Windows
Analysis Report
Payslip_October_2024.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Payslip_October_2024.exe (PID: 7532 cmdline:
"C:\Users\ user\Deskt op\Payslip _October_2 024.exe" MD5: A0DADB7997E2B13144275B1C164F1C84) - Payslip_October_2024.exe (PID: 7692 cmdline:
"C:\Users\ user\Deskt op\Payslip _October_2 024.exe" MD5: A0DADB7997E2B13144275B1C164F1C84)
- sgxIb.exe (PID: 7952 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: A0DADB7997E2B13144275B1C164F1C84) - sgxIb.exe (PID: 8000 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: A0DADB7997E2B13144275B1C164F1C84) - sgxIb.exe (PID: 8008 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: A0DADB7997E2B13144275B1C164F1C84)
- sgxIb.exe (PID: 7324 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: A0DADB7997E2B13144275B1C164F1C84) - sgxIb.exe (PID: 6128 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: A0DADB7997E2B13144275B1C164F1C84)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.haliza.com.my", "Username": "origin@haliza.com.my", "Password": "JesusChrist007$"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
Click to see the 18 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 17 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T21:25:12.909275+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.4 | 49742 | TCP |
2024-11-04T21:25:52.030022+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.4 | 49755 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T21:25:13.322096+0100 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-11-04T21:25:22.350303+0100 | 2029927 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T21:25:14.233376+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 52210 | TCP |
2024-11-04T21:25:14.238674+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 110.4.45.197 | 52210 | TCP |
2024-11-04T21:25:23.295388+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 110.4.45.197 | 54816 | TCP |
2024-11-04T21:25:23.301069+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 110.4.45.197 | 54816 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Code function: | 0_2_0E584845 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic: |
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Windows user hook set: | Jump to behavior | ||
Source: | Windows user hook set: |
Source: | Window created: | Jump to behavior | ||
Source: | Window created: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_074A6730 | |
Source: | Code function: | 0_2_074AD5E0 | |
Source: | Code function: | 0_2_074A5460 | |
Source: | Code function: | 0_2_074A02B0 | |
Source: | Code function: | 0_2_074A9A58 | |
Source: | Code function: | 0_2_074AF620 | |
Source: | Code function: | 0_2_074A02A0 | |
Source: | Code function: | 0_2_074A9CD7 | |
Source: | Code function: | 0_2_074A9CE8 | |
Source: | Code function: | 0_2_074A9A49 | |
Source: | Code function: | 0_2_074A8A38 | |
Source: | Code function: | 0_2_0E5868D8 | |
Source: | Code function: | 0_2_0E5827D0 | |
Source: | Code function: | 0_2_0E5827C0 | |
Source: | Code function: | 0_2_0E580C70 | |
Source: | Code function: | 0_2_0E580C60 | |
Source: | Code function: | 0_2_0E5814E0 | |
Source: | Code function: | 0_2_0E580838 | |
Source: | Code function: | 0_2_0E58109A | |
Source: | Code function: | 0_2_0E5810A8 | |
Source: | Code function: | 2_2_00C7E9F8 | |
Source: | Code function: | 2_2_00C74A68 | |
Source: | Code function: | 2_2_00C7AD90 | |
Source: | Code function: | 2_2_00C73E50 | |
Source: | Code function: | 2_2_00C74198 | |
Source: | Code function: | 2_2_04FB1550 | |
Source: | Code function: | 2_2_04FB1540 | |
Source: | Code function: | 2_2_0562C76C | |
Source: | Code function: | 2_2_056255E3 | |
Source: | Code function: | 2_2_056255E8 | |
Source: | Code function: | 2_2_066256A8 | |
Source: | Code function: | 2_2_06627E90 | |
Source: | Code function: | 2_2_06626700 | |
Source: | Code function: | 2_2_06623578 | |
Source: | Code function: | 2_2_0662B342 | |
Source: | Code function: | 2_2_06622710 | |
Source: | Code function: | 2_2_066277B0 | |
Source: | Code function: | 2_2_0662E4C8 | |
Source: | Code function: | 2_2_06625DF7 | |
Source: | Code function: | 2_2_06620040 | |
Source: | Code function: | 2_2_0662003E | |
Source: | Code function: | 3_2_05A1D5E0 | |
Source: | Code function: | 3_2_05A15460 | |
Source: | Code function: | 3_2_05A16730 | |
Source: | Code function: | 3_2_05A102B0 | |
Source: | Code function: | 3_2_05A1F620 | |
Source: | Code function: | 3_2_05A102A0 | |
Source: | Code function: | 3_2_05A19CE8 | |
Source: | Code function: | 3_2_05A19CD7 | |
Source: | Code function: | 3_2_05A18A38 | |
Source: | Code function: | 3_2_05A19A49 | |
Source: | Code function: | 3_2_05A19A58 | |
Source: | Code function: | 3_2_070169D0 | |
Source: | Code function: | 3_2_070127C0 | |
Source: | Code function: | 3_2_070127D0 | |
Source: | Code function: | 3_2_07010C60 | |
Source: | Code function: | 3_2_07010C70 | |
Source: | Code function: | 3_2_070114E0 | |
Source: | Code function: | 3_2_07010838 | |
Source: | Code function: | 3_2_070110A8 | |
Source: | Code function: | 5_2_02984A68 | |
Source: | Code function: | 5_2_0298E8A0 | |
Source: | Code function: | 5_2_02983E50 | |
Source: | Code function: | 5_2_0298AC80 | |
Source: | Code function: | 5_2_02984198 | |
Source: | Code function: | 5_2_06841800 | |
Source: | Code function: | 5_2_06857E98 | |
Source: | Code function: | 5_2_068556B0 | |
Source: | Code function: | 5_2_06856708 | |
Source: | Code function: | 5_2_06853580 | |
Source: | Code function: | 5_2_06850040 | |
Source: | Code function: | 5_2_06855E10 | |
Source: | Code function: | 5_2_068577B8 | |
Source: | Code function: | 5_2_0685E4D0 | |
Source: | Code function: | 5_2_06850007 | |
Source: | Code function: | 7_2_06E968D8 | |
Source: | Code function: | 7_2_06E927C0 | |
Source: | Code function: | 7_2_06E927D0 | |
Source: | Code function: | 7_2_06E914E0 | |
Source: | Code function: | 7_2_06E90C60 | |
Source: | Code function: | 7_2_06E90C70 | |
Source: | Code function: | 7_2_06E910A8 | |
Source: | Code function: | 7_2_06E90838 | |
Source: | Code function: | 8_2_00FEC514 | |
Source: | Code function: | 8_2_00FEE8A0 | |
Source: | Code function: | 8_2_00FE4A68 | |
Source: | Code function: | 8_2_00FE3E50 | |
Source: | Code function: | 8_2_00FE4198 | |
Source: | Code function: | 8_2_06857E98 | |
Source: | Code function: | 8_2_068556B0 | |
Source: | Code function: | 8_2_06856708 | |
Source: | Code function: | 8_2_06853580 | |
Source: | Code function: | 8_2_06850040 | |
Source: | Code function: | 8_2_068577B8 | |
Source: | Code function: | 8_2_0685E4D0 | |
Source: | Code function: | 8_2_06855DFF | |
Source: | Code function: | 8_2_0685001D |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 2_2_00C70C7A | |
Source: | Code function: | 2_2_04FB2348 | |
Source: | Code function: | 2_2_0562ECC0 | |
Source: | Code function: | 5_2_0298F7D1 | |
Source: | Code function: | 8_2_00FEF7D1 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | |||
Source: | Window / User API: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: |
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: | ||
Source: | File opened: |
Source: | File opened: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | File opened: | |||
Source: | File opened: | |||
Source: | Key opened: | |||
Source: | Key opened: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 112 Process Injection | 1 Deobfuscate/Decode Files or Information | 21 Input Capture | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 Registry Run Keys / Startup Folder | 3 Obfuscated Files or Information | 1 Credentials in Registry | 1 Query Registry | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 12 Software Packing | NTDS | 211 Security Software Discovery | Distributed Component Object Model | 21 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 2 Process Discovery | SSH | 1 Clipboard Data | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 141 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 112 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Hidden Files and Directories | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
32% | ReversingLabs | Win32.Trojan.Generic | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
32% | ReversingLabs | Win32.Trojan.AgentTesla |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.12.205 | true | false | high | |
ftp.haliza.com.my | 110.4.45.197 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.26.12.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false | |
110.4.45.197 | ftp.haliza.com.my | Malaysia | 46015 | EXABYTES-AS-APExaBytesNetworkSdnBhdMY | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1548796 |
Start date and time: | 2024-11-04 21:24:03 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 12 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Payslip_October_2024.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@11/4@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: Payslip_October_2024.exe
Time | Type | Description |
---|---|---|
15:24:52 | API Interceptor | |
15:25:06 | API Interceptor | |
20:24:57 | Autostart | |
20:25:06 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
104.26.12.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
110.4.45.197 | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | Discord Token Stealer | Browse |
| |
Get hash | malicious | Discord Token Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
ftp.haliza.com.my | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC, Stealc, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
EXABYTES-AS-APExaBytesNetworkSdnBhdMY | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Outlook Phishing, HTMLPhisher | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Flesh Stealer | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
|
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0_32\UsageLogs\Payslip_October_2024.exe.log
Download File
Process: | C:\Users\user\Desktop\Payslip_October_2024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\Payslip_October_2024.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 800256 |
Entropy (8bit): | 7.728157439911338 |
Encrypted: | false |
SSDEEP: | 12288:hM3ZJZEkrV/BUNWGlWblcCSU+gXsT3Srkezl4VQRv7P9vZPqWeQh:eL5yWEWbl5LcT36zuVm7lvZPVh |
MD5: | A0DADB7997E2B13144275B1C164F1C84 |
SHA1: | 6F63137C9A20C05C04B53EAEA60EAE9355022A97 |
SHA-256: | 7602098A6B2A95CA014488CE7C67B273A6189D7CC4DAA09FB639C32FC21AFA99 |
SHA-512: | 62EFF8465B244C5550DB674C7F49E0EDDE9F127816A735D331F53CA8988631629C9BFE9366742F121FA40B45C1928E3B80B6F0077B2604F636CBF5BA38BBE4AB |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\Payslip_October_2024.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.728157439911338 |
TrID: |
|
File name: | Payslip_October_2024.exe |
File size: | 800'256 bytes |
MD5: | a0dadb7997e2b13144275b1c164f1c84 |
SHA1: | 6f63137c9a20c05c04b53eaea60eae9355022a97 |
SHA256: | 7602098a6b2a95ca014488ce7c67b273a6189d7cc4daa09fb639c32fc21afa99 |
SHA512: | 62eff8465b244c5550db674c7f49e0edde9f127816a735d331f53ca8988631629c9bfe9366742f121fa40b45c1928e3b80b6f0077b2604f636cbf5ba38bbe4ab |
SSDEEP: | 12288:hM3ZJZEkrV/BUNWGlWblcCSU+gXsT3Srkezl4VQRv7P9vZPqWeQh:eL5yWEWbl5LcT36zuVm7lvZPVh |
TLSH: | F505DFD03B36B719DE695A74D659DDB582F11AA8B101FAE31ADC3B53388C3219E0CF42 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....(g..............0..&...........D... ...`....@.. ....................................@................................ |
Icon Hash: | 26ccd9ddd9dddda0 |
Entrypoint: | 0x4c44ea |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6728E5A9 [Mon Nov 4 15:18:01 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc4498 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc6000 | 0xba0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xc8000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xc24f0 | 0xc2600 | 90e11eb56940eae5925d8612f07fcde5 | False | 0.8751444433279743 | data | 7.734734914632359 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc6000 | 0xba0 | 0xc00 | 283aa62e151331db0322a689c7ae8750 | False | 0.4641927083333333 | data | 5.918595339968432 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xc8000 | 0xc | 0x200 | 5377fd2afd5411ef46a5727c22edd3a8 | False | 0.044921875 | data | 0.09800417566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xc60c8 | 0x7c3 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.5123301459486663 | ||
RT_GROUP_ICON | 0xc689c | 0x14 | data | 1.05 | ||
RT_VERSION | 0xc68c0 | 0x2da | data | 0.4506849315068493 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-04T21:25:12.909275+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.4 | 49742 | TCP |
2024-11-04T21:25:13.322096+0100 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49741 | 110.4.45.197 | 21 | TCP |
2024-11-04T21:25:14.233376+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 52210 | TCP |
2024-11-04T21:25:14.238674+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49746 | 110.4.45.197 | 52210 | TCP |
2024-11-04T21:25:22.350303+0100 | 2029927 | ET MALWARE AgentTesla Exfil via FTP | 1 | 192.168.2.4 | 49751 | 110.4.45.197 | 21 | TCP |
2024-11-04T21:25:23.295388+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49752 | 110.4.45.197 | 54816 | TCP |
2024-11-04T21:25:23.301069+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.4 | 49752 | 110.4.45.197 | 54816 | TCP |
2024-11-04T21:25:52.030022+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.4 | 49755 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 4, 2024 21:24:55.527642012 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:55.527683020 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:55.527760029 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:55.533924103 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:55.533937931 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.156689882 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.156786919 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:56.159403086 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:56.159413099 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.159626961 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.211335897 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:56.214478016 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:56.259335041 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.396697044 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.396761894 CET | 443 | 49733 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:24:56.396802902 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:56.406963110 CET | 49733 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:24:57.172457933 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:57.178833008 CET | 21 | 49734 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:57.178906918 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:57.181943893 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:57.188072920 CET | 21 | 49734 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:57.188191891 CET | 49734 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:57.209469080 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:57.214432955 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:57.214519978 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:58.145982981 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:58.149497032 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:58.154443026 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:58.498543024 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:58.498661041 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:58.503539085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:58.877778053 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:58.877887011 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:58.883068085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.228914022 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.229027987 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:59.235553980 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.579032898 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.579164982 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:59.584208965 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.928574085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:24:59.928759098 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:24:59.933819056 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:00.277859926 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:00.280299902 CET | 49738 | 49239 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:00.285224915 CET | 49239 | 49738 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:00.285345078 CET | 49738 | 49239 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:00.285343885 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:00.290321112 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.185388088 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.188746929 CET | 49738 | 49239 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.188786030 CET | 49738 | 49239 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.193861008 CET | 49239 | 49738 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.193898916 CET | 49239 | 49738 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.194161892 CET | 49239 | 49738 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.196033955 CET | 49239 | 49738 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.196085930 CET | 49738 | 49239 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.226983070 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.533375978 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.533736944 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.538949013 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.884216070 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.884578943 CET | 49739 | 63989 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.889532089 CET | 63989 | 49739 