Windows
Analysis Report
S6DgRF1SSD.xlsx
Overview
General Information
Sample name: | S6DgRF1SSD.xlsxrenamed because original name is a hash value |
Original sample name: | 6bba78df2ac67668eb837a1593b6c1e3fc198fa4c1a4725a5d2370f8121c3a3b.xlsx |
Analysis ID: | 1543658 |
MD5: | 334d7d30d9327e30d300d5ed3326d098 |
SHA1: | cdac6096bcc46f8ab2d668bba92d124beb7794d4 |
SHA256: | 6bba78df2ac67668eb837a1593b6c1e3fc198fa4c1a4725a5d2370f8121c3a3b |
Infos: | |
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- EXCEL.EXE (PID: 6672 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" "C:\ Users\user \Desktop\S 6DgRF1SSD. xlsx" MD5: 4A871771235598812032C822E6F68F19)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
System Summary |
---|
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Window title found: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Exploitation for Client Execution | Path Interception | Path Interception | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | Rootkit | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | 1 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
66% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.107.246.45 | s-part-0017.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1543658 |
Start date and time: | 2024-10-28 08:08:13 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | S6DgRF1SSD.xlsxrenamed because original name is a hash value |
Original Sample Name: | 6bba78df2ac67668eb837a1593b6c1e3fc198fa4c1a4725a5d2370f8121c3a3b.xlsx |
Detection: | MAL |
Classification: | mal64.winXLSX@1/1@0/1 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.109.28.46, 52.109.76.243, 184.28.90.27, 52.113.194.132, 13.89.179.8, 20.42.73.28
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, eur.roaming1.live.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, neu-azsc-000.roaming.officeapps.live.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, s-0005.s-msedge.net, config.officeapps.live.com, osiprod-neu-buff-azsc-000.northeurope.cloudapp.azure.com, onedscolprdcus06.centralus.cloudapp.azure.com, azureedge-t-prod.trafficmanager.net, onedscolprdeus15.eastus.cloudapp.azure.com, ecs.office.trafficmanager.net, europe.configsvc1.live.c
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: S6DgRF1SSD.xlsx
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
13.107.246.45 | Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | Stealc, Vidar | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Blackshades | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, AsyncRAT, LummaC Stealer, Stealc, XWorm | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.3520167401771568 |
Encrypted: | false |
SSDEEP: | 3:8Nultln:X1n |
MD5: | 9AC4D67F6E514F452D4A1DB79CE3B2E8 |
SHA1: | 33F8C665ECBB81275D2E49D48F2565A58A282043 |
SHA-256: | 407E1D871964C93DBDBD4D00613CD0A9E30D3ED6352D8052C58E7A252D52FC5A |
SHA-512: | 018D0F54AB0AB01F27E9FB870A128F2F581A58487399DD7FB56A94EC4AAEC6874708A5AD5650F362485E45E2C6A557ED08524C5B8335F83F240E0962281A0F1A |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.982401310884206 |
TrID: |
|
File name: | S6DgRF1SSD.xlsx |
File size: | 779'181 bytes |
MD5: | 334d7d30d9327e30d300d5ed3326d098 |
SHA1: | cdac6096bcc46f8ab2d668bba92d124beb7794d4 |
SHA256: | 6bba78df2ac67668eb837a1593b6c1e3fc198fa4c1a4725a5d2370f8121c3a3b |
SHA512: | 29a51f19d8c22b48f977b3e038ca5c82021adcbd7c59f9b44908e58410c872a3593439810de77b7cb821d1bd4d7d98276f8fc533e505b15c37af8e3ff6a237d2 |
SSDEEP: | 12288:jHUhf6WgiHmPhTCS/nNM9xH6+NKoQ/yj2JglKY+9G+d4BYDWpw44h7j:jHUhfsacya+MoVVKr9GaFDh |
TLSH: | 54F402057068E9B5B3AEC1A94E44BD222BC380057C0B005E2FF7FB476AD97968F5D92D |
File Content Preview: | PK.........@XY.|{7............[Content_Types].xmlUT......g...g...g.T.n.0....?..."......C....A..."..k.@n.......(`..}.@P3.;;..r.]..\l......0.hlX6.....*.B......[,......i..T.....Q..T..z(2&.|.....6/U...%......c .TS.!.fs. [..=d...:j..1....d>Q...{.F@J.j .\...G.. |
Icon Hash: | 35e58a8c0c8a85b9 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2024-09-30T12:55:35Z |
Last Saved Time: | 2024-10-01T18:04:35Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1Ole10NATIvE |
CLSID: | |
File Type: | data |
Stream Size: | 934659 |
Entropy: | 5.994528560105819 |
Base64 Encoded: | False |
Data ASCII: | S . . } ) K . p . . . z . . M . . G % g V H . S . # c - b # c . E . o 2 . . ! 0 : . 6 . c C L H F . ! . i . O . @ K J d . ' g ) } . . > + . 7 Z . ( 1 y . m y ( z l . . . . . b % = ; V . l . Y a . b 9 , [ . K . " @ o . W . l ' . . . } 2 : d U L T . C [ . a : . . ? " @ q I { 7 q F Q d c - N + F G n , . Q . ] + m I B . . . = o | . L . . } ? e 8 m . K " 3 . U . 1 I i $ P . 9 X P . \\ . ? F J S . 7 = 5 . . m B = Y , u v . N m R . M l < , @ S 0 P W . $ . . . . c 6 3 ^ . x . 7 3 f j X $ . [ j ] . . x e 1 8 . M P |
Data Raw: | 53 c1 e3 00 02 7d 29 4b 03 70 01 08 1e 8c bd df e9 b1 7a 81 c5 94 d3 93 85 8b 4d c9 8b 19 b8 bb e7 47 a2 25 b4 67 56 48 8b 10 53 ff d2 05 ee 23 ea 63 2d 62 23 ea 63 ff e0 96 fc 10 45 00 c0 e1 df 6f 32 b2 1e c7 bb 91 e5 98 21 bc 30 9f 3a 82 f9 07 36 ea 09 63 43 4c 48 46 85 01 21 12 69 c4 c2 1f 4f d5 1a 40 a1 fc 9d bd 4b 4a fc 64 1e 27 67 29 9a 7d 1a 07 3e 2b ad 16 37 5a 80 a1 18 28 |
General | |
Stream Path: | ubwgReBzZL5dui7PBNwgJN3 |
CLSID: | |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 28, 2024 08:09:56.087928057 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.087984085 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:56.088104963 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.091006041 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.091023922 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:56.839994907 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:56.840168953 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.842391014 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.842411041 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:56.842781067 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:56.844381094 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:56.891350031 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.468267918 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.468306065 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.468355894 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.468465090 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.468508005 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.468530893 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.468571901 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.585941076 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.585978031 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.586112976 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.586164951 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.586216927 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.703681946 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.703711033 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.703824997 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.703860998 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.703908920 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.820188999 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.820219994 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.820405006 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.820472956 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.820549011 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.937053919 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.937084913 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.937236071 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:57.937277079 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:57.937371969 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.054114103 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.054152012 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.054336071 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.054403067 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.054474115 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.170603991 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.170681000 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.170891047 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.170953989 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.171066046 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.212629080 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.212697983 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.212861061 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.212932110 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.212955952 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.212992907 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.329278946 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.329366922 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.329471111 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.329511881 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.329539061 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.329580069 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.407865047 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.407895088 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.408118963 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.408152103 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.408252001 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.522597075 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.522629023 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.522828102 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.522864103 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.522955894 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.566076994 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.566107988 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.566268921 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.566302061 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.566401005 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.682300091 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.682327032 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.682596922 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.682647943 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.682730913 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.757046938 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.757112026 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.757230043 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.757263899 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.757296085 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.757343054 