Windows
Analysis Report
SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe (PID: 1900 cmdline:
"C:\Users\ user\Deskt op\Securit eInfo.com. Win32.PWSX -gen.31738 .17793.exe " MD5: 34F978912D45CE5DF9309990ECFB0232) - cvtres.exe (PID: 4900 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Cvt Res.exe" MD5: 70D838A7DC5B359C3F938A71FAD77DB0) - cvtres.exe (PID: 1344 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\Cvt Res.exe" MD5: 70D838A7DC5B359C3F938A71FAD77DB0)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"C2 url": "https://api.telegram.org/bot7141101422:AAHWm4uo7ZyvbT3-ERU62IF6HA54iYXM-NI/sendMessage"}
{"Exfil Mode": "Telegram", "Telegram Url": "https://api.telegram.org/bot7141101422:AAHWm4uo7ZyvbT3-ERU62IF6HA54iYXM-NI/sendMessage?chat_id=7102900518"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
Click to see the 9 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 7 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-30T16:23:07.471899+0100 | 2851779 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 149.154.167.220 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-30T16:23:07.471899+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49737 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:24:40.569660+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49958 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:24:56.090448+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50006 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:11.087794+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50007 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:13.983975+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50008 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:22.964661+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50010 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:23.176038+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50011 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:38.033265+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50013 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:38.096839+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50014 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:43.761955+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50015 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:45.656405+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50016 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:52.335815+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50017 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:55.536826+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50018 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:03.795139+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50019 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:25.527591+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50020 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:40.854623+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50021 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:59.947693+0100 | 2852815 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50022 | 149.154.167.220 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Windows user hook set: | Jump to behavior |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Long String: | ||
Source: | Long String: |
Source: | Process Stats: |
Source: | Code function: | 0_2_009824A8 | |
Source: | Code function: | 0_2_0098A825 | |
Source: | Code function: | 0_2_00982DD0 | |
Source: | Code function: | 0_2_00980A88 | |
Source: | Code function: | 0_2_00984650 | |
Source: | Code function: | 0_2_00983791 | |
Source: | Code function: | 0_2_0098A893 | |
Source: | Code function: | 0_2_009878F8 | |
Source: | Code function: | 0_2_00986418 | |
Source: | Code function: | 0_2_0098A818 | |
Source: | Code function: | 0_2_00982414 | |
Source: | Code function: | 0_2_0098A877 | |
Source: | Code function: | 0_2_00981868 | |
Source: | Code function: | 0_2_009869D0 | |
Source: | Code function: | 0_2_009855C0 | |
Source: | Code function: | 0_2_009869C0 | |
Source: | Code function: | 0_2_0098A610 | |
Source: | Code function: | 0_2_0098A620 | |
Source: | Code function: | 0_2_00988A68 | |
Source: | Code function: | 0_2_00986798 | |
Source: | Code function: | 0_2_0098730A | |
Source: | Code function: | 0_2_00987328 | |
Source: | Code function: | 2_2_0136E361 | |
Source: | Code function: | 2_2_0136AA09 | |
Source: | Code function: | 2_2_01364A68 | |
Source: | Code function: | 2_2_01363E50 | |
Source: | Code function: | 2_2_0136DEE0 | |
Source: | Code function: | 2_2_01364198 | |
Source: | Code function: | 2_2_06A55598 | |
Source: | Code function: | 2_2_06A565E0 | |
Source: | Code function: | 2_2_06A57D68 | |
Source: | Code function: | 2_2_06A5B210 | |
Source: | Code function: | 2_2_06A53050 | |
Source: | Code function: | 2_2_06A5C178 | |
Source: | Code function: | 2_2_06A57688 | |
Source: | Code function: | 2_2_06A55CCB | |
Source: | Code function: | 2_2_06A5E398 | |
Source: | Code function: | 2_2_06A52351 | |
Source: | Code function: | 2_2_06A50040 | |
Source: | Code function: | 2_2_06A50023 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 2_2_01360C7A |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 311 Process Injection | 1 Deobfuscate/Decode Files or Information | 21 Input Capture | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | 1 Credentials in Registry | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Software Packing | NTDS | 1 Process Discovery | Distributed Component Object Model | 21 Input Capture | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 141 Virtualization/Sandbox Evasion | SSH | 1 Clipboard Data | 14 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 311 Process Injection | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
53% | ReversingLabs | Win32.Trojan.Generic | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.12.205 | true | false | unknown | |
api.telegram.org | 149.154.167.220 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
true | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
true | unknown | |||
false | unknown | |||
false |
| unknown | ||
true | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | true | |
104.26.12.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1545509 |
Start date and time: | 2024-10-30 16:22:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 29s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@5/1@4/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.azureedge.net, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe
Time | Type | Description |
---|---|---|
11:23:04 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | GuLoader, Snake Keylogger | Browse | ||
Get hash | malicious | Snake Keylogger | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | WhiteSnake Stealer | Browse | |||
104.26.12.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | EvilProxy, HTMLPhisher | Browse |
| |
Get hash | malicious | Skuld Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
api.telegram.org | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | WhiteSnake Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | WhiteSnake Stealer | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe.log
Download File
Process: | C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 226 |
Entropy (8bit): | 5.360398796477698 |
Encrypted: | false |
SSDEEP: | 6:Q3La/xw5DLIP12MUAvvR+uTL2ql2ABgTv:Q3La/KDLI4MWuPTAv |