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:01.889624119 CET | 49739 | 63989 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.889717102 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:01.895145893 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:02.811544895 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:02.811722994 CET | 49739 | 63989 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:02.817255974 CET | 63989 | 49739 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:02.817313910 CET | 49739 | 63989 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:02.851970911 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:03.163824081 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:03.212147951 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:08.294945002 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:08.295022011 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:08.295094013 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:08.298239946 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:08.298276901 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:08.912060976 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:08.912182093 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:08.913573027 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:08.913599014 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:08.913880110 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:08.966228962 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:09.007354021 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:09.145492077 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:09.145559072 CET | 443 | 49740 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:09.146796942 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:09.149893045 CET | 49740 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:10.244138002 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:10.250215054 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:10.250303984 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:11.196496010 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:11.206302881 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:11.211330891 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:11.551081896 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:11.551650047 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:11.558927059 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:11.926958084 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:11.927092075 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:11.931963921 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.271320105 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.271470070 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:12.276504993 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.627825975 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.628004074 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:12.632769108 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.971760988 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:12.971892118 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:12.976646900 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:13.316006899 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:13.316637993 CET | 49746 | 52210 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:13.321974039 CET | 52210 | 49746 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:13.322031021 CET | 49746 | 52210 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:13.322096109 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:13.327677965 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.233009100 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.233376026 CET | 49746 | 52210 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:14.233419895 CET | 49746 | 52210 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:14.238198042 CET | 52210 | 49746 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.238617897 CET | 52210 | 49746 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.238673925 CET | 49746 | 52210 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:14.273894072 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:14.812055111 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.813723087 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:14.813807011 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:15.089061975 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:15.093981981 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:15.433594942 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:15.433974028 CET | 49748 | 64457 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:15.439146996 CET | 64457 | 49748 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:15.439227104 CET | 49748 | 64457 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:15.439353943 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:15.444212914 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:16.548047066 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:16.548079014 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:16.548146963 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:16.551259041 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:16.551273108 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:17.385520935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:17.385582924 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:17.385644913 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:17.385813951 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:17.385921001 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:17.386035919 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:17.386354923 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:17.483439922 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:17.483498096 CET | 49748 | 64457 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:17.985162020 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:17.985272884 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:18.071252108 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:18.071279049 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:18.071614981 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:18.117788076 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:18.460254908 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:18.507337093 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:18.643800974 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:18.643872023 CET | 443 | 49750 | 104.26.12.205 | 192.168.2.4 |
Nov 4, 2024 21:25:18.644088030 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:18.648585081 CET | 49750 | 443 | 192.168.2.4 | 104.26.12.205 |
Nov 4, 2024 21:25:19.230648041 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:19.235605955 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:19.235682011 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:20.177556992 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:20.180557966 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:20.187156916 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:20.532474995 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:20.536825895 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:20.541747093 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:20.914602041 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:20.914763927 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:20.919826984 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.268820047 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.269021988 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:21.274319887 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.639569998 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.639883041 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:21.644867897 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.991764069 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:21.992010117 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:21.996855974 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:22.344014883 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:22.344866037 CET | 49752 | 54816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:22.350110054 CET | 54816 | 49752 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:22.350241899 CET | 49752 | 54816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:22.350302935 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:22.355935097 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:23.295093060 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:23.295387983 CET | 49752 | 54816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:23.295429945 CET | 49752 | 54816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:23.300520897 CET | 54816 | 49752 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:23.301002979 CET | 54816 | 49752 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:23.301069021 CET | 49752 | 54816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:23.336467028 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:23.654500961 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:23.678637981 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:23.683963060 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.031280041 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.031840086 CET | 49753 | 59440 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:24.037142992 CET | 59440 | 49753 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.037254095 CET | 49753 | 59440 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:24.037296057 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:24.042269945 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.978235006 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.978447914 CET | 49753 | 59440 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:24.978449106 CET | 49753 | 59440 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:24.983552933 CET | 59440 | 49753 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.983616114 CET | 59440 | 49753 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.983632088 CET | 59440 | 49753 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.984672070 CET | 59440 | 49753 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:24.984729052 CET | 49753 | 59440 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.023899078 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.331723928 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:25.332184076 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.337414980 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:25.686129093 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:25.686661959 CET | 49754 | 57287 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.692924976 CET | 57287 | 49754 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:25.693010092 CET | 49754 | 57287 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.693078041 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:25.698853016 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:26.639322042 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:26.639621973 CET | 49754 | 57287 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:26.645237923 CET | 57287 | 49754 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:26.645299911 CET | 49754 | 57287 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:26.680185080 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:25:26.984440088 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:25:27.039566040 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:27.785145044 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:27.790132999 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:27.859034061 CET | 49933 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:27.864330053 CET | 21 | 49933 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:27.864409924 CET | 49933 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:27.864694118 CET | 49933 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:27.870354891 CET | 21 | 49933 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:27.870398998 CET | 49933 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:28.134579897 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:28.135178089 CET | 49935 | 58004 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:28.140201092 CET | 58004 | 49935 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:28.140311956 CET | 49935 | 58004 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:28.140477896 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:28.145438910 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:29.055278063 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:29.055563927 CET | 49935 | 58004 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:29.055592060 CET | 49935 | 58004 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:29.060450077 CET | 58004 | 49935 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:29.062361956 CET | 58004 | 49935 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:29.062407017 CET | 49935 | 58004 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:29.102153063 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:29.404416084 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:29.445883036 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:32.110491037 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:32.115453959 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:32.459836006 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:32.460699081 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:32.469028950 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:32.469204903 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:32.469227076 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:32.474154949 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.367384911 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.367645979 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.372716904 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.372728109 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.372785091 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.372814894 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.372826099 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.372859955 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.372889042 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.372900009 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.372941971 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.373048067 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.373059034 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.373090029 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.373106956 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.373136044 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.373166084 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.373178959 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.373208046 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.373250961 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.373292923 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379329920 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379352093 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379393101 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379393101 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379404068 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379420996 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379441977 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379487038 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379549980 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379565954 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379584074 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379592896 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.379604101 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379646063 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.379673004 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.380075932 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.380127907 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.384545088 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.384706974 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.384753942 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.384829044 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.384973049 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385057926 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385070086 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385080099 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385145903 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385189056 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385274887 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385287046 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385303020 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385320902 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385374069 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385385036 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.385409117 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.390908957 CET | 56495 | 49960 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:33.390954971 CET | 49960 | 56495 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:33.414638996 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:34.121799946 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:34.180377007 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:42.923118114 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:42.928118944 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:43.272464037 