: | false |
SSDEEP: | 96:0nFxjGrxYid6cRH3Uje0eD/JuNnN9KQXIGZAX/d5FMT2SlPkpXmTArnf/VXT5NHn:iHGmG6cR30wAAzuiFbZ24lO8 |
MD5: | 18C88BB7D9DD3C12D8EB72339F96D5C2 |
SHA1: | AE5C8543503D4DE652043D177EE943FDADFD452F |
SHA-256: | 1F27DB385D4FC3CB520505BE08E40934324F2928B886487C6A3E59FA8C1CA347 |
SHA-512: | 185D99893BCC87B25F6B1FC7399C96E31416068411830E2E8345AB0C6EB45EDF53796352F4292984E10A36A17355F80B3F81EA1B24680E1E893A193881FE37C6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7418 |
Entropy (8bit): | 3.6853919664549597 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJURdjVDBO6YSZ2XbGgmftqBppZm:R6lXJgpDI6Y826gmftq+ |
MD5: | 808E3E253D3C68C96AEB3F91791F8AEE |
SHA1: | 635F27D7FD80AD740B869E86372ECFD92A4DAD12 |
SHA-256: | 0C367DC938849B0739F2083FA224A7D3CB52B481F1B6299087F7617FC2D4E384 |
SHA-512: | 7E779D0F89BBCBC5E118C680B6C60FD193B0CDDA04A4EE0085A567585044DF88F5151F1A6DDB67B9623C42F3881D0073FD60124FA34B992BACD2A8320AF3A239 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4899 |
Entropy (8bit): | 4.569460746123698 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsfJg771I9xWWpW8VYlPYm8M4JFKlnOtSFvIyq8vT0OtN/ytfmd:uIjfBI7G37VtJFKlnpIWT0k/ufmd |
MD5: | FB4587E92414F27E5AE2B5CA52118CD0 |
SHA1: | C0A3BC91F696377197A18433AF15DE9AA12667EE |
SHA-256: | BF6146081042E9E0A47792352CC336D0592434011910464E22BF515F2808E7EB |
SHA-512: | 02428DD097C8D4F0267B1578ABB6C38E95929292760BE7C0E16F44402BE441C33E1E75DE0E985539AA631C8C84C07313BAAC093F95364AC04198574CC2BF9D2D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7228 |
Entropy (8bit): | 3.6849038638877993 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJQk0Cif6YSh2XbGgmftvcBppRZm:R6lXJQfCif6Yk26gmft0k |
MD5: | C7DF7B6821B2C3C306CA481DFBABA1D7 |
SHA1: | 6624ADFB61F9653165AD7D4339A7CE55553FB9D7 |
SHA-256: | 5339817CC94F9E1C8418272E811D54E0FACD97E6D58DAB901086594CEDEBB710 |
SHA-512: | EAC5CE2AAF61782F7C8E0C2C314FF3D784BD6331B0EAD520111D971BF75D4E391AE74CD1E921CFB67098FF783CBF98BCE9D9D1C9B60BF65B7FFAFCF0057C61DE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4711 |
Entropy (8bit): | 4.509051390600491 |
Encrypted: | false |
SSDEEP: | 96:uIjfBI7G37VdJFKl0F3DFt28WTnF3DFF/ufPd:uIlYG37x4EwVfufF |
MD5: | FDA66F5903A1D4BE4B4C00AADCD61D45 |
SHA1: | 8FBBDBD48885F9A3DA6029A816DBC4744D3B9D3E |
SHA-256: | 6D473CEE9A6B517AB08FAC51567AF2AEEAAFF12424187DBC9427DEF6457F54B5 |
SHA-512: | 23A6A44C9670616B76B4CB22FE827EAA3FE8E2872E494D5225FEC30A0BE0DFABC2763ECA236B9BEF520C679EF3A8B0996C9F41948425FC2BFA2D33547CA775AC |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11887 |
Entropy (8bit): | 4.901437212034066 |
Encrypted: | false |
SSDEEP: | 192:Zxoe5qpOZxoe54ib4ZVsm5emdR2Ca6pZlbjvwRjdHPRhAgkjDt4iWN3yBGHVQ9sY:Srib4ZoopbjvwRjdvRNkjh4iUxsNYW6m |
MD5: | DDAC12D6036E986FE7B5A5E062A8CC14 |
SHA1: | FA891410075C9E647754E894CDCB14751FE9E3C7 |
SHA-256: | B3B4B4AF761334818B7924740A84E55CE8ECA480F13077854469E8D9C7C1DF7E |
SHA-512: | F7BD65E3B361D0F02B541273A6D99BD1F6B438F2304D4F061C262164166E4FAB6F56614CFD1C44A0D99C9E1A1B46D5DF0138A4656F96B7390162F54E1679B776 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3260 |
Entropy (8bit): | 5.402789045006677 |
Encrypted: | false |
SSDEEP: | 96:vkU1zlHyIFKL2O9qrh7Kf+2J5Eo9AdrxwF:vz1yt2jrAVLL2a |
MD5: | 992E42D1FA15F73BDD0184387A0F8CE7 |
SHA1: | 4C1D9E270A198B72ABB50525895F491732C6BB13 |
SHA-256: | 31B2DD018BFE02C0B5A2F2871C0C385F5F9D33A8A31522E9F1DCF1C122BA9E6E |
SHA-512: | DEB26838E45C25ED33CA34CFB86FE69A5D0DDBFF2B29145DEDD1B7F54AF2629224674408A5C78D1239C273946AF895C228CF43E7A7A084C6CEC51572D88B51CE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 5.401985169194339 |
Encrypted: | false |
SSDEEP: | 6:xVwe5ljxsu2xKbLtSXqo83gMXTBDEoXZuBiA2V0LYERmBPyXFI59:772EtSXqd5ZEoJci1V0LYEIyo |
MD5: | 73622137D903689DFEBD28DD0A5B17A8 |
SHA1: | 63AC79ADE35AB949BE311604267239D322CE42C1 |
SHA-256: | CE201780D48B4687EA1F3D0F66DB0E415E9CF8653C297D466AA6B688213B03CC |
SHA-512: | D7E6728A57DF3D33FFC0ADFBCB6C376BD885AE43EE4EF44320AFCC3AAE22DAA19DD08DF5B3B8197F212B97F40E6E6863E3CB6F9909037F78D993EC850384DEF0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7015427903408895 |
Encrypted: | false |
SSDEEP: | 96:8QwFdCteo7kvhkvCCtc23a+MHP23a+xHU:8QwFQeUc23+23M |
MD5: | 4F2B713B6EBE6F92A346F9CE41A4F7A4 |
SHA1: | 33940515D07A15DB9F662E3CF9900E71F0113C1F |
SHA-256: | 6979972E8E09B0C8C03B17239CD71F64FCA6C6C6DCA830EB4C0A0E0FAD679FD3 |
SHA-512: | 40A878D9B41BAC851C5D9C3BAE8E0E7BA4841C718DE771EA739B9984DA890986BBD03B05E51FEDDC766E2CFFF0C00909FA6EB280932C23A474168F2853E75E7F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF479a81.TMP (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7015427903408895 |
Encrypted: | false |
SSDEEP: | 96:8QwFdCteo7kvhkvCCtc23a+MHP23a+xHU:8QwFQeUc23+23M |
MD5: | 4F2B713B6EBE6F92A346F9CE41A4F7A4 |
SHA1: | 33940515D07A15DB9F662E3CF9900E71F0113C1F |
SHA-256: | 6979972E8E09B0C8C03B17239CD71F64FCA6C6C6DCA830EB4C0A0E0FAD679FD3 |
SHA-512: | 40A878D9B41BAC851C5D9C3BAE8E0E7BA4841C718DE771EA739B9984DA890986BBD03B05E51FEDDC766E2CFFF0C00909FA6EB280932C23A474168F2853E75E7F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\P608ORYJ144CISTDHR3X.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7015427903408895 |
Encrypted: | false |
SSDEEP: | 96:8QwFdCteo7kvhkvCCtc23a+MHP23a+xHU:8QwFQeUc23+23M |
MD5: | 4F2B713B6EBE6F92A346F9CE41A4F7A4 |
SHA1: | 33940515D07A15DB9F662E3CF9900E71F0113C1F |
SHA-256: | 6979972E8E09B0C8C03B17239CD71F64FCA6C6C6DCA830EB4C0A0E0FAD679FD3 |
SHA-512: | 40A878D9B41BAC851C5D9C3BAE8E0E7BA4841C718DE771EA739B9984DA890986BBD03B05E51FEDDC766E2CFFF0C00909FA6EB280932C23A474168F2853E75E7F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\QPJ9ZTU2GAL7VTXY1PMN.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.700906988898656 |
Encrypted: | false |
SSDEEP: | 48:Da9s/JCVbU2H+6BukvhkvklCyw8n2k2qqa+lIjSogZofE2qqa+lIjSogZoz1:+9QJCG97kvhkvCCtc23a+xHP23a+xHU |
MD5: | BA6F050EE8307A631209DF5FA4BFFB87 |
SHA1: | A8F4976A73F3C65A04B180A2E5B9A3F0CAD72307 |
SHA-256: | 25F717A614DEF91B646BD4C8EA75EDB7F874B4745AFC7AB9EB5A7745E0333EF9 |
SHA-512: | 83744DBABB9AD085FA5C5CFB94F97DBD49BCD188AFC34522B94B996443B01FF3B9CA596E7E3673461559E4A8F9C96CC29A8CDCD3D33244B5F797CE55E7CA91A5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2809 |
Entropy (8bit): | 4.971159920674946 |
Encrypted: | false |
SSDEEP: | 48:jQn8VxQ2Ii7jnHilEfzcub6OtzFnc3mqgjHVWRWvxdczYhfWgOq3WldACk8AYQAb:jQ8Vx99OOjcW7Iz08q+k9YDWg9QU |
MD5: | 83DF580BFC1F30657B01031C6C23263A |
SHA1: | D7688ECB62A261B0EA6216617A4F3D5B66715536 |
SHA-256: | BC2D8273C66E12ED28BA3A504601F26943DD950F8FAD00A51AC7112697653795 |
SHA-512: | BFB08E2BE8F2AC17905FBCF0A4225ABA1FE4A1AC105F702BB37C96C0CC8FA84D1D81327D27112D55BA7FC3ED2B4CA60E91640F02610CB2AAD907E9A563007F28 |
Malicious: | true |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1605 |
Entropy (8bit): | 4.425749981547822 |
Encrypted: | false |
SSDEEP: | 24:Eip7/tkNvNa2V269+Iz5JSjeKm3uSmcHugxOAX4WLeX4WgeX4WgeX4WneX4WueXZ:EcWxZzSyjOAX+X5XpXKX/XFXoXQXDX5 |
MD5: | 2B099B22D2137B9BFD17FC56E3F69280 |
SHA1: | 1124B137D2EB3E434A0CC969D6D229EFE37599F3 |
SHA-256: | 419EAC386ACEA5A77C46B9DAC14F29DC6C0DC0A3B377CEEF11CB847B9DC137CF |
SHA-512: | 3E7DAD6CC6B6A1FCF27B05658CB1F3E444D596822B1C56CF54A59072FDDC6028B31EBD86924773CD31C4DB9EDD010BD74E64F7449AF7F12E2C6FD12EAE3ACE98 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 3.939201181970454 |
TrID: |
|
File name: | Ref#150689.vbe |
File size: | 12'114 bytes |
MD5: | 3ee57f19875a1b263377d8ab4af8f677 |
SHA1: | 619eec8b7c7a819a87959fd9026dc58dfe965e68 |
SHA256: | 3fa9114a2d3fddc77550a3567cac63db1bf0c72bebe23d9ceed62cf47ea68c34 |
SHA512: | b53be96cec95ea0281a796e8c01f034c0739d9391bda447e67cc469d49643f2d8b0926c51a69b6a918beb4f51290501a621256fa2987437b67ad9249bbb89d13 |
SSDEEP: | 192:5JNhDRAnShs0fn5nwVFUKq2oJkNMG2BXtqzXlcFqF6SAzzAnJA0Y/7qOsK:nNs0fn5nwck4C098J2/7qOt |
TLSH: | 12428844CE8D42C1E3216B976FCA9AD5172F9A21BF0F0BD52C6443D5232ADC1E566F32 |
File Content Preview: | ..#.@.~.^.j.x.c.A.A.A.=.=.v.9.k...G.Z.4.f.9.K.}...].L.b.N.@.#.@.&.}.w.O.r.K.x.P.A.a.w.^.k.m.b.O.@.#.@.&.@.#.@.&.E.P.M.e.M.~.;.W.U.\...../.b.....x.~.[...P.t.n.a.m.N.n.m.b.h.m.V.~.m.P.D.+.6.D.W.,.M.e.C.@.#.@.&.s.!.x.^.O.b.W.x.,./.W...\.+.M.O.r.D._.+.X.b.P.+ |
Icon Hash: | 68d69b8f86ab9a86 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-22T14:45:59.281919+0200 | 2030171 | ET MALWARE AgentTesla Exfil Via SMTP | 1 | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
2024-10-22T14:45:59.281919+0200 | 2840032 | ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 1 | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