MD5: | 3A8957C6382192B71471BD14359D0B12 |
SHA1: | 71B96C965B65A051E7E7D10F61BEBD8CCBB88587 |
SHA-256: | 282FBEFDDCFAA0A9DBDEE6E123791FC4B8CB870AE9D450E6394D2ACDA3D8F56D |
SHA-512: | 76C108641F682F785A97017728ED51565C4F74B61B24E190468E3A2843FCC43615C6C8ABE298750AF238D7A44E97C001E3BE427B49900432F905A7CE114AA9AD |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 4.12183450055652 |
TrID: |
|
File name: | SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe |
File size: | 860'672 bytes |
MD5: | 34f978912d45ce5df9309990ecfb0232 |
SHA1: | 05505050b157f8fe6da04a06484835f75c8f0bdc |
SHA256: | 89456271970de32ecdfadbfada5c9ef76d75cc3b2fd7bf0b36c1cf14167117fd |
SHA512: | dd73c32b081b1f585781ad1b699a861e9518da987c4bd0bf3fcbd4d89868a7005ef62523777f300115325b1e9b1c9a6040c1d9c882f1868ce7a2b20406eed9dc |
SSDEEP: | 6144:PxiBwnO+ndhCFIjsoVBiy01XuAfzebFaW7ZnuMvFKLPxorZi0m3lD+jA:PJnnt7Zqsm3lD6 |
TLSH: | 4905999E245A004FF4B6AB681B50F575D1D6E2FD37CB5AB244231A660331B41A8FE3F2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....."g................................. ...@....@.. ....................................@................................ |
Icon Hash: | 51525373611d461b |
Entrypoint: | 0x4c2ede |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67220585 [Wed Oct 30 10:08:05 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc2e84 | 0x57 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc4000 | 0x10dc0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xd6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xc0ee4 | 0xc1000 | c325e85fd0b918c28810d58eb265e3d6 | False | 0.22620957132448186 | data | 3.808009600285966 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc4000 | 0x10dc0 | 0x10e00 | 0efd292f5a328605c13130de497ba32b | False | 0.20866608796296296 | data | 4.933201378904148 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xd6000 | 0xc | 0x200 | 0500be52f3e878ceafee825f0c751e7c | False | 0.044921875 | data | 0.09800417566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xc4390 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 2834 x 2834 px/m | 0.2025907961670413 | ||
RT_GROUP_ICON | 0xd4bb8 | 0x14 | data | 1.25 | ||
RT_VERSION | 0xc4130 | 0x25c | data | 0.4586092715231788 | ||
RT_MANIFEST | 0xd4bd0 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-10-30T16:23:07.471899+0100 | 2851779 | ETPRO MALWARE Agent Tesla Telegram Exfil | 1 | 192.168.2.4 | 49737 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:23:07.471899+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 49737 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:24:40.569660+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 49958 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:24:56.090448+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50006 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:11.087794+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50007 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:13.983975+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50008 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:22.964661+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50010 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:23.176038+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50011 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:38.033265+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50013 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:38.096839+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50014 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:43.761955+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50015 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:45.656405+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50016 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:52.335815+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50017 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:25:55.536826+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50018 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:03.795139+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50019 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:25.527591+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50020 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:40.854623+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50021 | 149.154.167.220 | 443 | TCP |
2024-10-30T16:26:59.947693+0100 | 2852815 | ETPRO MALWARE Agent Tesla Telegram Exfil M2 | 1 | 192.168.2.4 | 50022 | 149.154.167.220 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 30, 2024 16:23:03.026257038 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:03.026287079 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:03.026356936 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:03.048283100 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:03.048296928 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.058621883 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.058784008 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:04.066663980 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:04.066682100 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.067106009 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.111824036 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:04.201348066 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:04.247370005 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.377547026 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.377628088 CET | 443 | 49736 | 104.26.12.205 | 192.168.2.4 |
Oct 30, 2024 16:23:04.378412962 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:04.408179998 CET | 49736 | 443 | 192.168.2.4 | 104.26.12.205 |
Oct 30, 2024 16:23:06.133153915 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:06.133194923 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:06.133296967 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:06.133642912 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:06.133657932 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:06.981703043 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:06.981848001 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:06.983900070 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:06.983921051 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:06.984262943 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:06.985851049 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:07.031348944 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:07.229988098 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:07.230453968 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:07.230493069 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:07.471884012 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:07.514153957 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:23:07.514265060 CET | 443 | 49737 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:23:07.514355898 CET | 49737 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:39.424690008 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:39.424712896 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:39.424827099 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:39.425328016 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:39.425338984 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.291152000 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.291224003 