Windows
Analysis Report
Payment_Advice_USD_48,054.40_.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Payment_Advice_USD_48,054.40_.exe (PID: 5144 cmdline:
"C:\Users\ user\Deskt op\Payment _Advice_US D_48,054.4 0_.exe" MD5: F488EA907A7447947FDD751CE2D1D0DA) - RegSvcs.exe (PID: 6656 cmdline:
"C:\Users\ user\Deskt op\Payment _Advice_US D_48,054.4 0_.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94)
- sgxIb.exe (PID: 5496 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - conhost.exe (PID: 528 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- sgxIb.exe (PID: 2452 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - conhost.exe (PID: 2676 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.haliza.com.my", "Username": "origin@haliza.com.my", "Password": "JesusChrist007$"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 7 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 7 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-05T17:11:04.702504+0100 | 2022930 | 1 | A Network Trojan was detected | 20.12.23.50 | 443 | 192.168.2.5 | 49710 | TCP |
2024-11-05T17:11:43.737557+0100 | 2022930 | 1 | A Network Trojan was detected | 20.12.23.50 | 443 | 192.168.2.5 | 49910 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_004AC2A2 | |
Source: | Code function: | 0_2_004E68EE | |
Source: | Code function: | 0_2_004E698F | |
Source: | Code function: | 0_2_004DD076 | |
Source: | Code function: | 0_2_004DD3A9 | |
Source: | Code function: | 0_2_004E9642 | |
Source: | Code function: | 0_2_004E979D | |
Source: | Code function: | 0_2_004E9B2B | |
Source: | Code function: | 0_2_004DDBBE | |
Source: | Code function: | 0_2_004E5C97 |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_004ECE44 |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Windows user hook set: | Jump to behavior |
Source: | Code function: | 0_2_004EEAFF |
Source: | Code function: | 0_2_004EED6A |
Source: | Code function: | 0_2_004EEAFF |
Source: | Code function: | 0_2_004DAA57 |
Source: | Window created: | Jump to behavior |
Source: | Code function: | 0_2_00509576 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | memstr_9b0ef250-b | |
Source: | String found in binary or memory: | memstr_c473f4a1-3 | |
Source: | String found in binary or memory: | memstr_e83f4b03-9 | |
Source: | String found in binary or memory: | memstr_31f5c64a-6 |
Source: | Static PE information: |
Source: | Process Stats: |
Source: | Code function: | 0_2_004DD5EB |
Source: | Code function: | 0_2_004D1201 |
Source: | Code function: | 0_2_004DE8F6 |
Source: | Code function: | 0_2_0047BF40 | |
Source: | Code function: | 0_2_004E2046 | |
Source: | Code function: | 0_2_00478060 | |
Source: | Code function: | 0_2_004D8298 | |
Source: | Code function: | 0_2_004AE4FF | |
Source: | Code function: | 0_2_004A676B | |
Source: | Code function: | 0_2_00504873 | |
Source: | Code function: | 0_2_0047CAF0 | |
Source: | Code function: | 0_2_0049CAA0 | |
Source: | Code function: | 0_2_0048CC39 | |
Source: | Code function: | 0_2_004A6DD9 | |
Source: | Code function: | 0_2_0048B119 | |
Source: | Code function: | 0_2_004791C0 | |
Source: | Code function: | 0_2_00491394 | |
Source: | Code function: | 0_2_00491706 | |
Source: | Code function: | 0_2_0049781B | |
Source: | Code function: | 0_2_0048997D | |
Source: | Code function: | 0_2_00477920 | |
Source: | Code function: | 0_2_004919B0 | |
Source: | Code function: | 0_2_00497A4A | |
Source: | Code function: | 0_2_00491C77 | |
Source: | Code function: | 0_2_004C3CD2 | |
Source: | Code function: | 0_2_00497CA7 | |
Source: | Code function: | 0_2_004FBE44 | |
Source: | Code function: | 0_2_004A9EEE | |
Source: | Code function: | 0_2_00491F32 | |
Source: | Code function: | 0_2_00E2AD38 | |
Source: | Code function: | 2_2_01554198 | |
Source: | Code function: | 2_2_0155E915 | |
Source: | Code function: | 2_2_01554A68 | |
Source: | Code function: | 2_2_0155AD90 | |
Source: | Code function: | 2_2_01553E50 | |
Source: | Code function: | 2_2_06A5C4AC | |
Source: | Code function: | 2_2_06A53924 | |
Source: | Code function: | 2_2_06A56036 | |
Source: | Code function: | 2_2_06A55342 | |
Source: | Code function: | 2_2_06A55348 | |
Source: | Code function: | 2_2_06A51C68 | |
Source: | Code function: | 2_2_06A53918 | |
Source: | Code function: | 2_2_06A756B0 | |
Source: | Code function: | 2_2_06A77E98 | |
Source: | Code function: | 2_2_06A76708 | |
Source: | Code function: | 2_2_06A73580 | |
Source: | Code function: | 2_2_06A777B8 | |
Source: | Code function: | 2_2_06A7E4D0 | |
Source: | Code function: | 2_2_06A75DFF | |
Source: | Code function: | 2_2_06A70040 | |
Source: | Code function: | 2_2_06A7003E |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Code function: | 0_2_004E37B5 |
Source: | Code function: | 0_2_004D10BF | |
Source: | Code function: | 0_2_004D16C3 |
Source: | Code function: | 0_2_004E51CD |
Source: | Code function: | 0_2_004FA67C |
Source: | Code function: | 0_2_004E648E |
Source: | Code function: | 0_2_004742A2 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_004742DE |
Source: | Code function: | 0_2_00490A89 | |
Source: | Code function: | 2_2_06A5EA20 | |
Source: | Code function: | 2_2_06A5A820 |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_0048F98E | |
Source: | Code function: | 0_2_00501C41 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Sandbox detection routine: | graph_0-96794 |
Source: | WMI Queries: |
Source: | API/Special instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Code function: | 0_2_004AC2A2 | |
Source: | Code function: | 0_2_004E68EE | |
Source: | Code function: | 0_2_004E698F | |
Source: | Code function: | 0_2_004DD076 | |
Source: | Code function: | 0_2_004DD3A9 | |
Source: | Code function: | 0_2_004E9642 | |
Source: | Code function: | 0_2_004E979D | |
Source: | Code function: | 0_2_004E9B2B | |
Source: | Code function: | 0_2_004DDBBE | |
Source: | Code function: | 0_2_004E5C97 |
Source: | Code function: | 0_2_004742DE |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Code function: | 0_2_004EEAA2 |
Source: | Code function: | 0_2_004A2622 |
Source: | Code function: | 0_2_004742DE |
Source: | Code function: | 0_2_00494CE8 | |
Source: | Code function: | 0_2_00E2ABC8 | |
Source: | Code function: | 0_2_00E2AC28 | |
Source: | Code function: | 0_2_00E29588 |
Source: | Code function: | 0_2_004D0B62 |
Source: | Code function: | 0_2_004A2622 | |
Source: | Code function: | 0_2_0049083F | |
Source: | Code function: | 0_2_004909D5 | |
Source: | Code function: | 0_2_00490C21 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Section loaded: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 0_2_004D1201 |
Source: | Code function: | 0_2_004B2BA5 |
Source: | Code function: | 0_2_004DB226 |
Source: | Code function: | 0_2_004F22DA |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_004D0B62 |
Source: | Code function: | 0_2_004D1663 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00490698 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004E8195 |
Source: | Code function: | 0_2_004CD27A |
Source: | Code function: | 0_2_004AB952 |
Source: | Code function: | 0_2_004742DE |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_004F1204 | |
Source: | Code function: | 0_2_004F1806 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 11 Disable or Modify Tools | 2 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 2 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 Native API | 2 Valid Accounts | 1 DLL Side-Loading | 11 Deobfuscate/Decode Files or Information | 221 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Registry Run Keys / Startup Folder | 2 Valid Accounts | 2 Obfuscated Files or Information | 1 Credentials in Registry | 2 File and Directory Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 21 Access Token Manipulation | 1 DLL Side-Loading | NTDS | 138 System Information Discovery | Distributed Component Object Model | 221 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 212 Process Injection | 1 Masquerading | LSA Secrets | 331 Security Software Discovery | SSH | 4 Clipboard Data | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | 1 Registry Run Keys / Startup Folder | 2 Valid Accounts | Cached Domain Credentials | 241 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 241 Virtualization/Sandbox Evasion | DCSync | 2 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 21 Access Token Manipulation | Proc Filesystem | 11 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 212 Process Injection | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 1 Hidden Files and Directories | Network Sniffing | 1 System Network Configuration Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
47% | ReversingLabs | Win32.Trojan.AgentTesla | ||
100% | Avira | DR/AutoIt.Gen8 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 104.26.13.205 | true | false | high | |
ftp.haliza.com.my | 110.4.45.197 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
110.4.45.197 | ftp.haliza.com.my | Malaysia | 46015 | EXABYTES-AS-APExaBytesNetworkSdnBhdMY | true | |
104.26.13.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1549489 |
Start date and time: | 2024-11-05 17:09:54 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 35s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Payment_Advice_USD_48,054.40_.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@7/5@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target sgxIb.exe, PID 2452 because it is empty
- Execution Graph export aborted for target sgxIb.exe, PID 5496 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: Payment_Advice_USD_48,054.40_.exe
Time | Type | Description |
---|---|---|
11:10:48 | API Interceptor | |
17:10:49 | Autostart | |
17:10:57 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
110.4.45.197 | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
104.26.13.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Node Stealer | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, RDPWrap Tool, LummaC Stealer, Stealc, Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.ipify.org | Get hash | malicious | AgentTesla, GuLoader | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Targeted Ransomware | Browse |
| ||
ftp.haliza.com.my | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EXABYTES-AS-APExaBytesNetworkSdnBhdMY | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | PureLog Stealer, RedLine | Browse |
| |
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | PureLog Stealer, RedLine | Browse |
| |
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe | Get hash | malicious | FormBook | Browse | ||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | modified |
Size (bytes): | 142 |
Entropy (8bit): | 5.090621108356562 |
Encrypted: | false |
SSDEEP: | 3:QHXMKa/xwwUC7WglAFXMWA2yTMGfsbNRLFS9Am12MFuAvOAsDeieVyn:Q3La/xwczlAFXMWTyAGCDLIP12MUAvvw |
MD5: | 8C0458BB9EA02D50565175E38D577E35 |
SHA1: | F0B50702CD6470F3C17D637908F83212FDBDB2F2 |
SHA-256: | C578E86DB701B9AFA3626E804CF434F9D32272FF59FB32FA9A51835E5A148B53 |
SHA-512: | 804A47494D9A462FFA6F39759480700ECBE5A7F3A15EC3A6330176ED9C04695D2684BF6BF85AB86286D52E7B727436D0BB2E8DA96E20D47740B5CE3F856B5D0F |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\Payment_Advice_USD_48,054.40_.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 247808 |
Entropy (8bit): | 6.706396374241907 |
Encrypted: | false |
SSDEEP: | 6144:MvI7nqtBMf7IoAbXNy7Gi7nSZ0kACltSC52xcIiIE7ckW/mjzkts+Wjip9n:wI7MB47IoAbX07PmACltSC52xcIiIEXG |
MD5: | A5D914334A62D03297B68300D8194820 |
SHA1: | 8FF5CE59D27694781C7FB8B2E038BA9AA29983D4 |
SHA-256: | 40A1448E651D9ED90121FFE77BFD9A60EE0BE238884BB77D5AE2E2FE07337544 |
SHA-512: | 5CA932536CA1F974BB70B84ECA078D0D02CE6A6B6390F70B327DA25748EEFD56D527C76ED0F40D31CC46667FCC964E2B0D73595D103EB6A16C8EC757C31476E8 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
File Type: | |
Category: | modified |
Size (bytes): | 45984 |
Entropy (8bit): | 6.16795797263964 |
Encrypted: | false |
SSDEEP: | 768:4BbSoy+SdIBf0k2dsjYg6Iq8S1GYqWH8BR:noOIBf0ddsjY/ZGyc7 |
MD5: | 9D352BC46709F0CB5EC974633A0C3C94 |
SHA1: | 1969771B2F022F9A86D77AC4D4D239BECDF08D07 |
SHA-256: | 2C1EEB7097023C784C2BD040A2005A5070ED6F3A4ABF13929377A9E39FAB1390 |
SHA-512: | 13C714244EC56BEEB202279E4109D59C2A43C3CF29F90A374A751C04FD472B45228CA5A0178F41109ED863DBD34E0879E4A21F5E38AE3D89559C57E6BE990A9B |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1141 |
Entropy (8bit): | 4.442398121585593 |
Encrypted: | false |
SSDEEP: | 24:zKLXkhDObntKlglUEnfQtvNuNpKOK5aM9YJC:zKL0hDQntKKH1MqJC |
MD5: | 6FB4D27A716A8851BC0505666E7C7A10 |
SHA1: | AD2A232C6E709223532C4D1AB892303273D8C814 |
SHA-256: | 1DC36F296CE49BDF1D560B527DB06E1E9791C10263459A67EACE706C6DDCDEAE |
SHA-512: | 3192095C68C6B7AD94212B7BCA0563F2058BCE00C0C439B90F0E96EA2F029A37C2F2B69487591B494C1BA54697FE891E214582E392127CB8C90AB682E0D81ADB |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.286740382427047 |
TrID: |
|
File name: | Payment_Advice_USD_48,054.40_.exe |
File size: | 1'414'144 bytes |
MD5: | f488ea907a7447947fdd751ce2d1d0da |
SHA1: | 0bb00f266d676584b35752d98878465fe20953b9 |
SHA256: | af1c4d4509e271497c9eac4c96c1fc5c4e419c6d73b69a5141380589e479c16a |
SHA512: | e6c3a36ea1b6d85bbdfa0cdc40ee220697afa97fe32c95623167e571161b38df1c6109fb7c7d1d6149a288e2a0848b7ee9a95df750467ee18b26399400bc2ac6 |
SSDEEP: | 24576:WqDEvCTbMWu7rQYlBQcBiT6rprG8aCWRwo62TuEWlHtqMMOrBdJcPW6:WTvC/MTQYxsWR7aCpo65EWLA |
TLSH: | 6A65D00273D1C062FFAB92334B5AF6515BBC69260123A61F13A81D7DBE701B1563E7A3 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................j:......j:..C...j:......@.*...............................n.......~.............{.......{.......{.........z.... |
Icon Hash: | aaf3e3e3938382a0 |
Entrypoint: | 0x420577 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6729FC7A [Tue Nov 5 11:07:38 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 948cc502fe9226992dce9417f952fce3 |
Instruction |
---|
call 00007FB228B5F7B3h |
jmp 00007FB228B5F0BFh |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007FB228B5F29Dh |
mov dword ptr [esi], 0049FDF0h |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FDF8h |
mov dword ptr [ecx], 0049FDF0h |
