Windows
Analysis Report
VJoillkb6X.exe
Overview
General Information
Sample name: | VJoillkb6X.exerenamed because original name is a hash value |
Original sample name: | 8dbcecf4f09cdb10ef4f2ac2ac3f66a28d148a63a381877f413cd5f5b39db4e0.exe |
Analysis ID: | 1554437 |
MD5: | c9b68b9567cc9067794e32999c02bfa7 |
SHA1: | d999f0701086e1ecc87380cf002f37f985c6de4c |
SHA256: | 8dbcecf4f09cdb10ef4f2ac2ac3f66a28d148a63a381877f413cd5f5b39db4e0 |
Tags: | 4-251-123-83exeuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- VJoillkb6X.exe (PID: 4904 cmdline:
"C:\Users\ user\Deskt op\VJoillk b6X.exe" MD5: C9B68B9567CC9067794E32999C02BFA7)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
RedLine Stealer | RedLine Stealer is a malware available on underground forums for sale apparently as a standalone ($100/$150 depending on the version) or also on a subscription basis ($100/month). This malware harvests information from browsers such as saved credentials, autocomplete data, and credit card information. A system inventory is also taken when running on a target machine, to include details such as the username, location data, hardware configuration, and information regarding installed security software. More recent versions of RedLine added the ability to steal cryptocurrency. FTP and IM clients are also apparently targeted by this family, and this malware has the ability to upload and download files, execute commands, and periodically send back information about the infected computer. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
{"C2 url": "4.251.123.83:6677"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_RedLine_1 | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_RedLine | Yara detected RedLine Stealer | Joe Security | ||
MALWARE_Win_zgRAT | Detects zgRAT | ditekSHen |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-12T14:55:54.388224+0100 | 2046056 | 1 | A Network Trojan was detected | 4.251.123.83 | 6677 | 192.168.2.6 | 49711 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-12T14:55:53.903474+0100 | 2046045 | 1 | A Network Trojan was detected | 192.168.2.6 | 49711 | 4.251.123.83 | 6677 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | TCP traffic: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Large array initialization: |
Source: | Code function: | 0_2_00007FFD343816B3 | |
Source: | Code function: | 0_2_00007FFD3438C4CB | |
Source: | Code function: | 0_2_00007FFD344DA599 | |
Source: | Code function: | 0_2_00007FFD344DF865 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FFD342B5CBB | |
Source: | Code function: | 0_2_00007FFD34382005 | |
Source: | Code function: | 0_2_00007FFD3451756A |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 221 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Masquerading | 1 OS Credential Dumping | 321 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | 3 Data from Local System | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 241 Virtualization/Sandbox Evasion | Security Account Manager | 241 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | 1 Clipboard Data | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 113 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Timestomp | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
66% | ReversingLabs | ByteCode-MSIL.Ransomware.RedLine | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
fp2e7a.wpc.phicdn.net | 192.229.221.95 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
4.251.123.83 | unknown | United States | 3356 | LEVEL3US | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1554437 |
Start date and time: | 2024-11-12 14:54:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 2m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 2 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | VJoillkb6X.exerenamed because original name is a hash value |
Original Sample Name: | 8dbcecf4f09cdb10ef4f2ac2ac3f66a28d148a63a381877f413cd5f5b39db4e0.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@1/1@0/1 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe
- Excluded IPs from analysis (whitelisted): 172.202.163.200
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ocsp.edge.digicert.com, sls.update.microsoft.com, glb.sls.prod.dcat.dsp.trafficmanager.net
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: VJoillkb6X.exe
Time | Type | Description |
---|---|---|
08:55:54 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
4.251.123.83 | Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
fp2e7a.wpc.phicdn.net | Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| |
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
LEVEL3US | Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| |
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Meduza Stealer, PureLog Stealer, RedLine, zgRAT | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Process: | C:\Users\user\Desktop\VJoillkb6X.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2611 |
Entropy (8bit): | 5.363358188931451 |
Encrypted: | false |
SSDEEP: | 48:MxHKQ71qHGIs0HKCYHKGSI6oPtHTHhAHKKkafHKWA1eXrHKlT48BHK7HKmTHlHNW:iq+wmj0qCYqGSI6oPtzHeqKkGqhA7qZR |
MD5: | CEA017D10C4D437981D19F21660A47FA |
SHA1: | 61AAFCECB5325DE172857CEF7C7E1F230F73AFFD |
SHA-256: | 60B099420455DECD1878FE84F217CFE478BA0BA5E6E574077150D08355A1DD96 |
SHA-512: | 413384BF9D2EDC9BC2DF6D5175D09A33B91CCF9C53FE3CB21892CB57AF4FD8A9BE0608E9BCA57AF4A7F2709A4C110148719DA3210460DF433CFD77FA753B9CF8 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 6.572244662396641 |
TrID: |
|
File name: | VJoillkb6X.exe |
File size: | 346'112 bytes |
MD5: | c9b68b9567cc9067794e32999c02bfa7 |
SHA1: | d999f0701086e1ecc87380cf002f37f985c6de4c |
SHA256: | 8dbcecf4f09cdb10ef4f2ac2ac3f66a28d148a63a381877f413cd5f5b39db4e0 |
SHA512: | 9e24e7fab933fbd5ad500b0759582d3417ccd571c248010be486c53574f21e38a5d10dd2b14128cc4d4b4d922dc25806a14d46793b9e2ffe951b8c797f458c6a |
SSDEEP: | 6144:2DKXJVqDD/qxgATuaBNt1BrivR0V4TBjgYxs1wl206gBawFV2ceSb0BQ/GfM/4Qx:2DgYDzqxdXBNt1BrivR0V4TBjgYxs1wQ |
TLSH: | 3F744D2463825A19D8BEC63A8421D44897B8D61A4FC3E70DB8C865F27DE2353F1F6F16 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....................0.................. ........@.. ....................................@................................ |
Icon Hash: | 1707032b9b1b3117 |
Entrypoint: | 0x44d0ee |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0xE3FEC0F4 [Mon Mar 19 06:19:32 2091 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4d09c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4e000 | 0x908e | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x58000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x4b0f4 | 0x4b200 | 80dff83ad519262e116abc93bd794eb4 | False | 0.418020746672213 | data | 6.5286514424727455 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4e000 | 0x908e | 0x9200 | 2703d9d5ff8837633ec354c62ac8f2f3 | False | 0.540480522260274 | data | 6.103423039317328 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x58000 | 0xc | 0x200 | 3a13fecd19ca9773d82cc3855bc1b8eb | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x4e250 | 0x3172 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9999209985779745 | ||
RT_ICON | 0x513c4 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2688, resolution 11811 x 11811 px/m | 0.4064498933901919 | ||
RT_ICON | 0x5226c | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600, resolution 11811 x 11811 px/m | 0.2074688796680498 | ||
RT_ICON | 0x54814 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1152, resolution 11811 x 11811 px/m | 0.45803249097472926 | ||
RT_ICON | 0x550bc | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224, resolution 11811 x 11811 px/m | 0.2840056285178236 | ||
RT_ICON | 0x56164 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 320, resolution 11811 x 11811 px/m | 0.3930635838150289 | ||
RT_ICON | 0x566cc | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088, resolution 11811 x 11811 px/m | 0.4973404255319149 | ||
RT_GROUP_ICON | 0x56b34 | 0x68 | data | 0.6826923076923077 | ||
RT_VERSION | 0x56b9c | 0x308 | data | 0.45489690721649484 | ||
RT_MANIFEST | 0x56ea4 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-12T14:55:53.903474+0100 | 2046045 | ET MALWARE [ANY.RUN] RedLine Stealer/MetaStealer Family Related (MC-NMF Authorization) | 1 | 192.168.2.6 | 49711 | 4.251.123.83 | 6677 | TCP |
2024-11-12T14:55:54.388224+0100 | 2046056 | ET MALWARE Redline Stealer/MetaStealer Family Activity (Response) | 1 | 4.251.123.83 | 6677 | 192.168.2.6 | 49711 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 12, 2024 14:55:52.875335932 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:52.880642891 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:52.880907059 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:52.882863998 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:52.887710094 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:53.704209089 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:53.746113062 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:53.903474092 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:53.908411980 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.140927076 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.149236917 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.154205084 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388083935 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388124943 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388137102 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388206005 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.388223886 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388235092 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388246059 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388257027 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388273001 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388283968 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388290882 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.388294935 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388318062 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.388343096 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.388343096 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.388564110 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388653040 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.388722897 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.393346071 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.393424988 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.393544912 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.505289078 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505312920 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505325079 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505342007 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505353928 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505503893 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:54.505570889 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:54.505626917 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.457714081 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462562084 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462584972 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462595940 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462637901 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462649107 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462649107 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462685108 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462709904 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462718964 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462738037 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462757111 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462763071 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462770939 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462822914 