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.295491934 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.295509100 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.296034098 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.299094915 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.343332052 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.568507910 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.568926096 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.568958044 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.569056034 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.569066048 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:40.569164038 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:40.569263935 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:41.118953943 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:41.119808912 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:41.119901896 CET | 443 | 49958 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:41.120017052 CET | 49958 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:54.971565008 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:54.971620083 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:54.971883059 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:54.972223043 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:54.972246885 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:55.828332901 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:55.828402996 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:55.830501080 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:55.830507040 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:55.830982924 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:55.832679987 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:55.875334978 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.089627028 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.089984894 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:56.090014935 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.090106010 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:56.090136051 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.090230942 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:56.090316057 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.617701054 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.618324041 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:24:56.618379116 CET | 443 | 50006 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:24:56.618540049 CET | 50006 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:09.921099901 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:09.921219110 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:09.921303988 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:09.921678066 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:09.921720982 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:10.825191975 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:10.827286959 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:10.829190016 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:10.829226971 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:10.829479933 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:10.833184958 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:10.879329920 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.086226940 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.086800098 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:11.086899996 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.087222099 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:11.087264061 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.087434053 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:11.087589025 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.620069981 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.623883009 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:11.623976946 CET | 443 | 50007 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:11.624085903 CET | 50007 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:12.879215002 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:12.879286051 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:12.883518934 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:12.887260914 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:12.887286901 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.736113071 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.736213923 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.738112926 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.738143921 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.738419056 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.740801096 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.787333012 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.983131886 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.983549118 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.983598948 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.983694077 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.983716965 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:13.983824968 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:13.983853102 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:14.478497028 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:14.479144096 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:14.479233027 CET | 443 | 50008 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:14.479296923 CET | 50008 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:20.324606895 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:20.324664116 CET | 443 | 50009 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:20.324743032 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:20.325114012 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:20.325128078 CET | 443 | 50009 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:21.887026072 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:21.887083054 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:21.887161970 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:21.887496948 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:21.887511969 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:21.895565987 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:21.943337917 CET | 443 | 50009 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.100167990 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.100220919 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.100334883 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.100663900 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.100676060 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.222816944 CET | 443 | 50009 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.222892046 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.222892046 CET | 50009 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.714456081 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.714545965 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.716258049 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.716274977 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.716519117 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.717889071 