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.879832983 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.879903078 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.880052090 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.880093098 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.880108118 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.880146980 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.919037104 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.919060946 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.919224024 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.919245958 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.919322968 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.997195005 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.997216940 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.997416019 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:58.997438908 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:58.997503996 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.034764051 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.034787893 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.034945011 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.034975052 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.035059929 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.150199890 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.150223970 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.150363922 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.150377989 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.150475025 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.153192997 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.153209925 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.153280973 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.153286934 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.153357029 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.267908096 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.267930031 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.268048048 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.268068075 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.268116951 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.340873003 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.340924025 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.341037989 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.341049910 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.341085911 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.385283947 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.385313988 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.385452032 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.385468006 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.385539055 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.464399099 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.464436054 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.464616060 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.464624882 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.464692116 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.502815008 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.502909899 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.502989054 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.502999067 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.503087044 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.581701040 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.581736088 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.581847906 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.581856966 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.581924915 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.619265079 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.619306087 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.619376898 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.619384050 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.619431019 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.619450092 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.692711115 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.692787886 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.692936897 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.692969084 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.692990065 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.693022013 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.736924887 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.736967087 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.737257004 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.737289906 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.737430096 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.776807070 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.776849985 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.777115107 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:09:59.777153969 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:09:59.777245045 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.017465115 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.017501116 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.017554998 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.017673016 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.017762899 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.017802954 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.017838001 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.020153999 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.020205975 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.020265102 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.020279884 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.020308018 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.020431995 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.022655964 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.022682905 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.022793055 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.022793055 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.022809982 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.022871971 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.024523973 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.024559021 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.024611950 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.024624109 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.024669886 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.024694920 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.046720982 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.046746016 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.046858072 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.046869993 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.046966076 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.087955952 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.088025093 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.088157892 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.088172913 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.088191032 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.088253975 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.090233088 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.090257883 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.090365887 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.090374947 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.090466976 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.346666098 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.346683025 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.346729040 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.346776009 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.346806049 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.346824884 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.346849918 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.349031925 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.349055052 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.349136114 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.349154949 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.349174976 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.349201918 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.351416111 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.351435900 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.351505995 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.351525068 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.351577997 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.561950922 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.561969042 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.562020063 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.562134981 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.562200069 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.562324047 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.562324047 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.566939116 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.566971064 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.567054033 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.567074060 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.567147970 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.569747925 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.569777012 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.569855928 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.569871902 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.569936037 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.572580099 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.572607040 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.572705984 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.572720051 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.572786093 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.574517965 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.574543953 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.574621916 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.574647903 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.574677944 