2024-10-22T14:46:31.537759+0200 | 2855245 | ETPRO MALWARE Agent Tesla Exfil via SMTP | 1 | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
2024-10-22T14:46:31.537759+0200 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.5 | 49764 | 162.254.34.31 | 587 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 22, 2024 14:46:03.726713896 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:03.732211113 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:03.732393026 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:03.732659101 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:03.737960100 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588548899 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588563919 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588589907 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588601112 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588610888 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588620901 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.588850975 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.589106083 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.589116096 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.589122057 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.589168072 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.589391947 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.589493036 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.594352007 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.594404936 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.594417095 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.594538927 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.594558001 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.594609976 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.719301939 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719367027 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719378948 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719438076 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.719600916 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719649076 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.719676971 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719779968 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719825983 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.719856024 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719927073 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.719964981 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.720086098 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.720097065 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.720107079 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.720134020 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.720627069 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.720679045 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.720685005 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:04.765830994 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:04.771303892 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021224976 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021281958 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021318913 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021353006 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021354914 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.021394014 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.021533966 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021564007 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021606922 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.021636963 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021791935 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021825075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.021833897 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.021996975 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.022047043 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.022438049 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.022571087 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.022604942 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.022615910 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.022818089 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.022871017 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.023242950 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.023392916 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.023428917 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.023437977 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.023576021 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.023626089 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.024044037 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024096966 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024130106 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024138927 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.024333954 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024384022 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.024842024 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024893999 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024928093 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.024935961 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.078775883 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.138569117 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.138662100 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.138700008 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.138729095 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.138745070 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.138781071 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.138796091 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.139024019 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.139060020 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.139076948 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.139276028 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.139333010 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.139311075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.188122034 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.246551037 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.252235889 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502326012 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502393007 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502405882 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502573013 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502572060 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.502584934 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502623081 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.502794981 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.502859116 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.502909899 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503086090 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503098011 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503108025 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503133059 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.503144979 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.503365993 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503490925 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503503084 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503534079 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.503705978 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503726959 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503745079 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.503941059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.503988981 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.504082918 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504095078 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504126072 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.504327059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504338980 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504384995 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.504654884 