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.763328075 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.932245016 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.932533026 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.935209990 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.935216904 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.935456991 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.939353943 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.959779024 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.964127064 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.964164019 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.964329958 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.964354992 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.964534044 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:22.964560032 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:22.987329960 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.174942970 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.175544024 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.175590992 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.175795078 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.175827026 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.175893068 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.175904989 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.175936937 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.175957918 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.478409052 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.478928089 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.478976011 CET | 443 | 50010 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.479083061 CET | 50010 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.844238997 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.859158993 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:23.859231949 CET | 443 | 50011 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:23.859283924 CET | 50011 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.866589069 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.866640091 CET | 443 | 50012 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:36.866703987 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.867063999 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.867075920 CET | 443 | 50012 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:36.907027006 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.907027006 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.907078981 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:36.907618046 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.907618046 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:36.907654047 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:36.951332092 CET | 443 | 50012 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.016014099 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.016056061 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.019542933 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.019857883 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.019875050 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.728774071 CET | 443 | 50012 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.728897095 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.728897095 CET | 50012 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.775027990 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.775134087 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.777045965 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.777069092 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.777348995 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.779201984 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.819346905 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.851335049 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.851440907 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.853229046 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.853240967 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.853478909 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:37.855077982 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:37.899334908 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.032114983 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.032546997 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.032598019 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.032699108 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.032717943 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.032824993 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.032851934 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.095454931 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.096471071 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.096498966 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.096601963 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.096616983 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.096744061 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.096761942 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.561788082 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.562350035 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.562413931 CET | 443 | 50013 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.562465906 CET | 50013 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.595585108 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.596203089 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:38.596252918 CET | 443 | 50014 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:38.596307993 CET | 50014 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:42.636126041 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:42.636178970 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:42.636260033 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:42.636620045 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:42.636634111 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.506953955 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.507038116 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.509234905 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.509257078 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.509493113 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.510924101 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.555330992 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.756247044 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.760864973 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.760894060 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.761310101 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.761334896 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.761850119 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.761872053 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:43.761965990 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:43.761974096 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:44.292728901 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:44.293476105 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:44.293529987 CET | 443 | 50015 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:44.293612957 CET | 50015 