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:43.273071051 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:43.278577089 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:43.278724909 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:43.278801918 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:43.283845901 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.220077038 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.220370054 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225460052 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225529909 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225529909 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225545883 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225558043 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225572109 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225581884 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225615978 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225617886 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225657940 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225660086 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225673914 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225698948 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225699902 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225713968 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225740910 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.225775003 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.225816965 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230607986 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230654955 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230670929 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230674028 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230699062 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230705023 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230726004 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230736971 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230778933 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230822086 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230860949 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230875015 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.230906963 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230926991 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.230966091 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.231024981 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.231215954 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.231266975 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.235867023 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.235976934 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236017942 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236190081 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236238956 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236274958 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236377001 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236391068 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236416101 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236483097 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236498117 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236510992 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236524105 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236588001 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236603022 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236615896 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.236638069 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.237298965 CET | 57997 | 50018 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.237377882 CET | 50018 | 57997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.289643049 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.641707897 CET | 50023 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.647551060 CET | 21 | 50023 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.647639990 CET | 50023 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.647826910 CET | 50023 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:44.652883053 CET | 21 | 50023 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:44.652935982 CET | 50023 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:45.020203114 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:45.088752031 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:51.670495033 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:51.675405979 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.019615889 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.020286083 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.025171041 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.025238991 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.025342941 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.030245066 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.943694115 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.944009066 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949037075 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949125051 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949135065 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949153900 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949179888 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949203968 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949213982 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949223995 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949248075 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949273109 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949282885 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949354887 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949364901 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949373960 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949383974 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.949398041 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949424028 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.949424028 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954066038 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954116106 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954118013 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954161882 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954277992 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954288006 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954296112 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954304934 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.954319000 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954354048 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954354048 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.954969883 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.955030918 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.955566883 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.955626965 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.959258080 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.959311008 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.959323883 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.959362984 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.959419966 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.959460020 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.960189104 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.960237026 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:52.960258961 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.960514069 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.961163044 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.964343071 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.964363098 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.964493036 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.965082884 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.965092897 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.966165066 CET | 61072 | 50026 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:52.966214895 CET | 50026 | 61072 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:53.088542938 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:53.722090960 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:53.792846918 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.060810089 CET | 50027 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.066885948 CET | 21 | 50027 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:56.066970110 CET | 50027 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.070226908 CET | 50027 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.077003002 CET | 21 | 50027 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:56.077083111 CET | 50027 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.157516956 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.163002968 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:56.507267952 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:56.507849932 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.512981892 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:56.513071060 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.513139009 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:56.518682957 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.422035933 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.423206091 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.428293943 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428347111 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428356886 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428375959 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428385973 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428395033 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428432941 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.428440094 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428459883 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.428469896 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428484917 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428502083 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.428599119 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.428713083 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.428925037 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.433453083 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433526993 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433540106 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433547974 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433557034 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433571100 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.433619976 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.433686972 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.433820009 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.434087038 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.434191942 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.438599110 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.438762903 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.438987017 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.439068079 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.439088106 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.439261913 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.439929008 CET | 63370 | 50028 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:57.441179037 CET | 50028 | 63370 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:57.494576931 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:26:58.176453114 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:26:58.289685011 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:02.209230900 CET | 50029 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:02.214783907 CET | 21 | 50029 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:02.214869976 CET | 50029 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:02.215329885 CET | 50029 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:02.220307112 CET | 21 | 50029 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:02.220367908 CET | 50029 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:10.904073954 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:10.909151077 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:11.253354073 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:11.253901958 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:11.258809090 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:11.262634993 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:11.262636900 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:11.267632008 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.201129913 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.201467991 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.206707954 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206768036 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206778049 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206788063 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206809998 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206820965 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206820011 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.206831932 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206841946 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206845999 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.206856012 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.206898928 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.206935883 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.207055092 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.207094908 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.211889982 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.211941957 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.211951971 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.211952925 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.211962938 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.211971998 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.211991072 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.212028027 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.212078094 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.212086916 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.212126017 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.212162971 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.212271929 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.212330103 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.217722893 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.218266010 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.219208002 CET | 52997 | 50030 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:12.219332933 CET | 50030 | 52997 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.289716959 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:12.980257988 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:13.180394888 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.153726101 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.160250902 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.517566919 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.518552065 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.523463964 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.523608923 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.523673058 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.528733015 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.845097065 CET | 50032 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.850440025 CET | 21 | 50032 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.852694035 CET | 50032 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.856864929 CET | 50032 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:19.861867905 CET | 21 | 50032 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:19.864717007 CET | 50032 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.061707973 CET | 50033 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.067055941 CET | 21 | 50033 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.067130089 CET | 50033 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.067466021 CET | 50033 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.072511911 CET | 21 | 50033 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.072571039 CET | 50033 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.464711905 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.464972973 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470247984 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470261097 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470273972 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470283985 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470313072 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470336914 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470367908 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470635891 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470647097 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470657110 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470669031 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470683098 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470685959 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470693111 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.470721006 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.470750093 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475291014 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475318909 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475339890 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475351095 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475361109 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475373030 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475378990 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475383043 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475424051 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475438118 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475447893 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475497007 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475632906 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475682020 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475712061 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475765944 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.475867987 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475878000 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.475915909 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.480830908 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481044054 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481059074 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481081009 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481115103 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481125116 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481192112 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.481487036 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.482161999 CET | 49859 | 50031 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:20.482208014 CET | 50031 | 49859 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:20.680341005 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:21.283404112 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:21.492925882 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:27.094959974 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:27.100173950 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:27.100246906 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:28.014493942 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:28.014645100 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:28.019500017 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:28.356697083 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:28.362658978 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:28.367646933 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:28.732450962 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:28.734714985 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:28.739526987 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.074615955 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.076683044 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:29.081657887 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.416821957 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.416964054 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:29.421859980 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.757000923 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:29.757158041 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:29.762212038 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:30.097412109 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:30.102657080 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:30.107516050 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:30.108760118 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:30.108757973 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:30.113867998 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.024893999 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.032742977 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.037775993 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.037833929 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.037904978 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.037942886 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.037993908 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038005114 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038014889 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038058043 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.038090944 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038101912 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038125992 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.038201094 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038211107 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.038228035 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.040679932 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.042747974 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042831898 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042845011 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042855024 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042939901 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042951107 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.042989969 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.043050051 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.043059111 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.043064117 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.043092012 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.043158054 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.043217897 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.043426991 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.044645071 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.045651913 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.046171904 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048000097 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048018932 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048228979 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048396111 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048405886 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048444033 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048579931 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.048696041 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049465895 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049557924 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049607992 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049618006 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049627066 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049638987 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.049649000 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.050117970 CET | 54487 | 50035 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.056576014 CET | 50035 | 54487 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.161933899 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:31.807467937 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:31.899138927 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:42.158437014 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:42.163845062 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:42.503351927 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:42.503834009 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:42.508804083 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:42.508961916 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:42.509063005 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:42.514035940 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.494218111 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.497608900 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.548508883 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548531055 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548552036 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548563957 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548573971 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548585892 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548595905 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548608065 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548619986 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548626900 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.548639059 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.548674107 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.548711061 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.575603008 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.575613976 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.575623989 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.575634956 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.575673103 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.575691938 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.577186108 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.577197075 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.577207088 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.577218056 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.577228069 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.577229977 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.577289104 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.606122017 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.606134892 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.606146097 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.606154919 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.606180906 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.606204033 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.620482922 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620495081 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620503902 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620512962 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620523930 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620560884 CET | 51271 | 50036 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.620606899 CET | 50036 | 51271 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:43.695734978 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:43.695787907 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:44.300317049 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:44.469809055 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:46.045569897 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:46.050576925 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:46.385701895 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:46.386384964 CET | 50037 | 62468 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:46.391477108 CET | 62468 | 50037 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:46.391542912 CET | 50037 | 62468 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:46.391652107 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:46.396455050 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:47.339618921 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:47.343463898 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:47.349348068 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:47.349533081 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:47.921853065 CET | 62468 | 50037 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:47.921979904 CET | 50037 | 62468 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:59.079837084 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:59.084712029 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:59.428966045 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:59.430979013 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:59.435966969 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:27:59.438647985 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:59.438764095 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:27:59.444082975 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.356689930 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.356966972 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362113953 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362147093 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362157106 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362163067 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362194061 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362221003 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362251997 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362323999 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362334013 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362366915 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362385035 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362416983 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362458944 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362538099 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362554073 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362579107 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362593889 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.362610102 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.362646103 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367393970 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367436886 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367551088 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367561102 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367568970 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367589951 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367613077 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367750883 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367760897 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.367788076 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367820978 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.367981911 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.368024111 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.368037939 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.368088007 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.368314981 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.368359089 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.368406057 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.368416071 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.368455887 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.368490934 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.372509956 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373363018 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373449087 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373459101 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373500109 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373509884 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373562098 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373610020 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373620033 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.373630047 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.379014969 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.381572008 CET | 60511 | 50038 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:00.381622076 CET | 50038 | 60511 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:00.492906094 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:01.145380974 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:01.290642023 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:05.200150967 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:05.205251932 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:05.549232960 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:05.551028013 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:05.555936098 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:05.558631897 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:05.558703899 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:05.564135075 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.484287024 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.484582901 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.489415884 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489437103 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489445925 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489490986 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.489527941 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489537001 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489541054 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489550114 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489566088 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.489603996 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.489609957 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489624023 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489645958 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.489720106 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.494473934 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494529009 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494560957 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.494587898 