Windows
Analysis Report
8CO4P3HwDt.exe
Overview
General Information
Sample name: | 8CO4P3HwDt.exerenamed because original name is a hash value |
Original sample name: | a45535760b1cab75d55825736dcdec6e9cc7d3521247731af0e4010b3c9b005b.exe |
Analysis ID: | 1551213 |
MD5: | c3c8df0d6043078abdf157a68d37eb96 |
SHA1: | 4ef0b88e12b3770fbaa6e5683b15b51c130f38ad |
SHA256: | a45535760b1cab75d55825736dcdec6e9cc7d3521247731af0e4010b3c9b005b |
Tags: | exeuser-adrian__luca |
Infos: | |
Detection
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 8CO4P3HwDt.exe (PID: 6916 cmdline:
"C:\Users\ user\Deskt op\8CO4P3H wDt.exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96) - uzqv383gxrrqx7oiosyki.exe (PID: 6972 cmdline:
"C:\oblimp yrbviueg\u zqv383gxrr qx7oiosyki .exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96) - usncdvbjyrwr.exe (PID: 7072 cmdline:
"C:\oblimp yrbviueg\u sncdvbjyrw r.exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96)
- usncdvbjyrwr.exe (PID: 6988 cmdline:
C:\oblimpy rbviueg\us ncdvbjyrwr .exe MD5: C3C8DF0D6043078ABDF157A68D37EB96) - hrzceasx.exe (PID: 7048 cmdline:
uwauanknl3 ss "c:\obl impyrbviue g\usncdvbj yrwr.exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96) - usncdvbjyrwr.exe (PID: 4064 cmdline:
"c:\oblimp yrbviueg\u sncdvbjyrw r.exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96) - hrzceasx.exe (PID: 5040 cmdline:
uwauanknl3 ss "c:\obl impyrbviue g\usncdvbj yrwr.exe" MD5: C3C8DF0D6043078ABDF157A68D37EB96)
- cleanup
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:45.143921+0100 | 2022930 | 1 | A Network Trojan was detected | 20.12.23.50 | 443 | 192.168.2.12 | 49717 | TCP |
2024-11-07T15:51:24.425231+0100 | 2022930 | 1 | A Network Trojan was detected | 20.12.23.50 | 443 | 192.168.2.12 | 49726 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:38.470948+0100 | 2018141 | 1 | A Network Trojan was detected | 54.244.188.177 | 80 | 192.168.2.12 | 49713 | TCP |
2024-11-07T15:50:42.469182+0100 | 2018141 | 1 | A Network Trojan was detected | 18.143.155.63 | 80 | 192.168.2.12 | 49715 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:38.470948+0100 | 2037771 | 1 | A Network Trojan was detected | 54.244.188.177 | 80 | 192.168.2.12 | 49713 | TCP |
2024-11-07T15:50:42.469182+0100 | 2037771 | 1 | A Network Trojan was detected | 18.143.155.63 | 80 | 192.168.2.12 | 49715 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:32.391304+0100 | 2018316 | 1 | A Network Trojan was detected | 1.1.1.1 | 53 | 192.168.2.12 | 61040 | UDP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:43.090729+0100 | 2811542 | 1 | A Network Trojan was detected | 1.1.1.1 | 53 | 192.168.2.12 | 52795 | UDP |
2024-11-07T15:50:43.761660+0100 | 2811542 | 1 | A Network Trojan was detected | 1.1.1.1 | 53 | 192.168.2.12 | 54810 | UDP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:35.597709+0100 | 2815568 | 1 | A Network Trojan was detected | 192.168.2.12 | 49712 | 18.143.155.63 | 80 | TCP |
2024-11-07T15:52:09.305733+0100 | 2815568 | 1 | A Network Trojan was detected | 192.168.2.12 | 49728 | 199.59.243.227 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:35.597709+0100 | 2820680 | 1 | Malware Command and Control Activity Detected | 192.168.2.12 | 49712 | 18.143.155.63 | 80 | TCP |
2024-11-07T15:52:09.305733+0100 | 2820680 | 1 | Malware Command and Control Activity Detected | 192.168.2.12 | 49728 | 199.59.243.227 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_008BA780 | |
Source: | Code function: | 2_2_0034A780 | |
Source: | Code function: | 3_2_00DAA780 | |
Source: | Code function: | 4_2_0039A780 | |
Source: | Code function: | 10_2_00B6A780 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | Network traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_008EF820 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Code function: | 0_2_008CACF0 | |
Source: | Code function: | 2_2_0035ACF0 | |
Source: | Code function: | 2_2_003610DA | |
Source: | Code function: | 3_2_00DBACF0 | |
Source: | Code function: | 4_2_003AACF0 | |
Source: | Code function: | 4_2_003B10CC | |
Source: | Code function: | 10_2_00B7ACF0 |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_008B2250 | |
Source: | Code function: | 2_2_00342250 | |
Source: | Code function: | 3_2_00DA2250 | |
Source: | Code function: | 4_2_00392250 | |
Source: | Code function: | 10_2_00B62250 |
Source: | Code function: | 0_2_008D4C00 |
Source: | Code function: | 0_2_008BAD00 |
Source: | Code function: | 0_2_008BAD00 | |
Source: | Code function: | 2_2_0034AD00 | |
Source: | Code function: | 3_2_00DAAD00 | |
Source: | Code function: | 4_2_0039AD00 | |
Source: | Code function: | 10_2_00B6AD00 |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 0_2_008DC35F |
Source: | Code function: | 0_2_008F1C94 | |
Source: | Code function: | 0_2_008F1CBC | |
Source: | Code function: | 0_2_008CD870 | |
Source: | Code function: | 2_2_00381C94 | |
Source: | Code function: | 2_2_00381CBC | |
Source: | Code function: | 3_2_00DE1C94 | |
Source: | Code function: | 3_2_00DE1CBC | |
Source: | Code function: | 4_2_003AD870 | |
Source: | Code function: | 4_2_003D1C94 | |
Source: | Code function: | 4_2_003D1CBC | |
Source: | Code function: | 10_2_00BA1C94 | |
Source: | Code function: | 10_2_00BA1CBC | |
Source: | Code function: | 10_2_00B7D870 |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_008BAD00 |
Source: | Code function: | 0_2_008DC35F |
Source: | Code function: | 0_2_008D2500 | |
Source: | Code function: | 2_2_00362500 | |
Source: | Code function: | 3_2_00DC2500 | |
Source: | Code function: | 4_2_003B2500 | |
Source: | Code function: | 10_2_00B82500 |
Source: | Code function: | 2_2_00343770 | |
Source: | Code function: | 3_2_00DA3770 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Decision node followed by non-executed suspicious API: |
Source: | Evasive API call chain: | graph_2-11847 | ||
Source: | Evasive API call chain: | |||
Source: | Evasive API call chain: | graph_0-9971 | ||
Source: | Evasive API call chain: | graph_3-10139 |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 0_2_008BA780 | |
Source: | Code function: | 2_2_0034A780 | |
Source: | Code function: | 3_2_00DAA780 | |
Source: | Code function: | 4_2_0039A780 | |
Source: | Code function: | 10_2_00B6A780 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-9932 | ||
Source: | API call chain: | graph_2-11836 | ||
Source: | API call chain: | graph_3-10076 | ||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: | |||
Source: | API call chain: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_008DC35F |
Source: | Code function: | 0_2_008E5570 |
Source: | Code function: | 0_2_008E7710 |
Source: | Code function: | 0_2_008E68B0 |
Source: | Code function: | 0_2_008C15A0 |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Service Execution | 4 Windows Service | 4 Windows Service | 1 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 2 Native API | 1 DLL Side-Loading | 1 Process Injection | 11 Virtualization/Sandbox Evasion | LSASS Memory | 111 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 Process Injection | Security Account Manager | 11 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 2 Process Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 File Deletion | Cached Domain Credentials | 1 System Service Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 1 File and Directory Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 4 System Information Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
89% | ReversingLabs | Win32.Adware.Multiverze | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Avira | TR/Nivdort.Gen2 | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
89% | ReversingLabs | Win32.Adware.Multiverze | ||
89% | ReversingLabs | Win32.Adware.Multiverze | ||
89% | ReversingLabs | Win32.Adware.Multiverze |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
degreedaughter.net | 85.214.228.140 | true | false | high | |
7450.bodis.com | 199.59.243.227 | true | false | high | |
gentleanother.net | 54.244.188.177 | true | false | high | |
returnbottle.net | 18.143.155.63 | true | false | high | |
pleasantinstead.net | 18.143.155.63 | true | false | high | |
forwardpeople.net | unknown | unknown | true | unknown | |
degreeanother.net | unknown | unknown | false | high | |
degreeexplain.net | unknown | unknown | true | unknown | |
heaveninside.net | unknown | unknown | true | unknown | |
answerappear.net | unknown | unknown | false | high | |
heavybusiness.net | unknown | unknown | true | unknown | |
pleasantinside.net | unknown | unknown | true | unknown | |
requirebusiness.net | unknown | unknown | false | high | |
forwardinside.net | unknown | unknown | true | unknown | |
glassmanner.net | unknown | unknown | false | high | |
answerexplain.net | unknown | unknown | true | unknown | |
orderinside.net | unknown | unknown | true | unknown | |
variousappear.net | unknown | unknown | true | unknown | |
returnbright.net | unknown | unknown | true | unknown | |
difficultanother.net | unknown | unknown | false | high | |
heavyinside.net | unknown | unknown | true | unknown | |
forwardready.net | unknown | unknown | true | unknown | |
glassdaughter.net | unknown | unknown | true | unknown | |
necessarymanner.net | unknown | unknown | false | high | |
leadernothing.net | unknown | unknown | false | high | |
answeranother.net | unknown | unknown | false | high | |
leadermanner.net | unknown | unknown | false | high | |
heavybottle.net | unknown | unknown | false | high | |
heavenbright.net | unknown | unknown | true | unknown | |
heavydivide.net | unknown | unknown | false | high | |
degreebrown.net | unknown | unknown | true | unknown | |
gentleinstead.net | unknown | unknown | true | unknown | |
glassanother.net | unknown | unknown | false | high | |
heavenanother.net | unknown | unknown | false | high | |
difficultmanner.net | unknown | unknown | false | high | |
glassexplain.net | unknown | unknown | true | unknown | |
requireinside.net | unknown | unknown | true | unknown | |
heavenexplain.net | unknown | unknown | true | unknown | |
forwardbusiness.net | unknown | unknown | false | high | |
difficultexplain.net | unknown | unknown | true | unknown | |
gentleappear.net | unknown | unknown | true | unknown | |
pleasantbright.net | unknown | unknown | true | unknown | |
returnexplain.net | unknown | unknown | true | unknown | |
gentlemanner.net | unknown | unknown | true | unknown | |
answerdaughter.net | unknown | unknown | true | unknown | |
heardinside.net | unknown | unknown | true | unknown | |
requiremanner.net | unknown | unknown | false | high | |
gentleexplain.net | unknown | unknown | true | unknown | |
glassappear.net | unknown | unknown | false | high | |
necessaryanother.net | unknown | unknown | false | high | |
glassinside.net | unknown | unknown | true | unknown | |
difficultbright.net | unknown | unknown | true | unknown | |
glasspeople.net | unknown | unknown | true | unknown | |
requireinstead.net | unknown | unknown | true | unknown | |
necessaryinside.net | unknown | unknown | true | unknown | |
returndivide.net | unknown | unknown | false | high | |
heardinstead.net | unknown | unknown | true | unknown | |
variousbright.net | unknown | unknown | true | unknown | |
degreebusiness.net | unknown | unknown | false | high | |
answerbusiness.net | unknown | unknown | false | high | |
heavenbusiness.net | unknown | unknown | true | unknown | |
gentledivide.net | unknown | unknown | false | high | |
variousinstead.net | unknown | unknown | true | unknown | |
gentlestream.net | unknown | unknown | false | high | |
pleasantmanner.net | unknown | unknown | false | high | |
necessaryappear.net | unknown | unknown | false | high | |
pleasantbusiness.net | unknown | unknown | false | high | |
heardbright.net | unknown | unknown | true | unknown | |
heavenbottle.net | unknown | unknown | false | high | |
heavynothing.net | unknown | unknown | false | high | |
gentlebusiness.net | unknown | unknown | true | unknown | |
ordermanner.net | unknown | unknown | false | high | |
leaderbottle.net | unknown | unknown | false | high | |
pleasantanother.net | unknown | unknown | false | high | |
heavyanother.net | unknown | unknown | true | unknown | |
degreeinstead.net | unknown | unknown | true | unknown | |
degreepeople.net | unknown | unknown | true | unknown | |
answerready.net | unknown | unknown | true | unknown | |
difficultbrown.net | unknown | unknown | true | unknown | |
answerbright.net | unknown | unknown | true | unknown | |
heavennothing.net | unknown | unknown | false | high | |
returninside.net | unknown | unknown | true | unknown | |
forwardbright.net | unknown | unknown | true | unknown | |
difficultinside.net | unknown | unknown | true | unknown | |
heavybright.net | unknown | unknown | true | unknown | |
leaderanother.net | unknown | unknown | false | high | |
returninstead.net | unknown | unknown | true | unknown | |
difficultinstead.net | unknown | unknown | true | unknown | |
heavenappear.net | unknown | unknown | true | unknown | |
answerinside.net | unknown | unknown | true | unknown | |
degreebright.net | unknown | unknown | true | unknown | |
forwardbrown.net | unknown | unknown | true | unknown | |
heavyinstead.net | unknown | unknown | true | unknown | |
gentleinside.net | unknown | unknown | true | unknown | |
heardexplain.net | unknown | unknown | true | unknown | |
heavyappear.net | unknown | unknown | true | unknown | |
answerpeople.net | unknown | unknown | true | unknown | |
pleasantexplain.net | unknown | unknown | true | unknown | |
requireexplain.net | unknown | unknown | true | unknown | |
orderappear.net | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.143.155.63 | returnbottle.net | United States | 16509 | AMAZON-02US | false | |
85.214.228.140 | degreedaughter.net | Germany | 6724 | STRATOSTRATOAGDE | false | |
199.59.243.227 | 7450.bodis.com | United States | 395082 | BODIS-NJUS | false | |
54.244.188.177 | gentleanother.net | United States | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1551213 |
Start date and time: | 2024-11-07 15:49:29 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 8CO4P3HwDt.exerenamed because original name is a hash value |
Original Sample Name: | a45535760b1cab75d55825736dcdec6e9cc7d3521247731af0e4010b3c9b005b.exe |
Detection: | MAL |
Classification: | mal96.troj.evad.winEXE@12/5@213/4 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, tile-service.weather.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Report size exceeded maximum capacity and may have missing disassembly code.
- VT rate limit hit for: 8CO4P3HwDt.exe
Time | Type | Description |
---|---|---|
09:51:02 | API Interceptor | |
09:51:49 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
18.143.155.63 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
85.214.228.140 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine | Browse |
| ||
Get hash | malicious | DBatLoader, Nitol, PureLog Stealer, XWorm | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
gentleanother.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
returnbottle.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
degreedaughter.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
7450.bodis.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
| ||
STRATOSTRATOAGDE | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | PureLog Stealer, RedLine | Browse |
| ||
BODIS-NJUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
| ||
Get hash | malicious | Ducktail | Browse |
|
Process: | C:\Users\user\Desktop\8CO4P3HwDt.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9 |
Entropy (8bit): | 2.94770277922009 |
Encrypted: | false |
SSDEEP: | 3:EDGCf3:EL3 |
MD5: | 46E5BCD6997E903847E4E88C16E5855E |
SHA1: | 378A9B0E6F3DA4C35C7711198509623232FF3BBF |
SHA-256: | C7BB3FCAEF237E69116176515D297C58563485A620A8D12405ADE6D0B42F2EBB |
SHA-512: | B79BA76D152EA659E77249942406F0618904EE10BF3AE3B1321ACE85EA70E45F67C37C22308BFAD3F8E74E197F7E8CD7790C9583204B6EE7998016A2DA38D249 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 362496 |
Entropy (8bit): | 6.788547539713091 |
Encrypted: | false |
SSDEEP: | 6144:UsuM2SxOxXDp5YPIgX5ZzPQ4Hv1/NptKicU77pWmUFnaKaX4xHfG1rnvv28T1dcB:LuMrQ9p5YPXLzVHvxjtKP29cIzifyrnu |
MD5: | C3C8DF0D6043078ABDF157A68D37EB96 |
SHA1: | 4EF0B88E12B3770FBAA6E5683B15B51C130F38AD |
SHA-256: | A45535760B1CAB75D55825736DCDEC6E9CC7D3521247731AF0E4010B3C9B005B |
SHA-512: | A3E80BFC92D0959D5037385967EBCC3DB5022E075B0B86323FC23171B9B5123D49014E24CB6E2F6A7E2DAC145633B794D637BD22AA2F48EF3255A7E662050946 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\oblimpyrbviueg\uzqv383gxrrqx7oiosyki.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 362496 |
Entropy (8bit): | 6.788547539713091 |
Encrypted: | false |
SSDEEP: | 6144:UsuM2SxOxXDp5YPIgX5ZzPQ4Hv1/NptKicU77pWmUFnaKaX4xHfG1rnvv28T1dcB:LuMrQ9p5YPXLzVHvxjtKP29cIzifyrnu |
MD5: | C3C8DF0D6043078ABDF157A68D37EB96 |
SHA1: | 4EF0B88E12B3770FBAA6E5683B15B51C130F38AD |
SHA-256: | A45535760B1CAB75D55825736DCDEC6E9CC7D3521247731AF0E4010B3C9B005B |
SHA-512: | A3E80BFC92D0959D5037385967EBCC3DB5022E075B0B86323FC23171B9B5123D49014E24CB6E2F6A7E2DAC145633B794D637BD22AA2F48EF3255A7E662050946 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\8CO4P3HwDt.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 362496 |
Entropy (8bit): | 6.788547539713091 |
Encrypted: | false |
SSDEEP: | 6144:UsuM2SxOxXDp5YPIgX5ZzPQ4Hv1/NptKicU77pWmUFnaKaX4xHfG1rnvv28T1dcB:LuMrQ9p5YPXLzVHvxjtKP29cIzifyrnu |
MD5: | C3C8DF0D6043078ABDF157A68D37EB96 |
SHA1: | 4EF0B88E12B3770FBAA6E5683B15B51C130F38AD |
SHA-256: | A45535760B1CAB75D55825736DCDEC6E9CC7D3521247731AF0E4010B3C9B005B |
SHA-512: | A3E80BFC92D0959D5037385967EBCC3DB5022E075B0B86323FC23171B9B5123D49014E24CB6E2F6A7E2DAC145633B794D637BD22AA2F48EF3255A7E662050946 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\8CO4P3HwDt.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9 |
Entropy (8bit): | 2.94770277922009 |
Encrypted: | false |
SSDEEP: | 3:EDGCf3:EL3 |
MD5: | 46E5BCD6997E903847E4E88C16E5855E |
SHA1: | 378A9B0E6F3DA4C35C7711198509623232FF3BBF |
SHA-256: | C7BB3FCAEF237E69116176515D297C58563485A620A8D12405ADE6D0B42F2EBB |
SHA-512: | B79BA76D152EA659E77249942406F0618904EE10BF3AE3B1321ACE85EA70E45F67C37C22308BFAD3F8E74E197F7E8CD7790C9583204B6EE7998016A2DA38D249 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.788547539713091 |
TrID: |
|
File name: | 8CO4P3HwDt.exe |
File size: | 362'496 bytes |
MD5: | c3c8df0d6043078abdf157a68d37eb96 |
SHA1: | 4ef0b88e12b3770fbaa6e5683b15b51c130f38ad |
SHA256: | a45535760b1cab75d55825736dcdec6e9cc7d3521247731af0e4010b3c9b005b |
SHA512: | a3e80bfc92d0959d5037385967ebcc3db5022e075b0b86323fc23171b9b5123d49014e24cb6e2f6a7e2dac145633b794d637bd22aa2f48ef3255a7e662050946 |
SSDEEP: | 6144:UsuM2SxOxXDp5YPIgX5ZzPQ4Hv1/NptKicU77pWmUFnaKaX4xHfG1rnvv28T1dcB:LuMrQ9p5YPXLzVHvxjtKP29cIzifyrnu |
TLSH: | 0D74E5FEDD8281EEDC42A0B8857B2773E3AD205477A861DB6180379464B99F4D93730B |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q!...O...O...O...4...O...N...O..B....O...@...O..B....O.Rich..O.........................PE..L....!zV........................... |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x439d30 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x567A21DA [Wed Dec 23 04:23:54 2015 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 7a1c04e3869a3f036d363cbe0174fe1a |
Instruction |
---|
push ebp |
mov ebp, esp |
movzx eax, word ptr [0044D468h] |
sub esp, 08h |
push esi |
sub eax, 68644053h |
push edi |
mov word ptr [0044D468h], ax |
call 00007F2945A1EB76h |
mov esi, 00000001h |
add word ptr [0044D090h], si |
mov cx, word ptr [0044D35Ch] |
mov dx, word ptr [0044D090h] |
add word ptr [0044D35Ch], si |
movsx eax, cx |
movsx ecx, dx |
add eax, BB104443h |
cmp eax, ecx |
jle 00007F2945A20B74h |
fld qword ptr [0044D118h] |
fadd qword ptr [0044BC98h] |
fstp qword ptr [0044D118h] |
call 00007F2945A0ABFFh |
fld dword ptr [0044D470h] |
fld1 |
fsub st(1), st(0) |
fxch st(0), st(1) |
fstp dword ptr [0044D470h] |
mov edx, dword ptr [0044D4BCh] |
mov dword ptr [ebp-04h], edx |
fild dword ptr [ebp-04h] |
fld dword ptr [0044D470h] |
fadd qword ptr [0044BC90h] |
fsubp st(1), st(0) |
fcomp qword ptr [0044BC88h] |
fstsw |
test ah, 00000044h |
jp 00007F2945A20BC3h |
mov ax, word ptr [0044D0D0h] |
movsx ecx, ax |
sub ecx, 755D6C2Bh |
mov dword ptr [ebp-04h], ecx |
fild dword ptr [ebp-04h] |
fld dword ptr [0044D4E0h] |
fadd qword ptr [0044BC80h] |
fucompp |
fstsw |
fadd dword ptr [0000D4E0h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4bca0 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x4f000 | 0xc884 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x42000 | 0x11c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x40ffa | 0x41000 | 5a9a8d96b5f64734f57e7b2baaa57c62 | False | 0.5254845252403846 | data | 6.3165136802931405 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x42000 | 0xa2a6 | 0xa400 | 4d907b36f74b44746b114cc40fdbae71 | False | 0.7407583841463414 | data | 6.482155544995024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x4d000 | 0x107c | 0x600 | 73290f6375722a8ce1cd1240da1c5b65 | False | 0.8548177083333334 | data | 6.29086260359177 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x4f000 | 0xc928 | 0xca00 | dbb909cb46c8431f801e8c1f33f54a36 | False | 0.6598275061881188 | data | 6.835926954483472 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
GDI32.dll | SetTextJustification, GetMetaRgn, GetPixelFormat, GetFontUnicodeRanges, SetPixel, GetDCPenColor, GetGraphicsMode, SetTextColor, GetMapMode |
USER32.dll | wvsprintfA, GetDlgItem, GetMenuCheckMarkDimensions, DrawTextA, GetMenuItemCount, GetWindowLongA, IsWindowUnicode, EnableWindow, SetFocus, GetMenu, SetDlgItemTextA, IsWindowEnabled, LoadIconA, GetScrollPos, PostMessageA, SetWindowTextA, GetMenuContextHelpId, EndDialog, CheckDlgButton, GetInputState, BeginPaint, GetForegroundWindow, MoveWindow, GetCursor, GetKeyboardType, RemovePropA, GetPropA, GetDialogBaseUnits, CharLowerBuffA, CallWindowProcA |
KERNEL32.dll | GetModuleHandleA, CloseHandle, CreateFileA, WriteFile, GetFileSize, HeapReAlloc, FlushFileBuffers, LoadResource, GetFileTime, GetCurrentThreadId, GlobalFlags, GetCurrentProcessId, QueryPerformanceCounter, IsProcessorFeaturePresent, SetFilePointer, GlobalHandle, LocalFlags, IsDebuggerPresent, GetProcAddress, GetVersion, GetLastError, GetStdHandle, HeapFree, ExitProcess, GetProcessHeap, HeapAlloc, GetSystemTime, SystemTimeToFileTime, lstrlenA |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-07T15:50:32.391304+0100 | 2018316 | ET MALWARE Possible Zeus GameOver/FluBot Related DGA NXDOMAIN Responses | 1 | 1.1.1.1 | 53 | 192.168.2.12 | 61040 | UDP |
2024-11-07T15:50:35.597709+0100 | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 1 | 192.168.2.12 | 49712 | 18.143.155.63 | 80 | TCP |
2024-11-07T15:50:35.597709+0100 | 2820680 | ETPRO MALWARE W32/Bayrob Attempted Checkin 2 | 1 | 192.168.2.12 | 49712 | 18.143.155.63 | 80 | TCP |
2024-11-07T15:50:38.470948+0100 | 2018141 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz | 1 | 54.244.188.177 | 80 | 192.168.2.12 | 49713 | TCP |
2024-11-07T15:50:38.470948+0100 | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 1 | 54.244.188.177 | 80 | 192.168.2.12 | 49713 | TCP |
2024-11-07T15:50:42.469182+0100 | 2018141 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz | 1 | 18.143.155.63 | 80 | 192.168.2.12 | 49715 | TCP |
2024-11-07T15:50:42.469182+0100 | 2037771 | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst | 1 | 18.143.155.63 | 80 | 192.168.2.12 | 49715 | TCP |
2024-11-07T15:50:43.090729+0100 | 2811542 | ETPRO MALWARE Possible Tinba DGA NXDOMAIN Responses (net) | 1 | 1.1.1.1 | 53 | 192.168.2.12 | 52795 | UDP |
2024-11-07T15:50:43.761660+0100 | 2811542 | ETPRO MALWARE Possible Tinba DGA NXDOMAIN Responses (net) | 1 | 1.1.1.1 | 53 | 192.168.2.12 | 54810 | UDP |
2024-11-07T15:50:45.143921+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 20.12.23.50 | 443 | 192.168.2.12 | 49717 | TCP |
2024-11-07T15:51:24.425231+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 20.12.23.50 | 443 | 192.168.2.12 | 49726 | TCP |
2024-11-07T15:52:09.305733+0100 | 2815568 | ETPRO MALWARE Terse HTTP 1.0 Request Possible Nivdort | 1 | 192.168.2.12 | 49728 | 199.59.243.227 | 80 | TCP |
2024-11-07T15:52:09.305733+0100 | 2820680 | ETPRO MALWARE W32/Bayrob Attempted Checkin 2 | 1 | 192.168.2.12 | 49728 | 199.59.243.227 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 7, 2024 15:50:33.017055988 CET | 49711 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:33.022098064 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.022188902 CET | 49711 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:33.022269011 CET | 49711 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:33.027275085 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.846889973 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.847028017 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.847048998 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.847057104 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:33.847124100 CET | 49711 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:33.848169088 CET | 49711 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:33.853404999 CET | 80 | 49711 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:34.107758045 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:34.112782001 CET | 80 | 49712 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:34.112879992 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:34.113013029 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:34.118542910 CET | 80 | 49712 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:35.553335905 CET | 80 | 49712 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:35.597708941 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:35.957968950 CET | 80 | 49712 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:35.958059072 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:35.958121061 CET | 49712 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:35.964277983 CET | 80 | 49712 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:37.458581924 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:37.463578939 CET | 80 | 49713 | 54.244.188.177 | 192.168.2.12 |
Nov 7, 2024 15:50:37.463658094 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:37.470662117 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:37.475969076 CET | 80 | 49713 | 54.244.188.177 | 192.168.2.12 |
Nov 7, 2024 15:50:38.343558073 CET | 80 | 49713 | 54.244.188.177 | 192.168.2.12 |
Nov 7, 2024 15:50:38.394351006 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:38.470947981 CET | 80 | 49713 | 54.244.188.177 | 192.168.2.12 |
Nov 7, 2024 15:50:38.471096039 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:38.471421003 CET | 49713 | 80 | 192.168.2.12 | 54.244.188.177 |
Nov 7, 2024 15:50:38.476959944 CET | 80 | 49713 | 54.244.188.177 | 192.168.2.12 |
Nov 7, 2024 15:50:39.348402977 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:39.353569031 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:39.353688002 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:39.353786945 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:39.358644962 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:40.029390097 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:40.029539108 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:40.029622078 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:40.061903000 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:40.062052965 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:40.063730955 CET | 49714 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:50:40.068866968 CET | 80 | 49714 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:50:40.598248005 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:40.603164911 CET | 80 | 49715 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:40.603296995 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:40.603492022 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:40.608274937 CET | 80 | 49715 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:42.053514004 CET | 80 | 49715 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:42.097421885 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:42.469182014 CET | 80 | 49715 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:42.469261885 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:42.469300032 CET | 49715 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:50:42.474421024 CET | 80 | 49715 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:50:44.020972013 CET | 49719 | 80 | 192.168.2.12 | 85.214.228.140 |
Nov 7, 2024 15:50:44.027000904 CET | 80 | 49719 | 85.214.228.140 | 192.168.2.12 |
Nov 7, 2024 15:50:44.027081966 CET | 49719 | 80 | 192.168.2.12 | 85.214.228.140 |
Nov 7, 2024 15:50:44.027134895 CET | 49719 | 80 | 192.168.2.12 | 85.214.228.140 |
Nov 7, 2024 15:50:44.033591032 CET | 80 | 49719 | 85.214.228.140 | 192.168.2.12 |
Nov 7, 2024 15:50:44.905226946 CET | 80 | 49719 | 85.214.228.140 | 192.168.2.12 |
Nov 7, 2024 15:50:44.905646086 CET | 49719 | 80 | 192.168.2.12 | 85.214.228.140 |
Nov 7, 2024 15:50:44.911237001 CET | 80 | 49719 | 85.214.228.140 | 192.168.2.12 |
Nov 7, 2024 15:50:44.911303043 CET | 49719 | 80 | 192.168.2.12 | 85.214.228.140 |
Nov 7, 2024 15:52:08.664349079 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:08.669409990 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:08.669593096 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:08.669750929 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:08.677541971 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:09.305361032 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:09.305672884 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:09.305732965 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:09.306257010 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:09.306303978 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:09.306588888 CET | 49728 | 80 | 192.168.2.12 | 199.59.243.227 |
Nov 7, 2024 15:52:09.311486959 CET | 80 | 49728 | 199.59.243.227 | 192.168.2.12 |
Nov 7, 2024 15:52:14.426393032 CET | 49729 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:52:14.546691895 CET | 80 | 49729 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:52:14.546781063 CET | 49729 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:52:14.546895981 CET | 49729 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:52:14.551703930 CET | 80 | 49729 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:52:16.004764080 CET | 80 | 49729 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:52:16.004925013 CET | 49729 | 80 | 192.168.2.12 | 18.143.155.63 |
Nov 7, 2024 15:52:16.010896921 CET | 80 | 49729 | 18.143.155.63 | 192.168.2.12 |
Nov 7, 2024 15:52:16.010987043 CET | 49729 | 80 | 192.168.2.12 | 18.143.155.63 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 7, 2024 15:50:32.061055899 CET | 55878 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.071244955 CET | 53 | 55878 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.111917973 CET | 53411 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.121053934 CET | 53 | 53411 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.193698883 CET | 63400 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.202768087 CET | 53 | 63400 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.210737944 CET | 58660 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.242705107 CET | 53 | 58660 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.243936062 CET | 58781 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.275132895 CET | 53 | 58781 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.276457071 CET | 59659 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.288017988 CET | 53 | 59659 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.289321899 CET | 61978 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.300187111 CET | 53 | 61978 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.303232908 CET | 55103 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.335155964 CET | 53 | 55103 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.336568117 CET | 65082 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.346949100 CET | 53 | 65082 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.348006964 CET | 53986 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.380029917 CET | 53 | 53986 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.381208897 CET | 61040 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.391304016 CET | 53 | 61040 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.401412964 CET | 59300 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.412921906 CET | 53 | 59300 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.414256096 CET | 52176 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.571103096 CET | 53 | 52176 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.572403908 CET | 52575 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.583162069 CET | 53 | 52575 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.584578037 CET | 62868 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:32.597249985 CET | 53 | 62868 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:32.599634886 CET | 63277 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:33.014821053 CET | 53 | 63277 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:33.849387884 CET | 58522 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:33.859556913 CET | 53 | 58522 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:33.860847950 CET | 51386 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:33.872083902 CET | 53 | 51386 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:33.873311043 CET | 58182 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:33.904542923 CET | 53 | 58182 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:33.906032085 CET | 62924 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:33.915256023 CET | 53 | 62924 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:33.916457891 CET | 65267 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:34.107028008 CET | 53 | 65267 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:35.959131956 CET | 55524 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:35.992850065 CET | 53 | 55524 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:35.994096041 CET | 61398 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.004683971 CET | 53 | 61398 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.005716085 CET | 60911 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.018410921 CET | 53 | 60911 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.019709110 CET | 52556 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.029875040 CET | 53 | 52556 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.030996084 CET | 54630 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.042032957 CET | 53 | 54630 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.043268919 CET | 54333 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.073939085 CET | 53 | 54333 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.075202942 CET | 63881 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.106527090 CET | 53 | 63881 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.107708931 CET | 62455 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.118455887 CET | 53 | 62455 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.119703054 CET | 59622 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.129980087 CET | 53 | 59622 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.131140947 CET | 53254 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.141983032 CET | 53 | 53254 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.143102884 CET | 64960 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.152947903 CET | 53 | 64960 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.154073000 CET | 62052 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.185976028 CET | 53 | 62052 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.187191963 CET | 54006 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.195962906 CET | 53 | 54006 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.196903944 CET | 65385 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.207361937 CET | 53 | 65385 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.208410025 CET | 63560 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.375502110 CET | 53 | 63560 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.376693964 CET | 49474 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.388797045 CET | 53 | 49474 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.390199900 CET | 54167 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.398511887 CET | 53 | 54167 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.399653912 CET | 52652 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.431021929 CET | 53 | 52652 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.432921886 CET | 56999 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.596924067 CET | 53 | 56999 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.598845005 CET | 51371 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.609118938 CET | 53 | 51371 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.610866070 CET | 49263 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.620577097 CET | 53 | 49263 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.621695042 CET | 56129 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.652581930 CET | 53 | 56129 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.653825998 CET | 49434 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.663974047 CET | 53 | 49434 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.665091991 CET | 52014 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.674887896 CET | 53 | 52014 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.676348925 CET | 49903 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.694242954 CET | 53 | 49903 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.699486017 CET | 61515 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.707346916 CET | 53 | 61515 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.709897041 CET | 49793 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.719021082 CET | 53 | 49793 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.720170975 CET | 54123 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.751260996 CET | 53 | 54123 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.753268003 CET | 63967 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.763493061 CET | 53 | 63967 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.765487909 CET | 49332 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.798727989 CET | 53 | 49332 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.800281048 CET | 49900 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.808063030 CET | 53 | 49900 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.809489965 CET | 52886 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.816996098 CET | 53 | 52886 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.818222046 CET | 64139 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.825573921 CET | 53 | 64139 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.826747894 CET | 59683 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.857584953 CET | 53 | 59683 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.858894110 CET | 56391 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.872421026 CET | 53 | 56391 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.876452923 CET | 56949 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.887038946 CET | 53 | 56949 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.888290882 CET | 60037 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.898539066 CET | 53 | 60037 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.900391102 CET | 50806 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.909567118 CET | 53 | 50806 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.911684990 CET | 62194 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.922736883 CET | 53 | 62194 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.926268101 CET | 60799 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.936700106 CET | 53 | 60799 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.937891960 CET | 50548 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.950093031 CET | 53 | 50548 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.951394081 CET | 53084 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.983128071 CET | 53 | 53084 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.984416008 CET | 60950 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:36.994483948 CET | 53 | 60950 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:36.995716095 CET | 62464 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.006149054 CET | 53 | 62464 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.007405043 CET | 56681 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.018970966 CET | 53 | 56681 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.020015001 CET | 58417 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.030833960 CET | 53 | 58417 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.031716108 CET | 60429 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.064296007 CET | 53 | 60429 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.065376997 CET | 53324 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.075678110 CET | 53 | 53324 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.080423117 CET | 54910 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.091466904 CET | 53 | 54910 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.094731092 CET | 60740 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.104702950 CET | 53 | 60740 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.105887890 CET | 51969 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.117088079 CET | 53 | 51969 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.118273973 CET | 53501 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.128886938 CET | 53 | 53501 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.135714054 CET | 64198 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.147527933 CET | 53 | 64198 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:37.239980936 CET | 52980 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:37.438239098 CET | 53 | 52980 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.472532034 CET | 55819 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.482202053 CET | 53 | 55819 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.483479023 CET | 59309 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.514782906 CET | 53 | 59309 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.516201973 CET | 62935 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.527385950 CET | 53 | 62935 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.528678894 CET | 61769 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.539263010 CET | 53 | 61769 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.540628910 CET | 59765 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.573142052 CET | 53 | 59765 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.574743032 CET | 55329 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.585866928 CET | 53 | 55329 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.587299109 CET | 55021 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.596869946 CET | 53 | 55021 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.598417997 CET | 65030 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.609096050 CET | 53 | 65030 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.610598087 CET | 56384 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.623939037 CET | 53 | 56384 