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504722118 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504734039 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504760981 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.504975080 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504986048 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.504996061 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.505019903 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.505042076 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.622957945 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.622994900 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623007059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623140097 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.623162031 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623303890 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623326063 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623332024 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.623337984 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623366117 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.623774052 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623786926 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623796940 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623809099 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.623828888 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.623866081 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.624177933 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624191046 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624202013 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624228001 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.624247074 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.624572039 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624583960 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624593973 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624605894 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.624619961 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.624648094 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.625040054 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625051975 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625062943 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625092030 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.625435114 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625447035 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625458956 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625472069 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625487089 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.625514984 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.625895977 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625910997 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625924110 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.625945091 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.625967026 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.626230955 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626384020 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626395941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626441002 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.626693010 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626704931 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626714945 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626728058 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.626740932 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.626768112 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.627118111 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.627163887 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.627258062 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.627271891 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.627321959 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.627463102 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.632795095 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.632819891 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.632831097 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.632853985 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.632878065 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.632956028 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.632973909 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633023024 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.633068085 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633230925 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633241892 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633285999 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.633305073 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633349895 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.633392096 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633419037 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633462906 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.633514881 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633533955 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633547068 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.633575916 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.688257933 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.736804962 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.736879110 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.736911058 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.736932039 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.736968040 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737004042 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737019062 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.737242937 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737293959 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737294912 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.737329960 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737365961 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737420082 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.737696886 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737728119 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737756968 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.737903118 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737938881 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.737970114 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.738118887 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738169909 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738172054 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.738220930 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738256931 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738272905 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.738291979 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738346100 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.738775969 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738810062 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738846064 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.738859892 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.739332914 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739367962 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739391088 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.739403963 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739439011 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739454031 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.739640951 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739687920 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739694118 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.739722967 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739759922 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739783049 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.739797115 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.739841938 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.740255117 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740288019 