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494597912 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494606972 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.494628906 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494677067 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.494714022 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.494724989 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494887114 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494956017 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494973898 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.494988918 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.495007992 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.495058060 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.495496035 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499474049 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499522924 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499543905 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499556065 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499680996 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499825954 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499887943 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.499897003 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500056028 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500138998 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500147104 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500154972 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500173092 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500181913 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500190973 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500255108 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500263929 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500272989 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.500281096 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.501059055 CET | 59616 | 50039 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:06.501281977 CET | 50039 | 59616 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:06.682585001 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:07.280531883 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:07.492934942 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:17.310868025 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:17.316135883 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:17.316214085 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:18.235924006 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:18.236058950 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:18.241478920 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:18.579554081 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:18.579694033 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:18.584517956 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:18.950798035 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:18.950944901 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:18.955909014 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.295345068 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.295480967 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:19.300924063 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.654599905 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.654776096 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:19.659710884 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.997891903 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:19.998037100 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:20.003582001 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:20.341048002 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:20.341597080 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:20.347496986 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:20.347573042 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:20.347642899 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:20.352833986 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.256980896 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.264699936 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.269654989 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269701004 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269718885 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269730091 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269738913 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269877911 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.269889116 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269900084 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269908905 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269926071 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.269929886 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.269948006 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.270123959 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.270158052 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.270220041 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.275044918 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275055885 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275094032 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275103092 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275192976 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275245905 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.275300026 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275310040 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275516033 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275527000 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275535107 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.275578976 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.275639057 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.275664091 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.280143023 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.280452013 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.280668974 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.280786037 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.281264067 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.281799078 CET | 65028 | 50041 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.284595966 CET | 50041 | 65028 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:21.468003035 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:21.468945980 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.018806934 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:22.180685043 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.275010109 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.280653000 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:22.654452085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:22.654942989 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.660114050 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:22.660178900 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.660265923 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:22.665262938 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.579749107 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.580677986 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.585788012 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585808039 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585819006 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585866928 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.585880041 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585890055 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585891008 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.585907936 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585920095 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585942984 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.585942984 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585954905 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585957050 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.585973978 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.585982084 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.586219072 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.586219072 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.591012001 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591044903 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591053963 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591064930 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591175079 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591185093 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591243029 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.591371059 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.591551065 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.591764927 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.596515894 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.596651077 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.596751928 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.596796989 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.597208977 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.601998091 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602042913 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602061033 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602070093 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602078915 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602089882 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602098942 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602108002 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602279902 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.602806091 CET | 59156 | 50042 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:23.603213072 CET | 50042 | 59156 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:23.680521965 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:24.379509926 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:24.477339029 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:37.753177881 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:37.758310080 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:38.102790117 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:38.103236914 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:38.108555079 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:38.108654022 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:38.108731985 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:38.113632917 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.042651892 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.047185898 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.052325964 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052349091 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052359104 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052395105 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052403927 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052541018 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.052892923 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052902937 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.052911997 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.053272009 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.053281069 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.054477930 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.057455063 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.057490110 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.057543039 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.057552099 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.057629108 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.058053970 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.058123112 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.060218096 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.060509920 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.063071966 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.063148022 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.063157082 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.063244104 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.063265085 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.066828012 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.067023039 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.067986012 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.069139957 CET | 56373 | 50043 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.082603931 CET | 50043 | 56373 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.183341026 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:39.863949060 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:39.993041992 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:46.652870893 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:46.658432007 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.001415968 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.001885891 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.007582903 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.007723093 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.007858992 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.013056040 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.921161890 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.921396971 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926417112 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926467896 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926467896 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926477909 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926486969 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926526070 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926546097 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926557064 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926565886 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926605940 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926621914 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926640034 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926650047 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926664114 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926682949 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926686049 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.926707029 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.926736116 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.931370974 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931416988 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.931518078 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931566000 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931567907 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.931574106 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931600094 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931608915 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.931610107 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.931621075 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.931652069 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.932156086 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.932240963 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.936378956 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.936573982 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.936613083 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.937058926 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.938281059 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.941216946 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.941226006 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.941574097 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.942127943 CET | 50371 | 50044 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:47.942174911 CET | 50044 | 50371 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:47.992996931 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:48.665375948 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:48.790659904 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:50.512969017 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:50.518081903 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:50.862457037 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:50.863075972 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:50.868721008 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:50.868864059 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:50.869215965 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:50.875266075 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.800158978 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.800479889 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805507898 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805541992 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805557966 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805562973 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805569887 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805579901 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805596113 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805624008 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805630922 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805641890 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805656910 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805665970 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805672884 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805691957 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805696011 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805706978 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805751085 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.805880070 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.805917025 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810498953 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810528994 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810539961 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810549974 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810558081 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810568094 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810583115 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810592890 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810614109 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810628891 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810653925 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810738087 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810822964 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.810867071 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.810914040 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.815808058 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.816402912 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.816446066 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.816807985 CET | 59816 | 50045 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:51.816854000 CET | 50045 | 59816 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:51.993005991 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:52.232244968 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:52.238329887 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:52.571675062 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:52.577948093 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:52.581541061 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:52.586884022 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:52.587097883 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:52.588850021 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:52.594065905 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:52.789918900 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.481708050 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.481980085 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487047911 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487073898 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487096071 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487122059 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487138987 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487149000 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487159014 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487176895 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487199068 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487323999 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487334013 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487343073 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487353086 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487368107 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487399101 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.487413883 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.487462044 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492099047 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492139101 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492172003 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492182970 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492206097 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492213964 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492216110 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492225885 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492233038 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.492247105 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492268085 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.492291927 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.493091106 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.493171930 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.497436047 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.497457981 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.497503996 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.497514963 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.497833967 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.497893095 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.498226881 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.498295069 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.498435974 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.498445988 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.498584986 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.499067068 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.499628067 CET | 60363 | 50046 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:53.499671936 CET | 50046 | 60363 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:53.586764097 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:28:54.331672907 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:28:54.496790886 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:29:03.609679937 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:29:03.614762068 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:29:03.959089041 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:29:03.959532976 CET | 50047 | 60390 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:29:03.964752913 CET | 60390 | 50047 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:29:03.964875937 CET | 50047 | 60390 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:29:03.964960098 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Nov 4, 2024 21:29:03.970962048 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:29:04.867230892 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 |
Nov 4, 2024 21:29:04.914922953 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 4, 2024 21:24:55.516026020 CET | 53050 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 4, 2024 21:24:55.523209095 CET | 53 | 53050 | 1.1.1.1 | 192.168.2.4 |
Nov 4, 2024 21:24:56.901248932 CET | 62205 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 4, 2024 21:24:57.171571016 CET | 53 | 62205 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 4, 2024 21:24:55.516026020 CET | 192.168.2.4 | 1.1.1.1 | 0x7565 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 4, 2024 21:24:56.901248932 CET | 192.168.2.4 | 1.1.1.1 | 0xe40c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 4, 2024 21:24:55.523209095 CET | 1.1.1.1 | 192.168.2.4 | 0x7565 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 21:24:55.523209095 CET | 1.1.1.1 | 192.168.2.4 | 0x7565 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 21:24:55.523209095 CET | 1.1.1.1 | 192.168.2.4 | 0x7565 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Nov 4, 2024 21:24:57.171571016 CET | 1.1.1.1 | 192.168.2.4 | 0xe40c | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 104.26.12.205 | 443 | 7692 | C:\Users\user\Desktop\Payslip_October_2024.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 20:24:56 UTC | 155 | OUT | |
2024-11-04 20:24:56 UTC | 399 | IN | |
2024-11-04 20:24:56 UTC | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 104.26.12.205 | 443 | 8008 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 20:25:08 UTC | 155 | OUT | |
2024-11-04 20:25:09 UTC | 399 | IN | |
2024-11-04 20:25:09 UTC | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49750 | 104.26.12.205 | 443 | 6128 | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-04 20:25:18 UTC | 155 | OUT | |
2024-11-04 20:25:18 UTC | 399 | IN | |
2024-11-04 20:25:18 UTC | 14 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Nov 4, 2024 21:24:58.145982981 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 04:24. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 04:24. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 04:24. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 6 of 50 allowed.220-Local time is now 04:24. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 4, 2024 21:24:58.149497032 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 4, 2024 21:24:58.498543024 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Nov 4, 2024 21:24:58.498661041 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 4, 2024 21:24:58.877778053 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Nov 4, 2024 21:24:59.228914022 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Nov 4, 2024 21:24:59.229027987 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Nov 4, 2024 21:24:59.579032898 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Nov 4, 2024 21:24:59.579164982 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Nov 4, 2024 21:24:59.928574085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Nov 4, 2024 21:24:59.928759098 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:00.277859926 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,192,87) |
Nov 4, 2024 21:25:00.285343885 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-724536_2024_11_04_15_44_56.txt |
Nov 4, 2024 21:25:01.185388088 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:01.533375978 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.348 seconds (measured here), 9.41 Kbytes per second |
Nov 4, 2024 21:25:01.533736944 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:01.884216070 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,249,245) |
Nov 4, 2024 21:25:01.889717102 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-724536_2024_11_04_21_53_28.txt |
Nov 4, 2024 21:25:02.811544895 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:03.163824081 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Nov 4, 2024 21:25:11.196496010 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 4, 2024 21:25:11.206302881 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 4, 2024 21:25:11.551081896 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Nov 4, 2024 21:25:11.551650047 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 4, 2024 21:25:11.926958084 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Nov 4, 2024 21:25:12.271320105 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Nov 4, 2024 21:25:12.271470070 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Nov 4, 2024 21:25:12.627825975 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Nov 4, 2024 21:25:12.628004074 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Nov 4, 2024 21:25:12.971760988 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Nov 4, 2024 21:25:12.971892118 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:13.316006899 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,203,242) |
Nov 4, 2024 21:25:13.322096109 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-724536_2024_11_04_15_25_09.html |
Nov 4, 2024 21:25:14.233009100 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:14.812055111 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.346 seconds (measured here), 0.98 Kbytes per second |
Nov 4, 2024 21:25:14.813723087 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.346 seconds (measured here), 0.98 Kbytes per second |
Nov 4, 2024 21:25:15.089061975 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:15.433594942 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,251,201) |
Nov 4, 2024 21:25:15.439353943 CET | 49741 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-724536_2024_11_04_21_43_50.txt |
Nov 4, 2024 21:25:17.385520935 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:17.385582924 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:17.385813951 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:17.386035919 CET | 21 | 49741 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:20.177556992 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 04:25. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 4, 2024 21:25:20.180557966 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 4, 2024 21:25:20.532474995 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Nov 4, 2024 21:25:20.536825895 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 4, 2024 21:25:20.914602041 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Nov 4, 2024 21:25:21.268820047 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Nov 4, 2024 21:25:21.269021988 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Nov 4, 2024 21:25:21.639569998 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Nov 4, 2024 21:25:21.639883041 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Nov 4, 2024 21:25:21.991764069 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Nov 4, 2024 21:25:21.992010117 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:22.344014883 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,214,32) |
Nov 4, 2024 21:25:22.350302935 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR PW_user-724536_2024_11_04_15_25_18.html |
Nov 4, 2024 21:25:23.295093060 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:23.654500961 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.358 seconds (measured here), 0.95 Kbytes per second |
Nov 4, 2024 21:25:23.678637981 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:24.031280041 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,232,48) |
Nov 4, 2024 21:25:24.037296057 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-724536_2024_11_04_22_03_52.txt |
Nov 4, 2024 21:25:24.978235006 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:25.331723928 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.357 seconds (measured here), 9.17 Kbytes per second |
Nov 4, 2024 21:25:25.332184076 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:25:25.686129093 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,223,199) |
Nov 4, 2024 21:25:25.693078041 CET | 49751 | 21 | 192.168.2.4 | 110.4.45.197 | STOR CO_Firefox_fqs92o4p.default-release.txt_user-724536_2024_11_05_00_32_35.txt |
Nov 4, 2024 21:25:26.639322042 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:25:26.984440088 CET | 21 | 49751 | 110.4.45.197 | 192.168.2.4 | 226 File successfully transferred |
Nov 4, 2024 21:26:27.785145044 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:26:28.134579897 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,226,148) |
Nov 4, 2024 21:26:28.140477896 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR KL_user-724536_2024_11_18_19_04_53.html |
Nov 4, 2024 21:26:29.055278063 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:26:29.404416084 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.349 seconds (measured here), 0.80 Kbytes per second |
Nov 4, 2024 21:26:32.110491037 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:26:32.459836006 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,220,175) |
Nov 4, 2024 21:26:32.469227076 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_11_22_21_55_24.jpeg |
Nov 4, 2024 21:26:33.367384911 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:26:34.121799946 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.756 seconds (measured here), 97.69 Kbytes per second |
Nov 4, 2024 21:26:42.923118114 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:26:43.272464037 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,226,141) |
Nov 4, 2024 21:26:43.278801918 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_11_29_06_34_55.jpeg |
Nov 4, 2024 21:26:44.220077038 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:26:45.020203114 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.800 seconds (measured here), 92.29 Kbytes per second |
Nov 4, 2024 21:26:51.670495033 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:26:52.019615889 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,238,144) |
Nov 4, 2024 21:26:52.025342941 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_07_11_23_16.jpeg |
Nov 4, 2024 21:26:52.943694115 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:26:53.722090960 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.778 seconds (measured here), 94.93 Kbytes per second |
Nov 4, 2024 21:26:56.157516956 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:26:56.507267952 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,247,138) |
Nov 4, 2024 21:26:56.513139009 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_11_14_38_27.jpeg |
Nov 4, 2024 21:26:57.422035933 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:26:58.176453114 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.754 seconds (measured here), 97.91 Kbytes per second |
Nov 4, 2024 21:27:10.904073954 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:11.253354073 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,207,5) |
Nov 4, 2024 21:27:11.262636900 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_19_23_56_34.jpeg |
Nov 4, 2024 21:27:12.201129913 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:12.980257988 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.775 seconds (measured here), 95.34 Kbytes per second |
Nov 4, 2024 21:27:19.153726101 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:19.517566919 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,194,195) |
Nov 4, 2024 21:27:19.523673058 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_25_06_21_32.jpeg |