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:44.533102989 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:44.533148050 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:44.534164906 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:44.535330057 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:44.535343885 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.400337934 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.400439024 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.402472019 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.402484894 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.402739048 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.404186010 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.447335005 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.655065060 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.655774117 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.655797958 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.656125069 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.656140089 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:45.656269073 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:45.656282902 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:46.176538944 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:46.177293062 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:46.177356958 CET | 443 | 50016 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:46.177470922 CET | 50016 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:51.257383108 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:51.257420063 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:51.257611990 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:51.258081913 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:51.258090973 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.089075089 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.089139938 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.091908932 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.091922998 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.092255116 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.095150948 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.135329962 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.331197023 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.335386992 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.335438013 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.335520029 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.335540056 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.335634947 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.335691929 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.824450970 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.825221062 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:52.825277090 CET | 443 | 50017 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:52.825337887 CET | 50017 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:54.458178997 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:54.458244085 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:54.458311081 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:54.458652020 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:54.458667040 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.294887066 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.295051098 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.297250032 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.297261953 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.297502995 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.298924923 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.343338013 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.535788059 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.536246061 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.536278009 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.536478996 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.536499977 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:55.536695957 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:55.536720037 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:56.024810076 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:56.025468111 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:25:56.025532961 CET | 443 | 50018 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:25:56.025583982 CET | 50018 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:02.555413008 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:02.555471897 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:02.555531979 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:02.556129932 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:02.556145906 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.555665970 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.556473970 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.557557106 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.557574034 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.557832956 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.559436083 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.603334904 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.794444084 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.794723988 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.794748068 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.794755936 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.794764996 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.794919014 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.794933081 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:03.795058012 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:03.795077085 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:04.318983078 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:04.319612980 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:04.319701910 CET | 443 | 50019 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:04.319747925 CET | 50019 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:24.414232969 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:24.414284945 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:24.414385080 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:24.414756060 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:24.414776087 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.271471977 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.275671959 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.278009892 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.278039932 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.278390884 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.279916048 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.323332071 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.525335073 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.525695086 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.525727034 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.525897026 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.525913954 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:25.527429104 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:25.527457952 