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740322113 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740348101 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.740364075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740400076 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740417004 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.740865946 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740900040 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740912914 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.740933895 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740967989 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.740978956 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.741002083 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741050005 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.741511106 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741545916 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741580963 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741596937 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.741615057 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741650105 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741667032 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.741684914 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741722107 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.741738081 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.742387056 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742424011 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742446899 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.742458105 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742492914 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742507935 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.742527008 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742559910 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742571115 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.742594004 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.742640018 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.743308067 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743362904 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743396997 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743416071 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.743433952 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743468046 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743484020 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.743504047 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.743558884 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744029045 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744064093 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744112968 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744113922 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744147062 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744179964 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744198084 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744215012 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744250059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744265079 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744283915 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744328022 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744837999 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744889975 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744923115 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744940996 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.744956017 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744987965 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.744996071 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.745022058 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745054007 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745059967 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.745086908 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745121002 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745134115 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.745666981 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745701075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.745718002 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750003099 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750058889 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750061989 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750092030 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750149012 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750163078 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750309944 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750343084 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750359058 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750394106 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750428915 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750442028 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750612974 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750648022 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750658035 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750696898 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750739098 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750823975 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750855923 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750895023 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.750904083 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.750976086 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751008987 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751020908 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.751059055 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751092911 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751101971 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.751127958 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751177073 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.751379967 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751481056 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751516104 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751530886 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.751632929 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751667023 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.751681089 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.797602892 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.854089022 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854162931 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854199886 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854218960 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.854325056 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854357958 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854379892 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.854408026 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854443073 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854459047 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.854732990 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854765892 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854785919 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.854800940 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.854849100 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855038881 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855086088 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855120897 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855134964 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855154991 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855187893 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855206013 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855490923 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855525017 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855544090 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855559111 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855592012 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855608940 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855627060 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855659962 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855675936 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.855694056 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855726957 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.855743885 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.856292963 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856328964 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856344938 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.856395960 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856431961 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856450081 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.856466055 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856499910 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856515884 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.856534958 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.856585026 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.856991053 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857043982 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857076883 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857099056 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.857110977 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857144117 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857161045 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.857177973 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857209921 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857223034 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.857244015 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857278109 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857289076 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.857882977 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857917070 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857934952 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.857953072 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.857988119 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858001947 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.858021975 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858057022 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858072996 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.858088970 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858123064 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858136892 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.858800888 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858834982 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858851910 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.858867884 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858902931 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858921051 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.858935118 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858969927 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.858983040 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859003067 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859036922 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859050989 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859069109 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859113932 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859708071 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859743118 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859776020 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859795094 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859810114 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859843016 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859854937 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859877110 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859910965 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859930992 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.859946966 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859982014 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.859998941 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.860578060 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860610962 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860630035 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.860658884 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860692978 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860718012 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.860727072 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860760927 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860770941 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.860794067 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860829115 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860840082 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.860862970 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.860909939 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.861464024 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861511946 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861545086 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861562967 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.861578941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861612082 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861625910 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.861646891 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861681938 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861696005 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.861716032 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861748934 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.861763954 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862099886 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862135887 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862159014 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862199068 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862234116 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862251043 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862267017 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862299919 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862315893 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862333059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862373114 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862385988 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862411022 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862443924 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862453938 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.862478018 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.862521887 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.863106966 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863120079 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863130093 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863135099 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863146067 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863158941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863169909 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863177061 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.863181114 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863193035 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863207102 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863225937 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.863225937 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.863234043 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.863259077 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.863991022 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864002943 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864013910 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864025116 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864037037 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864038944 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864047050 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864051104 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864063978 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864077091 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864078999 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864089012 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864101887 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864113092 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864120960 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864151001 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864892960 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864903927 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864917040 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864929914 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864947081 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864959002 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864959955 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864972115 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864983082 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.864984989 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.864994049 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865005970 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865008116 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865019083 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865031958 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865057945 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865776062 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865787983 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865797997 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865809917 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865822077 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865828037 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865833998 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865844965 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865854025 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865859985 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865873098 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865875959 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865885019 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865894079 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865895033 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865907907 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.865922928 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.865950108 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.866681099 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866694927 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866704941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866718054 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866729021 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866731882 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.866745949 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866758108 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866759062 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.866769075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866780996 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.866780996 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866794109 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866806030 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.866808891 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.866841078 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.867481947 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867495060 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867505074 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867521048 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867531061 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.867568970 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.867748976 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867759943 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867769957 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867783070 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.867798090 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.867829084 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868030071 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868041992 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868052959 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868063927 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868074894 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868098021 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868273973 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868284941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868294954 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868307114 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868319988 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868324995 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868338108 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868349075 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868356943 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868360996 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868371964 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868375063 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868406057 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.868944883 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868957043 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868967056 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868978977 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868993044 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.868999958 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.869004965 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.869019032 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.869029999 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.869041920 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.869045019 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.869059086 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.869083881 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.894577980 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894634008 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894646883 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894690990 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.894737959 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894862890 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894871950 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894884109 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.894933939 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.894941092 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894952059 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894963026 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.894993067 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895169020 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895181894 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895193100 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895221949 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895247936 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895481110 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895492077 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895503998 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895534992 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895673990 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895690918 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895701885 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895714045 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895723104 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895725012 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895736933 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895755053 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895759106 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895771980 