Nov 4, 2024 21:27:20.464711905 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:21.283404112 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.819 seconds (measured here), 90.20 Kbytes per second |
Nov 4, 2024 21:27:28.014493942 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 18 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 18 of 50 allowed.220-Local time is now 04:27. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 18 of 50 allowed.220-Local time is now 04:27. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 18 of 50 allowed.220-Local time is now 04:27. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 18 of 50 allowed.220-Local time is now 04:27. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 4, 2024 21:27:28.014645100 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 4, 2024 21:27:28.356697083 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Nov 4, 2024 21:27:28.362658978 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 4, 2024 21:27:28.732450962 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Nov 4, 2024 21:27:29.074615955 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Nov 4, 2024 21:27:29.076683044 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Nov 4, 2024 21:27:29.416821957 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Nov 4, 2024 21:27:29.416964054 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Nov 4, 2024 21:27:29.757000923 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Nov 4, 2024 21:27:29.757158041 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:30.097412109 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,212,215) |
Nov 4, 2024 21:27:30.108757973 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_10_16_48_19.jpeg |
Nov 4, 2024 21:27:31.024893999 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:31.807467937 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.783 seconds (measured here), 94.35 Kbytes per second |
Nov 4, 2024 21:27:42.158437014 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:42.503351927 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,200,71) |
Nov 4, 2024 21:27:42.509063005 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_19_02_29_30.jpeg |
Nov 4, 2024 21:27:43.494218111 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:43.695734978 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:44.300317049 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.843 seconds (measured here), 87.61 Kbytes per second |
Nov 4, 2024 21:27:46.045569897 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:46.385701895 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,244,4) |
Nov 4, 2024 21:27:46.391652107 CET | 50034 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_12_24_02_40_35.jpeg |
Nov 4, 2024 21:27:47.339618921 CET | 21 | 50034 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:27:59.079837084 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:27:59.428966045 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,236,95) |
Nov 4, 2024 21:27:59.438764095 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_16_09_38_03.jpeg |
Nov 4, 2024 21:28:00.356689930 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:01.145380974 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.788 seconds (measured here), 93.72 Kbytes per second |
Nov 4, 2024 21:28:05.200150967 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:05.549232960 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,232,224) |
Nov 4, 2024 21:28:05.558703899 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_20_22_44_01.jpeg |
Nov 4, 2024 21:28:06.484287024 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:07.280531883 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.797 seconds (measured here), 92.66 Kbytes per second |
Nov 4, 2024 21:28:18.235924006 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 04:28. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 04:28. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 04:28. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 04:28. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 4, 2024 21:28:18.236058950 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 4, 2024 21:28:18.579554081 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 331 User origin@haliza.com.my OK. Password required |
Nov 4, 2024 21:28:18.579694033 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 4, 2024 21:28:18.950798035 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 230 OK. Current restricted directory is / |
Nov 4, 2024 21:28:19.295345068 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 504 Unknown command |
Nov 4, 2024 21:28:19.295480967 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | PWD |
Nov 4, 2024 21:28:19.654599905 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 257 "/" is your current location |
Nov 4, 2024 21:28:19.654776096 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | TYPE I |
Nov 4, 2024 21:28:19.997891903 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 200 TYPE is now 8-bit binary |
Nov 4, 2024 21:28:19.998037100 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:20.341048002 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,254,4) |
Nov 4, 2024 21:28:20.347642899 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_07_03_20_08.jpeg |
Nov 4, 2024 21:28:21.256980896 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:21.468003035 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:22.018806934 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.762 seconds (measured here), 96.90 Kbytes per second |
Nov 4, 2024 21:28:22.275010109 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:22.654452085 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,231,20) |
Nov 4, 2024 21:28:22.660265923 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_29_19_06_07.jpeg |
Nov 4, 2024 21:28:23.579749107 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:24.379509926 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.800 seconds (measured here), 97.63 Kbytes per second |
Nov 4, 2024 21:28:37.753177881 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:38.102790117 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,220,53) |
Nov 4, 2024 21:28:38.108731985 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_02_10_03_11_38.jpeg |
Nov 4, 2024 21:28:39.042651892 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:39.863949060 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.815 seconds (measured here), 90.63 Kbytes per second |
Nov 4, 2024 21:28:46.652870893 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:47.001415968 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,196,195) |
Nov 4, 2024 21:28:47.007858992 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_27_06_09_57.jpeg |
Nov 4, 2024 21:28:47.921161890 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:48.665375948 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.744 seconds (measured here), 99.27 Kbytes per second |
Nov 4, 2024 21:28:50.512969017 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:50.862457037 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,233,168) |
Nov 4, 2024 21:28:50.869215965 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_02_17_03_34_59.jpeg |
Nov 4, 2024 21:28:51.800158978 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:52.232244968 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:28:52.571675062 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.772 seconds (measured here), 95.71 Kbytes per second |
Nov 4, 2024 21:28:52.577948093 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,235,203) |
Nov 4, 2024 21:28:52.588850021 CET | 50040 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2025_01_31_17_17_46.jpeg |
Nov 4, 2024 21:28:53.481708050 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Nov 4, 2024 21:28:54.331672907 CET | 21 | 50040 | 110.4.45.197 | 192.168.2.4 | 226-File successfully transferred 226-File successfully transferred226 0.751 seconds (measured here), 98.36 Kbytes per second |
Nov 4, 2024 21:29:03.609679937 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | PASV |
Nov 4, 2024 21:29:03.959089041 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 227 Entering Passive Mode (110,4,45,197,235,230) |
Nov 4, 2024 21:29:03.964960098 CET | 49735 | 21 | 192.168.2.4 | 110.4.45.197 | STOR SC_user-724536_2024_11_04_15_29_02.jpeg |
Nov 4, 2024 21:29:04.867230892 CET | 21 | 49735 | 110.4.45.197 | 192.168.2.4 | 150 Accepted data connection |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:24:51 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\Desktop\Payslip_October_2024.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa30000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:24:54 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\Desktop\Payslip_October_2024.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5a0000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:25:06 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x470000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:25:07 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x1b0000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 15:25:07 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7b0000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 15:25:14 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x570000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 15:25:15 |
Start date: | 04/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x7b0000 |
File size: | 800'256 bytes |
MD5 hash: | A0DADB7997E2B13144275B1C164F1C84 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 11.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 4.3% |
Total number of Nodes: | 256 |
Total number of Limit Nodes: | 15 |
Graph
Function 074A02B0 Relevance: 6.9, Strings: 5, Instructions: 618COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A6730 Relevance: .5, Instructions: 511COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A5460 Relevance: .5, Instructions: 486COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5868D8 Relevance: .4, Instructions: 396COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A02A0 Relevance: .3, Instructions: 279COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A9A58 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074AD5E0 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A9A49 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E584845 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0130E2E0 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0130C038 Relevance: 1.7, APIs: 1, Instructions: 205COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01305905 Relevance: 1.6, APIs: 1, Instructions: 98COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 013044E4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A0BD8 Relevance: 1.6, APIs: 1, Instructions: 84windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E582FF0 Relevance: 1.6, APIs: 1, Instructions: 72threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E583328 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5830A1 Relevance: 1.6, APIs: 1, Instructions: 65threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E583330 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5830A8 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0130E930 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E583178 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E583180 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E582FF8 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0130C238 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5856EB Relevance: 1.5, APIs: 1, Instructions: 46windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5856F0 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E585780 Relevance: 1.5, APIs: 1, Instructions: 35windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010DD01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010DD1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010DD006 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010DD1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010CD759 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 010CD758 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A8A38 Relevance: .3, Instructions: 322COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5827D0 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E580C70 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5814E0 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E580838 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5810A8 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A9CE8 Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074AF620 Relevance: .1, Instructions: 139COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E580C60 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E58109A Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0E5827C0 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 074A9CD7 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 10.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 136 |
Total number of Limit Nodes: | 18 |
Graph
Function 06623578 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06627E90 Relevance: 3.0, Strings: 2, Instructions: 473COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066256A8 Relevance: 1.8, Strings: 1, Instructions: 590COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06622710 Relevance: 1.1, Instructions: 1067COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06626700 Relevance: .8, Instructions: 815COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662B342 Relevance: .6, Instructions: 568COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662ADE0 Relevance: 10.4, Strings: 8, Instructions: 389COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662B760 Relevance: 8.0, Strings: 6, Instructions: 471COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06629260 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662D068 Relevance: 4.5, Strings: 3, Instructions: 797COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB4690 Relevance: 4.1, Strings: 3, Instructions: 351COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624C78 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1DC0 Relevance: 2.8, Strings: 2, Instructions: 268COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1DB0 Relevance: 2.8, Strings: 2, Instructions: 252COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06629252 Relevance: 2.7, Strings: 2, Instructions: 169COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624C69 Relevance: 2.6, Strings: 2, Instructions: 140COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C7EE90 Relevance: 1.6, APIs: 1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05625FD3 Relevance: 1.6, APIs: 1, Instructions: 116COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05625FD8 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05629AB4 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05629ED0 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05629ED8 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C78038 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562D5F0 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562D5E8 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C78040 Relevance: 1.6, APIs: 1, Instructions: 56fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C7EF78 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562B3B4 Relevance: 1.5, APIs: 1, Instructions: 47comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562B3B8 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05629B0C Relevance: 1.5, APIs: 1, Instructions: 46COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0562B961 Relevance: 1.5, APIs: 1, Instructions: 44comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662DBDD Relevance: 1.4, Strings: 1, Instructions: 125COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066221BD Relevance: 1.4, Strings: 1, Instructions: 106COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066221D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624BD9 Relevance: 1.3, Strings: 1, Instructions: 81COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB0C1D Relevance: 1.3, Strings: 1, Instructions: 59COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066283E0 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624B61 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662C2A8 Relevance: .6, Instructions: 636COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB43F8 Relevance: .4, Instructions: 436COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06626300 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066243B2 Relevance: .2, Instructions: 224COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066246CC Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066246E0 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1A98 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662F040 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662F031 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662FCC1 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662FA70 Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662FA80 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06625522 Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1325 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662DA90 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1330 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06622081 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06622090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1219 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB4ED9 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06623FB9 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06623FC8 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED006 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB4EE8 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB4A04 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662B030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED118 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1050 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB43EC Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB28A8 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1C54 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB2D38 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066240D8 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB28B8 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1111 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB0BCC Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662F2B0 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624310 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3EC8 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06623D92 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662A418 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BED113 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB0C2C Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06623D98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06624320 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066240C9 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3E60 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662F2C0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3104 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662A428 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1BB8 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662C900 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1041 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB1A88 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3E88 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB11C0 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06626580 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3C00 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB11D0 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB2540 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB3C10 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB2E57 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB278B Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB0F20 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04FB2E35 Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066277B0 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662AA48 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066271B0 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 066284E8 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06628900 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0662ADD6 Relevance: 5.2, Strings: 4, Instructions: 158COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 10.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 196 |
Total number of Limit Nodes: | 15 |
Graph
Function 00B7E2E0 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B75A7C Relevance: 1.6, APIs: 1, Instructions: 99COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B744E4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B7590D Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05A10BD8 Relevance: 1.6, APIs: 1, Instructions: 83windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070130A1 Relevance: 1.6, APIs: 1, Instructions: 65threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07013328 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07013330 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070130A8 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B7E930 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07013178 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07013180 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07012FF0 Relevance: 1.6, APIs: 1, Instructions: 51threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07012FF8 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B7C238 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070157E8 Relevance: 1.5, APIs: 1, Instructions: 45windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070157F0 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 07015801 Relevance: 1.5, APIs: 1, Instructions: 37windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00B7FF30 Relevance: 1.3, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ABD4A0 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ACD01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ACD1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ACD006 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ABD49B Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ACD1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ABD759 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00ABD758 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 13.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 23 |
Total number of Limit Nodes: | 4 |
Graph
Function 06853580 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06857E98 Relevance: 3.0, Strings: 2, Instructions: 474COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06850007 Relevance: 2.0, Instructions: 1968COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06850040 Relevance: 2.0, Instructions: 1962COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068556B0 Relevance: 1.8, Strings: 1, Instructions: 590COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856708 Relevance: .8, Instructions: 819COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685ADE8 Relevance: 11.6, Strings: 9, Instructions: 390COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859268 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685D070 Relevance: 4.5, Strings: 3, Instructions: 799COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854C80 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068408CB Relevance: 2.7, Strings: 2, Instructions: 219COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685925B Relevance: 2.7, Strings: 2, Instructions: 171COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854C71 Relevance: 2.6, Strings: 2, Instructions: 141COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0298EE3F Relevance: 1.6, APIs: 1, Instructions: 61COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0298EE58 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840040 Relevance: 1.5, Strings: 1, Instructions: 207COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0684264E Relevance: 1.4, Strings: 1, Instructions: 125COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685DBE5 Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685DBF8 Relevance: 1.4, Strings: 1, Instructions: 117COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068521BD Relevance: 1.4, Strings: 1, Instructions: 109COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068521D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068583E8 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854B69 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685C2B0 Relevance: .6, Instructions: 641COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B3E7 Relevance: .6, Instructions: 557COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068411F8 Relevance: .3, Instructions: 291COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840E20 Relevance: .3, Instructions: 285COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856308 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068543B9 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068543C8 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068546D4 Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068546E8 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F039 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F048 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842823 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06841500 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FCC9 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FA78 Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FA88 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842440 Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842450 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06855538 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840FF0 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685DA98 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842A93 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842AA0 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06852080 Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06852090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853FC1 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853508 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853FD0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B038 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068405D6 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840AB8 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856E30 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068405E0 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854318 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068540E0 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F2B8 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840550 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685A420 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853D99 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840D63 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853DA0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854328 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068540D1 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F2C8 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685A430 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0684033B Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685C908 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0684026D Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840B28 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06840348 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856588 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06842A2B Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856598 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068577B8 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685AA50 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068571B8 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685BB30 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068584F0 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06858908 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685ADD8 Relevance: 5.2, Strings: 4, Instructions: 165COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 163 |
Total number of Limit Nodes: | 9 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C5C038 Relevance: 1.7, APIs: 1, Instructions: 205COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C55905 Relevance: 1.6, APIs: 1, Instructions: 99COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C544E4 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E93328 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E930A1 Relevance: 1.6, APIs: 1, Instructions: 65threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C5CDD0 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E93330 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E930A8 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E93178 Relevance: 1.6, APIs: 1, Instructions: 54memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E93180 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E92FF0 Relevance: 1.6, APIs: 1, Instructions: 51threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E92FF8 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C5C238 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E956EB Relevance: 1.5, APIs: 1, Instructions: 45windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E956F0 Relevance: 1.5, APIs: 1, Instructions: 44windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06E956E8 Relevance: 1.5, APIs: 1, Instructions: 23windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C5FF30 Relevance: 1.3, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BFD4A0 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0D005 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BFD49B Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BFD759 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BFD758 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 17 |
Total number of Limit Nodes: | 4 |
Graph
Function 06853580 Relevance: 8.0, Strings: 6, Instructions: 545COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06857E98 Relevance: 3.0, Strings: 2, Instructions: 471COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06850040 Relevance: 2.0, Instructions: 1971COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685001D Relevance: 2.0, Instructions: 1956COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068556B0 Relevance: 1.8, Strings: 1, Instructions: 587COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856708 Relevance: .8, Instructions: 812COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685ADE8 Relevance: 12.9, Strings: 10, Instructions: 390COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06859268 Relevance: 5.2, Strings: 4, Instructions: 231COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685D070 Relevance: 4.5, Strings: 3, Instructions: 797COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F32148 Relevance: 4.1, Strings: 3, Instructions: 351COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854C80 Relevance: 3.9, Strings: 3, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685925B Relevance: 2.7, Strings: 2, Instructions: 167COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854C71 Relevance: 2.6, Strings: 2, Instructions: 140COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00FEED70 Relevance: 1.6, APIs: 1, Instructions: 137COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00FEEE58 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685DBE5 Relevance: 1.4, Strings: 1, Instructions: 124COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068521BD Relevance: 1.4, Strings: 1, Instructions: 108COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068521D0 Relevance: 1.4, Strings: 1, Instructions: 105COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068583E8 Relevance: 1.3, Strings: 1, Instructions: 40COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854B69 Relevance: 1.3, Strings: 1, Instructions: 25COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685C2B0 Relevance: .6, Instructions: 632COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B3E7 Relevance: .6, Instructions: 558COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856308 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068543BB Relevance: .2, Instructions: 222COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068546D4 Relevance: .2, Instructions: 214COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068546E8 Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F048 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F039 Relevance: .2, Instructions: 199COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FCC9 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FA78 Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685FA88 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685552B Relevance: .1, Instructions: 129COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F32139 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685DA98 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06852080 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06852090 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F32990 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853508 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853FC1 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853FD0 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F324BC Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F329A0 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685B038 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D005 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D1F8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D3A8 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06F31E44 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068540E0 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854318 Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F2B8 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853D9B Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D1F3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E2D3A3 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06853DA0 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06854328 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685A420 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685F2C8 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068540D1 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685A430 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685C908 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06856588 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068577B8 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685AA50 Relevance: 10.2, Strings: 8, Instructions: 229COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068571B8 Relevance: 9.2, Strings: 7, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685BB30 Relevance: 7.7, Strings: 6, Instructions: 197COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068584F0 Relevance: 5.3, Strings: 4, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06858908 Relevance: 5.2, Strings: 4, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0685ADD8 Relevance: 5.2, Strings: 4, Instructions: 163COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|