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.574697018 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.576102018 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.576127052 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.576205969 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.576221943 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.576294899 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.577908993 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.577931881 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.578027010 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.578041077 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.578108072 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.578836918 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.578861952 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.578953028 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.578965902 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.579030991 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.630255938 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.630296946 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.630460024 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.630491018 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.630646944 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.673639059 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.673672915 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.673882008 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.673950911 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.674024105 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.674611092 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.674634933 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.674685955 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.674701929 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.674735069 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.674757004 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.747550964 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.747582912 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.747927904 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.748023033 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.748105049 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.790385008 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.790447950 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.790740967 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.790824890 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.790920973 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.791877031 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.791919947 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.791969061 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.791997910 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.792032003 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.792073965 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.830828905 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.830863953 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.831054926 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.831093073 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.831177950 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.907119036 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.907181978 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.907329082 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.907385111 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.907545090 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.907545090 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.908272028 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.908318996 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.908375978 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.908385038 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.908438921 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.909919977 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.909965992 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.910008907 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.910024881 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.910041094 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.910084009 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.982584953 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.982620955 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.982876062 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:00.982908010 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:00.983002901 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.024475098 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.024506092 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.024674892 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.024758101 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.024936914 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.025670052 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.025698900 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.025774956 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.025804996 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.025887012 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.026746035 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.026772022 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.026834965 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.026853085 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.026882887 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.026937962 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.101783991 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.101864100 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.101986885 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.102061033 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.102128983 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.102154970 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.142930984 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.142985106 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.143263102 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.143346071 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.143456936 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.144332886 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.144380093 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.144438982 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.144454956 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.144486904 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.144517899 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.216346979 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.216382027 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.216502905 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.216541052 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.216619015 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.217777014 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.217797995 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.217873096 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.217880964 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.217941046 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.259113073 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.259207964 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.259269953 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.259294987 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.259368896 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.259623051 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.259646893 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:01.259670973 CET | 49715 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:01.259677887 CET | 443 | 49715 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:04.334498882 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:04.334526062 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:04.334624052 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:04.334918976 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:04.334932089 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.087027073 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.087701082 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.087728024 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.088494062 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.088499069 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.351665974 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.351721048 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.351821899 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.351835966 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.351866961 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.351927996 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.352224112 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.352236986 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Oct 28, 2024 08:10:05.352257013 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.45 |
Oct 28, 2024 08:10:05.352262974 CET | 443 | 49716 | 13.107.246.45 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 28, 2024 08:09:56.083784103 CET | 1.1.1.1 | 192.168.2.16 | 0xa7a | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Oct 28, 2024 08:09:56.083784103 CET | 1.1.1.1 | 192.168.2.16 | 0xa7a | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49715 | 13.107.246.45 | 443 | 6672 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 07:09:56 UTC | 219 | OUT | |
2024-10-28 07:09:57 UTC | 542 | IN | |
2024-10-28 07:09:57 UTC | 15842 | IN | |
2024-10-28 07:09:57 UTC | 16384 | IN | |
2024-10-28 07:09:57 UTC | 16384 | IN | |
2024-10-28 07:09:57 UTC | 16384 | IN | |
2024-10-28 07:09:57 UTC | 16384 | IN | |
2024-10-28 07:09:58 UTC | 16384 | IN | |
2024-10-28 07:09:58 UTC | 16384 | IN | |
2024-10-28 07:09:58 UTC | 16384 | IN | |
2024-10-28 07:09:58 UTC | 16384 | IN | |
2024-10-28 07:09:58 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49716 | 13.107.246.45 | 443 | 6672 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-28 07:10:05 UTC | 207 | OUT | |
2024-10-28 07:10:05 UTC | 584 | IN | |
2024-10-28 07:10:05 UTC | 2128 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 1 |
Start time: | 03:08:45 |
Start date: | 28/10/2024 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xde0000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |