Windows
Analysis Report
Pi648je050.exe
Overview
General Information
Sample name: | Pi648je050.exerenamed because original name is a hash value |
Original sample name: | 22c46eed2c96ab6e83aa4e917bc36fb76ff4abc83e01fcceaef07fcc7e8d9265.exe |
Analysis ID: | 1550182 |
MD5: | b47427b1a08950c5d561d65b664f0100 |
SHA1: | 2c45c83042460e904ce6d0607b67472b505637ad |
SHA256: | 22c46eed2c96ab6e83aa4e917bc36fb76ff4abc83e01fcceaef07fcc7e8d9265 |
Tags: | AgentTeslaexeuser-adrian__luca |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Pi648je050.exe (PID: 5348 cmdline:
"C:\Users\ user\Deskt op\Pi648je 050.exe" MD5: B47427B1A08950C5D561D65B664F0100) - RegSvcs.exe (PID: 5960 cmdline:
"C:\Users\ user\Deskt op\Pi648je 050.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - Pi648je050.exe (PID: 5716 cmdline:
"C:\Users\ user\Deskt op\Pi648je 050.exe" MD5: B47427B1A08950C5D561D65B664F0100) - RegSvcs.exe (PID: 6484 cmdline:
"C:\Users\ user\Deskt op\Pi648je 050.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94)
- sgxIb.exe (PID: 5724 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - conhost.exe (PID: 2448 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- sgxIb.exe (PID: 6508 cmdline:
"C:\Users\ user\AppDa ta\Roaming \sgxIb\sgx Ib.exe" MD5: 9D352BC46709F0CB5EC974633A0C3C94) - conhost.exe (PID: 1016 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "FTP", "Host": "ftp://ftp.haliza.com.my", "Username": "origin@haliza.com.my", "Password": "JesusChrist007$"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
MALWARE_Win_AgentTeslaV2 | AgenetTesla Type 2 Keylogger payload | ditekSHen |
| |
Click to see the 16 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
MALWARE_Win_RedLine | Detects RedLine infostealer | ditekSHen |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
| |
Click to see the 49 entries |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-06T15:08:14.496660+0100 | 2022930 | 1 | A Network Trojan was detected | 52.149.20.212 | 443 | 192.168.2.6 | 49754 | TCP |
2024-11-06T15:08:53.390109+0100 | 2022930 | 1 | A Network Trojan was detected | 52.149.20.212 | 443 | 192.168.2.6 | 49954 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00452126 | |
Source: | Code function: | 0_2_0045C999 | |
Source: | Code function: | 0_2_00436ADE | |
Source: | Code function: | 0_2_00434BEE | |
Source: | Code function: | 0_2_0045DD7C | |
Source: | Code function: | 0_2_0044BD29 | |
Source: | Code function: | 0_2_00436D2D | |
Source: | Code function: | 0_2_00442E1F | |
Source: | Code function: | 0_2_00475FE5 | |
Source: | Code function: | 0_2_0044BF8D | |
Source: | Code function: | 3_2_00452126 | |
Source: | Code function: | 3_2_0045C999 | |
Source: | Code function: | 3_2_00436ADE | |
Source: | Code function: | 3_2_00434BEE | |
Source: | Code function: | 3_2_0045DD7C | |
Source: | Code function: | 3_2_0044BD29 | |
Source: | Code function: | 3_2_00436D2D | |
Source: | Code function: | 3_2_00442E1F | |
Source: | Code function: | 3_2_00475FE5 | |
Source: | Code function: | 3_2_0044BF8D |
Networking |
---|
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | FTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_0044289D |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Windows user hook set: | Jump to behavior |
Source: | Code function: | 0_2_0046C5D0 |
Source: | Code function: | 0_2_00459FFF | |
Source: | Code function: | 3_2_00459FFF |
Source: | Code function: | 0_2_0046C5D0 |
Source: | Code function: | 0_2_00456354 |
Source: | Window created: | Jump to behavior |
Source: | Code function: | 0_2_0047C08E | |
Source: | Code function: | 3_2_0047C08E |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00434D50 |
Source: | Code function: | 0_2_004461ED |
Source: | Code function: | 0_2_004364AA | |
Source: | Code function: | 3_2_004364AA |
Source: | Code function: | 0_2_00409A40 | |
Source: | Code function: | 0_2_00412038 | |
Source: | Code function: | 0_2_00427161 | |
Source: | Code function: | 0_2_0047E1FA | |
Source: | Code function: | 0_2_004212BE | |
Source: | Code function: | 0_2_00443390 | |
Source: | Code function: | 0_2_00443391 | |
Source: | Code function: | 0_2_0041A46B | |
Source: | Code function: | 0_2_0041240C | |
Source: | Code function: | 0_2_00446566 | |
Source: | Code function: | 0_2_004045E0 | |
Source: | Code function: | 0_2_0041D750 | |
Source: | Code function: | 0_2_004037E0 | |
Source: | Code function: | 0_2_00427859 | |
Source: | Code function: | 0_2_00412818 | |
Source: | Code function: | 0_2_0040F890 | |
Source: | Code function: | 0_2_0042397B | |
Source: | Code function: | 0_2_00411B63 | |
Source: | Code function: | 0_2_0047CBF0 | |
Source: | Code function: | 0_2_0044EBBC | |
Source: | Code function: | 0_2_00412C38 | |
Source: | Code function: | 0_2_0044ED9A | |
Source: | Code function: | 0_2_00423EBF | |
Source: | Code function: | 0_2_00424F70 | |
Source: | Code function: | 0_2_0041AF0D | |
Source: | Code function: | 0_2_03F50A38 | |
Source: | Code function: | 3_2_00409A40 | |
Source: | Code function: | 3_2_00412038 | |
Source: | Code function: | 3_2_00427161 | |
Source: | Code function: | 3_2_0047E1FA | |
Source: | Code function: | 3_2_004212BE | |
Source: | Code function: | 3_2_00443390 | |
Source: | Code function: | 3_2_00443391 | |
Source: | Code function: | 3_2_0041A46B | |
Source: | Code function: | 3_2_0041240C | |
Source: | Code function: | 3_2_00446566 | |
Source: | Code function: | 3_2_004045E0 | |
Source: | Code function: | 3_2_0041D750 | |
Source: | Code function: | 3_2_004037E0 | |
Source: | Code function: | 3_2_00427859 | |
Source: | Code function: | 3_2_00412818 | |
Source: | Code function: | 3_2_0040F890 | |
Source: | Code function: | 3_2_0042397B | |
Source: | Code function: | 3_2_00411B63 | |
Source: | Code function: | 3_2_0047CBF0 | |
Source: | Code function: | 3_2_0044EBBC | |
Source: | Code function: | 3_2_00412C38 | |
Source: | Code function: | 3_2_0044ED9A | |
Source: | Code function: | 3_2_00423EBF | |
Source: | Code function: | 3_2_00424F70 | |
Source: | Code function: | 3_2_0041AF0D | |
Source: | Code function: | 3_2_03F9FA38 | |
Source: | Code function: | 4_2_00408C60 | |
Source: | Code function: | 4_2_0040DC11 | |
Source: | Code function: | 4_2_00407C3F | |
Source: | Code function: | 4_2_00418CCC | |
Source: | Code function: | 4_2_00406CA0 | |
Source: | Code function: | 4_2_004028B0 | |
Source: | Code function: | 4_2_0041A4BE | |
Source: | Code function: | 4_2_00418244 | |
Source: | Code function: | 4_2_00401650 | |
Source: | Code function: | 4_2_00402F20 | |
Source: | Code function: | 4_2_004193C4 | |
Source: | Code function: | 4_2_00418788 | |
Source: | Code function: | 4_2_00402F89 | |
Source: | Code function: | 4_2_00402B90 | |
Source: | Code function: | 4_2_004073A0 | |
Source: | Code function: | 4_2_026ED8B0 | |
Source: | Code function: | 4_2_026ECC98 | |
Source: | Code function: | 4_2_026ECFE0 | |
Source: | Code function: | 4_2_026E0FD0 | |
Source: | Code function: | 4_2_026E1030 | |
Source: | Code function: | 4_2_060B6748 | |
Source: | Code function: | 4_2_060BCFC8 | |
Source: | Code function: | 4_2_060BF278 | |
Source: | Code function: | 4_2_060B9A88 | |
Source: | Code function: | 4_2_060B857C | |
Source: | Code function: | 4_2_060B0006 | |
Source: | Code function: | 4_2_060B0040 | |
Source: | Code function: | 4_2_060BC0E8 | |
Source: | Code function: | 4_2_060BF9C7 | |
Source: | Code function: | 4_2_064B0740 | |
Source: | Code function: | 4_2_064B552A | |
Source: | Code function: | 4_2_064BA810 | |
Source: | Code function: | 4_2_064B86E0 | |
Source: | Code function: | 4_2_064BDAE8 | |
Source: | Code function: | 4_2_064B1838 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Code function: | 0_2_0044AF5C |
Source: | Code function: | 0_2_00464422 | |
Source: | Code function: | 0_2_004364AA | |
Source: | Code function: | 3_2_00464422 | |
Source: | Code function: | 3_2_004364AA |
Source: | Code function: | 0_2_0045D517 |
Source: | Code function: | 0_2_0043701F |
Source: | Code function: | 0_2_0047A999 |
Source: | Code function: | 0_2_0043614F |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Command line argument: | 0_2_0040D7F0 | |
Source: | Command line argument: | 3_2_0040D7F0 |
Source: | Static PE information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_0040EB70 |
Source: | Static PE information: |
Source: | Code function: | 0_2_004171E4 | |
Source: | Code function: | 3_2_004171E4 | |
Source: | Code function: | 3_2_00490CD5 | |
Source: | Code function: | 4_2_0041C4E2 | |
Source: | Code function: | 4_2_00423179 | |
Source: | Code function: | 4_2_0041C4E2 | |
Source: | Code function: | 4_2_00423179 | |
Source: | Code function: | 4_2_0040E230 | |
Source: | Code function: | 4_2_0041C6BF | |
Source: | Code function: | 4_2_026E4760 |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_004772DE | |
Source: | Code function: | 0_2_004375B0 | |
Source: | Code function: | 3_2_004772DE | |
Source: | Code function: | 3_2_004375B0 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 0_2_00444078 | |
Source: | Code function: | 3_2_00444078 |
Source: | WMI Queries: |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 4_2_004019F0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: | ||
Source: | API coverage: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Code function: | 0_2_00452126 | |
Source: | Code function: | 0_2_0045C999 | |
Source: | Code function: | 0_2_00436ADE | |
Source: | Code function: | 0_2_00434BEE | |
Source: | Code function: | 0_2_0045DD7C | |
Source: | Code function: | 0_2_0044BD29 | |
Source: | Code function: | 0_2_00436D2D | |
Source: | Code function: | 0_2_00442E1F | |
Source: | Code function: | 0_2_00475FE5 | |
Source: | Code function: | 0_2_0044BF8D | |
Source: | Code function: | 3_2_00452126 | |
Source: | Code function: | 3_2_0045C999 | |
Source: | Code function: | 3_2_00436ADE | |
Source: | Code function: | 3_2_00434BEE | |
Source: | Code function: | 3_2_0045DD7C | |
Source: | Code function: | 3_2_0044BD29 | |
Source: | Code function: | 3_2_00436D2D | |
Source: | Code function: | 3_2_00442E1F | |
Source: | Code function: | 3_2_00475FE5 | |
Source: | Code function: | 3_2_0044BF8D |
Source: | Code function: | 0_2_0040E470 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | API call chain: |
Source: | Code function: | 0_2_0045A259 |
Source: | Code function: | 0_2_0040D6D0 |
Source: | Code function: | 4_2_004019F0 |
Source: | Code function: | 0_2_0040EB70 |
Source: | Code function: | 0_2_03F4F2C8 | |
Source: | Code function: | 0_2_03F50928 | |
Source: | Code function: | 0_2_03F508C8 | |
Source: | Code function: | 3_2_03F9E2C8 | |
Source: | Code function: | 3_2_03F9F928 | |
Source: | Code function: | 3_2_03F9F8C8 |
Source: | Code function: | 0_2_00426DA1 |
Source: | Code function: | 0_2_0042202E | |
Source: | Code function: | 0_2_004230F5 | |
Source: | Code function: | 0_2_00417D93 | |
Source: | Code function: | 0_2_00421FA7 | |
Source: | Code function: | 3_2_0042202E | |
Source: | Code function: | 3_2_004230F5 | |
Source: | Code function: | 3_2_00417D93 | |
Source: | Code function: | 3_2_00421FA7 | |
Source: | Code function: | 4_2_0040CE09 | |
Source: | Code function: | 4_2_0040E61C | |
Source: | Code function: | 4_2_00416F6A | |
Source: | Code function: | 4_2_004123F1 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Section loaded: | Jump to behavior |
Source: | Section unmapped: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 0_2_0043916A |
Source: | Code function: | 0_2_0040D6D0 |
Source: | Code function: | 0_2_004375B0 |
Source: | Code function: | 0_2_00436431 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 0_2_00445DD3 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00410D10 |
Source: | Code function: | 4_2_00417A20 |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004223BC |
Source: | Code function: | 0_2_004711D2 |
Source: | Code function: | 0_2_0042039F |
Source: | Code function: | 0_2_0040E470 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_004741BB | |
Source: | Code function: | 0_2_0046483C | |
Source: | Code function: | 0_2_0047AD92 | |
Source: | Code function: | 3_2_004741BB | |
Source: | Code function: | 3_2_0046483C | |
Source: | Code function: | 3_2_0047AD92 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 121 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Exploitation for Privilege Escalation | 11 Disable or Modify Tools | 2 OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 2 Ingress Tool Transfer | 1 Exfiltration Over Alternative Protocol | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 1 Native API | 2 Valid Accounts | 1 DLL Side-Loading | 11 Deobfuscate/Decode Files or Information | 221 Input Capture | 1 Account Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Shared Modules | 1 Registry Run Keys / Startup Folder | 2 Valid Accounts | 2 Obfuscated Files or Information | 1 Credentials in Registry | 2 File and Directory Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 Command and Scripting Interpreter | Login Hook | 21 Access Token Manipulation | 1 Software Packing | NTDS | 148 System Information Discovery | Distributed Component Object Model | 221 Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 312 Process Injection | 1 DLL Side-Loading | LSA Secrets | 341 Security Software Discovery | SSH | 4 Clipboard Data | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | 1 Registry Run Keys / Startup Folder | 1 Masquerading | Cached Domain Credentials | 141 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 2 Valid Accounts | DCSync | 2 Process Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 141 Virtualization/Sandbox Evasion | Proc Filesystem | 11 Application Window Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 21 Access Token Manipulation | /etc/passwd and /etc/shadow | 1 System Owner/User Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
IP Addresses | Compromise Infrastructure | Supply Chain Compromise | PowerShell | Cron | Cron | 312 Process Injection | Network Sniffing | 1 System Network Configuration Discovery | Shared Webroot | Local Data Staging | File Transfer Protocols | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | External Defacement |
Network Security Appliances | Domains | Compromise Software Dependencies and Development Tools | AppleScript | Launchd | Launchd | 1 Hidden Files and Directories | Input Capture | System Network Connections Discovery | Software Deployment Tools | Remote Data Staging | Mail Protocols | Exfiltration Over Unencrypted Non-C2 Protocol | Firmware Corruption |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
61% | ReversingLabs | Win32.Trojan.AutoitInject | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.ipify.org | 172.67.74.152 | true | false | high | |
ftp.haliza.com.my | 110.4.45.197 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
110.4.45.197 | ftp.haliza.com.my | Malaysia | 46015 | EXABYTES-AS-APExaBytesNetworkSdnBhdMY | false | |
172.67.74.152 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1550182 |
Start date and time: | 2024-11-06 15:07:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 42s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Pi648je050.exerenamed because original name is a hash value |
Original Sample Name: | 22c46eed2c96ab6e83aa4e917bc36fb76ff4abc83e01fcceaef07fcc7e8d9265.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@11/5@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target sgxIb.exe, PID 5724 because it is empty
- Execution Graph export aborted for target sgxIb.exe, PID 6508 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: Pi648je050.exe
Time | Type | Description |
---|---|---|
09:08:03 | API Interceptor | |
15:08:05 | Autostart | |
15:08:13 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
110.4.45.197 | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse | |||
172.67.74.152 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ftp.haliza.com.my | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| ||
api.ipify.org | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mamba2FA | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EXABYTES-AS-APExaBytesNetworkSdnBhdMY | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Mamba2FA | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher, Mamba2FA | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Amadey, LummaC Stealer, Stealc | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | DBatLoader, PureLog Stealer, Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | MalLnk | Browse |
| ||
Get hash | malicious | MalLnk | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | FormBook | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | XWorm | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | modified |
Size (bytes): | 142 |
Entropy (8bit): | 5.090621108356562 |
Encrypted: | false |
SSDEEP: | 3:QHXMKa/xwwUC7WglAFXMWA2yTMGfsbNRLFS9Am12MFuAvOAsDeieVyn:Q3La/xwczlAFXMWTyAGCDLIP12MUAvvw |
MD5: | 8C0458BB9EA02D50565175E38D577E35 |
SHA1: | F0B50702CD6470F3C17D637908F83212FDBDB2F2 |
SHA-256: | C578E86DB701B9AFA3626E804CF434F9D32272FF59FB32FA9A51835E5A148B53 |
SHA-512: | 804A47494D9A462FFA6F39759480700ECBE5A7F3A15EC3A6330176ED9C04695D2684BF6BF85AB86286D52E7B727436D0BB2E8DA96E20D47740B5CE3F856B5D0F |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\Pi648je050.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 271360 |
Entropy (8bit): | 7.889620923018979 |
Encrypted: | false |
SSDEEP: | 6144:9RhHrVPOIjoME5wTZ6/w7x4zCJBUd9KOWdotR2:VLVPOIj9E5wmwkEe9KOWdoK |
MD5: | 8C70AA14440FAEFC27AF2CE3157BD0BB |
SHA1: | 1F6EE61FF797DD800D4D9319BCEF026997EE8DC4 |
SHA-256: | 0B5960093B0253747B31AAFDB541A6688D386ADB9E3E4FC769E713E4FBAAEC50 |
SHA-512: | EEFE6A46DE54F693F21339605F63FAC3019A78FF035D143D84652D354A1BB330CDE5C8887197CB8C4533CD9DE05F9EAD5C856C75556AE2E1C10F59D9659728A0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
File Type: | |
Category: | modified |
Size (bytes): | 45984 |
Entropy (8bit): | 6.16795797263964 |
Encrypted: | false |
SSDEEP: | 768:4BbSoy+SdIBf0k2dsjYg6Iq8S1GYqWH8BR:noOIBf0ddsjY/ZGyc7 |
MD5: | 9D352BC46709F0CB5EC974633A0C3C94 |
SHA1: | 1969771B2F022F9A86D77AC4D4D239BECDF08D07 |
SHA-256: | 2C1EEB7097023C784C2BD040A2005A5070ED6F3A4ABF13929377A9E39FAB1390 |
SHA-512: | 13C714244EC56BEEB202279E4109D59C2A43C3CF29F90A374A751C04FD472B45228CA5A0178F41109ED863DBD34E0879E4A21F5E38AE3D89559C57E6BE990A9B |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1141 |
Entropy (8bit): | 4.442398121585593 |
Encrypted: | false |
SSDEEP: | 24:zKLXkhDObntKlglUEnfQtvNuNpKOK5aM9YJC:zKL0hDQntKKH1MqJC |
MD5: | 6FB4D27A716A8851BC0505666E7C7A10 |
SHA1: | AD2A232C6E709223532C4D1AB892303273D8C814 |
SHA-256: | 1DC36F296CE49BDF1D560B527DB06E1E9791C10263459A67EACE706C6DDCDEAE |
SHA-512: | 3192095C68C6B7AD94212B7BCA0563F2058BCE00C0C439B90F0E96EA2F029A37C2F2B69487591B494C1BA54697FE891E214582E392127CB8C90AB682E0D81ADB |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.47493858374487 |
TrID: |
|
File name: | Pi648je050.exe |
File size: | 1'267'163 bytes |
MD5: | b47427b1a08950c5d561d65b664f0100 |
SHA1: | 2c45c83042460e904ce6d0607b67472b505637ad |
SHA256: | 22c46eed2c96ab6e83aa4e917bc36fb76ff4abc83e01fcceaef07fcc7e8d9265 |
SHA512: | dd9436a72a69f125c7770642c7d69ddcc926fdbc10103637c669a07572c72266673db010fdecd275b0b0d4f951b3a53bf41f6a407113f058616ef09204021457 |
SSDEEP: | 24576:ffmMv6Ckr7Mny5QLX11+BXqBsBAl/36BqsV:f3v+7/5QLXcqy+36BqsV |
TLSH: | 4645E112B3D680B6D9A339B02D7BE31BEB3575194323C58BA7E02E778E111419B37762 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......-...i...i...i.....9.k...`.:.w...`.,.....`.+.P...N%..c...N%..H...i...d...`. ./...w.:.k...w.;.h...i.8.h...`.>.h...Richi.......... |
Icon Hash: | 1733312925935517 |
Entrypoint: | 0x416310 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x4B93CF87 [Sun Mar 7 16:08:39 2010 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | aaaa8913c89c8aa4a5d93f06853894da |
Instruction |
---|
call 00007F6A2CEB829Ch |
jmp 00007F6A2CEAC06Eh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push ebp |
mov ebp, esp |
push edi |
push esi |
mov esi, dword ptr [ebp+0Ch] |
mov ecx, dword ptr [ebp+10h] |
mov edi, dword ptr [ebp+08h] |
mov eax, ecx |
mov edx, ecx |
add eax, esi |
cmp edi, esi |
jbe 00007F6A2CEAC1FAh |
cmp edi, eax |
jc 00007F6A2CEAC39Ah |
cmp ecx, 00000100h |
jc 00007F6A2CEAC211h |
cmp dword ptr [004A94E0h], 00000000h |
je 00007F6A2CEAC208h |
push edi |
push esi |
and edi, 0Fh |
and esi, 0Fh |
cmp edi, esi |
pop esi |
pop edi |
jne 00007F6A2CEAC1FAh |
pop esi |
pop edi |
pop ebp |
jmp 00007F6A2CEAC65Ah |
test edi, 00000003h |
jne 00007F6A2CEAC207h |
shr ecx, 02h |
and edx, 03h |
cmp ecx, 08h |
jc 00007F6A2CEAC21Ch |
rep movsd |
jmp dword ptr [00416494h+edx*4] |
nop |
mov eax, edi |
mov edx, 00000003h |
sub ecx, 04h |
jc 00007F6A2CEAC1FEh |
and eax, 03h |
add ecx, eax |
jmp dword ptr [004163A8h+eax*4] |
jmp dword ptr [004164A4h+ecx*4] |
nop |
jmp dword ptr [00416428h+ecx*4] |
nop |
mov eax, E4004163h |
arpl word ptr [ecx+00h], ax |
or byte ptr [ecx+eax*2+00h], ah |
and edx, ecx |
mov al, byte ptr [esi] |
mov byte ptr [edi], al |
mov al, byte ptr [esi+01h] |
mov byte ptr [edi+01h], al |
mov al, byte ptr [esi+02h] |
shr ecx, 02h |
mov byte ptr [edi+02h], al |
add esi, 03h |
add edi, 03h |
cmp ecx, 08h |
jc 00007F6A2CEAC1BEh |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8cd3c | 0x154 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xab000 | 0x9298 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x82000 | 0x840 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x80017 | 0x80200 | 6c20c6bf686768b6f134f5bd508171bc | False | 0.5602991615853659 | data | 6.634688230255595 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x82000 | 0xd95c | 0xda00 | f979966509a93083729d23cdfd2a6f2d | False | 0.36256450688073394 | data | 4.880040824124099 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x90000 | 0x1a518 | 0x6800 | e5d77411f751d28c6eee48a743606795 | False | 0.1600060096153846 | data | 2.2017649896261107 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0xab000 | 0x9298 | 0x9400 | f6be76de0ef2c68f397158bf01bdef3e | False | 0.4896801097972973 | data | 5.530303089784181 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0xab5c8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colors | English | Great Britain | 0.3277027027027027 |
RT_ICON | 0xab6f0 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.7466216216216216 |
RT_ICON | 0xab818 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 192 | English | Great Britain | 0.3885135135135135 |
RT_ICON | 0xab940 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 1152 | English | Great Britain | 0.48109756097560974 |
RT_ICON | 0xabfa8 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | English | Great Britain | 0.5672043010752689 |
RT_ICON | 0xac290 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128 | English | Great Britain | 0.6418918918918919 |
RT_ICON | 0xac3b8 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | English | Great Britain | 0.7044243070362474 |
RT_ICON | 0xad260 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | English | Great Britain | 0.8077617328519856 |
RT_ICON | 0xadb08 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | English | Great Britain | 0.5903179190751445 |
RT_ICON | 0xae070 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | Great Britain | 0.5503112033195021 |
RT_ICON | 0xb0618 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | Great Britain | 0.6050656660412758 |
RT_ICON | 0xb16c0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | Great Britain | 0.7553191489361702 |
RT_MENU | 0xb1b28 | 0x50 | data | English | Great Britain | 0.9 |
RT_DIALOG | 0xb1b78 | 0xfc | data | English | Great Britain | 0.6507936507936508 |
RT_STRING | 0xb1c78 | 0x530 | data | English | Great Britain | 0.33960843373493976 |
RT_STRING | 0xb21a8 | 0x690 | data | English | Great Britain | 0.26964285714285713 |
RT_STRING | 0xb2838 | 0x43a | data | English | Great Britain | 0.3733826247689464 |
RT_STRING | 0xb2c78 | 0x5fc | data | English | Great Britain | 0.3087467362924282 |
RT_STRING | 0xb3278 | 0x65c | data | English | Great Britain | 0.34336609336609336 |
RT_STRING | 0xb38d8 | 0x388 | data | English | Great Britain | 0.377212389380531 |
RT_STRING | 0xb3c60 | 0x158 | Matlab v4 mat-file (little endian) n, numeric, rows 0, columns 0 | English | United States | 0.502906976744186 |
RT_GROUP_ICON | 0xb3db8 | 0x84 | data | English | Great Britain | 0.6439393939393939 |
RT_GROUP_ICON | 0xb3e40 | 0x14 | data | English | Great Britain | 1.15 |
RT_GROUP_ICON | 0xb3e58 | 0x14 | data | English | Great Britain | 1.25 |
RT_GROUP_ICON | 0xb3e70 | 0x14 | data | English | Great Britain | 1.25 |
RT_VERSION | 0xb3e88 | 0x19c | data | English | Great Britain | 0.5339805825242718 |
RT_MANIFEST | 0xb4028 | 0x26c | ASCII text, with CRLF line terminators | English | United States | 0.5145161290322581 |
DLL | Import |
---|---|
WSOCK32.dll | __WSAFDIsSet, setsockopt, ntohs, recvfrom, sendto, htons, select, listen, WSAStartup, bind, closesocket, connect, socket, send, WSACleanup, ioctlsocket, accept, WSAGetLastError, inet_addr, gethostbyname, gethostname, recv |
VERSION.dll | VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW |
WINMM.dll | timeGetTime, waveOutSetVolume, mciSendStringW |
COMCTL32.dll | ImageList_Remove, ImageList_SetDragCursorImage, ImageList_BeginDrag, ImageList_DragEnter, ImageList_DragLeave, ImageList_EndDrag, ImageList_DragMove, ImageList_ReplaceIcon, ImageList_Create, InitCommonControlsEx, ImageList_Destroy |
MPR.dll | WNetCancelConnection2W, WNetGetConnectionW, WNetAddConnection2W, WNetUseConnectionW |
WININET.dll | InternetReadFile, InternetCloseHandle, InternetOpenW, InternetSetOptionW, InternetCrackUrlW, HttpQueryInfoW, InternetConnectW, HttpOpenRequestW, HttpSendRequestW, FtpOpenFileW, FtpGetFileSize, InternetOpenUrlW, InternetQueryOptionW, InternetQueryDataAvailable |
PSAPI.DLL | EnumProcesses, GetModuleBaseNameW, GetProcessMemoryInfo, EnumProcessModules |
USERENV.dll | CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile, LoadUserProfileW |
KERNEL32.dll | HeapAlloc, Sleep, GetCurrentThreadId, RaiseException, MulDiv, GetVersionExW, GetSystemInfo, MultiByteToWideChar, WideCharToMultiByte, GetModuleHandleW, QueryPerformanceCounter, VirtualFreeEx, OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateFileW, SetFilePointerEx, ReadFile, WriteFile, FlushFileBuffers, TerminateProcess, CreateToolhelp32Snapshot, Process32FirstW, Process32NextW, SetFileTime, GetFileAttributesW, FindFirstFileW, FindClose, DeleteFileW, FindNextFileW, lstrcmpiW, MoveFileW, CopyFileW, CreateDirectoryW, RemoveDirectoryW, SetSystemPowerState, QueryPerformanceFrequency, FindResourceW, LoadResource, LockResource, SizeofResource, GetProcessHeap, OutputDebugStringW, GetLocalTime, CompareStringW, CompareStringA, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, GetStdHandle, CreatePipe, InterlockedExchange, TerminateThread, GetTempPathW, GetTempFileNameW, VirtualFree, FormatMessageW, GetExitCodeProcess, SetErrorMode, GetPrivateProfileStringW, WritePrivateProfileStringW, GetPrivateProfileSectionW, WritePrivateProfileSectionW, GetPrivateProfileSectionNamesW, FileTimeToLocalFileTime, FileTimeToSystemTime, SystemTimeToFileTime, LocalFileTimeToFileTime, GetDriveTypeW, GetDiskFreeSpaceExW, GetDiskFreeSpaceW, GetVolumeInformationW, SetVolumeLabelW, CreateHardLinkW, DeviceIoControl, SetFileAttributesW, GetShortPathNameW, CreateEventW, SetEvent, GetEnvironmentVariableW, SetEnvironmentVariableW, GlobalLock, GlobalUnlock, GlobalAlloc, GetFileSize, GlobalFree, GlobalMemoryStatusEx, Beep, GetComputerNameW, GetWindowsDirectoryW, GetSystemDirectoryW, GetCurrentProcessId, GetCurrentThread, GetProcessIoCounters, CreateProcessW, SetPriorityClass, LoadLibraryW, VirtualAlloc, LoadLibraryExW, HeapFree, WaitForSingleObject, CreateThread, DuplicateHandle, GetLastError, CloseHandle, GetCurrentProcess, GetProcAddress, LoadLibraryA, FreeLibrary, GetModuleFileNameW, GetFullPathNameW, ExitProcess, ExitThread, GetSystemTimeAsFileTime, SetCurrentDirectoryW, IsDebuggerPresent, GetCurrentDirectoryW, ResumeThread, GetStartupInfoW, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetModuleFileNameA, HeapReAlloc, HeapCreate, SetHandleCount, GetFileType, GetStartupInfoA, SetStdHandle, GetConsoleCP, GetConsoleMode, LCMapStringW, LCMapStringA, RtlUnwind, SetFilePointer, GetTimeZoneInformation, GetTimeFormatA, GetDateFormatA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, GetTickCount, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetModuleHandleA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, SetEndOfFile, EnumResourceNamesW, SetEnvironmentVariableA |
USER32.dll | SetWindowPos, GetCursorInfo, RegisterHotKey, ClientToScreen, GetKeyboardLayoutNameW, IsCharAlphaW, IsCharAlphaNumericW, IsCharLowerW, IsCharUpperW, GetMenuStringW, GetSubMenu, GetCaretPos, IsZoomed, MonitorFromPoint, GetMonitorInfoW, SetWindowLongW, SetLayeredWindowAttributes, FlashWindow, GetClassLongW, TranslateAcceleratorW, IsDialogMessageW, GetSysColor, InflateRect, DrawFocusRect, DrawTextW, FrameRect, DrawFrameControl, FillRect, PtInRect, DestroyAcceleratorTable, CreateAcceleratorTableW, SetCursor, GetWindowDC, GetSystemMetrics, GetActiveWindow, CharNextW, wsprintfW, RedrawWindow, DrawMenuBar, DestroyMenu, SetMenu, GetWindowTextLengthW, CreateMenu, IsDlgButtonChecked, DefDlgProcW, ReleaseCapture, SetCapture, WindowFromPoint, CreateIconFromResourceEx, mouse_event, ExitWindowsEx, SetActiveWindow, FindWindowExW, EnumThreadWindows, SetMenuDefaultItem, InsertMenuItemW, IsMenu, TrackPopupMenuEx, GetCursorPos, DeleteMenu, CheckMenuRadioItem, CopyImage, GetMenuItemCount, SetMenuItemInfoW, GetMenuItemInfoW, SetForegroundWindow, IsIconic, FindWindowW, SystemParametersInfoW, PeekMessageW, SendInput, GetAsyncKeyState, SetKeyboardState, GetKeyboardState, GetKeyState, VkKeyScanW, LoadStringW, DialogBoxParamW, MessageBeep, EndDialog, SendDlgItemMessageW, GetDlgItem, SetWindowTextW, CopyRect, ReleaseDC, GetDC, EndPaint, BeginPaint, GetClientRect, GetMenu, DestroyWindow, EnumWindows, GetDesktopWindow, IsWindow, IsWindowEnabled, IsWindowVisible, EnableWindow, InvalidateRect, GetWindowThreadProcessId, AttachThreadInput, GetFocus, GetWindowTextW, ScreenToClient, SendMessageTimeoutW, EnumChildWindows, CharUpperBuffW, GetClassNameW, GetParent, GetDlgCtrlID, SendMessageW, MapVirtualKeyW, PostMessageW, GetWindowRect, SetUserObjectSecurity, GetUserObjectSecurity, CloseDesktop, CloseWindowStation, OpenDesktopW, SetProcessWindowStation, GetProcessWindowStation, OpenWindowStationW, MessageBoxW, DefWindowProcW, MoveWindow, AdjustWindowRectEx, SetRect, SetClipboardData, EmptyClipboard, CountClipboardFormats, CloseClipboard, GetClipboardData, IsClipboardFormatAvailable, OpenClipboard, BlockInput, GetMessageW, LockWindowUpdate, DispatchMessageW, GetMenuItemID, TranslateMessage, SetFocus, PostQuitMessage, KillTimer, CreatePopupMenu, RegisterWindowMessageW, SetTimer, ShowWindow, CreateWindowExW, RegisterClassExW, LoadIconW, LoadCursorW, GetSysColorBrush, GetForegroundWindow, MessageBoxA, DestroyIcon, UnregisterHotKey, CharLowerBuffW, MonitorFromRect, keybd_event, LoadImageW, GetWindowLongW |
GDI32.dll | DeleteObject, GetObjectW, GetTextExtentPoint32W, ExtCreatePen, StrokeAndFillPath, StrokePath, EndPath, SetPixel, CloseFigure, CreateCompatibleBitmap, CreateCompatibleDC, SelectObject, StretchBlt, GetDIBits, LineTo, AngleArc, MoveToEx, Ellipse, PolyDraw, BeginPath, Rectangle, GetDeviceCaps, SetBkMode, RoundRect, SetBkColor, CreatePen, CreateSolidBrush, SetTextColor, CreateFontW, GetTextFaceW, GetStockObject, CreateDCW, GetPixel, DeleteDC, SetViewportOrgEx |
COMDLG32.dll | GetSaveFileNameW, GetOpenFileNameW |
ADVAPI32.dll | RegEnumValueW, RegDeleteValueW, RegDeleteKeyW, RegSetValueExW, RegCreateKeyExW, GetUserNameW, RegConnectRegistryW, RegEnumKeyExW, CloseServiceHandle, UnlockServiceDatabase, LockServiceDatabase, OpenSCManagerW, InitiateSystemShutdownExW, AdjustTokenPrivileges, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, DuplicateTokenEx, CreateProcessAsUserW, CreateProcessWithLogonW, InitializeSecurityDescriptor, InitializeAcl, GetLengthSid, SetSecurityDescriptorDacl, CopySid, LogonUserW, GetTokenInformation, GetAclInformation, GetAce, AddAce, GetSecurityDescriptorDacl |
SHELL32.dll | DragQueryPoint, ShellExecuteExW, SHGetFolderPathW, DragQueryFileW, SHEmptyRecycleBinW, SHBrowseForFolderW, SHFileOperationW, SHGetPathFromIDListW, SHGetDesktopFolder, SHGetMalloc, ExtractIconExW, Shell_NotifyIconW, ShellExecuteW, DragFinish |
ole32.dll | OleSetMenuDescriptor, MkParseDisplayName, OleSetContainedObject, CoInitialize, CoUninitialize, CoCreateInstance, CreateStreamOnHGlobal, CoTaskMemAlloc, CoTaskMemFree, CLSIDFromString, StringFromCLSID, IIDFromString, StringFromIID, OleInitialize, CreateBindCtx, CLSIDFromProgID, CoInitializeSecurity, CoCreateInstanceEx, CoSetProxyBlanket, OleUninitialize |
OLEAUT32.dll | SafeArrayAllocData, SafeArrayAllocDescriptorEx, SysAllocString, OleLoadPicture, SafeArrayGetVartype, SafeArrayDestroyData, SafeArrayAccessData, VarR8FromDec, VariantTimeToSystemTime, VariantClear, VariantCopy, VariantInit, SafeArrayDestroyDescriptor, LoadRegTypeLib, GetActiveObject, SafeArrayUnaccessData |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | Great Britain | |
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-06T15:08:14.496660+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 52.149.20.212 | 443 | 192.168.2.6 | 49754 | TCP |
2024-11-06T15:08:53.390109+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 52.149.20.212 | 443 | 192.168.2.6 | 49954 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 6, 2024 15:08:03.647478104 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:03.647540092 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:03.647605896 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:03.657243013 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:03.657272100 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.267769098 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.267913103 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:04.281003952 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:04.281039953 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.281388998 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.325659990 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:04.334899902 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:04.375339031 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.505425930 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.505495071 CET | 443 | 49712 | 172.67.74.152 | 192.168.2.6 |
Nov 6, 2024 15:08:04.505582094 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:04.511969090 CET | 49712 | 443 | 192.168.2.6 | 172.67.74.152 |
Nov 6, 2024 15:08:05.436608076 CET | 49714 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:05.442445993 CET | 21 | 49714 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:05.442595005 CET | 49714 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:05.447175980 CET | 49714 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:05.452166080 CET | 21 | 49714 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:05.452234983 CET | 49714 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:05.486974955 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:05.492058992 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:05.492178917 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:06.386138916 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:06.386460066 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:06.391324043 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:06.716487885 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:06.716634035 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:06.721704960 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.061952114 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.062114000 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:07.067410946 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.391413927 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.392249107 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:07.397027969 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.720525980 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:07.721949100 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:07.727175951 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:08.051364899 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:08.057339907 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:08.062163115 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:08.388428926 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:08.389157057 CET | 49731 | 56341 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:08.394421101 CET | 56341 | 49731 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:08.395306110 CET | 49731 | 56341 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:08.395306110 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:08.400320053 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:09.347238064 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:09.351016998 CET | 49731 | 56341 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:09.355912924 CET | 56341 | 49731 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:09.369950056 CET | 49731 | 56341 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:09.385286093 CET | 56341 | 49731 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:09.385987997 CET | 49731 | 56341 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:09.403779984 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:09.723651886 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:09.724426985 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:09.729347944 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.053410053 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.054320097 CET | 49737 | 56986 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:10.059283972 CET | 56986 | 49737 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.059376955 CET | 49737 | 56986 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:10.059528112 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:10.065210104 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.967376947 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.967716932 CET | 49737 | 56986 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:10.972803116 CET | 56986 | 49737 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.973177910 CET | 56986 | 49737 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:10.973236084 CET | 49737 | 56986 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.013931990 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.311857939 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:11.312459946 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.317497969 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:11.642340899 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:11.642863989 CET | 49748 | 60753 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.647949934 CET | 60753 | 49748 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:11.648053885 CET | 49748 | 60753 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.649931908 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:11.655045033 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:12.564027071 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:12.585619926 CET | 49748 | 60753 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:12.591089010 CET | 60753 | 49748 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:12.591145992 CET | 49748 | 60753 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:12.607187986 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:08:12.918576002 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:08:12.968033075 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:54.151441097 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:54.156459093 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:54.156527042 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:54.207977057 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:54.212977886 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:54.213041067 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.064202070 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.065488100 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.070391893 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.113933086 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.114808083 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.122304916 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.400418997 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.400553942 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.406913042 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.450510979 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.450664997 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.455481052 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.785609007 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.785794020 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.790790081 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.812012911 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:55.812402010 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:55.817325115 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.120951891 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.121135950 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.126050949 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.145541906 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.145706892 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.150676966 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.456497908 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.457571030 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.462487936 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.478585005 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.481615067 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.486593962 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.794536114 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.794990063 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.800299883 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.816080093 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:56.816236019 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:56.821073055 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.131975889 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.133917093 CET | 49991 | 57947 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.139971972 CET | 57947 | 49991 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.141660929 CET | 49991 | 57947 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.141813993 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.146898031 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.149430990 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.149807930 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.154680014 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:57.154771090 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.154934883 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:57.159950972 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.042538881 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.042891979 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.047872066 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.047903061 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.047915936 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.047928095 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.047957897 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.047981977 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048001051 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048002005 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048015118 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048068047 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048075914 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048088074 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048090935 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048110008 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048119068 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048130989 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048154116 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.048382044 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.048429966 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.052870035 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052881956 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052894115 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052902937 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052920103 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.052942038 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052953005 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.052953959 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053003073 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.053020000 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053047895 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.053057909 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.053061008 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053098917 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.053112984 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053152084 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053183079 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.053235054 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.053533077 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.057804108 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.057869911 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058341026 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058351040 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058362961 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058372974 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058929920 CET | 65008 | 49992 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.058974981 CET | 49992 | 65008 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.095956087 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.096102953 CET | 49991 | 57947 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.096232891 CET | 49991 | 57947 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.100949049 CET | 57947 | 49991 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.101564884 CET | 57947 | 49991 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.101607084 CET | 49991 | 57947 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.137610912 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.176913977 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.446115971 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.497472048 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:09:58.775192976 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:09:58.889456034 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:09.354366064 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:09.359255075 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:09.687819004 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:09.711165905 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:09.716072083 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:09.716144085 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:09.723207951 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:09.728064060 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.625885010 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.633223057 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639072895 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639178991 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639188051 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639205933 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639230013 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639244080 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639259100 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639278889 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639287949 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639309883 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639329910 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639338970 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639348984 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.639360905 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639381886 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.639503002 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644171000 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644311905 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644337893 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644346952 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644354105 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644357920 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644366980 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644377947 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644433975 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644433975 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644474030 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644505024 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.644546032 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.644612074 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.649187088 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.649270058 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.649713039 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.649775028 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.654390097 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654556990 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654567957 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654633045 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654640913 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654675961 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654684067 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.654736996 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.655534983 CET | 50443 | 49993 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:10.657536983 CET | 49993 | 50443 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:10.781394958 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:11.417869091 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:11.481296062 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:22.688045979 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:22.693099022 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.021492958 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.021991014 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.026760101 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.026844978 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.026897907 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.031696081 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.940109968 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.940407991 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945604086 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945637941 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945687056 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945736885 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945775986 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945804119 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945825100 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945856094 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945899963 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945929050 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.945956945 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.945986032 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.946013927 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.946043015 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.946063995 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.946088076 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.946120977 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.946175098 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.946208000 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.946295023 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951103926 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951157093 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951220036 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951248884 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951272011 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951334000 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951386929 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951416969 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951453924 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951474905 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951500893 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.951555967 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951584101 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.951656103 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:23.956645966 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.956780910 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.956813097 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.956918955 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957088947 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957142115 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957175970 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957225084 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957252979 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957279921 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957328081 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957356930 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957386017 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957614899 CET | 59023 | 49995 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:23.957686901 CET | 49995 | 59023 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:24.007955074 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:24.704694033 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:24.889337063 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:33.362147093 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:33.367042065 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:33.695883989 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:33.696419954 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:33.701304913 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:33.701368093 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:33.701457024 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:33.706633091 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.607419968 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.607666969 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.612792969 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.612812996 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.612863064 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.612911940 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.612922907 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.612941027 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.612968922 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.612991095 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.613013029 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.613019943 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.613099098 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.613102913 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.613117933 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.613135099 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.613245010 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.613266945 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.613317013 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.617744923 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617805004 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617830038 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.617842913 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617873907 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.617893934 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617903948 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617908001 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617933989 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.617958069 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.617974997 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618002892 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.618022919 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.618110895 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618129015 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618161917 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.618231058 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.618275881 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618398905 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618416071 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.618427992 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.622668982 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.622704983 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.622859955 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.622912884 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.622967958 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623018980 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623070002 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623080015 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623126984 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623148918 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623352051 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623426914 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623436928 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623446941 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623502016 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.623953104 CET | 51380 | 49996 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:34.624058008 CET | 49996 | 51380 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:34.778358936 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:35.407906055 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:35.481215000 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:52.640809059 CET | 49997 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:52.645953894 CET | 21 | 49997 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:52.649341106 CET | 49997 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:52.653223991 CET | 49997 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:52.658289909 CET | 21 | 49997 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:52.661319017 CET | 49997 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:59.146872044 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:10:59.153333902 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:10:59.153398991 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:00.051328897 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:00.051539898 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:00.057657003 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:00.406196117 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:00.409353971 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:00.414402008 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:00.763201952 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:00.763329983 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:00.768449068 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.092736959 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.092880964 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:01.097759008 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.422888994 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.429200888 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:01.434097052 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.758826017 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:01.762841940 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:01.767779112 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:02.092914104 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:02.093723059 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:02.098555088 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:02.099216938 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:02.099225044 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:02.104206085 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:02.993196011 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:02.995759964 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001100063 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001113892 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001133919 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001144886 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001163006 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001189947 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001204967 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001215935 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001225948 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001238108 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001266956 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001281977 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001292944 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001331091 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001370907 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001380920 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.001411915 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.001422882 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006149054 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006175041 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006184101 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006208897 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006232023 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006242990 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006253004 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006263971 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006279945 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006290913 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006313086 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006320953 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006334066 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006359100 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006371975 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006536007 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006577969 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006604910 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006616116 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006642103 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006654024 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.006664991 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.006701946 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.011179924 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011229038 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.011255980 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011266947 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011320114 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.011343956 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011353970 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011456013 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011466026 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011483908 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.011739016 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016180992 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016218901 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016230106 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016309977 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016321898 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016331911 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016343117 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016355991 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016752958 CET | 62480 | 49999 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.016881943 CET | 49999 | 62480 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.123059988 CET | 50000 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.123624086 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.312352896 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.312462091 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.313888073 CET | 21 | 50000 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.313952923 CET | 50000 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.314858913 CET | 50000 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.319899082 CET | 21 | 50000 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.319952011 CET | 50000 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:03.750379086 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:03.887409925 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:04.269177914 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:04.274905920 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:04.600888968 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:04.601433992 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:04.606544018 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:04.606611967 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:04.606942892 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:04.612507105 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.511127949 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.513142109 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.518253088 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518270969 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518280983 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518290997 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518326998 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518337011 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518347025 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518388033 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.518399000 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518429995 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.518487930 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.518487930 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518596888 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.518699884 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.523377895 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523396015 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523410082 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523418903 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523495913 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523557901 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.523591042 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523602009 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523610115 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523627996 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.523667097 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523737907 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.523792982 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523837090 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.523912907 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523924112 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523942947 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.523984909 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.528522015 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.528690100 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.528703928 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.528815985 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.529162884 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.529602051 CET | 64330 | 50001 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:05.533293962 CET | 50001 | 64330 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:05.577172995 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:06.276916981 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:06.354357958 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:08.081168890 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:08.086354017 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:08.411665916 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:08.417392969 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:08.422820091 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:08.425277948 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:08.425318956 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:08.430248976 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.336128950 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.336373091 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341403961 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341453075 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341455936 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341463089 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341470957 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341506958 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341522932 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341573000 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341625929 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341630936 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341638088 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341659069 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341664076 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341680050 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341691017 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341695070 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341700077 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.341727972 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.341751099 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346410990 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346421957 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346437931 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346467018 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346502066 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346513033 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346523046 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346533060 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346551895 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346585989 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346672058 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346745014 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.346849918 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.346894979 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.351697922 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351746082 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351767063 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351845980 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351855040 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351933002 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351943016 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351958036 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351974010 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351983070 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.351994991 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.352776051 CET | 58262 | 50002 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:09.352833033 CET | 50002 | 58262 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:09.387309074 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:10.093621969 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:10.184287071 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:20.314758062 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:20.319698095 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:20.646693945 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:20.647201061 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:20.652308941 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:20.652405024 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:20.652486086 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:20.657248020 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.548082113 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.548367023 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.553570032 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553581953 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553592920 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553603888 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553657055 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553684950 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.553745985 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553749084 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.553760052 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553770065 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553805113 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.553833008 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553833961 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.553843021 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.553900957 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.559021950 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559091091 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559099913 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559108019 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559142113 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559151888 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559176922 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.559186935 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559230089 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.559345961 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559355974 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559402943 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559480906 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.559514999 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559827089 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.559890032 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.564208031 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564265013 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564414024 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564515114 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564594030 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564702988 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564790010 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564800024 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564809084 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564870119 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564917088 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564925909 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.564935923 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.565018892 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.565028906 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.565434933 CET | 63314 | 50003 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:21.565500021 CET | 50003 | 63314 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:21.590384960 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:22.293498993 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:22.343750000 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:40.822057009 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:40.826884985 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:41.159176111 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:41.159563065 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:41.164364100 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:41.164433956 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:41.164501905 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:41.169323921 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.115654945 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.116122961 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.123217106 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123233080 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123243093 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123246908 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123259068 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123269081 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123282909 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123286963 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123296976 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123306036 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.123348951 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.124905109 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.130469084 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.130531073 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.130669117 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.130739927 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.131004095 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131016016 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131026030 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131047010 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131076097 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.131248951 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.131953001 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131963015 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131970882 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.131985903 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.132025957 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.132077932 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.132390976 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.132509947 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.135389090 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.135576963 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.135940075 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.136010885 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.136089087 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.136133909 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.136804104 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.137136936 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.137334108 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.137531996 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.137543917 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.138063908 CET | 64682 | 50005 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:42.138128996 CET | 50005 | 64682 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.217020988 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:42.948185921 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:43.105935097 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:50.136940002 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:50.141954899 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:50.466926098 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:50.467569113 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:50.472445011 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:50.472537041 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:50.472620964 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:50.477379084 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.400015116 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.400619984 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.405534029 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405550003 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405567884 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405574083 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405586958 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405606985 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405694008 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405776978 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.405846119 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.405864000 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405878067 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405904055 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.405941010 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.406021118 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.410727024 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410738945 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410743952 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410753012 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410773039 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410782099 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410836935 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.410876989 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410888910 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410912991 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410959959 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.410985947 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.411181927 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.411194086 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.415673971 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.415796995 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.415808916 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.415887117 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.415898085 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416064978 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416075945 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416085958 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416129112 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416522026 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416534901 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416546106 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416557074 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416565895 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416578054 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416589975 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416599989 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416613102 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.416961908 CET | 59550 | 50006 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:51.417112112 CET | 50006 | 59550 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:51.512995005 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Nov 6, 2024 15:11:52.191838026 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 |
Nov 6, 2024 15:11:52.418433905 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 6, 2024 15:08:03.042294025 CET | 58994 | 53 | 192.168.2.6 | 1.1.1.1 |
Nov 6, 2024 15:08:03.640728951 CET | 53 | 58994 | 1.1.1.1 | 192.168.2.6 |
Nov 6, 2024 15:08:05.131011963 CET | 57146 | 53 | 192.168.2.6 | 1.1.1.1 |
Nov 6, 2024 15:08:05.435801029 CET | 53 | 57146 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 6, 2024 15:08:03.042294025 CET | 192.168.2.6 | 1.1.1.1 | 0xc49c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 6, 2024 15:08:05.131011963 CET | 192.168.2.6 | 1.1.1.1 | 0xf2d8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 6, 2024 15:08:03.640728951 CET | 1.1.1.1 | 192.168.2.6 | 0xc49c | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Nov 6, 2024 15:08:03.640728951 CET | 1.1.1.1 | 192.168.2.6 | 0xc49c | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Nov 6, 2024 15:08:03.640728951 CET | 1.1.1.1 | 192.168.2.6 | 0xc49c | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Nov 6, 2024 15:08:05.435801029 CET | 1.1.1.1 | 192.168.2.6 | 0xf2d8 | No error (0) | 110.4.45.197 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49712 | 172.67.74.152 | 443 | 6484 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-06 14:08:04 UTC | 155 | OUT | |
2024-11-06 14:08:04 UTC | 398 | IN | |
2024-11-06 14:08:04 UTC | 14 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Nov 6, 2024 15:08:06.386138916 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 22:08. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 22:08. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 22:08. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 8 of 50 allowed.220-Local time is now 22:08. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 6, 2024 15:08:06.386460066 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 6, 2024 15:08:06.716487885 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 331 User origin@haliza.com.my OK. Password required |
Nov 6, 2024 15:08:06.716634035 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 6, 2024 15:08:07.061952114 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 230 OK. Current restricted directory is / |
Nov 6, 2024 15:08:07.391413927 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 504 Unknown command |
Nov 6, 2024 15:08:07.392249107 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | PWD |
Nov 6, 2024 15:08:07.720525980 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 257 "/" is your current location |
Nov 6, 2024 15:08:07.721949100 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | TYPE I |
Nov 6, 2024 15:08:08.051364899 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 200 TYPE is now 8-bit binary |
Nov 6, 2024 15:08:08.057339907 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:08:08.388428926 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,220,21) |
Nov 6, 2024 15:08:08.395306110 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | STOR CO_Chrome_Default.txt_user-585948_2024_11_06_09_38_03.txt |
Nov 6, 2024 15:08:09.347238064 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:08:09.723651886 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.376 seconds (measured here), 0.75 Kbytes per second |
Nov 6, 2024 15:08:09.724426985 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:08:10.053410053 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,222,154) |
Nov 6, 2024 15:08:10.059528112 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | STOR CO_Edge Chromium_Default.txt_user-585948_2024_11_06_14_26_51.txt |
Nov 6, 2024 15:08:10.967376947 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:08:11.311857939 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 226 File successfully transferred |
Nov 6, 2024 15:08:11.312459946 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:08:11.642340899 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,237,81) |
Nov 6, 2024 15:08:11.649931908 CET | 49715 | 21 | 192.168.2.6 | 110.4.45.197 | STOR CO_Firefox_2o7hffxt.default-release.txt_user-585948_2024_11_06_16_55_32.txt |
Nov 6, 2024 15:08:12.564027071 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:08:12.918576002 CET | 21 | 49715 | 110.4.45.197 | 192.168.2.6 | 226 File successfully transferred |
Nov 6, 2024 15:09:55.064202070 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 22:09. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 11 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 6, 2024 15:09:55.065488100 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 6, 2024 15:09:55.113933086 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 12 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 12 of 50 allowed.220-Local time is now 22:09. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 12 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 12 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 12 of 50 allowed.220-Local time is now 22:09. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 6, 2024 15:09:55.114808083 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 6, 2024 15:09:55.400418997 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 331 User origin@haliza.com.my OK. Password required |
Nov 6, 2024 15:09:55.400553942 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 6, 2024 15:09:55.450510979 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 331 User origin@haliza.com.my OK. Password required |
Nov 6, 2024 15:09:55.450664997 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 6, 2024 15:09:55.785609007 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 230 OK. Current restricted directory is / |
Nov 6, 2024 15:09:55.812012911 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 230 OK. Current restricted directory is / |
Nov 6, 2024 15:09:56.120951891 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 504 Unknown command |
Nov 6, 2024 15:09:56.121135950 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | PWD |
Nov 6, 2024 15:09:56.145541906 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 504 Unknown command |
Nov 6, 2024 15:09:56.145706892 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PWD |
Nov 6, 2024 15:09:56.456497908 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 257 "/" is your current location |
Nov 6, 2024 15:09:56.457571030 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | TYPE I |
Nov 6, 2024 15:09:56.478585005 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 257 "/" is your current location |
Nov 6, 2024 15:09:56.481615067 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | TYPE I |
Nov 6, 2024 15:09:56.794536114 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 200 TYPE is now 8-bit binary |
Nov 6, 2024 15:09:56.794990063 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:09:56.816080093 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 200 TYPE is now 8-bit binary |
Nov 6, 2024 15:09:56.816236019 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:09:57.131975889 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,226,91) |
Nov 6, 2024 15:09:57.141813993 CET | 49989 | 21 | 192.168.2.6 | 110.4.45.197 | STOR KL_user-585948_2024_11_27_05_36_13.html |
Nov 6, 2024 15:09:57.149430990 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,253,240) |
Nov 6, 2024 15:09:57.154934883 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2024_11_27_06_56_22.jpeg |
Nov 6, 2024 15:09:58.042538881 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:09:58.095956087 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:09:58.446115971 CET | 21 | 49989 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.350 seconds (measured here), 0.90 Kbytes per second |
Nov 6, 2024 15:09:58.775192976 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.733 seconds (measured here), 107.56 Kbytes per second |
Nov 6, 2024 15:10:09.354366064 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:10:09.687819004 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,197,11) |
Nov 6, 2024 15:10:09.723207951 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2024_12_05_20_13_38.jpeg |
Nov 6, 2024 15:10:10.625885010 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:10:11.417869091 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.792 seconds (measured here), 93.56 Kbytes per second |
Nov 6, 2024 15:10:22.688045979 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:10:23.021492958 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,230,143) |
Nov 6, 2024 15:10:23.026897907 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2024_12_13_18_35_59.jpeg |
Nov 6, 2024 15:10:23.940109968 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:10:24.704694033 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.764 seconds (measured here), 96.90 Kbytes per second |
Nov 6, 2024 15:10:33.362147093 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:10:33.695883989 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,200,180) |
Nov 6, 2024 15:10:33.701457024 CET | 49990 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2024_12_20_08_42_09.jpeg |
Nov 6, 2024 15:10:34.607419968 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:10:35.407906055 CET | 21 | 49990 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.801 seconds (measured here), 92.53 Kbytes per second |
Nov 6, 2024 15:11:00.051328897 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 220---------- Welcome to Pure-FTPd [privsep] [TLS] ---------- 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 22:11. Server port: 21. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 22:11. Server port: 21.220-This is a private system - No anonymous login 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 22:11. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server. 220---------- Welcome to Pure-FTPd [privsep] [TLS] ----------220-You are user number 13 of 50 allowed.220-Local time is now 22:11. Server port: 21.220-This is a private system - No anonymous login220-IPv6 connections are also welcome on this server.220 You will be disconnected after 15 minutes of inactivity. |
Nov 6, 2024 15:11:00.051539898 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | USER origin@haliza.com.my |
Nov 6, 2024 15:11:00.406196117 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 331 User origin@haliza.com.my OK. Password required |
Nov 6, 2024 15:11:00.409353971 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASS JesusChrist007$ |
Nov 6, 2024 15:11:00.763201952 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 230 OK. Current restricted directory is / |
Nov 6, 2024 15:11:01.092736959 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 504 Unknown command |
Nov 6, 2024 15:11:01.092880964 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PWD |
Nov 6, 2024 15:11:01.422888994 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 257 "/" is your current location |
Nov 6, 2024 15:11:01.429200888 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | TYPE I |
Nov 6, 2024 15:11:01.758826017 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 200 TYPE is now 8-bit binary |
Nov 6, 2024 15:11:01.762841940 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:02.092914104 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,244,16) |
Nov 6, 2024 15:11:02.099225044 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_01_08_02_10_52.jpeg |
Nov 6, 2024 15:11:02.993196011 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:03.312352896 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:03.750379086 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.757 seconds (measured here), 97.91 Kbytes per second |
Nov 6, 2024 15:11:04.269177914 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:04.600888968 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,251,74) |
Nov 6, 2024 15:11:04.606942892 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_01_14_12_03_24.jpeg |
Nov 6, 2024 15:11:05.511127949 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:06.276916981 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.766 seconds (measured here), 96.75 Kbytes per second |
Nov 6, 2024 15:11:08.081168890 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:08.411665916 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,227,150) |
Nov 6, 2024 15:11:08.425318956 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_01_18_08_27_49.jpeg |
Nov 6, 2024 15:11:09.336128950 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:10.093621969 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.758 seconds (measured here), 97.75 Kbytes per second |
Nov 6, 2024 15:11:20.314758062 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:20.646693945 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,247,82) |
Nov 6, 2024 15:11:20.652486086 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_01_25_23_31_03.jpeg |
Nov 6, 2024 15:11:21.548082113 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:22.293498993 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.745 seconds (measured here), 99.37 Kbytes per second |
Nov 6, 2024 15:11:40.822057009 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:41.159176111 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,252,170) |
Nov 6, 2024 15:11:41.164501905 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_02_05_11_16_24.jpeg |
Nov 6, 2024 15:11:42.115654945 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:42.948185921 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.835 seconds (measured here), 88.71 Kbytes per second |
Nov 6, 2024 15:11:50.136940002 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | PASV |
Nov 6, 2024 15:11:50.466926098 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 227 Entering Passive Mode (110,4,45,197,232,158) |
Nov 6, 2024 15:11:50.472620964 CET | 49998 | 21 | 192.168.2.6 | 110.4.45.197 | STOR SC_user-585948_2025_02_11_11_22_33.jpeg |
Nov 6, 2024 15:11:51.400015116 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 150 Accepted data connection |
Nov 6, 2024 15:11:52.191838026 CET | 21 | 49998 | 110.4.45.197 | 192.168.2.6 | 226-File successfully transferred 226-File successfully transferred226 0.797 seconds (measured here), 92.88 Kbytes per second |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:07:55 |
Start date: | 06/11/2024 |
Path: | C:\Users\user\Desktop\Pi648je050.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1'267'163 bytes |
MD5 hash: | B47427B1A08950C5D561D65B664F0100 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:07:57 |
Start date: | 06/11/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x410000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 09:07:58 |
Start date: | 06/11/2024 |
Path: | C:\Users\user\Desktop\Pi648je050.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1'267'163 bytes |
MD5 hash: | B47427B1A08950C5D561D65B664F0100 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 09:08:00 |
Start date: | 06/11/2024 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 09:08:13 |
Start date: | 06/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1a0000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 09:08:13 |
Start date: | 06/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 09:08:22 |
Start date: | 06/11/2024 |
Path: | C:\Users\user\AppData\Roaming\sgxIb\sgxIb.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x560000 |
File size: | 45'984 bytes |
MD5 hash: | 9D352BC46709F0CB5EC974633A0C3C94 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 09:08:22 |
Start date: | 06/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 3.2% |
Dynamic/Decrypted Code Coverage: | 1.1% |
Signature Coverage: | 4% |
Total number of Nodes: | 1683 |
Total number of Limit Nodes: | 52 |
Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040D6D0 Relevance: 28.1, APIs: 11, Strings: 5, Instructions: 141windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EB70 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 12libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410B90 Relevance: 28.2, APIs: 13, Strings: 3, Instructions: 167registryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004102F0 Relevance: 19.3, APIs: 7, Strings: 4, Instructions: 53windowregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004101F0 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 74windowregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00452574 Relevance: 13.7, APIs: 9, Instructions: 171COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03F4FA18 Relevance: 10.7, APIs: 7, Instructions: 239fileCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BE0 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 90windowCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03F4F808 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 137fileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413A88 Relevance: 7.5, APIs: 5, Instructions: 44memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E1E0 Relevance: 6.1, APIs: 4, Instructions: 82windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041171A Relevance: 6.0, APIs: 4, Instructions: 34COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043526E Relevance: 4.5, APIs: 3, Instructions: 26COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03F4F788 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 46processCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EFE0 Relevance: 3.1, APIs: 2, Instructions: 51fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004098B8 Relevance: 3.0, APIs: 2, Instructions: 32windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004098B6 Relevance: 3.0, APIs: 2, Instructions: 31windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410D40 Relevance: 1.6, APIs: 1, Instructions: 94memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004092C0 Relevance: 1.6, APIs: 1, Instructions: 71COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401108 Relevance: 1.5, APIs: 1, Instructions: 36COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041AA31 Relevance: 1.5, APIs: 1, Instructions: 20memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00444343 Relevance: 1.5, APIs: 1, Instructions: 19fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040116E Relevance: 1.5, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414E06 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040D900 Relevance: 1.3, APIs: 1, Instructions: 22COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03F4F6F4 Relevance: 1.3, APIs: 1, Instructions: 21sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03F4F6F8 Relevance: 1.3, APIs: 1, Instructions: 18sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047C08E Relevance: 74.2, APIs: 40, Strings: 2, Instructions: 676windowkeyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004045E0 Relevance: 46.9, Strings: 35, Instructions: 3193COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004375B0 Relevance: 43.9, APIs: 24, Strings: 1, Instructions: 126threadkeyboardwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004461ED Relevance: 37.0, APIs: 18, Strings: 3, Instructions: 227processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044BD29 Relevance: 31.7, APIs: 17, Strings: 1, Instructions: 178filestringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042039F Relevance: 30.0, APIs: 16, Strings: 1, Instructions: 282timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434D50 Relevance: 29.9, APIs: 14, Strings: 3, Instructions: 114fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00464422 Relevance: 28.2, APIs: 15, Strings: 1, Instructions: 193threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434BEE Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 139fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00444078 Relevance: 21.1, APIs: 11, Strings: 1, Instructions: 94timesleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00445DD3 Relevance: 18.2, APIs: 12, Instructions: 179COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047A999 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 288comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004364AA Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 79shutdownCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043614F Relevance: 16.6, APIs: 11, Instructions: 103COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047AD92 Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 251comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00452126 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 127filesleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046C5D0 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 69clipboardCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004772DE Relevance: 7.6, APIs: 5, Instructions: 67windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00446566 Relevance: 5.9, Strings: 4, Instructions: 868COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045C999 Relevance: 4.6, APIs: 3, Instructions: 130fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436ADE Relevance: 4.5, APIs: 3, Instructions: 28fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045DD7C Relevance: 3.1, APIs: 2, Instructions: 56fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047CBF0 Relevance: 2.9, Strings: 2, Instructions: 418COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040F890 Relevance: 2.1, APIs: 1, Instructions: 589COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047E1FA Relevance: 2.0, APIs: 1, Instructions: 499COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043916A Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004711D2 Relevance: 1.5, APIs: 1, Instructions: 19COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042202E Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412C38 Relevance: .4, Instructions: 384COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412818 Relevance: .4, Instructions: 378COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041240C Relevance: .4, Instructions: 361COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412038 Relevance: .4, Instructions: 351COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410D10 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00459384 Relevance: 79.2, APIs: 41, Strings: 4, Instructions: 480filewindowcomCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00441E05 Relevance: 49.8, APIs: 33, Instructions: 276COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046C604 Relevance: 40.5, APIs: 22, Strings: 1, Instructions: 216clipboardCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045657D Relevance: 38.8, APIs: 19, Strings: 3, Instructions: 287windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00454DAA Relevance: 38.7, APIs: 18, Strings: 4, Instructions: 203windowlibraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00452788 Relevance: 34.8, APIs: 23, Instructions: 344COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00476A8A Relevance: 27.3, APIs: 18, Instructions: 332COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043737D Relevance: 26.3, APIs: 10, Strings: 5, Instructions: 83windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00458D1C Relevance: 25.6, APIs: 17, Instructions: 112COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00469681 Relevance: 24.8, APIs: 13, Strings: 1, Instructions: 253windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004680EB Relevance: 24.7, APIs: 13, Strings: 1, Instructions: 204windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046F2B0 Relevance: 24.7, APIs: 11, Strings: 3, Instructions: 185windowfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045F48E Relevance: 23.0, APIs: 12, Strings: 1, Instructions: 226windowsleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045510D Relevance: 22.9, APIs: 12, Strings: 1, Instructions: 115windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415C25 Relevance: 22.7, APIs: 15, Instructions: 236COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00433BAC Relevance: 22.6, APIs: 15, Instructions: 79COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00460ABB Relevance: 21.3, APIs: 11, Strings: 1, Instructions: 294windowtimeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434506 Relevance: 21.2, APIs: 11, Strings: 1, Instructions: 162windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00435A35 Relevance: 21.1, APIs: 14, Instructions: 136timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00445A77 Relevance: 21.1, APIs: 7, Strings: 5, Instructions: 73windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004582BF Relevance: 19.4, APIs: 8, Strings: 3, Instructions: 165registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004580E1 Relevance: 19.4, APIs: 8, Strings: 3, Instructions: 136registryshareCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004584D6 Relevance: 19.4, APIs: 8, Strings: 3, Instructions: 105registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436582 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 79networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416B12 Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 57libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00437DB1 Relevance: 18.2, APIs: 12, Instructions: 180COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436879 Relevance: 18.1, APIs: 12, Instructions: 115COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046B39A Relevance: 17.9, APIs: 9, Strings: 1, Instructions: 401registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046F50B Relevance: 17.7, APIs: 7, Strings: 3, Instructions: 157windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046FD7F Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 143windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004393E2 Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 109threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00467214 Relevance: 16.8, APIs: 11, Instructions: 313COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004507E7 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 146windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448602 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 105windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004691F4 Relevance: 15.8, APIs: 7, Strings: 2, Instructions: 88windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004693F0 Relevance: 15.8, APIs: 7, Strings: 2, Instructions: 87windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046ECBF Relevance: 15.1, APIs: 10, Instructions: 101COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045E912 Relevance: 14.4, APIs: 7, Strings: 1, Instructions: 353timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042FE54 Relevance: 14.3, APIs: 4, Strings: 4, Instructions: 298sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046A75F Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 179registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045F2C5 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 146windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043717F Relevance: 14.0, APIs: 6, Strings: 2, Instructions: 46windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00456168 Relevance: 13.7, APIs: 9, Instructions: 181COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004417BC Relevance: 13.6, APIs: 9, Instructions: 142COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00445CF9 Relevance: 13.6, APIs: 9, Instructions: 69sleepkeyboardwindowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045427D Relevance: 12.5, APIs: 6, Strings: 1, Instructions: 259libraryloaderCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044AA1F Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 171networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046BB59 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 168networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044BBC9 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 100filestringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004140DB Relevance: 12.0, APIs: 8, Instructions: 42threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004357AD Relevance: 12.0, APIs: 8, Instructions: 36COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00440B39 Relevance: 10.8, APIs: 7, Instructions: 261COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045377F Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 236windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004472C8 Relevance: 10.7, APIs: 7, Instructions: 207COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00447303 Relevance: 10.7, APIs: 7, Instructions: 192COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044733D Relevance: 10.7, APIs: 7, Instructions: 177COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004498BD Relevance: 10.7, APIs: 7, Instructions: 159COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046A98D Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 158registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00463D7E Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 141libraryloaderCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044849C Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 106windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047244D Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 104sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448AFF Relevance: 10.6, APIs: 7, Instructions: 98windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00450DB4 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 76windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00455449 Relevance: 10.6, APIs: 7, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415702 Relevance: 10.6, APIs: 7, Instructions: 74threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00439102 Relevance: 10.5, APIs: 7, Instructions: 46threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041568B Relevance: 10.5, APIs: 7, Instructions: 37threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434124 Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 15libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047B1D0 Relevance: 9.5, APIs: 6, Instructions: 489COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004336C7 Relevance: 9.3, APIs: 6, Instructions: 253COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00457838 Relevance: 9.2, APIs: 6, Instructions: 176COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00445153 Relevance: 9.1, APIs: 6, Instructions: 142COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00447B66 Relevance: 9.1, APIs: 6, Instructions: 119COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044B474 Relevance: 9.1, APIs: 6, Instructions: 113fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00441077 Relevance: 9.1, APIs: 6, Instructions: 111windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00449063 Relevance: 9.1, APIs: 6, Instructions: 108windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00442582 Relevance: 9.1, APIs: 6, Instructions: 104COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448851 Relevance: 9.1, APIs: 6, Instructions: 92windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00449606 Relevance: 9.1, APIs: 6, Instructions: 91windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004416D1 Relevance: 9.1, APIs: 6, Instructions: 84COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045552E Relevance: 9.1, APIs: 6, Instructions: 78windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00467E5E Relevance: 9.1, APIs: 6, Instructions: 78COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00455080 Relevance: 9.1, APIs: 6, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00455212 Relevance: 9.1, APIs: 6, Instructions: 72windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00439326 Relevance: 9.1, APIs: 6, Instructions: 72processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041415E Relevance: 9.1, APIs: 6, Instructions: 71threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004555E0 Relevance: 9.1, APIs: 6, Instructions: 67windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004554C0 Relevance: 9.1, APIs: 6, Instructions: 61windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043609C Relevance: 9.1, APIs: 6, Instructions: 59COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436272 Relevance: 9.1, APIs: 6, Instructions: 59sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004471EC Relevance: 9.0, APIs: 6, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044CBD3 Relevance: 9.0, APIs: 6, Instructions: 49COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044B64F Relevance: 9.0, APIs: 6, Instructions: 40synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043604B Relevance: 9.0, APIs: 6, Instructions: 33serviceCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045F132 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 128windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00437CA6 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 107libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004692E4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 98windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004412AE Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 84windowlibraryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00443009 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 82windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004609BD Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 76windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045C277 Relevance: 7.6, APIs: 5, Instructions: 105COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044796B Relevance: 7.6, APIs: 5, Instructions: 96COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00447BAF Relevance: 7.6, APIs: 5, Instructions: 95COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00447870 Relevance: 7.6, APIs: 5, Instructions: 94windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448837 Relevance: 7.6, APIs: 5, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00449549 Relevance: 7.6, APIs: 5, Instructions: 83windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00455014 Relevance: 7.6, APIs: 5, Instructions: 78COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00445719 Relevance: 7.6, APIs: 5, Instructions: 76windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00459DCF Relevance: 7.6, APIs: 5, Instructions: 71COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00464950 Relevance: 7.6, APIs: 5, Instructions: 68networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044710F Relevance: 7.6, APIs: 5, Instructions: 67COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043770A Relevance: 7.6, APIs: 5, Instructions: 56sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046FCC6 Relevance: 7.5, APIs: 5, Instructions: 49windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004555B8 Relevance: 7.5, APIs: 5, Instructions: 45windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00455505 Relevance: 7.5, APIs: 5, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045551F Relevance: 7.5, APIs: 5, Instructions: 42windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043315E Relevance: 7.5, APIs: 5, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004140CF Relevance: 7.5, APIs: 5, Instructions: 24threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415601 Relevance: 7.5, APIs: 5, Instructions: 23threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041567F Relevance: 7.5, APIs: 5, Instructions: 22threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004667A7 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 170shareCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00438A5D Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 154windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00465D41 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 119networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044A7DC Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 116networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00451191 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00450D00 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 70windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046BD4D Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 69networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004497A4 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 53windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004342A8 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 33memoryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043416A Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 15libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004343CE Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 15libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004343FD Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 15libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043442C Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 15libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EE70 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 12libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040ACA0 Relevance: 6.4, APIs: 4, Instructions: 368COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041456C Relevance: 6.1, APIs: 4, Instructions: 137COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004781AE Relevance: 6.1, APIs: 4, Instructions: 135COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00441CB4 Relevance: 6.1, APIs: 4, Instructions: 112windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045D070 Relevance: 6.1, APIs: 4, Instructions: 100fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045058D Relevance: 6.1, APIs: 4, Instructions: 98COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004613E0 Relevance: 6.1, APIs: 4, Instructions: 90windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004727F8 Relevance: 6.1, APIs: 4, Instructions: 82COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0047721A Relevance: 6.1, APIs: 4, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448C8B Relevance: 6.1, APIs: 4, Instructions: 73windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004588B0 Relevance: 6.1, APIs: 4, Instructions: 67networkCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00438D4E Relevance: 6.1, APIs: 4, Instructions: 67windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043362D Relevance: 6.1, APIs: 4, Instructions: 54windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044419B Relevance: 6.1, APIs: 4, Instructions: 53synchronizationthreadwindowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0043401C Relevance: 6.0, APIs: 4, Instructions: 50COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00436A1D Relevance: 6.0, APIs: 4, Instructions: 48COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00437AFE Relevance: 6.0, APIs: 4, Instructions: 44COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004555D6 Relevance: 6.0, APIs: 4, Instructions: 40windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044B600 Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00447268 Relevance: 6.0, APIs: 4, Instructions: 32COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00471144 Relevance: 6.0, APIs: 4, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00471102 Relevance: 6.0, APIs: 4, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041405D Relevance: 6.0, APIs: 4, Instructions: 19threadCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00444652 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 104windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00448358 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 99windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0045126C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 74windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004515AB Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00474827 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 72sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004647A2 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 59networkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004694DE Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 56windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00442AFE Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 55networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004695F7 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 54windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0046956F Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 53windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004560AD Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 36windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00442262 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 17windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0044222A Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 17windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00439514 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 8windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|