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.625407934 CET | 49775 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.658279896 CET | 53 | 49775 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.659610987 CET | 54442 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.692061901 CET | 53 | 54442 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.693331957 CET | 49369 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.725785017 CET | 53 | 49369 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.727310896 CET | 54136 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.760349989 CET | 53 | 54136 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.761543989 CET | 62645 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.792762995 CET | 53 | 62645 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.793943882 CET | 51602 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.804871082 CET | 53 | 51602 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.806032896 CET | 56069 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.815332890 CET | 53 | 56069 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.816703081 CET | 51711 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.826771021 CET | 53 | 51711 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.828016996 CET | 59437 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.858014107 CET | 53 | 59437 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.859339952 CET | 55379 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.869194031 CET | 53 | 55379 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.870381117 CET | 60758 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.901793003 CET | 53 | 60758 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.911035061 CET | 59374 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.920753002 CET | 53 | 59374 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.921946049 CET | 50799 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.932405949 CET | 53 | 50799 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.933685064 CET | 53607 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.943319082 CET | 53 | 53607 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.944565058 CET | 60019 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.976975918 CET | 53 | 60019 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.978297949 CET | 60223 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:38.989069939 CET | 53 | 60223 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:38.990175009 CET | 61079 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:39.347677946 CET | 53 | 61079 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.068571091 CET | 57230 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.099374056 CET | 53 | 57230 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.119277000 CET | 55991 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.150058031 CET | 53 | 55991 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.169529915 CET | 59172 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.181050062 CET | 53 | 59172 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.185806036 CET | 63285 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.197092056 CET | 53 | 63285 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.253731966 CET | 55383 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.266252041 CET | 53 | 55383 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.319753885 CET | 50108 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.331813097 CET | 53 | 50108 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.336393118 CET | 63224 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.348149061 CET | 53 | 63224 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.349582911 CET | 51736 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.359796047 CET | 53 | 51736 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.361592054 CET | 62520 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.373874903 CET | 53 | 62520 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.375204086 CET | 49234 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.386442900 CET | 53 | 49234 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:40.387890100 CET | 50654 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:40.597685099 CET | 53 | 50654 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.470266104 CET | 58581 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.479764938 CET | 53 | 58581 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.480931044 CET | 52051 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.491219044 CET | 53 | 52051 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.492441893 CET | 59401 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.502408981 CET | 53 | 59401 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.503568888 CET | 55030 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.511087894 CET | 53 | 55030 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.512459993 CET | 59105 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.522123098 CET | 53 | 59105 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.531462908 CET | 50204 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.561728001 CET | 53 | 50204 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.563071966 CET | 54353 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.594779968 CET | 53 | 54353 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.596116066 CET | 51958 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:42.759627104 CET | 53 | 51958 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:42.854782104 CET | 52214 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.013878107 CET | 53 | 52214 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.080676079 CET | 52795 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.090728998 CET | 53 | 52795 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.091844082 CET | 57223 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.122219086 CET | 53 | 57223 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.133059978 CET | 49291 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.164113045 CET | 53 | 49291 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.166635036 CET | 59043 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.177833080 CET | 53 | 59043 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.179464102 CET | 57582 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.189707994 CET | 53 | 57582 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.190999985 CET | 52649 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.224935055 CET | 53 | 52649 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.226085901 CET | 52629 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.237549067 CET | 53 | 52629 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.239110947 CET | 62532 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.249094009 CET | 53 | 62532 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.250960112 CET | 49455 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.260262012 CET | 53 | 49455 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.261773109 CET | 50094 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.272043943 CET | 53 | 50094 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.273907900 CET | 64281 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.284220934 CET | 53 | 64281 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.285676003 CET | 65320 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.316426039 CET | 53 | 65320 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.317713976 CET | 63384 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.327120066 CET | 53 | 63384 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.328691006 CET | 57036 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.337754011 CET | 53 | 57036 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.338885069 CET | 57503 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.348467112 CET | 53 | 57503 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.353317022 CET | 53278 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.363282919 CET | 53 | 53278 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.380511045 CET | 59799 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.389350891 CET | 53 | 59799 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.390388966 CET | 60558 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.400141954 CET | 53 | 60558 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.401166916 CET | 64665 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.431592941 CET | 53 | 64665 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.432663918 CET | 53246 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.464695930 CET | 53 | 53246 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.465941906 CET | 63725 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.476999998 CET | 53 | 63725 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.478089094 CET | 55563 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.488123894 CET | 53 | 55563 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.489490032 CET | 55685 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.498915911 CET | 53 | 55685 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.500036001 CET | 61883 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.510081053 CET | 53 | 61883 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.511238098 CET | 52284 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.519056082 CET | 53 | 52284 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.520224094 CET | 55065 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.530484915 CET | 53 | 55065 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.531517029 CET | 50689 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.563083887 CET | 53 | 50689 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.564354897 CET | 50684 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.737529039 CET | 53 | 50684 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.738893032 CET | 54594 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.749855995 CET | 53 | 54594 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.751023054 CET | 54810 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.761660099 CET | 53 | 54810 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.762669086 CET | 63247 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.920042038 CET | 53 | 63247 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.921403885 CET | 59645 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.953638077 CET | 53 | 59645 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.955495119 CET | 50438 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.965208054 CET | 53 | 50438 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.966486931 CET | 50106 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.977418900 CET | 53 | 50106 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.978571892 CET | 58421 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:43.988555908 CET | 53 | 58421 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:43.989830017 CET | 49896 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.003756046 CET | 53 | 49896 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.004937887 CET | 64768 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.020085096 CET | 53 | 64768 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.906639099 CET | 59919 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.915266991 CET | 53 | 59919 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.916501999 CET | 54798 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.926552057 CET | 53 | 54798 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.927695036 CET | 51161 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.937752008 CET | 53 | 51161 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.939047098 CET | 56095 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.949186087 CET | 53 | 56095 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.950342894 CET | 58248 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:44.980081081 CET | 53 | 58248 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:44.981360912 CET | 53990 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.143635035 CET | 53 | 53990 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.154129028 CET | 52148 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.164115906 CET | 53 | 52148 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.165505886 CET | 60302 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.176037073 CET | 53 | 60302 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.177978992 CET | 53633 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.191411972 CET | 53 | 53633 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.193425894 CET | 55464 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.225363970 CET | 53 | 55464 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.227000952 CET | 56118 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.236249924 CET | 53 | 56118 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:45.238771915 CET | 58987 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:45.271048069 CET | 53 | 58987 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:50:58.035965919 CET | 61358 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:50:58.046475887 CET | 53 | 61358 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:53.549278021 CET | 50315 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:53.935127974 CET | 53 | 50315 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:54.941850901 CET | 60212 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:54.951539993 CET | 53 | 60212 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:55.958080053 CET | 60585 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:55.968050957 CET | 53 | 60585 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:56.988593102 CET | 60823 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:56.999291897 CET | 53 | 60823 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:58.004246950 CET | 53881 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:58.014391899 CET | 53 | 53881 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:51:59.022233963 CET | 50299 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:51:59.032080889 CET | 53 | 50299 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:00.036933899 CET | 55281 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:00.050940037 CET | 53 | 55281 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:01.122180939 CET | 58046 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:01.148332119 CET | 58046 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:01.155534983 CET | 53 | 58046 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:01.157527924 CET | 53 | 58046 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:02.162286997 CET | 59907 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:02.190639973 CET | 59907 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:02.323637009 CET | 53 | 59907 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:02.323879004 CET | 53 | 59907 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:03.333918095 CET | 58435 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:03.341836929 CET | 53 | 58435 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:04.349649906 CET | 62005 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:04.359714985 CET | 53 | 62005 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:05.363652945 CET | 54560 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:05.393719912 CET | 54560 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:05.517164946 CET | 53 | 54560 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:05.517184973 CET | 53 | 54560 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:06.519807100 CET | 56897 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:06.549989939 CET | 56897 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:06.552776098 CET | 53 | 56897 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:06.557041883 CET | 53 | 56897 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:07.589507103 CET | 61872 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:07.600938082 CET | 53 | 61872 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:10.321799040 CET | 58565 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:10.333369017 CET | 53 | 58565 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:11.349198103 CET | 59222 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:11.360363007 CET | 53 | 59222 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:12.363647938 CET | 60844 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:12.377095938 CET | 53 | 60844 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:13.382306099 CET | 57177 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:13.409570932 CET | 57177 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:13.414598942 CET | 53 | 57177 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:13.417268038 CET | 53 | 57177 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:17.019814014 CET | 59353 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:17.050282955 CET | 59353 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:17.051208019 CET | 53 | 59353 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:17.057410002 CET | 53 | 59353 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:18.097644091 CET | 52698 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:18.127909899 CET | 52698 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:18.130179882 CET | 53 | 52698 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:18.135242939 CET | 53 | 52698 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:19.144499063 CET | 65415 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:19.156049967 CET | 53 | 65415 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:20.161726952 CET | 61319 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:20.173338890 CET | 53 | 61319 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:21.175951004 CET | 63940 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:21.185372114 CET | 53 | 63940 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:22.192511082 CET | 59254 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:22.202563047 CET | 53 | 59254 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:23.207057953 CET | 57650 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:23.237200975 CET | 57650 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:23.238806963 CET | 53 | 57650 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:23.244930029 CET | 53 | 57650 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:24.254065990 CET | 53932 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:24.265342951 CET | 53 | 53932 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:25.269614935 CET | 57903 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:25.281001091 CET | 53 | 57903 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:26.285334110 CET | 51747 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:26.295265913 CET | 53 | 51747 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:27.300828934 CET | 61329 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:27.331180096 CET | 61329 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:27.332876921 CET | 53 | 61329 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:27.338790894 CET | 53 | 61329 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:28.347543955 CET | 62280 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:28.357753038 CET | 53 | 62280 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:29.336440086 CET | 49746 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:29.346055984 CET | 53 | 49746 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:30.285355091 CET | 56288 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:30.295526981 CET | 53 | 56288 | 1.1.1.1 | 192.168.2.12 |
Nov 7, 2024 15:52:31.208456993 CET | 61050 | 53 | 192.168.2.12 | 1.1.1.1 |
Nov 7, 2024 15:52:31.218302965 CET | 53 | 61050 | 1.1.1.1 | 192.168.2.12 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 7, 2024 15:50:32.061055899 CET | 192.168.2.12 | 1.1.1.1 | 0x6fb1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.111917973 CET | 192.168.2.12 | 1.1.1.1 | 0x9f02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.193698883 CET | 192.168.2.12 | 1.1.1.1 | 0x1080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.210737944 CET | 192.168.2.12 | 1.1.1.1 | 0xf947 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.243936062 CET | 192.168.2.12 | 1.1.1.1 | 0x2035 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.276457071 CET | 192.168.2.12 | 1.1.1.1 | 0x725f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.289321899 CET | 192.168.2.12 | 1.1.1.1 | 0x9c63 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.303232908 CET | 192.168.2.12 | 1.1.1.1 | 0xddbc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.336568117 CET | 192.168.2.12 | 1.1.1.1 | 0x2a19 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.348006964 CET | 192.168.2.12 | 1.1.1.1 | 0x4b2c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.381208897 CET | 192.168.2.12 | 1.1.1.1 | 0xb2a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.401412964 CET | 192.168.2.12 | 1.1.1.1 | 0x4c67 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.414256096 CET | 192.168.2.12 | 1.1.1.1 | 0x46b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.572403908 CET | 192.168.2.12 | 1.1.1.1 | 0xc90e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.584578037 CET | 192.168.2.12 | 1.1.1.1 | 0x229b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.599634886 CET | 192.168.2.12 | 1.1.1.1 | 0xd7e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.849387884 CET | 192.168.2.12 | 1.1.1.1 | 0x10d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.860847950 CET | 192.168.2.12 | 1.1.1.1 | 0x556f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.873311043 CET | 192.168.2.12 | 1.1.1.1 | 0x8172 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.906032085 CET | 192.168.2.12 | 1.1.1.1 | 0xc596 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.916457891 CET | 192.168.2.12 | 1.1.1.1 | 0x2603 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:35.959131956 CET | 192.168.2.12 | 1.1.1.1 | 0x1983 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:35.994096041 CET | 192.168.2.12 | 1.1.1.1 | 0x3a90 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.005716085 CET | 192.168.2.12 | 1.1.1.1 | 0xf593 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.019709110 CET | 192.168.2.12 | 1.1.1.1 | 0x271 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.030996084 CET | 192.168.2.12 | 1.1.1.1 | 0x9f5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.043268919 CET | 192.168.2.12 | 1.1.1.1 | 0x9f06 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.075202942 CET | 192.168.2.12 | 1.1.1.1 | 0x12d4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.107708931 CET | 192.168.2.12 | 1.1.1.1 | 0xee5d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.119703054 CET | 192.168.2.12 | 1.1.1.1 | 0x597f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.131140947 CET | 192.168.2.12 | 1.1.1.1 | 0xe1c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.143102884 CET | 192.168.2.12 | 1.1.1.1 | 0x2967 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.154073000 CET | 192.168.2.12 | 1.1.1.1 | 0xaa70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.187191963 CET | 192.168.2.12 | 1.1.1.1 | 0xe4ef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.196903944 CET | 192.168.2.12 | 1.1.1.1 | 0xe62c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.208410025 CET | 192.168.2.12 | 1.1.1.1 | 0xc635 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.376693964 CET | 192.168.2.12 | 1.1.1.1 | 0xcd9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.390199900 CET | 192.168.2.12 | 1.1.1.1 | 0xc6e5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.399653912 CET | 192.168.2.12 | 1.1.1.1 | 0x97c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.432921886 CET | 192.168.2.12 | 1.1.1.1 | 0x60c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.598845005 CET | 192.168.2.12 | 1.1.1.1 | 0x8bb5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.610866070 CET | 192.168.2.12 | 1.1.1.1 | 0x9494 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.621695042 CET | 192.168.2.12 | 1.1.1.1 | 0x3c4c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.653825998 CET | 192.168.2.12 | 1.1.1.1 | 0x17c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.665091991 CET | 192.168.2.12 | 1.1.1.1 | 0x9d86 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.676348925 CET | 192.168.2.12 | 1.1.1.1 | 0x96af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.699486017 CET | 192.168.2.12 | 1.1.1.1 | 0xcc10 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.709897041 CET | 192.168.2.12 | 1.1.1.1 | 0x8504 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.720170975 CET | 192.168.2.12 | 1.1.1.1 | 0x593a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.753268003 CET | 192.168.2.12 | 1.1.1.1 | 0x3393 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.765487909 CET | 192.168.2.12 | 1.1.1.1 | 0xdf7e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.800281048 CET | 192.168.2.12 | 1.1.1.1 | 0x7c79 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.809489965 CET | 192.168.2.12 | 1.1.1.1 | 0xa0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.818222046 CET | 192.168.2.12 | 1.1.1.1 | 0xa22 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.826747894 CET | 192.168.2.12 | 1.1.1.1 | 0xb0d5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.858894110 CET | 192.168.2.12 | 1.1.1.1 | 0x3a7d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.876452923 CET | 192.168.2.12 | 1.1.1.1 | 0xe738 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.888290882 CET | 192.168.2.12 | 1.1.1.1 | 0xf1c3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.900391102 CET | 192.168.2.12 | 1.1.1.1 | 0xdff1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.911684990 CET | 192.168.2.12 | 1.1.1.1 | 0x7828 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.926268101 CET | 192.168.2.12 | 1.1.1.1 | 0x852 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.937891960 CET | 192.168.2.12 | 1.1.1.1 | 0x9330 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.951394081 CET | 192.168.2.12 | 1.1.1.1 | 0xcb8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.984416008 CET | 192.168.2.12 | 1.1.1.1 | 0x1a70 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.995716095 CET | 192.168.2.12 | 1.1.1.1 | 0xa641 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.007405043 CET | 192.168.2.12 | 1.1.1.1 | 0x4f53 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.020015001 CET | 192.168.2.12 | 1.1.1.1 | 0xb4dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.031716108 CET | 192.168.2.12 | 1.1.1.1 | 0xb927 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.065376997 CET | 192.168.2.12 | 1.1.1.1 | 0x6ac3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.080423117 CET | 192.168.2.12 | 1.1.1.1 | 0x951c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.094731092 CET | 192.168.2.12 | 1.1.1.1 | 0x3235 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.105887890 CET | 192.168.2.12 | 1.1.1.1 | 0xe52d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.118273973 CET | 192.168.2.12 | 1.1.1.1 | 0xf7e6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.135714054 CET | 192.168.2.12 | 1.1.1.1 | 0x324a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.239980936 CET | 192.168.2.12 | 1.1.1.1 | 0xbe1e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.472532034 CET | 192.168.2.12 | 1.1.1.1 | 0x9db6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.483479023 CET | 192.168.2.12 | 1.1.1.1 | 0x1bfb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.516201973 CET | 192.168.2.12 | 1.1.1.1 | 0x6ea6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.528678894 CET | 192.168.2.12 | 1.1.1.1 | 0x4495 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.540628910 CET | 192.168.2.12 | 1.1.1.1 | 0xa77 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.574743032 CET | 192.168.2.12 | 1.1.1.1 | 0xaed2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.587299109 CET | 192.168.2.12 | 1.1.1.1 | 0xb8f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.598417997 CET | 192.168.2.12 | 1.1.1.1 | 0x5eab | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.610598087 CET | 192.168.2.12 | 1.1.1.1 | 0xc77e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.625407934 CET | 192.168.2.12 | 1.1.1.1 | 0x5d04 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.659610987 CET | 192.168.2.12 | 1.1.1.1 | 0x42c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.693331957 CET | 192.168.2.12 | 1.1.1.1 | 0x40c6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.727310896 CET | 192.168.2.12 | 1.1.1.1 | 0xa219 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.761543989 CET | 192.168.2.12 | 1.1.1.1 | 0x14ca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.793943882 CET | 192.168.2.12 | 1.1.1.1 | 0x5c1e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.806032896 CET | 192.168.2.12 | 1.1.1.1 | 0x613e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.816703081 CET | 192.168.2.12 | 1.1.1.1 | 0x6012 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.828016996 CET | 192.168.2.12 | 1.1.1.1 | 0x5596 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.859339952 CET | 192.168.2.12 | 1.1.1.1 | 0x177a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.870381117 CET | 192.168.2.12 | 1.1.1.1 | 0x485c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.911035061 CET | 192.168.2.12 | 1.1.1.1 | 0x7f28 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.921946049 CET | 192.168.2.12 | 1.1.1.1 | 0x6785 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.933685064 CET | 192.168.2.12 | 1.1.1.1 | 0xde1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.944565058 CET | 192.168.2.12 | 1.1.1.1 | 0x813e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.978297949 CET | 192.168.2.12 | 1.1.1.1 | 0x6aaa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.990175009 CET | 192.168.2.12 | 1.1.1.1 | 0x9b48 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.068571091 CET | 192.168.2.12 | 1.1.1.1 | 0x5d9d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.119277000 CET | 192.168.2.12 | 1.1.1.1 | 0x3785 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.169529915 CET | 192.168.2.12 | 1.1.1.1 | 0x8cb0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.185806036 CET | 192.168.2.12 | 1.1.1.1 | 0x1ca2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.253731966 CET | 192.168.2.12 | 1.1.1.1 | 0xf7c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.319753885 CET | 192.168.2.12 | 1.1.1.1 | 0x418b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.336393118 CET | 192.168.2.12 | 1.1.1.1 | 0xfd79 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.349582911 CET | 192.168.2.12 | 1.1.1.1 | 0x4959 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.361592054 CET | 192.168.2.12 | 1.1.1.1 | 0xe209 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.375204086 CET | 192.168.2.12 | 1.1.1.1 | 0x13ef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.387890100 CET | 192.168.2.12 | 1.1.1.1 | 0xa28f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.470266104 CET | 192.168.2.12 | 1.1.1.1 | 0xec6f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.480931044 CET | 192.168.2.12 | 1.1.1.1 | 0x3dfc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.492441893 CET | 192.168.2.12 | 1.1.1.1 | 0x2328 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.503568888 CET | 192.168.2.12 | 1.1.1.1 | 0x9b53 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.512459993 CET | 192.168.2.12 | 1.1.1.1 | 0xa73c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.531462908 CET | 192.168.2.12 | 1.1.1.1 | 0xf742 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.563071966 CET | 192.168.2.12 | 1.1.1.1 | 0x7b3b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.596116066 CET | 192.168.2.12 | 1.1.1.1 | 0xc3ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.854782104 CET | 192.168.2.12 | 1.1.1.1 | 0x436c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.080676079 CET | 192.168.2.12 | 1.1.1.1 | 0x6482 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.091844082 CET | 192.168.2.12 | 1.1.1.1 | 0x5067 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.133059978 CET | 192.168.2.12 | 1.1.1.1 | 0x8836 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.166635036 CET | 192.168.2.12 | 1.1.1.1 | 0x1a06 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.179464102 CET | 192.168.2.12 | 1.1.1.1 | 0x1080 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.190999985 CET | 192.168.2.12 | 1.1.1.1 | 0x312 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.226085901 CET | 192.168.2.12 | 1.1.1.1 | 0x9f35 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.239110947 CET | 192.168.2.12 | 1.1.1.1 | 0x6949 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.250960112 CET | 192.168.2.12 | 1.1.1.1 | 0x422 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.261773109 CET | 192.168.2.12 | 1.1.1.1 | 0x2a1f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.273907900 CET | 192.168.2.12 | 1.1.1.1 | 0x8d40 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.285676003 CET | 192.168.2.12 | 1.1.1.1 | 0xab2c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.317713976 CET | 192.168.2.12 | 1.1.1.1 | 0x363d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.328691006 CET | 192.168.2.12 | 1.1.1.1 | 0x565 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.338885069 CET | 192.168.2.12 | 1.1.1.1 | 0xae8b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.353317022 CET | 192.168.2.12 | 1.1.1.1 | 0x5f6c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.380511045 CET | 192.168.2.12 | 1.1.1.1 | 0x891d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.390388966 CET | 192.168.2.12 | 1.1.1.1 | 0x1f10 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.401166916 CET | 192.168.2.12 | 1.1.1.1 | 0x6d7a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.432663918 CET | 192.168.2.12 | 1.1.1.1 | 0xcff5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.465941906 CET | 192.168.2.12 | 1.1.1.1 | 0x9b23 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.478089094 CET | 192.168.2.12 | 1.1.1.1 | 0x66d7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.489490032 CET | 192.168.2.12 | 1.1.1.1 | 0xcbb2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.500036001 CET | 192.168.2.12 | 1.1.1.1 | 0x8aad | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.511238098 CET | 192.168.2.12 | 1.1.1.1 | 0xae72 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.520224094 CET | 192.168.2.12 | 1.1.1.1 | 0xb30 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.531517029 CET | 192.168.2.12 | 1.1.1.1 | 0x8fee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.564354897 CET | 192.168.2.12 | 1.1.1.1 | 0xbee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.738893032 CET | 192.168.2.12 | 1.1.1.1 | 0xd646 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.751023054 CET | 192.168.2.12 | 1.1.1.1 | 0x783 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.762669086 CET | 192.168.2.12 | 1.1.1.1 | 0xdbd9 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.921403885 CET | 192.168.2.12 | 1.1.1.1 | 0x84ec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.955495119 CET | 192.168.2.12 | 1.1.1.1 | 0x9229 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.966486931 CET | 192.168.2.12 | 1.1.1.1 | 0x23f7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.978571892 CET | 192.168.2.12 | 1.1.1.1 | 0x216b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.989830017 CET | 192.168.2.12 | 1.1.1.1 | 0x642a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.004937887 CET | 192.168.2.12 | 1.1.1.1 | 0x8aed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.906639099 CET | 192.168.2.12 | 1.1.1.1 | 0x507e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.916501999 CET | 192.168.2.12 | 1.1.1.1 | 0x6ccc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.927695036 CET | 192.168.2.12 | 1.1.1.1 | 0xbfca | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.939047098 CET | 192.168.2.12 | 1.1.1.1 | 0xb1cd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.950342894 CET | 192.168.2.12 | 1.1.1.1 | 0x5d0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.981360912 CET | 192.168.2.12 | 1.1.1.1 | 0x97 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.154129028 CET | 192.168.2.12 | 1.1.1.1 | 0xacd3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.165505886 CET | 192.168.2.12 | 1.1.1.1 | 0xd50c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.177978992 CET | 192.168.2.12 | 1.1.1.1 | 0x45b7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.193425894 CET | 192.168.2.12 | 1.1.1.1 | 0x39 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.227000952 CET | 192.168.2.12 | 1.1.1.1 | 0x9568 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.238771915 CET | 192.168.2.12 | 1.1.1.1 | 0x3b02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:58.035965919 CET | 192.168.2.12 | 1.1.1.1 | 0x839f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:53.549278021 CET | 192.168.2.12 | 1.1.1.1 | 0xa8c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:54.941850901 CET | 192.168.2.12 | 1.1.1.1 | 0xa923 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:55.958080053 CET | 192.168.2.12 | 1.1.1.1 | 0xde81 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:56.988593102 CET | 192.168.2.12 | 1.1.1.1 | 0x8011 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:58.004246950 CET | 192.168.2.12 | 1.1.1.1 | 0x3544 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:59.022233963 CET | 192.168.2.12 | 1.1.1.1 | 0x560c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:00.036933899 CET | 192.168.2.12 | 1.1.1.1 | 0x6beb | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:01.122180939 CET | 192.168.2.12 | 1.1.1.1 | 0xbf22 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:01.148332119 CET | 192.168.2.12 | 1.1.1.1 | 0xbf22 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:02.162286997 CET | 192.168.2.12 | 1.1.1.1 | 0x3599 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:02.190639973 CET | 192.168.2.12 | 1.1.1.1 | 0x3599 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:03.333918095 CET | 192.168.2.12 | 1.1.1.1 | 0x1a3d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:04.349649906 CET | 192.168.2.12 | 1.1.1.1 | 0x6f42 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:05.363652945 CET | 192.168.2.12 | 1.1.1.1 | 0x3af4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:05.393719912 CET | 192.168.2.12 | 1.1.1.1 | 0x3af4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:06.519807100 CET | 192.168.2.12 | 1.1.1.1 | 0x699b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:06.549989939 CET | 192.168.2.12 | 1.1.1.1 | 0x699b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:07.589507103 CET | 192.168.2.12 | 1.1.1.1 | 0x84f6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:10.321799040 CET | 192.168.2.12 | 1.1.1.1 | 0x12e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:11.349198103 CET | 192.168.2.12 | 1.1.1.1 | 0xe12a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:12.363647938 CET | 192.168.2.12 | 1.1.1.1 | 0x76de | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:13.382306099 CET | 192.168.2.12 | 1.1.1.1 | 0x504e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:13.409570932 CET | 192.168.2.12 | 1.1.1.1 | 0x504e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:17.019814014 CET | 192.168.2.12 | 1.1.1.1 | 0x3904 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:17.050282955 CET | 192.168.2.12 | 1.1.1.1 | 0x3904 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:18.097644091 CET | 192.168.2.12 | 1.1.1.1 | 0x9a0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:18.127909899 CET | 192.168.2.12 | 1.1.1.1 | 0x9a0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:19.144499063 CET | 192.168.2.12 | 1.1.1.1 | 0x89a2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:20.161726952 CET | 192.168.2.12 | 1.1.1.1 | 0xc02b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:21.175951004 CET | 192.168.2.12 | 1.1.1.1 | 0x6223 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:22.192511082 CET | 192.168.2.12 | 1.1.1.1 | 0xf5dc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:23.207057953 CET | 192.168.2.12 | 1.1.1.1 | 0xc414 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:23.237200975 CET | 192.168.2.12 | 1.1.1.1 | 0xc414 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:24.254065990 CET | 192.168.2.12 | 1.1.1.1 | 0xff2b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:25.269614935 CET | 192.168.2.12 | 1.1.1.1 | 0x27f6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:26.285334110 CET | 192.168.2.12 | 1.1.1.1 | 0x54ee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:27.300828934 CET | 192.168.2.12 | 1.1.1.1 | 0x5fc8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:27.331180096 CET | 192.168.2.12 | 1.1.1.1 | 0x5fc8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:28.347543955 CET | 192.168.2.12 | 1.1.1.1 | 0xc9e4 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:29.336440086 CET | 192.168.2.12 | 1.1.1.1 | 0xb364 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:30.285355091 CET | 192.168.2.12 | 1.1.1.1 | 0x65d7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:31.208456993 CET | 192.168.2.12 | 1.1.1.1 | 0x358d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 7, 2024 15:50:32.071244955 CET | 1.1.1.1 | 192.168.2.12 | 0x6fb1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.121053934 CET | 1.1.1.1 | 192.168.2.12 | 0x9f02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.202768087 CET | 1.1.1.1 | 192.168.2.12 | 0x1080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.242705107 CET | 1.1.1.1 | 192.168.2.12 | 0xf947 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.275132895 CET | 1.1.1.1 | 192.168.2.12 | 0x2035 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.288017988 CET | 1.1.1.1 | 192.168.2.12 | 0x725f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.300187111 CET | 1.1.1.1 | 192.168.2.12 | 0x9c63 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.335155964 CET | 1.1.1.1 | 192.168.2.12 | 0xddbc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.346949100 CET | 1.1.1.1 | 192.168.2.12 | 0x2a19 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.380029917 CET | 1.1.1.1 | 192.168.2.12 | 0x4b2c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.391304016 CET | 1.1.1.1 | 192.168.2.12 | 0xb2a6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.412921906 CET | 1.1.1.1 | 192.168.2.12 | 0x4c67 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.571103096 CET | 1.1.1.1 | 192.168.2.12 | 0x46b6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.583162069 CET | 1.1.1.1 | 192.168.2.12 | 0xc90e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:32.597249985 CET | 1.1.1.1 | 192.168.2.12 | 0x229b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.014821053 CET | 1.1.1.1 | 192.168.2.12 | 0xd7e6 | No error (0) | 7450.bodis.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:33.014821053 CET | 1.1.1.1 | 192.168.2.12 | 0xd7e6 | No error (0) | 199.59.243.227 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:33.859556913 CET | 1.1.1.1 | 192.168.2.12 | 0x10d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.872083902 CET | 1.1.1.1 | 192.168.2.12 | 0x556f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.904542923 CET | 1.1.1.1 | 192.168.2.12 | 0x8172 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:33.915256023 CET | 1.1.1.1 | 192.168.2.12 | 0xc596 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:34.107028008 CET | 1.1.1.1 | 192.168.2.12 | 0x2603 | No error (0) | 18.143.155.63 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:35.992850065 CET | 1.1.1.1 | 192.168.2.12 | 0x1983 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.004683971 CET | 1.1.1.1 | 192.168.2.12 | 0x3a90 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.018410921 CET | 1.1.1.1 | 192.168.2.12 | 0xf593 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.029875040 CET | 1.1.1.1 | 192.168.2.12 | 0x271 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.042032957 CET | 1.1.1.1 | 192.168.2.12 | 0x9f5e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.073939085 CET | 1.1.1.1 | 192.168.2.12 | 0x9f06 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.106527090 CET | 1.1.1.1 | 192.168.2.12 | 0x12d4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.118455887 CET | 1.1.1.1 | 192.168.2.12 | 0xee5d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.129980087 CET | 1.1.1.1 | 192.168.2.12 | 0x597f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.141983032 CET | 1.1.1.1 | 192.168.2.12 | 0xe1c2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.152947903 CET | 1.1.1.1 | 192.168.2.12 | 0x2967 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.185976028 CET | 1.1.1.1 | 192.168.2.12 | 0xaa70 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.195962906 CET | 1.1.1.1 | 192.168.2.12 | 0xe4ef | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.207361937 CET | 1.1.1.1 | 192.168.2.12 | 0xe62c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.375502110 CET | 1.1.1.1 | 192.168.2.12 | 0xc635 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.388797045 CET | 1.1.1.1 | 192.168.2.12 | 0xcd9e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.398511887 CET | 1.1.1.1 | 192.168.2.12 | 0xc6e5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.431021929 CET | 1.1.1.1 | 192.168.2.12 | 0x97c3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.596924067 CET | 1.1.1.1 | 192.168.2.12 | 0x60c3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.609118938 CET | 1.1.1.1 | 192.168.2.12 | 0x8bb5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.620577097 CET | 1.1.1.1 | 192.168.2.12 | 0x9494 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.652581930 CET | 1.1.1.1 | 192.168.2.12 | 0x3c4c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.663974047 CET | 1.1.1.1 | 192.168.2.12 | 0x17c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.674887896 CET | 1.1.1.1 | 192.168.2.12 | 0x9d86 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.694242954 CET | 1.1.1.1 | 192.168.2.12 | 0x96af | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.707346916 CET | 1.1.1.1 | 192.168.2.12 | 0xcc10 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.719021082 CET | 1.1.1.1 | 192.168.2.12 | 0x8504 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.751260996 CET | 1.1.1.1 | 192.168.2.12 | 0x593a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.763493061 CET | 1.1.1.1 | 192.168.2.12 | 0x3393 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.798727989 CET | 1.1.1.1 | 192.168.2.12 | 0xdf7e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.808063030 CET | 1.1.1.1 | 192.168.2.12 | 0x7c79 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.816996098 CET | 1.1.1.1 | 192.168.2.12 | 0xa0e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.825573921 CET | 1.1.1.1 | 192.168.2.12 | 0xa22 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.857584953 CET | 1.1.1.1 | 192.168.2.12 | 0xb0d5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.872421026 CET | 1.1.1.1 | 192.168.2.12 | 0x3a7d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.887038946 CET | 1.1.1.1 | 192.168.2.12 | 0xe738 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.898539066 CET | 1.1.1.1 | 192.168.2.12 | 0xf1c3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.909567118 CET | 1.1.1.1 | 192.168.2.12 | 0xdff1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.922736883 CET | 1.1.1.1 | 192.168.2.12 | 0x7828 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.936700106 CET | 1.1.1.1 | 192.168.2.12 | 0x852 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.950093031 CET | 1.1.1.1 | 192.168.2.12 | 0x9330 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.983128071 CET | 1.1.1.1 | 192.168.2.12 | 0xcb8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:36.994483948 CET | 1.1.1.1 | 192.168.2.12 | 0x1a70 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.006149054 CET | 1.1.1.1 | 192.168.2.12 | 0xa641 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.018970966 CET | 1.1.1.1 | 192.168.2.12 | 0x4f53 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.030833960 CET | 1.1.1.1 | 192.168.2.12 | 0xb4dc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.064296007 CET | 1.1.1.1 | 192.168.2.12 | 0xb927 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.075678110 CET | 1.1.1.1 | 192.168.2.12 | 0x6ac3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.091466904 CET | 1.1.1.1 | 192.168.2.12 | 0x951c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.104702950 CET | 1.1.1.1 | 192.168.2.12 | 0x3235 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.117088079 CET | 1.1.1.1 | 192.168.2.12 | 0xe52d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.128886938 CET | 1.1.1.1 | 192.168.2.12 | 0xf7e6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.147527933 CET | 1.1.1.1 | 192.168.2.12 | 0x324a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:37.438239098 CET | 1.1.1.1 | 192.168.2.12 | 0xbe1e | No error (0) | 54.244.188.177 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:38.482202053 CET | 1.1.1.1 | 192.168.2.12 | 0x9db6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.514782906 CET | 1.1.1.1 | 192.168.2.12 | 0x1bfb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.527385950 CET | 1.1.1.1 | 192.168.2.12 | 0x6ea6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.539263010 CET | 1.1.1.1 | 192.168.2.12 | 0x4495 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.573142052 CET | 1.1.1.1 | 192.168.2.12 | 0xa77 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.585866928 CET | 1.1.1.1 | 192.168.2.12 | 0xaed2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.596869946 CET | 1.1.1.1 | 192.168.2.12 | 0xb8f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.609096050 CET | 1.1.1.1 | 192.168.2.12 | 0x5eab | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.623939037 CET | 1.1.1.1 | 192.168.2.12 | 0xc77e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.658279896 CET | 1.1.1.1 | 192.168.2.12 | 0x5d04 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.692061901 CET | 1.1.1.1 | 192.168.2.12 | 0x42c7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.725785017 CET | 1.1.1.1 | 192.168.2.12 | 0x40c6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.760349989 CET | 1.1.1.1 | 192.168.2.12 | 0xa219 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.792762995 CET | 1.1.1.1 | 192.168.2.12 | 0x14ca | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.804871082 CET | 1.1.1.1 | 192.168.2.12 | 0x5c1e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.815332890 CET | 1.1.1.1 | 192.168.2.12 | 0x613e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.826771021 CET | 1.1.1.1 | 192.168.2.12 | 0x6012 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.858014107 CET | 1.1.1.1 | 192.168.2.12 | 0x5596 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.869194031 CET | 1.1.1.1 | 192.168.2.12 | 0x177a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.901793003 CET | 1.1.1.1 | 192.168.2.12 | 0x485c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.920753002 CET | 1.1.1.1 | 192.168.2.12 | 0x7f28 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.932405949 CET | 1.1.1.1 | 192.168.2.12 | 0x6785 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.943319082 CET | 1.1.1.1 | 192.168.2.12 | 0xde1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.976975918 CET | 1.1.1.1 | 192.168.2.12 | 0x813e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:38.989069939 CET | 1.1.1.1 | 192.168.2.12 | 0x6aaa | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:39.347677946 CET | 1.1.1.1 | 192.168.2.12 | 0x9b48 | No error (0) | 7450.bodis.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:39.347677946 CET | 1.1.1.1 | 192.168.2.12 | 0x9b48 | No error (0) | 199.59.243.227 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:40.099374056 CET | 1.1.1.1 | 192.168.2.12 | 0x5d9d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.150058031 CET | 1.1.1.1 | 192.168.2.12 | 0x3785 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.181050062 CET | 1.1.1.1 | 192.168.2.12 | 0x8cb0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.197092056 CET | 1.1.1.1 | 192.168.2.12 | 0x1ca2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.266252041 CET | 1.1.1.1 | 192.168.2.12 | 0xf7c1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.331813097 CET | 1.1.1.1 | 192.168.2.12 | 0x418b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.348149061 CET | 1.1.1.1 | 192.168.2.12 | 0xfd79 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.359796047 CET | 1.1.1.1 | 192.168.2.12 | 0x4959 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.373874903 CET | 1.1.1.1 | 192.168.2.12 | 0xe209 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.386442900 CET | 1.1.1.1 | 192.168.2.12 | 0x13ef | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:40.597685099 CET | 1.1.1.1 | 192.168.2.12 | 0xa28f | No error (0) | 18.143.155.63 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:42.479764938 CET | 1.1.1.1 | 192.168.2.12 | 0xec6f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.491219044 CET | 1.1.1.1 | 192.168.2.12 | 0x3dfc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.502408981 CET | 1.1.1.1 | 192.168.2.12 | 0x2328 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.511087894 CET | 1.1.1.1 | 192.168.2.12 | 0x9b53 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.522123098 CET | 1.1.1.1 | 192.168.2.12 | 0xa73c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.561728001 CET | 1.1.1.1 | 192.168.2.12 | 0xf742 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.594779968 CET | 1.1.1.1 | 192.168.2.12 | 0x7b3b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:42.759627104 CET | 1.1.1.1 | 192.168.2.12 | 0xc3ba | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.013878107 CET | 1.1.1.1 | 192.168.2.12 | 0x436c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.090728998 CET | 1.1.1.1 | 192.168.2.12 | 0x6482 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.122219086 CET | 1.1.1.1 | 192.168.2.12 | 0x5067 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.164113045 CET | 1.1.1.1 | 192.168.2.12 | 0x8836 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.177833080 CET | 1.1.1.1 | 192.168.2.12 | 0x1a06 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.189707994 CET | 1.1.1.1 | 192.168.2.12 | 0x1080 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.224935055 CET | 1.1.1.1 | 192.168.2.12 | 0x312 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.237549067 CET | 1.1.1.1 | 192.168.2.12 | 0x9f35 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.249094009 CET | 1.1.1.1 | 192.168.2.12 | 0x6949 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.260262012 CET | 1.1.1.1 | 192.168.2.12 | 0x422 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.272043943 CET | 1.1.1.1 | 192.168.2.12 | 0x2a1f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.284220934 CET | 1.1.1.1 | 192.168.2.12 | 0x8d40 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.316426039 CET | 1.1.1.1 | 192.168.2.12 | 0xab2c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.327120066 CET | 1.1.1.1 | 192.168.2.12 | 0x363d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.337754011 CET | 1.1.1.1 | 192.168.2.12 | 0x565 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.348467112 CET | 1.1.1.1 | 192.168.2.12 | 0xae8b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.363282919 CET | 1.1.1.1 | 192.168.2.12 | 0x5f6c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.389350891 CET | 1.1.1.1 | 192.168.2.12 | 0x891d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.400141954 CET | 1.1.1.1 | 192.168.2.12 | 0x1f10 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.431592941 CET | 1.1.1.1 | 192.168.2.12 | 0x6d7a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.464695930 CET | 1.1.1.1 | 192.168.2.12 | 0xcff5 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.476999998 CET | 1.1.1.1 | 192.168.2.12 | 0x9b23 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.488123894 CET | 1.1.1.1 | 192.168.2.12 | 0x66d7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.498915911 CET | 1.1.1.1 | 192.168.2.12 | 0xcbb2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.510081053 CET | 1.1.1.1 | 192.168.2.12 | 0x8aad | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.519056082 CET | 1.1.1.1 | 192.168.2.12 | 0xae72 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.530484915 CET | 1.1.1.1 | 192.168.2.12 | 0xb30 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.563083887 CET | 1.1.1.1 | 192.168.2.12 | 0x8fee | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.737529039 CET | 1.1.1.1 | 192.168.2.12 | 0xbee | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.749855995 CET | 1.1.1.1 | 192.168.2.12 | 0xd646 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.761660099 CET | 1.1.1.1 | 192.168.2.12 | 0x783 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.920042038 CET | 1.1.1.1 | 192.168.2.12 | 0xdbd9 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.953638077 CET | 1.1.1.1 | 192.168.2.12 | 0x84ec | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.965208054 CET | 1.1.1.1 | 192.168.2.12 | 0x9229 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.977418900 CET | 1.1.1.1 | 192.168.2.12 | 0x23f7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:43.988555908 CET | 1.1.1.1 | 192.168.2.12 | 0x216b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.003756046 CET | 1.1.1.1 | 192.168.2.12 | 0x642a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.020085096 CET | 1.1.1.1 | 192.168.2.12 | 0x8aed | No error (0) | 85.214.228.140 | A (IP address) | IN (0x0001) | false | ||
Nov 7, 2024 15:50:44.915266991 CET | 1.1.1.1 | 192.168.2.12 | 0x507e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.926552057 CET | 1.1.1.1 | 192.168.2.12 | 0x6ccc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.937752008 CET | 1.1.1.1 | 192.168.2.12 | 0xbfca | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.949186087 CET | 1.1.1.1 | 192.168.2.12 | 0xb1cd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:44.980081081 CET | 1.1.1.1 | 192.168.2.12 | 0x5d0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.143635035 CET | 1.1.1.1 | 192.168.2.12 | 0x97 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.164115906 CET | 1.1.1.1 | 192.168.2.12 | 0xacd3 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.176037073 CET | 1.1.1.1 | 192.168.2.12 | 0xd50c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.191411972 CET | 1.1.1.1 | 192.168.2.12 | 0x45b7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.225363970 CET | 1.1.1.1 | 192.168.2.12 | 0x39 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.236249924 CET | 1.1.1.1 | 192.168.2.12 | 0x9568 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:45.271048069 CET | 1.1.1.1 | 192.168.2.12 | 0x3b02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:50:58.046475887 CET | 1.1.1.1 | 192.168.2.12 | 0x839f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:53.935127974 CET | 1.1.1.1 | 192.168.2.12 | 0xa8c0 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:54.951539993 CET | 1.1.1.1 | 192.168.2.12 | 0xa923 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:55.968050957 CET | 1.1.1.1 | 192.168.2.12 | 0xde81 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:56.999291897 CET | 1.1.1.1 | 192.168.2.12 | 0x8011 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:58.014391899 CET | 1.1.1.1 | 192.168.2.12 | 0x3544 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:51:59.032080889 CET | 1.1.1.1 | 192.168.2.12 | 0x560c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:00.050940037 CET | 1.1.1.1 | 192.168.2.12 | 0x6beb | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:01.155534983 CET | 1.1.1.1 | 192.168.2.12 | 0xbf22 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:01.157527924 CET | 1.1.1.1 | 192.168.2.12 | 0xbf22 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:02.323637009 CET | 1.1.1.1 | 192.168.2.12 | 0x3599 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:02.323879004 CET | 1.1.1.1 | 192.168.2.12 | 0x3599 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:03.341836929 CET | 1.1.1.1 | 192.168.2.12 | 0x1a3d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:04.359714985 CET | 1.1.1.1 | 192.168.2.12 | 0x6f42 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:05.517164946 CET | 1.1.1.1 | 192.168.2.12 | 0x3af4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:05.517184973 CET | 1.1.1.1 | 192.168.2.12 | 0x3af4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:06.552776098 CET | 1.1.1.1 | 192.168.2.12 | 0x699b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:06.557041883 CET | 1.1.1.1 | 192.168.2.12 | 0x699b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:07.600938082 CET | 1.1.1.1 | 192.168.2.12 | 0x84f6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:10.333369017 CET | 1.1.1.1 | 192.168.2.12 | 0x12e8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:11.360363007 CET | 1.1.1.1 | 192.168.2.12 | 0xe12a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:12.377095938 CET | 1.1.1.1 | 192.168.2.12 | 0x76de | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:13.414598942 CET | 1.1.1.1 | 192.168.2.12 | 0x504e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:13.417268038 CET | 1.1.1.1 | 192.168.2.12 | 0x504e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:17.051208019 CET | 1.1.1.1 | 192.168.2.12 | 0x3904 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:17.057410002 CET | 1.1.1.1 | 192.168.2.12 | 0x3904 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:18.130179882 CET | 1.1.1.1 | 192.168.2.12 | 0x9a0e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:19.156049967 CET | 1.1.1.1 | 192.168.2.12 | 0x89a2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:20.173338890 CET | 1.1.1.1 | 192.168.2.12 | 0xc02b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:21.185372114 CET | 1.1.1.1 | 192.168.2.12 | 0x6223 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:22.202563047 CET | 1.1.1.1 | 192.168.2.12 | 0xf5dc | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:23.238806963 CET | 1.1.1.1 | 192.168.2.12 | 0xc414 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:23.244930029 CET | 1.1.1.1 | 192.168.2.12 | 0xc414 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:24.265342951 CET | 1.1.1.1 | 192.168.2.12 | 0xff2b | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:25.281001091 CET | 1.1.1.1 | 192.168.2.12 | 0x27f6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:26.295265913 CET | 1.1.1.1 | 192.168.2.12 | 0x54ee | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:27.332876921 CET | 1.1.1.1 | 192.168.2.12 | 0x5fc8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:27.338790894 CET | 1.1.1.1 | 192.168.2.12 | 0x5fc8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:28.357753038 CET | 1.1.1.1 | 192.168.2.12 | 0xc9e4 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:29.346055984 CET | 1.1.1.1 | 192.168.2.12 | 0xb364 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:30.295526981 CET | 1.1.1.1 | 192.168.2.12 | 0x65d7 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 7, 2024 15:52:31.218302965 CET | 1.1.1.1 | 192.168.2.12 | 0x358d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.12 | 49711 | 199.59.243.227 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:33.022269011 CET | 84 | OUT | |
Nov 7, 2024 15:50:33.846889973 CET | 1236 | IN | |
Nov 7, 2024 15:50:33.847028017 CET | 519 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.12 | 49712 | 18.143.155.63 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:34.113013029 CET | 83 | OUT | |
Nov 7, 2024 15:50:35.553335905 CET | 387 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.12 | 49713 | 54.244.188.177 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:37.470662117 CET | 84 | OUT | |
Nov 7, 2024 15:50:38.343558073 CET | 388 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.12 | 49714 | 199.59.243.227 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:39.353786945 CET | 82 | OUT | |
Nov 7, 2024 15:50:40.029390097 CET | 1236 | IN | |
Nov 7, 2024 15:50:40.029539108 CET | 515 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.12 | 49715 | 18.143.155.63 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:40.603492022 CET | 86 | OUT | |
Nov 7, 2024 15:50:42.053514004 CET | 390 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.12 | 49719 | 85.214.228.140 | 80 | 6988 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:50:44.027134895 CET | 85 | OUT | |
Nov 7, 2024 15:50:44.905226946 CET | 176 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.12 | 49728 | 199.59.243.227 | 80 | 4064 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:52:08.669750929 CET | 84 | OUT | |
Nov 7, 2024 15:52:09.305361032 CET | 1236 | IN | |
Nov 7, 2024 15:52:09.305672884 CET | 519 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.12 | 49729 | 18.143.155.63 | 80 | 4064 | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 7, 2024 15:52:14.546895981 CET | 83 | OUT | |
Nov 7, 2024 15:52:16.004764080 CET | 387 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:50:26 |
Start date: | 07/11/2024 |
Path: | C:\Users\user\Desktop\8CO4P3HwDt.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x8b0000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:50:27 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\uzqv383gxrrqx7oiosyki.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x340000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 09:50:27 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xda0000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 09:50:29 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\hrzceasx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x390000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 5 |
Start time: | 09:50:30 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xda0000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 09:51:48 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\usncdvbjyrwr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xda0000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 10 |
Start time: | 09:51:49 |
Start date: | 07/11/2024 |
Path: | C:\oblimpyrbviueg\hrzceasx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb60000 |
File size: | 362'496 bytes |
MD5 hash: | C3C8DF0D6043078ABDF157A68D37EB96 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 26.5% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 3.9% |
Total number of Nodes: | 905 |
Total number of Limit Nodes: | 16 |
Graph
Function 008DC35F Relevance: 273.3, APIs: 118, Strings: 35, Instructions: 5532libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008C15A0 Relevance: 33.1, APIs: 12, Strings: 6, Instructions: 1602fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E7710 Relevance: 4.7, APIs: 3, Instructions: 152memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E5570 Relevance: 3.0, APIs: 2, Instructions: 24memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008DD366 Relevance: 230.4, APIs: 98, Strings: 31, Instructions: 4600libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008DE0B9 Relevance: 185.8, APIs: 79, Strings: 25, Instructions: 3825libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008DE6F6 Relevance: 168.0, APIs: 71, Strings: 23, Instructions: 3471libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E0F4E Relevance: 41.3, APIs: 15, Strings: 8, Instructions: 1085libraryloadersynchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008C7230 Relevance: 11.0, APIs: 7, Instructions: 456fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008D6700 Relevance: 7.4, APIs: 3, Strings: 1, Instructions: 429fileCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008C3A80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 149processCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008BAC20 Relevance: 3.1, APIs: 2, Instructions: 53stringCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008D4770 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E9D80 Relevance: 1.6, APIs: 1, Instructions: 77COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008CAA20 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008EF820 Relevance: 24.2, APIs: 11, Strings: 2, Instructions: 1429networkCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008D2500 Relevance: 11.1, APIs: 5, Strings: 1, Instructions: 575serviceCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E68B0 Relevance: 3.1, APIs: 2, Instructions: 128timeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008CACF0 Relevance: 1.8, Strings: 1, Instructions: 541COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008BAD00 Relevance: 1.5, APIs: 1, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008CCCA0 Relevance: 12.5, APIs: 8, Instructions: 454registrysynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008C2FF0 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 284processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008D3078 Relevance: 7.8, APIs: 5, Instructions: 262COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E7990 Relevance: 7.6, APIs: 5, Instructions: 109synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008EB680 Relevance: 6.3, APIs: 4, Instructions: 284fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008E3BDF Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 246sleepthreadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 008EB5A0 Relevance: 5.0, APIs: 4, Instructions: 45memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 29.4% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 1.8% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 31 |
Graph
Function 00343770 Relevance: 25.8, APIs: 13, Strings: 1, Instructions: 1321memorylibraryloaderCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0036C35F Relevance: 273.3, APIs: 118, Strings: 35, Instructions: 5532libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0036D366 Relevance: 230.4, APIs: 98, Strings: 31, Instructions: 4600libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0036E0B9 Relevance: 185.8, APIs: 79, Strings: 25, Instructions: 3825libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0036E6F6 Relevance: 168.0, APIs: 71, Strings: 23, Instructions: 3471libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00370F4E Relevance: 41.3, APIs: 15, Strings: 8, Instructions: 1085libraryloadersynchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 003515A0 Relevance: 33.1, APIs: 12, Strings: 6, Instructions: 1602fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00366700 Relevance: 7.4, APIs: 3, Strings: 1, Instructions: 429fileCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00353A80 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 149processCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0037B680 Relevance: 6.3, APIs: 4, Instructions: 284fileCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0034AC20 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 53stringCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00377710 Relevance: 4.7, APIs: 3, Instructions: 152memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00364770 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00375570 Relevance: 3.0, APIs: 2, Instructions: 24memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0035B950 Relevance: 1.7, APIs: 1, Instructions: 214fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00379D80 Relevance: 1.6, APIs: 1, Instructions: 77COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0035AA20 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0034A780 Relevance: 10.8, APIs: 5, Strings: 1, Instructions: 294filesleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0035CCA0 Relevance: 12.5, APIs: 8, Instructions: 454registrysynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00357230 Relevance: 11.0, APIs: 7, Instructions: 456fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00352FF0 Relevance: 9.0, APIs: 4, Strings: 1, Instructions: 284processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00363078 Relevance: 7.8, APIs: 5, Instructions: 262COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00377990 Relevance: 7.6, APIs: 5, Instructions: 109synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00373BD9 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 249sleepthreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0037B5A0 Relevance: 5.0, APIs: 4, Instructions: 45memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 33.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 1186 |
Total number of Limit Nodes: | 24 |
Graph
Function 00DCE0B9 Relevance: 187.6, APIs: 79, Strings: 26, Instructions: 3825libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DDF820 Relevance: 25.9, APIs: 11, Strings: 3, Instructions: 1429networkCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DBCCA0 Relevance: 12.5, APIs: 8, Instructions: 454registrysynchronizationCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DAAC20 Relevance: 3.1, APIs: 2, Instructions: 53stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|