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.895782948 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.895812035 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.896187067 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.896239996 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971148968 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971189976 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971299887 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971311092 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971352100 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971386909 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971411943 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971441031 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971474886 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971489906 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971508980 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971544027 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971554041 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971576929 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971611023 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971633911 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971646070 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971699953 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971725941 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971858978 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971892118 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971909046 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971925020 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971956968 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.971976995 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.971990108 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972022057 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972040892 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.972054958 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972100973 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.972296953 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972328901 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972362995 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972388029 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:05.972395897 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:05.972444057 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.189971924 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.280112982 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.531855106 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.578753948 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.621951103 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.627656937 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.877648115 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.877672911 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.877681971 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.877790928 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.877801895 CEST | 80 | 49705 | 144.91.79.54 | 192.168.2.5 |
Oct 22, 2024 14:46:06.879337072 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.879337072 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:06.922645092 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:07.722201109 CEST | 49705 | 80 | 192.168.2.5 | 144.91.79.54 |
Oct 22, 2024 14:46:27.829838037 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:27.829888105 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:27.830085993 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:27.835208893 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:27.835227013 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.437659025 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.437861919 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:28.450162888 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:28.450187922 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.450434923 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.500616074 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:28.636591911 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:28.679327011 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.823514938 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.823602915 CEST | 443 | 49751 | 104.26.13.205 | 192.168.2.5 |
Oct 22, 2024 14:46:28.823656082 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:28.873050928 CEST | 49751 | 443 | 192.168.2.5 | 104.26.13.205 |
Oct 22, 2024 14:46:29.716372013 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:29.721887112 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:29.721959114 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:30.533571005 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:30.536145926 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:30.541593075 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:30.698116064 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:30.704118013 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:30.709590912 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:30.866111040 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:30.875611067 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:30.881145954 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.045274973 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.045531034 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.050904989 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.209078074 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.210385084 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.215876102 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.375787973 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.375917912 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.381452084 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.537045002 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.537710905 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.537759066 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.537776947 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.537789106 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Oct 22, 2024 14:46:31.543262959 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.543278933 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.543292999 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.543306112 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.704010010 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 |
Oct 22, 2024 14:46:31.750612974 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 22, 2024 14:46:27.815975904 CEST | 55399 | 53 | 192.168.2.5 | 1.1.1.1 |
Oct 22, 2024 14:46:27.823873997 CEST | 53 | 55399 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 22, 2024 14:46:27.815975904 CEST | 192.168.2.5 | 1.1.1.1 | 0x5953 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 22, 2024 14:46:27.823873997 CEST | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Oct 22, 2024 14:46:27.823873997 CEST | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Oct 22, 2024 14:46:27.823873997 CEST | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 144.91.79.54 | 80 | 6200 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Oct 22, 2024 14:46:03.732659101 CEST | 152 | OUT | |
Oct 22, 2024 14:46:04.588548899 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.588563919 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.588589907 CEST | 424 | IN | |
Oct 22, 2024 14:46:04.588601112 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.588610888 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.588620901 CEST | 424 | IN | |
Oct 22, 2024 14:46:04.589106083 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.589116096 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.589122057 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.589391947 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.594352007 CEST | 1236 | IN | |
Oct 22, 2024 14:46:04.765830994 CEST | 152 | OUT | |
Oct 22, 2024 14:46:05.021224976 CEST | 1236 | IN | |
Oct 22, 2024 14:46:05.246551037 CEST | 175 | OUT | |
Oct 22, 2024 14:46:05.502326012 CEST | 1236 | IN | |
Oct 22, 2024 14:46:06.189971924 CEST | 152 | OUT | |
Oct 22, 2024 14:46:06.531855106 CEST | 761 | IN | |