ret |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007FB228B5F26Ah |
mov dword ptr [esi], 0049FE0Ch |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 0049FE14h |
mov dword ptr [ecx], 0049FE0Ch |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
and dword ptr [eax], 00000000h |
and dword ptr [eax+04h], 00000000h |
push eax |
mov eax, dword ptr [ebp+08h] |
add eax, 04h |
push eax |
call 00007FB228B61E5Dh |
pop ecx |
pop ecx |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
lea eax, dword ptr [ecx+04h] |
mov dword ptr [ecx], 0049FDD0h |
push eax |
call 00007FB228B61EA8h |
pop ecx |
ret |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 0049FDD0h |
push eax |
call 00007FB228B61E91h |
test byte ptr [ebp+08h], 00000001h |
pop ecx |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xc8e64 | 0x17c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xd4000 | 0x8293c | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x157000 | 0x7594 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0xb0ff0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0xc3400 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0xb1010 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x9c000 | 0x894 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x9ab1d | 0x9ac00 | 0a1473f3064dcbc32ef93c5c8a90f3a6 | False | 0.565500681542811 | data | 6.668273581389308 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x9c000 | 0x2fb82 | 0x2fc00 | c9cf2468b60bf4f80f136ed54b3989fb | False | 0.35289185209424084 | data | 5.691811547483722 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xcc000 | 0x706c | 0x4800 | 53b9025d545d65e23295e30afdbd16d9 | False | 0.04356553819444445 | DOS executable (block device driver @\273\) | 0.5846666986982398 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xd4000 | 0x8293c | 0x82a00 | 4b6c1c7575aed01f8dcae02b6e8a09b5 | False | 0.9499046800239235 | data | 7.9393542959654315 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x157000 | 0x7594 | 0x7600 | c68ee8931a32d45eb82dc450ee40efc3 | False | 0.7628111758474576 | data | 6.7972128181359786 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xd45a8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0xd46d0 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0xd47f8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0xd4920 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | Great Britain | 0.3333333333333333 |
RT_ICON | 0xd4c08 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | Great Britain | 0.5 |
RT_ICON | 0xd4d30 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | Great Britain | 0.2835820895522388 |
RT_ICON | 0xd5bd8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | Great Britain | 0.37906137184115524 |
RT_ICON | 0xd6480 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | Great Britain | 0.23699421965317918 |
RT_ICON | 0xd69e8 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | Great Britain | 0.13858921161825727 |
RT_ICON | 0xd8f90 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | Great Britain | 0.25070356472795496 |
RT_ICON | 0xda038 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | Great Britain | 0.3173758865248227 |
RT_MENU | 0xda4a0 | 0x50 | data | English | Great Britain | 0.9 |
RT_STRING | 0xda4f0 | 0x594 | data | English | Great Britain | 0.3333333333333333 |
RT_STRING | 0xdaa84 | 0x68a | data | English | Great Britain | 0.2735961768219833 |
RT_STRING | 0xdb110 | 0x490 | data | English | Great Britain | 0.3715753424657534 |
RT_STRING | 0xdb5a0 | 0x5fc | data | English | Great Britain | 0.3087467362924282 |
RT_STRING | 0xdbb9c | 0x65c | data | English | Great Britain | 0.34336609336609336 |
RT_STRING | 0xdc1f8 | 0x466 | data | English | Great Britain | 0.3605683836589698 |
RT_STRING | 0xdc660 | 0x158 | Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0 | English | Great Britain | 0.502906976744186 |
RT_RCDATA | 0xdc7b8 | 0x79c04 | data | 1.0003228445613725 | ||
RT_GROUP_ICON | 0x1563bc | 0x76 | data | English | Great Britain | 0.6610169491525424 |
RT_GROUP_ICON | 0x156434 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0x156448 | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0x15645c | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0x156470 | 0xdc | data | English | Great Britain | 0.6181818181818182 |
RT_MANIFEST | 0x15654c | 0x3ef | ASCII text, with CRLF line terminators | English | Great Britain | 0.5074478649453823 |
DLL | Import |
---|---|
WSOCK32.dll | gethostbyname, recv, send, socket, inet_ntoa, setsockopt, ntohs, WSACleanup, WSAStartup, sendto, htons, __WSAFDIsSet, select, accept, listen, bind, inet_addr, ioctlsocket, recvfrom, WSAGetLastError, closesocket, gethostname, connect |
VERSION.dll | GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW |
WINMM.dll | timeGetTime, waveOutSetVolume, mciSendStringW |
COMCTL32.dll | ImageList_ReplaceIcon, ImageList_Destroy, ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, InitCommonControlsEx, ImageList_Create |
MPR.dll | WNetGetConnectionW, WNetCancelConnection2W, WNetUseConnectionW, WNetAddConnection2W |
WININET.dll | HttpOpenRequestW, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetQueryOptionW, InternetConnectW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetReadFile, InternetQueryDataAvailable |
PSAPI.DLL | GetProcessMemoryInfo |
IPHLPAPI.DLL | IcmpSendEcho, IcmpCloseHandle, IcmpCreateFile |
USERENV.dll | DestroyEnvironmentBlock, LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile |
UxTheme.dll | IsThemeActive |
KERNEL32.dll | DuplicateHandle, CreateThread, WaitForSingleObject, HeapAlloc, GetProcessHeap, HeapFree, Sleep, GetCurrentThreadId, MultiByteToWideChar, MulDiv, GetVersionExW, IsWow64Process, GetSystemInfo, FreeLibrary, LoadLibraryA, GetProcAddress, SetErrorMode, GetModuleFileNameW, WideCharToMultiByte, lstrcpyW, lstrlenW, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, SetEndOfFile, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, GetLongPathNameW, GetShortPathNameW, DeleteFileW, IsDebuggerPresent, CopyFileExW, MoveFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, LoadResource, LockResource, SizeofResource, OutputDebugStringW, GetTempPathW, GetTempFileNameW, DeviceIoControl, LoadLibraryW, GetLocalTime, CompareStringW, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, LoadLibraryExW, FindResourceExW, CopyFileW, VirtualFree, FormatMessageW, GetExitCodeProcess, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, SetFileAttributesW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetSystemDirectoryW, HeapReAlloc, HeapSize, GetComputerNameW, GetWindowsDirectoryW, GetCurrentProcessId, GetProcessIoCounters, CreateProcessW, GetProcessId, SetPriorityClass, VirtualAlloc, GetCurrentDirectoryW, lstrcmpiW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, ResetEvent, WaitForSingleObjectEx, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, CloseHandle, GetFullPathNameW, GetStartupInfoW, GetSystemTimeAsFileTime, InitializeSListHead, RtlUnwind, SetLastError, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, ExitProcess, GetModuleHandleExW, ExitThread, ResumeThread, FreeLibraryAndExitThread, GetACP, GetDateFormatW, GetTimeFormatW, LCMapStringW, GetStringTypeW, GetFileType, SetStdHandle, GetConsoleCP, GetConsoleMode, ReadConsoleW, GetTimeZoneInformation, FindFirstFileExW, IsValidCodePage, GetOEMCP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableA, SetCurrentDirectoryW, FindNextFileW, WriteConsoleW |
USER32.dll | GetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, CallWindowProcW, ReleaseCapture, SetCapture, PeekMessageW, GetInputState, UnregisterHotKey, CharLowerBuffW, MonitorFromPoint, MonitorFromRect, LoadImageW, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, ClientToScreen, GetCursorPos, DeleteMenu, CheckMenuRadioItem, GetMenuItemID, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, LockWindowUpdate, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowLongW, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, RegisterHotKey, GetCursorInfo, SetWindowPos, CopyImage, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, TrackPopupMenuEx, GetMessageW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, GetUserObjectSecurity, MessageBoxW, DefWindowProcW, MoveWindow, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, DispatchMessageW, keybd_event, TranslateMessage, ScreenToClient |
GDI32.dll | EndPath, DeleteObject, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, GetDeviceCaps, SetPixel, CloseFigure, LineTo, AngleArc, MoveToEx, Ellipse, CreateCompatibleBitmap, CreateCompatibleDC, PolyDraw, BeginPath, Rectangle, SetViewportOrgEx, GetObjectW, SetBkMode, RoundRect, SetBkColor, CreatePen, SelectObject, StretchBlt, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, GetDIBits, StrokePath |
COMDLG32.dll | GetSaveFileNameW, GetOpenFileNameW |
ADVAPI32.dll | GetAce, RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegEnumKeyExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegConnectRegistryW, InitializeSecurityDescriptor, InitializeAcl, AdjustTokenPrivileges, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, GetLengthSid, CopySid, LogonUserW, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, GetTokenInformation, RegCreateKeyExW, GetSecurityDescriptorDacl, GetAclInformation, GetUserNameW, AddAce, SetSecurityDescriptorDacl, InitiateSystemShutdownExW |
SHELL32.dll | DragFinish, DragQueryPoint, ShellExecuteExW, DragQueryFileW, SHEmptyRecycleBinW, SHGetPathFromIDListW, SHBrowseForFolderW, SHCreateShellItem, SHGetDesktopFolder, SHGetSpecialFolderLocation, SHGetFolderPathW, SHFileOperationW, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW |
ole32.dll | CoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, ProgIDFromCLSID, CLSIDFromProgID, OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoCreateInstance, IIDFromString, StringFromGUID2, CreateStreamOnHGlobal, OleInitialize, OleUninitialize, CoInitialize, CoUninitialize, GetRunningObjectTable, CoGetInstanceFromFile, CoGetObject, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket |
OLEAUT32.dll | CreateStdDispatch, CreateDispTypeInfo, UnRegisterTypeLib, UnRegisterTypeLibForUser, RegisterTypeLibForUser, RegisterTypeLib, LoadTypeLibEx, VariantCopyInd, SysReAllocString, SysFreeString, VariantChangeType, SafeArrayDestroyData, SafeArrayUnaccessData, SafeArrayAccessData, SafeArrayAllocData, SafeArrayAllocDescriptorEx, SafeArrayCreateVector, SysStringLen, QueryPathOfRegTypeLib, SysAllocString, VariantInit, VariantClear, DispCallFunc, VariantTimeToSystemTime, VarR8FromDec, SafeArrayGetVartype, SafeArrayDestroyDescriptor, VariantCopy, OleLoadPicture |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-05T17:11:04.702504+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 20.12.23.50 | 443 | 192.168.2.5 | 49710 | TCP |
2024-11-05T17:11:43.737557+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 20.12.23.50 | 443 | 192.168.2.5 | 49910 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 5, 2024 17:10:48.217149019 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.217200041 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:48.217323065 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.225362062 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.225373983 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:48.841398001 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:48.841514111 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.846012115 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.846021891 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:48.846314907 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:48.896133900 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.899250984 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:48.943335056 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:49.080260038 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:49.080439091 CET | 443 | 49704 | 104.26.13.205 | 192.168.2.5 |
Nov 5, 2024 17:10:49.080512047 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:49.087086916 CET | 49704 | 443 | 192.168.2.5 | 104.26.13.205 |
Nov 5, 2024 17:10:49.945261002 CET | 49705 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:49.950284958 CET | 21 | 49705 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:49.950439930 CET | 49705 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:49.977458954 CET | 49705 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:49.982403994 CET | 21 | 49705 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:49.982510090 CET | 49705 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:50.020809889 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:50.025777102 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:50.025878906 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:50.978171110 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:50.978432894 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:50.983609915 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:51.336916924 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:51.337089062 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:51.341871023 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:51.741452932 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:51.741705894 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:51.746546030 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.099395990 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.099703074 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:52.105087996 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.469384909 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.469938993 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:52.474790096 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.829356909 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:52.829595089 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:52.834424973 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:53.197475910 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:53.208343983 CET | 49707 | 55400 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:53.213210106 CET | 55400 | 49707 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:53.213318110 CET | 49707 | 55400 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:53.215704918 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:53.220649004 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.183792114 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.184099913 CET | 49707 | 55400 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.184154987 CET | 49707 | 55400 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.188970089 CET | 55400 | 49707 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.189637899 CET | 55400 | 49707 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.189691067 CET | 49707 | 55400 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.224416018 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.549909115 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.550702095 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.555697918 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.940757036 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.941332102 CET | 49708 | 51240 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.946460009 CET | 51240 | 49708 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:54.946593046 CET | 49708 | 51240 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.946747065 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:54.951601028 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:55.899368048 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:55.899677038 CET | 49708 | 51240 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:55.904966116 CET | 51240 | 49708 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:55.905379057 CET | 51240 | 49708 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:55.905441046 CET | 49708 | 51240 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:55.943022013 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:56.263839960 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:56.264426947 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:56.269709110 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:56.632280111 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:56.632824898 CET | 49709 | 55039 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:56.637639046 CET | 55039 | 49709 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:56.637703896 CET | 49709 | 55039 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:56.637815952 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:56.643281937 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:57.686714888 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:57.686956882 CET | 49709 | 55039 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:57.692728043 CET | 55039 | 49709 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:57.692785025 CET | 49709 | 55039 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:57.739902973 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:10:58.040682077 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:10:58.083663940 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:32.297159910 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:32.302635908 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:32.302719116 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:32.355961084 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:32.361068010 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:32.361140013 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:33.272506952 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.272980928 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:33.278048038 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.308090925 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.313579082 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:33.318485022 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.653305054 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.657690048 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:33.663325071 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.672970057 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:33.677644968 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:33.682487011 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.065985918 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.075620890 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.075965881 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.080550909 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.086736917 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.091562033 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.426153898 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.426343918 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.431499004 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.433691025 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.433847904 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.438678980 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.789622068 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.789750099 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.794620991 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.803688049 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:34.803956032 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:34.809438944 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.145148039 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.145499945 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.151070118 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.181807041 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.182012081 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.187006950 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.498697042 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.499159098 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.504225016 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.504295111 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.504350901 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.509229898 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.546495914 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.546925068 CET | 49984 | 51110 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.551836014 CET | 51110 | 49984 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:35.551909924 CET | 49984 | 51110 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.551964998 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:35.556986094 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.439886093 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.440212965 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445131063 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445153952 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445163965 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445173979 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445194960 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445245981 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445282936 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445324898 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445365906 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445413113 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445446014 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445456028 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445463896 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445499897 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445517063 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.445589066 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.445633888 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450102091 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450113058 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450123072 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450131893 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450164080 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450176954 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450186014 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450187922 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450206041 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450227976 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450248003 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450383902 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450402021 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450422049 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450438976 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450467110 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.450503111 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.450896025 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455290079 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455370903 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455379963 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455389977 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455399036 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455410004 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455419064 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455429077 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.455437899 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.456434011 CET | 59048 | 49983 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.456486940 CET | 49983 | 59048 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.516165018 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.517388105 CET | 49984 | 51110 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.517695904 CET | 49984 | 51110 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.522310019 CET | 51110 | 49984 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.522905111 CET | 51110 | 49984 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.522955894 CET | 49984 | 51110 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.532089949 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.572428942 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.879206896 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.879631042 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.885138035 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.885189056 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.895669937 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:36.900541067 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:36.900607109 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:37.258063078 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:37.381911993 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:37.916678905 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:37.916836977 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:37.921974897 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.269865990 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.270133018 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:38.275028944 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.631747007 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.631886005 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:38.636785984 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.979712963 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:38.981667995 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:38.986954927 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:39.338624001 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:39.338812113 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:39.345292091 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:39.689390898 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:39.689719915 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:39.696058035 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:40.036015034 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:40.039695978 CET | 49986 | 60859 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:40.046217918 CET | 60859 | 49986 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:40.047791958 CET | 49986 | 60859 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:40.051757097 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:40.056852102 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:41.036556959 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:41.036904097 CET | 49986 | 60859 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:41.036925077 CET | 49986 | 60859 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:41.041764021 CET | 60859 | 49986 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:41.042527914 CET | 60859 | 49986 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:41.042576075 CET | 49986 | 60859 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:41.085062027 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:41.381006002 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:41.589687109 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:42.277147055 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:42.282594919 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:42.626965046 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:42.627485991 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:42.632327080 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:42.632386923 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:42.632441044 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:42.637861013 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.573545933 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.576064110 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.580935955 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.580990076 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581037045 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581046104 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581054926 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581095934 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.581268072 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.581465960 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581475973 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581511021 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581520081 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581559896 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.581619978 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.585951090 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.585975885 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586039066 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586110115 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586118937 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586155891 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586158991 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.586189032 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.586211920 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586241961 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.586292028 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586504936 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.586569071 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586600065 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586699009 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.586740017 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.586873055 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591041088 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591172934 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591392040 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591448069 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591456890 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591495037 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591948032 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.591995001 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592092037 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592101097 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592116117 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592160940 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592248917 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592257977 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592272043 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.592662096 CET | 57907 | 49987 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:43.597814083 CET | 49987 | 57907 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:43.681714058 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:44.151632071 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:44.156748056 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:44.474982977 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:44.521121979 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:44.521759033 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:44.527585030 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:44.527661085 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:44.527796030 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:44.533055067 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:44.564940929 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.471944094 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.481786013 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.486685991 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486701012 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486721992 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486732006 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486736059 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486936092 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486944914 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486989975 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.486995935 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.486999035 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.487030983 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.487031937 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.491928101 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.491940022 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.491952896 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.491961956 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.492003918 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.492053032 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.492146015 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.492156029 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.492326975 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.492357016 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.492429972 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.492490053 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.493758917 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.496841908 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.496911049 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.496922016 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.496948957 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497483969 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497493982 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497504950 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497514963 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497524023 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497531891 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497550964 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497560024 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497603893 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497612953 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497756004 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497765064 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.497775078 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.498541117 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.498550892 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.498809099 CET | 54693 | 49988 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:45.499845982 CET | 49988 | 54693 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:45.678900003 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:46.316385031 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:46.390718937 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:54.950130939 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:54.955044031 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:55.318734884 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:55.319370031 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:55.324287891 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:55.324361086 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:55.324455023 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:55.329830885 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.275445938 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.278249025 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.283293962 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283320904 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283343077 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283353090 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283364058 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283385038 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283392906 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283421993 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283454895 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.283545971 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.283548117 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.283593893 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.285620928 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.288537979 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288553953 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288575888 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288590908 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288602114 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288610935 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288621902 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288635969 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.288680077 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.288695097 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.288738966 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.288773060 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.290628910 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.290791988 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.290890932 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.293534040 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.315298080 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.323945999 CET | 54551 | 49989 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:56.326044083 CET | 49989 | 54551 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.410815001 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.860074997 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:56.865051031 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:57.098598003 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:57.179074049 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:57.206954956 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:57.207407951 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:57.212562084 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:57.212662935 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:57.212723970 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:57.218302011 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.155122042 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.155455112 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.160567045 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160615921 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160667896 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160677910 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160703897 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.160792112 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160795927 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.160814047 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160881042 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160883904 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.160932064 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.160958052 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.161006927 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.161020041 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.161026955 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.161065102 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.161065102 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.165632963 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165714979 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165724039 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165733099 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165751934 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165760994 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165841103 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165863991 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.165919065 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.165934086 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165968895 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.165994883 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.166145086 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.171116114 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.171253920 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.171416044 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.176299095 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.176307917 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.177170992 CET | 60673 | 49990 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:58.177303076 CET | 49990 | 60673 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.289916039 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:12:58.969660044 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:12:59.079931974 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:02.215408087 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:02.220278978 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:02.556874990 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:02.557399035 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:02.562971115 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:02.563034058 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:02.563152075 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:02.568017006 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.471445084 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.476197004 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.481040001 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481084108 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481095076 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481144905 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481153965 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481199026 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.481285095 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481303930 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481389999 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481400013 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481410027 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.481494904 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.486002922 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486126900 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486136913 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486152887 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486162901 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486171007 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486180067 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486254930 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486279011 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.486371040 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486402035 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.486416101 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486432076 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486450911 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.486692905 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.486737967 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.491187096 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491218090 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491235018 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491297007 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491395950 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491482973 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491571903 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491642952 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491651058 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491678953 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491703987 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491724014 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491777897 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491786957 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491887093 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491895914 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491913080 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.491928101 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.492255926 CET | 60691 | 49991 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:03.494041920 CET | 49991 | 60691 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:03.585396051 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:04.256613970 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:04.426954031 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:22.172518969 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:22.177650928 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:22.507436037 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:22.508059025 CET | 49992 | 63446 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:22.512995958 CET | 63446 | 49992 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:22.513060093 CET | 49992 | 63446 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:22.513149023 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:22.517975092 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:23.414892912 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:23.420263052 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:23.425437927 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:23.432295084 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:23.975974083 CET | 63446 | 49992 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:23.976059914 CET | 49992 | 63446 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:35.123091936 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:35.128060102 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:35.489629030 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:35.490199089 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:35.495279074 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:35.495498896 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:35.495609045 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:35.500364065 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.294410944 CET | 49994 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.302838087 CET | 21 | 49994 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.303112984 CET | 49994 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.303347111 CET | 49994 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.311788082 CET | 21 | 49994 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.323060989 CET | 21 | 49994 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.323211908 CET | 49994 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.447402954 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.447752953 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.452955008 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453003883 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453011990 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453067064 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453073025 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.453075886 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453083992 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453124046 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453133106 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453140974 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453142881 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.453151941 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.453223944 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458158970 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458173990 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458183050 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458192110 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458213091 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458221912 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458251953 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458261013 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458271027 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458281040 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458282948 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458337069 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458343983 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458353043 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458362103 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458365917 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.458379030 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.458421946 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.463973045 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464025021 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464034081 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464042902 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464054108 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464061975 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464066029 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464075089 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464087009 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464095116 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464102983 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464111090 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464119911 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464133024 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464142084 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464149952 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464158058 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464165926 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464174032 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464231968 CET | 64496 | 49993 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:36.464410067 CET | 49993 | 64496 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:36.492006063 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:13:37.252393961 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:13:37.304501057 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:14.860318899 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:14.865211010 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:15.193813086 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:15.194364071 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:15.199193954 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:15.199256897 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:15.199348927 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:15.204150915 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.193522930 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.193831921 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.198990107 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199016094 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199081898 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199110031 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199111938 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199121952 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199157000 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199182987 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199197054 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199242115 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199306011 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199348927 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199350119 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199399948 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199429035 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199446917 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199456930 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.199482918 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.199523926 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204125881 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204135895 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204145908 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204154968 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204195023 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204219103 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204262018 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204271078 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204303026 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204315901 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204391003 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204400063 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204453945 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204500914 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204533100 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204555035 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204607964 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.204706907 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.204752922 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.209193945 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209287882 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209342957 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209477901 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209522009 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209569931 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209630013 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209701061 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209708929 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209723949 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209783077 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209791899 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209800959 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209836006 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209845066 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.209947109 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.210015059 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.210024118 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.211337090 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.211348057 CET | 55289 | 49995 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:17.211395025 CET | 49995 | 55289 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:17.351712942 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:18.035343885 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:18.117568016 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:24.389051914 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:24.394294024 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:24.723521948 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:24.724056005 CET | 49996 | 54575 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:24.729166031 CET | 54575 | 49996 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:24.729235888 CET | 49996 | 54575 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:24.729357958 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:24.734368086 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:25.133531094 CET | 49996 | 54575 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:25.139075994 CET | 54575 | 49996 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:25.139137983 CET | 49996 | 54575 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:25.631181955 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:25.631582975 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:25.631719112 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:25.633989096 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:26.595221996 CET | 49997 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:26.601161003 CET | 21 | 49997 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:26.601248980 CET | 49997 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:26.601572990 CET | 49997 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:26.608114004 CET | 21 | 49997 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:26.608169079 CET | 49997 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:30.612314939 CET | 49998 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:30.617454052 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:30.617515087 CET | 49998 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:30.617871046 CET | 49998 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:30.622989893 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:30.623044014 CET | 49998 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.756378889 CET | 49999 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.761430025 CET | 21 | 49999 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:34.761548042 CET | 49999 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.761750937 CET | 49999 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.767178059 CET | 21 | 49999 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:34.767230034 CET | 49999 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.768794060 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:34.768888950 CET | 49992 | 63446 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:41.653592110 CET | 50000 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:41.662815094 CET | 21 | 50000 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:41.667798996 CET | 50000 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:41.667799950 CET | 50000 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:41.674467087 CET | 21 | 50000 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:41.681387901 CET | 50000 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:52.700786114 CET | 50001 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:52.705840111 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:52.705938101 CET | 50001 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:53.616082907 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:53.616255999 CET | 50001 | 21 | 192.168.2.5 | 110.4.45.197 |
Nov 5, 2024 17:14:53.621121883 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:53.949790955 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 |
Nov 5, 2024 17:14:53.992858887 CET | 50001 | 21 | 192.168.2.5 | 110.4.45.197 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 5, 2024 17:10:48.201493025 CET | 53148 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 5, 2024 17:10:48.208720922 CET | 53 | 53148 | 1.1.1.1 | 192.168.2.5 |
Nov 5, 2024 17:10:49.675369978 CET | 51551 | 53 | 192.168.2.5 | 1.1.1.1 |
Nov 5, 2024 17:10:49.944159031 CET | 53 | 51551 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 5, 2024 17:10:48.201493025 CET | 192.168.2.5 | 1.1.1.1 | 0xf080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 5, 2024 17:10:49.675369978 CET | 192.168.2.5 | 1.1.1.1 | 0x3c85 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 5, 2024 17:10:48.208720922 CET | 1.1.1.1 | 192.168.2.5 | 0xf080 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Nov 5, 2024 17:10:48.208720922 CET | 1.1.1.1 | 192.168.2.5 | 0xf080 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Nov 5, 2024 17:10:48.208720922 CET | 1.1.1.1 | 192.168.2.5 | 0xf080 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Nov 5, 2024 17:10:49.944159031 CET | 1.1.1.1 | 192.168.2.5 | 0x3c85 | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 104.26.13.205 | 443 | 6656 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-05 16:10:48 UTC | 155 | OUT | |
2024-11-05 16:10:49 UTC | 399 | IN | |
2024-11-05 16:10:49 UTC | 14 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Nov 5, 2024 17:10:50.978171110 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 9 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 9 of 50 allowed.220-Local time is now 00:10. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 9 of 50 allowed.220-Local time is now 00:10. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 9 of 50 allowed.220-Local time is now 00:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 9 of 50 allowed.220-Local time is now 00:10. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 5, 2024 17:10:50.978432894 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 5, 2024 17:10:51.336916924 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 331 User origin@haliza.com.my OK. Password required |
Nov 5, 2024 17:10:51.337089062 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 5, 2024 17:10:51.741452932 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 230 OK. Current restricted directory is / |
Nov 5, 2024 17:10:52.099395990 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 504 Unknown command |
Nov 5, 2024 17:10:52.099703074 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | PWD |
Nov 5, 2024 17:10:52.469384909 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 257 "/" is your current location |
Nov 5, 2024 17:10:52.469938993 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | TYPE I |
Nov 5, 2024 17:10:52.829356909 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 200 TYPE is now 8-bit binary |
Nov 5, 2024 17:10:52.829595089 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:10:53.197475910 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,216,104) |
Nov 5, 2024 17:10:53.215704918 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-936905_2024_11_05_11_40_48.txt |
Nov 5, 2024 17:10:54.183792114 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:10:54.549909115 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.375 seconds (measured here), 0.75 Kbytes per second |
Nov 5, 2024 17:10:54.550702095 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:10:54.940757036 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,200,40) |
Nov 5, 2024 17:10:54.946747065 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | STOR CO_Edge Chromium_Default.txt_user-936905_2024_11_05_17_59_10.txt |
Nov 5, 2024 17:10:55.899368048 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:10:56.263839960 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 226 File successfully transferred |
Nov 5, 2024 17:10:56.264426947 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:10:56.632280111 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,214,255) |
Nov 5, 2024 17:10:56.637815952 CET | 49706 | 21 | 192.168.2.5 | 110.4.45.197 | STOR CO_Firefox_v6zchhhv.default-release.txt_user-936905_2024_11_05_20_17_52.txt |
Nov 5, 2024 17:10:57.686714888 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:10:58.040682077 CET | 21 | 49706 | 110.4.45.197 | 192.168.2.5 | 226 File successfully transferred |
Nov 5, 2024 17:12:33.272506952 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 00:12. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 10 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 5, 2024 17:12:33.272980928 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 5, 2024 17:12:33.308090925 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 5, 2024 17:12:33.313579082 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 5, 2024 17:12:33.653305054 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 331 User origin@haliza.com.my OK. Password required |
Nov 5, 2024 17:12:33.657690048 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 5, 2024 17:12:33.672970057 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 331 User origin@haliza.com.my OK. Password required |
Nov 5, 2024 17:12:33.677644968 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 5, 2024 17:12:34.065985918 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 230 OK. Current restricted directory is / |
Nov 5, 2024 17:12:34.075965881 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 230 OK. Current restricted directory is / |
Nov 5, 2024 17:12:34.426153898 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 504 Unknown command |
Nov 5, 2024 17:12:34.426343918 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PWD |
Nov 5, 2024 17:12:34.433691025 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 504 Unknown command |
Nov 5, 2024 17:12:34.433847904 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | PWD |
Nov 5, 2024 17:12:34.789622068 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 257 "/" is your current location |
Nov 5, 2024 17:12:34.789750099 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | TYPE I |
Nov 5, 2024 17:12:34.803688049 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 257 "/" is your current location |
Nov 5, 2024 17:12:34.803956032 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | TYPE I |
Nov 5, 2024 17:12:35.145148039 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 200 TYPE is now 8-bit binary |
Nov 5, 2024 17:12:35.145499945 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:35.181807041 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 200 TYPE is now 8-bit binary |
Nov 5, 2024 17:12:35.182012081 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:35.498697042 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,230,168) |
Nov 5, 2024 17:12:35.504350901 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_11_23_17_53_34.jpeg |
Nov 5, 2024 17:12:35.546495914 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,199,166) |
Nov 5, 2024 17:12:35.551964998 CET | 49981 | 21 | 192.168.2.5 | 110.4.45.197 | STOR KL_user-936905_2024_11_23_16_42_45.html |
Nov 5, 2024 17:12:36.439886093 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:36.516165018 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:36.879206896 CET | 21 | 49981 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.362 seconds (measured here), 0.77 Kbytes per second |
Nov 5, 2024 17:12:37.258063078 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.808 seconds (measured here), 91.16 Kbytes per second |
Nov 5, 2024 17:12:37.916678905 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 00:12. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 5, 2024 17:12:37.916836977 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 5, 2024 17:12:38.269865990 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 331 User origin@haliza.com.my OK. Password required |
Nov 5, 2024 17:12:38.270133018 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 5, 2024 17:12:38.631747007 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 230 OK. Current restricted directory is / |
Nov 5, 2024 17:12:38.979712963 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 504 Unknown command |
Nov 5, 2024 17:12:38.981667995 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PWD |
Nov 5, 2024 17:12:39.338624001 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 257 "/" is your current location |
Nov 5, 2024 17:12:39.338812113 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | TYPE I |
Nov 5, 2024 17:12:39.689390898 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 200 TYPE is now 8-bit binary |
Nov 5, 2024 17:12:39.689719915 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:40.036015034 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,237,187) |
Nov 5, 2024 17:12:40.051757097 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | STOR KL_user-936905_2024_11_27_16_18_29.html |
Nov 5, 2024 17:12:41.036556959 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:41.381006002 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.362 seconds (measured here), 0.62 Kbytes per second |
Nov 5, 2024 17:12:42.277147055 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:42.626965046 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,226,51) |
Nov 5, 2024 17:12:42.632441044 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_12_02_05_29_34.jpeg |
Nov 5, 2024 17:12:43.573545933 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:44.151632071 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:44.474982977 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.877 seconds (measured here), 84.03 Kbytes per second |
Nov 5, 2024 17:12:44.521121979 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,213,165) |
Nov 5, 2024 17:12:44.527796030 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_12_05_05_44_07.jpeg |
Nov 5, 2024 17:12:45.471944094 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:46.316385031 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.853 seconds (measured here), 86.38 Kbytes per second |
Nov 5, 2024 17:12:54.950130939 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:55.318734884 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,213,23) |
Nov 5, 2024 17:12:55.324455023 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_12_13_03_01_36.jpeg |
Nov 5, 2024 17:12:56.275445938 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:56.860074997 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:12:57.098598003 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.834 seconds (measured here), 88.27 Kbytes per second |
Nov 5, 2024 17:12:57.206954956 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,237,1) |
Nov 5, 2024 17:12:57.212723970 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_12_16_03_14_31.jpeg |
Nov 5, 2024 17:12:58.155122042 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:12:58.969660044 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.828 seconds (measured here), 88.96 Kbytes per second |
Nov 5, 2024 17:13:02.215408087 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:13:02.556874990 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,237,19) |
Nov 5, 2024 17:13:02.563152075 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2024_12_20_14_13_44.jpeg |
Nov 5, 2024 17:13:03.471445084 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:13:04.256613970 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.778 seconds (measured here), 94.84 Kbytes per second |
Nov 5, 2024 17:13:22.172518969 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:13:22.507436037 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,247,214) |
Nov 5, 2024 17:13:22.513149023 CET | 49985 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2025_01_04_23_27_38.jpeg |
Nov 5, 2024 17:13:23.414892912 CET | 21 | 49985 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:13:35.123091936 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:13:35.489629030 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,251,240) |
Nov 5, 2024 17:13:35.495609045 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2025_01_12_14_50_58.jpeg |
Nov 5, 2024 17:13:36.447402954 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:13:37.252393961 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.812 seconds (measured here), 90.72 Kbytes per second |
Nov 5, 2024 17:14:14.860318899 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:14:15.193813086 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,215,249) |
Nov 5, 2024 17:14:15.199348927 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2025_02_02_13_00_38.jpeg |
Nov 5, 2024 17:14:17.193522930 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:14:18.035343885 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226-File successfully transferred 226-File successfully transferred226 0.866 seconds (measured here), 89.45 Kbytes per second |
Nov 5, 2024 17:14:24.389051914 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | PASV |
Nov 5, 2024 17:14:24.723521948 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 227 Entering Passive Mode (110,4,45,197,213,47) |
Nov 5, 2024 17:14:24.729357958 CET | 49982 | 21 | 192.168.2.5 | 110.4.45.197 | STOR SC_user-936905_2025_02_08_19_37_35.jpeg |
Nov 5, 2024 17:14:25.631181955 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 150 Accepted data connection |
Nov 5, 2024 17:14:25.631582975 CET | 21 | 49982 | 110.4.45.197 | 192.168.2.5 | 226 File successfully transferred |
Nov 5, 2024 17:14:53.616082907 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 50 allowed.220-Local time is now 00:14. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 50 allowed.220-Local time is now 00:14. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 50 allowed.220-Local time is now 00:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 7 of 50 allowed.220-Local time is now 00:14. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 5, 2024 17:14:53.616255999 CET | 50001 | 21 | 192.168.2.5 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 5, 2024 17:14:53.949790955 CET | 21 | 50001 | 110.4.45.197 | 192.168.2.5 | 331 User origin@haliza.com.my OK. Password required |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:10:44 |
Start date: | 05/11/2024 |
Path: | C:\Users\user\Desktop\Payment_Advice_USD_48,054.40_.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x470000 |
File size: | 1'414'144 bytes |
MD5 hash: | F488EA907A7447947FDD751CE2D1D0DA |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:10:45 |
Start date: | 05/11/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd00000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 11:10:57 |
Start date: | 05/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa90000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:10:57 |
Start date: | 05/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 11:11:05 |
Start date: | 05/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:11:05 |
Start date: | 05/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 2.7% |
Dynamic/Decrypted Code Coverage: | 1.1% |
Signature Coverage: | 5.5% |
Total number of Nodes: | 1583 |
Total number of Limit Nodes: | 42 |
Graph
Function 004742DE Relevance: 21.2, APIs: 9, Strings: 3, Instructions: 235libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047BF40 Relevance: 2.4, Strings: 1, Instructions: 1178COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047D730 Relevance: 21.6, APIs: 14, Instructions: 626windowsleeptimeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00472CD4 Relevance: 19.3, APIs: 7, Strings: 4, Instructions: 53windowregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004B065B Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 272COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047344D Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 201registryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00472B83 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 63windowregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00473170 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 145windowtimeregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E29D18 Relevance: 10.7, APIs: 7, Instructions: 239fileCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E29AC8 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 152fileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00473B1C Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 58registryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00473923 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 94windowCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F7F59 Relevance: 4.9, APIs: 3, Instructions: 430COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004710F3 Relevance: 4.7, APIs: 3, Instructions: 153comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00473837 Relevance: 3.1, APIs: 2, Instructions: 77windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00475745 Relevance: 3.1, APIs: 2, Instructions: 56fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048FC70 Relevance: 1.6, APIs: 1, Instructions: 94memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00474ECB Relevance: 1.6, APIs: 1, Instructions: 65libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A8402 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0049E602 Relevance: 1.5, APIs: 1, Instructions: 46COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00479CB3 Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A4C7D Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A3820 Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00474F39 Relevance: 1.5, APIs: 1, Instructions: 28COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DCCFF Relevance: 1.5, APIs: 1, Instructions: 26fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00472DA5 Relevance: 1.5, APIs: 1, Instructions: 23COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00472B3D Relevance: 1.5, APIs: 1, Instructions: 22COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00471CAD Relevance: 1.5, APIs: 1, Instructions: 8COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E744A Relevance: 1.5, APIs: 1, Instructions: 220COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00476246 Relevance: 1.3, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E299B8 Relevance: 1.3, APIs: 1, Instructions: 18sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00509576 Relevance: 74.1, APIs: 39, Strings: 3, Instructions: 625windowkeyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00504873 Relevance: 60.1, APIs: 33, Strings: 1, Instructions: 566windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048F98E Relevance: 43.9, APIs: 24, Strings: 1, Instructions: 130keyboardthreadwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E698F Relevance: 21.4, APIs: 7, Strings: 5, Instructions: 363timefileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E9642 Relevance: 21.1, APIs: 11, Strings: 1, Instructions: 118fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E979D Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 111fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E8195 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 186timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DD076 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 172fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EED6A Relevance: 13.6, APIs: 9, Instructions: 102clipboardmemoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DE8F6 Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 57shutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004AB952 Relevance: 10.9, APIs: 7, Instructions: 370timeCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DD3A9 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 91fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F22DA Relevance: 9.1, APIs: 6, Instructions: 103COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E9B2B Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 119filesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048997D Relevance: 7.9, APIs: 5, Instructions: 375COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00501C41 Relevance: 7.6, APIs: 5, Instructions: 83windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00478060 Relevance: 7.4, Strings: 5, Instructions: 1151COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D8298 Relevance: 6.6, APIs: 1, Strings: 3, Instructions: 568stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E5C97 Relevance: 4.6, APIs: 3, Instructions: 138fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E51CD Relevance: 4.6, APIs: 3, Instructions: 76COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D16C3 Relevance: 4.6, APIs: 3, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DD5EB Relevance: 4.6, APIs: 3, Instructions: 58fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1663 Relevance: 4.5, APIs: 3, Instructions: 40memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0049CAA0 Relevance: 3.5, APIs: 2, Instructions: 464COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047CAF0 Relevance: 3.2, Strings: 2, Instructions: 659COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E68EE Relevance: 3.1, APIs: 2, Instructions: 57fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E37B5 Relevance: 3.0, APIs: 2, Instructions: 33windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D10BF Relevance: 3.0, APIs: 2, Instructions: 24COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048B119 Relevance: 1.8, Strings: 1, Instructions: 511COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004909D5 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0049781B Relevance: 1.5, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E2046 Relevance: 1.3, Strings: 1, Instructions: 72COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A6DD9 Relevance: .6, Instructions: 637COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048CC39 Relevance: .6, Instructions: 635COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00477920 Relevance: .6, Instructions: 563COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004791C0 Relevance: .5, Instructions: 475COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00491C77 Relevance: .3, Instructions: 254COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004919B0 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00497A4A Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00497CA7 Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00491706 Relevance: .2, Instructions: 232COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004C3CD2 Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F2ADE Relevance: 77.5, APIs: 40, Strings: 4, Instructions: 486filecommemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005070D5 Relevance: 49.8, APIs: 33, Instructions: 273COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00488D85 Relevance: 47.7, APIs: 26, Strings: 1, Instructions: 480windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F2711 Relevance: 45.8, APIs: 22, Strings: 4, Instructions: 330windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00500FF3 Relevance: 37.0, APIs: 18, Strings: 3, Instructions: 284windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00500241 Relevance: 35.4, APIs: 7, Strings: 13, Instructions: 391windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00488891 Relevance: 35.3, APIs: 18, Strings: 2, Instructions: 282windowtimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FC3B7 Relevance: 30.2, APIs: 11, Strings: 6, Instructions: 495registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050091E Relevance: 30.1, APIs: 6, Strings: 11, Instructions: 372windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050833C Relevance: 29.9, APIs: 14, Strings: 3, Instructions: 196windowlibraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004900FD Relevance: 29.8, APIs: 12, Strings: 5, Instructions: 82libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050911E Relevance: 24.7, APIs: 10, Strings: 4, Instructions: 181windowfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047326F Relevance: 23.0, APIs: 12, Strings: 1, Instructions: 214windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00506CD9 Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 194windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EC476 Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 143networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E14BD Relevance: 21.4, APIs: 10, Strings: 2, Instructions: 360timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FB60E Relevance: 21.3, APIs: 10, Strings: 2, Instructions: 285registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F255C Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 169windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D365B Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 267windowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508D0E Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 221windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FCC34 Relevance: 19.4, APIs: 9, Strings: 2, Instructions: 104registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DE6B0 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 72sleepwindowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D5CC6 Relevance: 18.2, APIs: 12, Instructions: 173COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00488BCD Relevance: 18.2, APIs: 12, Instructions: 168timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00489838 Relevance: 18.1, APIs: 12, Instructions: 137COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A8D45 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 300COMMONLIBRARYCODE
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D96E2 Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 137windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D06DE Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 127registryshareCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F3C30 Relevance: 16.8, APIs: 11, Instructions: 344fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E7A96 Relevance: 16.8, APIs: 11, Instructions: 298comCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F055B Relevance: 16.0, APIs: 8, Strings: 1, Instructions: 207networkfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F372C Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 187comCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508B02 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 149windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00503C46 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 101windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A2C80 Relevance: 15.1, APIs: 10, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00471410 Relevance: 14.3, APIs: 7, Strings: 1, Instructions: 332comCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00475BEA Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 184windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EC253 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 94networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D989B Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 74windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D209F Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 71windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004ACE90 Relevance: 13.7, APIs: 9, Instructions: 209COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D25A2 Relevance: 13.6, APIs: 9, Instructions: 60sleepkeyboardwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00503886 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 141windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DBC5E Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 137windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DC874 Relevance: 12.3, APIs: 2, Strings: 5, Instructions: 81windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DED19 Relevance: 12.1, APIs: 8, Instructions: 137timeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048F8D8 Relevance: 12.1, APIs: 8, Instructions: 124COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502D03 Relevance: 12.1, APIs: 8, Instructions: 95windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D5622 Relevance: 12.1, APIs: 8, Instructions: 92COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004B1522 Relevance: 10.8, APIs: 7, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E1187 Relevance: 10.8, APIs: 7, Instructions: 254COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048948A Relevance: 10.8, APIs: 7, Instructions: 254COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A542E Relevance: 10.7, APIs: 7, Instructions: 152fileCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DCF00 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 108filestringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502DFD Relevance: 10.6, APIs: 7, Instructions: 99windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D7726 Relevance: 10.6, APIs: 7, Instructions: 94memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D77FD Relevance: 10.6, APIs: 7, Instructions: 89memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E04D2 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 80pipeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E05A7 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 80pipeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005040AD Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 75windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DDA5A Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E096B Relevance: 10.5, APIs: 7, Instructions: 35synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A01B7 Relevance: 9.3, APIs: 6, Instructions: 269COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A61FE Relevance: 9.2, APIs: 6, Instructions: 216COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004CF7AD Relevance: 9.2, APIs: 6, Instructions: 183memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048920C Relevance: 9.1, APIs: 6, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E07EF Relevance: 9.1, APIs: 6, Instructions: 107fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005081DB Relevance: 9.1, APIs: 6, Instructions: 104windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D4C7D Relevance: 9.1, APIs: 6, Instructions: 87windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D175D Relevance: 9.1, APIs: 6, Instructions: 68memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D14CE Relevance: 9.1, APIs: 6, Instructions: 64processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508A24 Relevance: 9.0, APIs: 6, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D51FD Relevance: 9.0, APIs: 6, Instructions: 49COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004C7439 Relevance: 9.0, APIs: 6, Instructions: 37windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1874 Relevance: 9.0, APIs: 6, Instructions: 23memorysynchronizationCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DC5D0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 191windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D719E Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 120comlibraryloaderCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502F17 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 78windowlibraryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00494D6D Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00474E90 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 24libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00474E59 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 22libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E2947 Relevance: 7.8, APIs: 5, Instructions: 313fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FA387 Relevance: 7.8, APIs: 5, Instructions: 256COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D8BB0 Relevance: 7.7, APIs: 5, Instructions: 159COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E8AFB Relevance: 7.6, APIs: 5, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00506B76 Relevance: 7.6, APIs: 5, Instructions: 131windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E3874 Relevance: 7.6, APIs: 5, Instructions: 101windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00505706 Relevance: 7.6, APIs: 5, Instructions: 82windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F0930 Relevance: 7.6, APIs: 5, Instructions: 69COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004ACDBD Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00489639 Relevance: 7.6, APIs: 5, Instructions: 66COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D5711 Relevance: 7.6, APIs: 5, Instructions: 61COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D000E Relevance: 7.5, APIs: 5, Instructions: 47stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DE97B Relevance: 7.5, APIs: 5, Instructions: 47sleepCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D10F9 Relevance: 7.5, APIs: 5, Instructions: 46memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D0FB4 Relevance: 7.5, APIs: 5, Instructions: 43memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1014 Relevance: 7.5, APIs: 5, Instructions: 43memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E030F Relevance: 7.5, APIs: 6, Instructions: 41COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A22A0 Relevance: 7.5, APIs: 5, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004895C5 Relevance: 7.5, APIs: 5, Instructions: 29COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A0F47 Relevance: 7.4, APIs: 2, Strings: 2, Instructions: 389COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A5AA9 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 186COMMONLIBRARYCODE
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A8A61 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 124COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D2716 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 121windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DC27D Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 114windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D6E71 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 92memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F304E Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 90networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00504653 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 87windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005037B7 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005041EB Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 67windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D2F52 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 67windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00505882 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 47windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004CD3A0 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 30libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D007F Relevance: 6.3, APIs: 4, Instructions: 322COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F342E Relevance: 6.3, APIs: 4, Instructions: 257COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D0436 Relevance: 6.2, APIs: 4, Instructions: 230COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00506278 Relevance: 6.1, APIs: 4, Instructions: 138COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004AB41F Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E56D9 Relevance: 6.1, APIs: 4, Instructions: 110fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005052C1 Relevance: 6.1, APIs: 4, Instructions: 104windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507674 Relevance: 6.1, APIs: 4, Instructions: 102windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005016DA Relevance: 6.1, APIs: 4, Instructions: 101COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DD4DC Relevance: 6.1, APIs: 4, Instructions: 86processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508FC9 Relevance: 6.1, APIs: 4, Instructions: 78windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DD2C1 Relevance: 6.1, APIs: 4, Instructions: 78COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1571 Relevance: 6.1, APIs: 4, Instructions: 78memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502782 Relevance: 6.1, APIs: 4, Instructions: 75COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D78F5 Relevance: 6.1, APIs: 3, Strings: 1, Instructions: 71stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507CC2 Relevance: 6.1, APIs: 4, Instructions: 70COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00505660 Relevance: 6.1, APIs: 4, Instructions: 67windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1A27 Relevance: 6.1, APIs: 4, Instructions: 56windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DE1D6 Relevance: 6.1, APIs: 4, Instructions: 55synchronizationthreadwindowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0049D1CC Relevance: 6.1, APIs: 4, Instructions: 55threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047600E Relevance: 6.1, APIs: 4, Instructions: 53windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004A3073 Relevance: 6.1, APIs: 4, Instructions: 52libraryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004DB0A8 Relevance: 6.0, APIs: 4, Instructions: 50sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508863 Relevance: 6.0, APIs: 4, Instructions: 31COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004898B0 Relevance: 6.0, APIs: 4, Instructions: 23COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D162B Relevance: 6.0, APIs: 4, Instructions: 22threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004CD858 Relevance: 6.0, APIs: 4, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004CD86C Relevance: 6.0, APIs: 4, Instructions: 18COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E4D87 Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 230shareCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0048F291 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 144sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004ED0F4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 98networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00504537 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 95windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005031EF Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004ECD1E Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 66networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00503429 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 64windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1CDE Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 52windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1BD8 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 50windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D1C5C Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 49windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508172 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 40processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004D0B15 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 28windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502356 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 15windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502322 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 15windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|