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:26.040786982 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:26.041373014 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:26.041419983 CET | 443 | 50020 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:26.041465044 CET | 50020 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:39.775917053 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:39.775958061 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:39.777415991 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:39.777714014 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:39.777730942 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.601274014 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.601360083 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.609972000 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.609989882 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.610304117 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.618159056 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.659336090 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.853729963 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.854091883 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.854132891 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.854222059 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.854242086 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:40.854352951 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:40.854384899 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:41.339212894 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:41.341331005 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:41.341384888 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:41.341598034 CET | 443 | 50021 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:41.341676950 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:41.341676950 CET | 50021 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:58.834760904 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:58.834809065 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:58.834882021 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:58.835270882 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:58.835283041 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.689798117 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.689930916 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.691598892 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.691605091 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.691837072 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.695364952 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.739337921 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.943061113 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.943427086 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.943449974 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.947457075 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.947488070 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:26:59.947613001 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:26:59.947632074 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:00.474306107 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:00.474920034 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:00.474980116 CET | 443 | 50022 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:00.475044966 CET | 50022 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.123611927 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.123663902 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:09.123879910 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.127404928 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.127419949 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:09.959738016 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:09.961133003 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.961133003 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:09.961154938 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:09.961393118 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:09.963373899 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Oct 30, 2024 16:27:10.011362076 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:10.201042891 CET | 443 | 50023 | 149.154.167.220 | 192.168.2.4 |
Oct 30, 2024 16:27:10.252953053 CET | 50023 | 443 | 192.168.2.4 | 149.154.167.220 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Oct 30, 2024 16:23:03.010938883 CET | 56252 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 30, 2024 16:23:03.018157959 CET | 53 | 56252 | 1.1.1.1 | 192.168.2.4 |
Oct 30, 2024 16:23:06.124845028 CET | 61438 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 30, 2024 16:23:06.132563114 CET | 53 | 61438 | 1.1.1.1 | 192.168.2.4 |
Oct 30, 2024 16:24:39.415992975 CET | 63537 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 30, 2024 16:24:39.423297882 CET | 53 | 63537 | 1.1.1.1 | 192.168.2.4 |
Oct 30, 2024 16:26:39.766613007 CET | 52765 | 53 | 192.168.2.4 | 1.1.1.1 |
Oct 30, 2024 16:26:39.775151968 CET | 53 | 52765 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Oct 30, 2024 16:23:03.010938883 CET | 192.168.2.4 | 1.1.1.1 | 0xa5e7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 30, 2024 16:23:06.124845028 CET | 192.168.2.4 | 1.1.1.1 | 0x5b99 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 30, 2024 16:24:39.415992975 CET | 192.168.2.4 | 1.1.1.1 | 0x4435 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Oct 30, 2024 16:26:39.766613007 CET | 192.168.2.4 | 1.1.1.1 | 0xb5f3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Oct 30, 2024 16:23:03.018157959 CET | 1.1.1.1 | 192.168.2.4 | 0xa5e7 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 16:23:03.018157959 CET | 1.1.1.1 | 192.168.2.4 | 0xa5e7 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 16:23:03.018157959 CET | 1.1.1.1 | 192.168.2.4 | 0xa5e7 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 16:23:06.132563114 CET | 1.1.1.1 | 192.168.2.4 | 0x5b99 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 16:24:39.423297882 CET | 1.1.1.1 | 192.168.2.4 | 0x4435 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false | ||
Oct 30, 2024 16:26:39.775151968 CET | 1.1.1.1 | 192.168.2.4 | 0xb5f3 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 104.26.12.205 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:23:04 UTC | 155 | OUT | |
2024-10-30 15:23:04 UTC | 211 | IN | |
2024-10-30 15:23:04 UTC | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:23:06 UTC | 260 | OUT | |
2024-10-30 15:23:07 UTC | 25 | IN | |
2024-10-30 15:23:07 UTC | 972 | OUT | |
2024-10-30 15:23:07 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49958 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:24:40 UTC | 238 | OUT | |
2024-10-30 15:24:40 UTC | 25 | IN | |
2024-10-30 15:24:40 UTC | 1024 | OUT | |
2024-10-30 15:24:40 UTC | 16355 | OUT | |
2024-10-30 15:24:40 UTC | 16355 | OUT | |
2024-10-30 15:24:40 UTC | 16355 | OUT | |
2024-10-30 15:24:40 UTC | 15447 | OUT | |
2024-10-30 15:24:40 UTC | 10871 | OUT | |
2024-10-30 15:24:40 UTC | 50 | OUT | |
2024-10-30 15:24:41 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 50006 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:24:55 UTC | 238 | OUT | |
2024-10-30 15:24:56 UTC | 25 | IN | |
2024-10-30 15:24:56 UTC | 1024 | OUT | |
2024-10-30 15:24:56 UTC | 16355 | OUT | |
2024-10-30 15:24:56 UTC | 16355 | OUT | |
2024-10-30 15:24:56 UTC | 16355 | OUT | |
2024-10-30 15:24:56 UTC | 15447 | OUT | |
2024-10-30 15:24:56 UTC | 10871 | OUT | |
2024-10-30 15:24:56 UTC | 50 | OUT | |
2024-10-30 15:24:56 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 50007 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:10 UTC | 262 | OUT | |
2024-10-30 15:25:11 UTC | 25 | IN | |
2024-10-30 15:25:11 UTC | 1024 | OUT | |
2024-10-30 15:25:11 UTC | 16355 | OUT | |
2024-10-30 15:25:11 UTC | 16355 | OUT | |
2024-10-30 15:25:11 UTC | 16355 | OUT | |
2024-10-30 15:25:11 UTC | 15447 | OUT | |
2024-10-30 15:25:11 UTC | 10874 | OUT | |
2024-10-30 15:25:11 UTC | 50 | OUT | |
2024-10-30 15:25:11 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 50008 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:13 UTC | 262 | OUT | |
2024-10-30 15:25:13 UTC | 25 | IN | |
2024-10-30 15:25:13 UTC | 1024 | OUT | |
2024-10-30 15:25:13 UTC | 16355 | OUT | |
2024-10-30 15:25:13 UTC | 16355 | OUT | |
2024-10-30 15:25:13 UTC | 16355 | OUT | |
2024-10-30 15:25:13 UTC | 15447 | OUT | |
2024-10-30 15:25:13 UTC | 10874 | OUT | |
2024-10-30 15:25:13 UTC | 50 | OUT | |
2024-10-30 15:25:14 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 50010 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:22 UTC | 262 | OUT | |
2024-10-30 15:25:22 UTC | 25 | IN | |
2024-10-30 15:25:22 UTC | 1024 | OUT | |
2024-10-30 15:25:22 UTC | 16355 | OUT | |
2024-10-30 15:25:22 UTC | 16355 | OUT | |
2024-10-30 15:25:22 UTC | 16355 | OUT | |
2024-10-30 15:25:22 UTC | 15447 | OUT | |
2024-10-30 15:25:22 UTC | 10923 | OUT | |
2024-10-30 15:25:22 UTC | 50 | OUT | |
2024-10-30 15:25:23 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 50011 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:22 UTC | 262 | OUT | |
2024-10-30 15:25:23 UTC | 25 | IN | |
2024-10-30 15:25:23 UTC | 1024 | OUT | |
2024-10-30 15:25:23 UTC | 16355 | OUT | |
2024-10-30 15:25:23 UTC | 16355 | OUT | |
2024-10-30 15:25:23 UTC | 16355 | OUT | |
2024-10-30 15:25:23 UTC | 15447 | OUT | |
2024-10-30 15:25:23 UTC | 11251 | OUT | |
2024-10-30 15:25:23 UTC | 50 | OUT | |
2024-10-30 15:25:23 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 50013 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:37 UTC | 262 | OUT | |
2024-10-30 15:25:38 UTC | 25 | IN | |
2024-10-30 15:25:38 UTC | 1024 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 15447 | OUT | |
2024-10-30 15:25:38 UTC | 10874 | OUT | |
2024-10-30 15:25:38 UTC | 50 | OUT | |
2024-10-30 15:25:38 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 50014 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:37 UTC | 262 | OUT | |
2024-10-30 15:25:38 UTC | 25 | IN | |
2024-10-30 15:25:38 UTC | 1024 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 16355 | OUT | |
2024-10-30 15:25:38 UTC | 15447 | OUT | |
2024-10-30 15:25:38 UTC | 10874 | OUT | |
2024-10-30 15:25:38 UTC | 50 | OUT | |
2024-10-30 15:25:38 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 50015 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:43 UTC | 238 | OUT | |
2024-10-30 15:25:43 UTC | 25 | IN | |
2024-10-30 15:25:43 UTC | 1024 | OUT | |
2024-10-30 15:25:43 UTC | 16355 | OUT | |
2024-10-30 15:25:43 UTC | 16355 | OUT | |
2024-10-30 15:25:43 UTC | 16355 | OUT | |
2024-10-30 15:25:43 UTC | 15447 | OUT | |
2024-10-30 15:25:43 UTC | 15854 | OUT | |
2024-10-30 15:25:43 UTC | 50 | OUT | |
2024-10-30 15:25:44 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 50016 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:45 UTC | 262 | OUT | |
2024-10-30 15:25:45 UTC | 25 | IN | |
2024-10-30 15:25:45 UTC | 1024 | OUT | |
2024-10-30 15:25:45 UTC | 16355 | OUT | |
2024-10-30 15:25:45 UTC | 16355 | OUT | |
2024-10-30 15:25:45 UTC | 16355 | OUT | |
2024-10-30 15:25:45 UTC | 15447 | OUT | |
2024-10-30 15:25:45 UTC | 10874 | OUT | |
2024-10-30 15:25:45 UTC | 50 | OUT | |
2024-10-30 15:25:46 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 50017 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:52 UTC | 262 | OUT | |
2024-10-30 15:25:52 UTC | 25 | IN | |
2024-10-30 15:25:52 UTC | 1024 | OUT | |
2024-10-30 15:25:52 UTC | 16355 | OUT | |
2024-10-30 15:25:52 UTC | 16355 | OUT | |
2024-10-30 15:25:52 UTC | 16355 | OUT | |
2024-10-30 15:25:52 UTC | 15447 | OUT | |
2024-10-30 15:25:52 UTC | 10874 | OUT | |
2024-10-30 15:25:52 UTC | 50 | OUT | |
2024-10-30 15:25:52 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 50018 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:25:55 UTC | 262 | OUT | |
2024-10-30 15:25:55 UTC | 25 | IN | |
2024-10-30 15:25:55 UTC | 1024 | OUT | |
2024-10-30 15:25:55 UTC | 16355 | OUT | |
2024-10-30 15:25:55 UTC | 16355 | OUT | |
2024-10-30 15:25:55 UTC | 16355 | OUT | |
2024-10-30 15:25:55 UTC | 15447 | OUT | |
2024-10-30 15:25:55 UTC | 10874 | OUT | |
2024-10-30 15:25:55 UTC | 50 | OUT | |
2024-10-30 15:25:56 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 50019 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:26:03 UTC | 262 | OUT | |
2024-10-30 15:26:03 UTC | 25 | IN | |
2024-10-30 15:26:03 UTC | 1024 | OUT | |
2024-10-30 15:26:03 UTC | 16355 | OUT | |
2024-10-30 15:26:03 UTC | 16355 | OUT | |
2024-10-30 15:26:03 UTC | 16355 | OUT | |
2024-10-30 15:26:03 UTC | 15447 | OUT | |
2024-10-30 15:26:03 UTC | 10892 | OUT | |
2024-10-30 15:26:03 UTC | 50 | OUT | |
2024-10-30 15:26:04 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 50020 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:26:25 UTC | 262 | OUT | |
2024-10-30 15:26:25 UTC | 25 | IN | |
2024-10-30 15:26:25 UTC | 1024 | OUT | |
2024-10-30 15:26:25 UTC | 16355 | OUT | |
2024-10-30 15:26:25 UTC | 16355 | OUT | |
2024-10-30 15:26:25 UTC | 16355 | OUT | |
2024-10-30 15:26:25 UTC | 15447 | OUT | |
2024-10-30 15:26:25 UTC | 10892 | OUT | |
2024-10-30 15:26:25 UTC | 50 | OUT | |
2024-10-30 15:26:26 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 50021 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:26:40 UTC | 262 | OUT | |
2024-10-30 15:26:40 UTC | 25 | IN | |
2024-10-30 15:26:40 UTC | 1024 | OUT | |
2024-10-30 15:26:40 UTC | 16355 | OUT | |
2024-10-30 15:26:40 UTC | 16355 | OUT | |
2024-10-30 15:26:40 UTC | 16355 | OUT | |
2024-10-30 15:26:40 UTC | 15447 | OUT | |
2024-10-30 15:26:40 UTC | 10892 | OUT | |
2024-10-30 15:26:40 UTC | 50 | OUT | |
2024-10-30 15:26:41 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 50022 | 149.154.167.220 | 443 | 1344 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:26:59 UTC | 262 | OUT | |
2024-10-30 15:26:59 UTC | 25 | IN | |
2024-10-30 15:26:59 UTC | 1024 | OUT | |
2024-10-30 15:26:59 UTC | 16355 | OUT | |
2024-10-30 15:26:59 UTC | 16355 | OUT | |
2024-10-30 15:26:59 UTC | 16355 | OUT | |
2024-10-30 15:26:59 UTC | 15447 | OUT | |
2024-10-30 15:26:59 UTC | 10892 | OUT | |
2024-10-30 15:26:59 UTC | 50 | OUT | |
2024-10-30 15:27:00 UTC | 402 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
18 | 192.168.2.4 | 50023 | 149.154.167.220 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-10-30 15:27:09 UTC | 262 | OUT | |
2024-10-30 15:27:10 UTC | 25 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:23:01 |
Start date: | 30/10/2024 |
Path: | C:\Users\user\Desktop\SecuriteInfo.com.Win32.PWSX-gen.31738.17793.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x90000 |
File size: | 860'672 bytes |
MD5 hash: | 34F978912D45CE5DF9309990ECFB0232 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:23:01 |
Start date: | 30/10/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x900000 |
File size: | 46'832 bytes |
MD5 hash: | 70D838A7DC5B359C3F938A71FAD77DB0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:23:01 |
Start date: | 30/10/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\cvtres.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x900000 |
File size: | 46'832 bytes |
MD5 hash: | 70D838A7DC5B359C3F938A71FAD77DB0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
Has exited: | false |
Execution Graph
Execution Coverage: | 19.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 6.7% |
Total number of Nodes: | 60 |
Total number of Limit Nodes: | 0 |
Graph
Function 00982414 Relevance: 4.0, Strings: 3, Instructions: 290COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009824A8 Relevance: 4.0, Strings: 3, Instructions: 251COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00980A88 Relevance: 2.6, Strings: 2, Instructions: 63COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00984650 Relevance: 1.6, Strings: 1, Instructions: 302COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A825 Relevance: 1.4, Strings: 1, Instructions: 133COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00982DD0 Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00983791 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A190 Relevance: 7.3, APIs: 1, Strings: 3, Instructions: 321processCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989B70 Relevance: 1.6, APIs: 1, Instructions: 129threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989F58 Relevance: 1.6, APIs: 1, Instructions: 111COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989F60 Relevance: 1.6, APIs: 1, Instructions: 106COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989CE8 Relevance: 1.6, APIs: 1, Instructions: 101memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989BC0 Relevance: 1.6, APIs: 1, Instructions: 94threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00989498 Relevance: 1.6, APIs: 1, Instructions: 78threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009894A0 Relevance: 1.6, APIs: 1, Instructions: 73threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009855C0 Relevance: 2.7, Strings: 2, Instructions: 180COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009869D0 Relevance: 2.6, Strings: 2, Instructions: 145COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A620 Relevance: 1.4, Strings: 1, Instructions: 162COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A610 Relevance: 1.4, Strings: 1, Instructions: 158COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009869C0 Relevance: 1.4, Strings: 1, Instructions: 154COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A893 Relevance: 1.4, Strings: 1, Instructions: 128COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A877 Relevance: 1.4, Strings: 1, Instructions: 120COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098A818 Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0098730A Relevance: .2, Instructions: 209COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00987328 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00981868 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00986418 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009878F8 Relevance: .2, Instructions: 152COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00986798 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00988A68 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 2 |
Graph
Function 06A53050 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A57D68 Relevance: 3.0, Strings: 2, Instructions: 476COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A55598 Relevance: 1.8, Strings: 1, Instructions: 599COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A52351 Relevance: 1.0, Instructions: 995COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A565E0 Relevance: .8, Instructions: 823COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5C178 Relevance: .6, Instructions: 646COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5B210 Relevance: .6, Instructions: 571COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5ACB8 Relevance: 10.4, Strings: 8, Instructions: 397COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5B640 Relevance: 8.0, Strings: 6, Instructions: 472COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A59138 Relevance: 5.2, Strings: 4, Instructions: 230COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5CF38 Relevance: 4.6, Strings: 3, Instructions: 802COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A54B60 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5912D Relevance: 2.7, Strings: 2, Instructions: 159COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A54B50 Relevance: 2.6, Strings: 2, Instructions: 144COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0136EBF8 Relevance: 1.6, APIs: 1, Instructions: 139COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0136ECE0 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5DAAD Relevance: 1.4, Strings: 1, Instructions: 124COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A521D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A582B8 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A561D8 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A54291 Relevance: .2, Instructions: 225COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A545B0 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A545C8 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5EB00 Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5EB10 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5FB9F Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5F960 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A55409 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A55588 Relevance: .1, Instructions: 128COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A52090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5208D Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53A90 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53AA0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD20C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD044 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD3BC Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53BB0 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A541F0 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53BA0 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53868 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5ED81 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD207 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD03F Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 012CD3B7 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A53870 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A54200 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5ED90 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5A300 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5A2FD Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A56460 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A57688 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5A920 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A57088 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A583C0 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A587D8 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A5ACAE Relevance: 5.2, Strings: 4, Instructions: 161COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|