Oct 22, 2024 14:46:06.621951103 CEST | 155 | OUT | |
Oct 22, 2024 14:46:06.877648115 CEST | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49751 | 104.26.13.205 | 443 | 6176 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-22 12:46:28 UTC | 155 | OUT | |
2024-10-22 12:46:28 UTC | 211 | IN | |
2024-10-22 12:46:28 UTC | 14 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Oct 22, 2024 14:46:30.533571005 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 220 server1.educt.shop127.0.0.1 ESMTP Postfix |
Oct 22, 2024 14:46:30.536145926 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | EHLO 473627 |
Oct 22, 2024 14:46:30.698116064 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 250-server1.educt.shop127.0.0.1 250-PIPELINING 250-SIZE 204800000 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250 CHUNKING |
Oct 22, 2024 14:46:30.704118013 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | AUTH login c2VuZHhhbWJyb0BlZHVjdC5zaG9w |
Oct 22, 2024 14:46:30.866111040 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 334 UGFzc3dvcmQ6 |
Oct 22, 2024 14:46:31.045274973 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 235 2.7.0 Authentication successful |
Oct 22, 2024 14:46:31.045531034 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | MAIL FROM:<sendxambro@educt.shop> |
Oct 22, 2024 14:46:31.209078074 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 250 2.1.0 Ok |
Oct 22, 2024 14:46:31.210385084 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | RCPT TO:<ambro@educt.shop> |
Oct 22, 2024 14:46:31.375787973 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 250 2.1.5 Ok |
Oct 22, 2024 14:46:31.375917912 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | DATA |
Oct 22, 2024 14:46:31.537045002 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 354 End data with <CR><LF>.<CR><LF> |
Oct 22, 2024 14:46:31.537789106 CEST | 49764 | 587 | 192.168.2.5 | 162.254.34.31 | . |
Oct 22, 2024 14:46:31.704010010 CEST | 587 | 49764 | 162.254.34.31 | 192.168.2.5 | 250 2.0.0 Ok: queued as 4907E60E81 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 08:46:02 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff644100000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 08:46:06 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff644100000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:46:07 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 08:46:08 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 08:46:23 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 08:46:23 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 08:46:26 |
Start date: | 22/10/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2a0000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 08:46:27 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\wermgr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6070d0000 |
File size: | 229'728 bytes |
MD5 hash: | 74A0194782E039ACE1F7349544DC1CF4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 11 |
Start time: | 08:46:27 |
Start date: | 22/10/2024 |
Path: | C:\Windows\System32\wermgr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6070d0000 |
File size: | 229'728 bytes |
MD5 hash: | 74A0194782E039ACE1F7349544DC1CF4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Execution Graph
Execution Coverage: | 10.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 184 |
Total number of Limit Nodes: | 19 |
Graph
Function 06053100 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06057DF0 Relevance: 3.0, Strings: 2, Instructions: 472COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097E270 Relevance: 2.8, Strings: 2, Instructions: 337COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097AA12 Relevance: 2.8, Instructions: 2762COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06052409 Relevance: 1.0, Instructions: 1011COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06056668 Relevance: .8, Instructions: 815COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605C200 Relevance: .6, Instructions: 639COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06055640 Relevance: .6, Instructions: 587COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605B2A2 Relevance: .6, Instructions: 563COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00974A98 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00973E80 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605AD48 Relevance: 10.4, Strings: 8, Instructions: 394COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605B6C8 Relevance: 8.0, Strings: 6, Instructions: 469COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060591C0 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605CFB8 Relevance: 4.5, Strings: 3, Instructions: 799COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06054C10 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060591B3 Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06054C00 Relevance: 2.6, Strings: 2, Instructions: 141COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604B328 Relevance: 1.7, APIs: 1, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604D504 Relevance: 1.6, APIs: 1, Instructions: 120COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604D510 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604E49C Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06043048 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06043050 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097EBF0 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0097EBF8 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604A28C Relevance: 1.6, APIs: 1, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605DB2D Relevance: 1.4, Strings: 1, Instructions: 122COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06052290 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06058340 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06056268 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06054341 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06054660 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06054678 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605EB98 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605EB89 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605FCF7 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605FAA9 Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605FAB8 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060554B8 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06052140 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06052150 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053B41 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053B50 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008ED030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053C60 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060542A0 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605EE08 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053918 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008ED02B Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053C4F Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06053920 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060542B0 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605A377 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605EE18 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605A388 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605C850 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060564E8 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06057710 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605E418 Relevance: 4.3, Strings: 3, Instructions: 568COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06055D5F Relevance: 2.9, Strings: 2, Instructions: 423COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06050040 Relevance: 2.0, Instructions: 1980COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009741C8 Relevance: .3, Instructions: 281COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0604A178 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605A9B0 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06057110 Relevance: 7.9, Strings: 6, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06058448 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06058860 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0605AD38 Relevance: 5.2, Strings: 4, Instructions: 162COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|