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.462836027 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.462878942 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.467751980 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467772007 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467782021 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467806101 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.467828035 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467837095 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467840910 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.467847109 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467894077 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.467910051 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.467926025 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467964888 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.467993021 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.468025923 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.468029022 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.468070984 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.468071938 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.468122005 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.468204975 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.468259096 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.468270063 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.468314886 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.472820997 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.472904921 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.472942114 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.472969055 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.472978115 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473010063 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473035097 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.473048925 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473067999 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.473093987 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.473097086 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473105907 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473130941 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473140001 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473151922 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.473174095 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473206997 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473220110 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.473290920 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474585056 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474648952 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474720001 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474730015 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474762917 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474778891 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474791050 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474797010 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474831104 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474834919 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474841118 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474843979 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474862099 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474869967 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474879980 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.474890947 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.474926949 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.477770090 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477818012 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.477833986 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477843046 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477881908 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477885008 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.477890968 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477900982 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477910042 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477920055 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477936983 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.477938890 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477972984 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.477974892 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.477987051 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.478002071 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478010893 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478023052 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.478039980 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.478046894 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478085995 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478095055 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478144884 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478161097 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478171110 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478180885 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478189945 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478208065 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478216887 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478224993 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478235960 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478353024 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478363037 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478373051 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478382111 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478390932 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478394985 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478399038 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478401899 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478405952 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478410006 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478445053 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478455067 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478458881 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478468895 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478477955 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478487015 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478511095 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478516102 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478526115 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478529930 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478533983 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478535891 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478562117 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478571892 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478579998 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.478653908 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.478729963 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.479604006 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479614019 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479680061 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479741096 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479800940 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479810953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479826927 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479835987 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479923964 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479935884 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479948044 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479958057 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479974031 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.479981899 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480006933 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480015039 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480087996 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480096102 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480107069 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.480115891 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482683897 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482703924 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482712984 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482800961 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482810020 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482825041 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482834101 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482877016 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482886076 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482896090 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482935905 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482945919 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482954025 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482975960 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482984066 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.482991934 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483004093 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483062029 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483072996 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483098984 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483114958 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483149052 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483335018 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.483398914 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.483458042 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483509064 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483519077 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483537912 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483546972 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483568907 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483577967 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483588934 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483652115 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483660936 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483678102 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483686924 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483695030 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483711958 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483721972 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483755112 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483763933 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483794928 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483805895 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483848095 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483856916 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483866930 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483875990 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483891964 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483901024 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483907938 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483967066 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483975887 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.483992100 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484004021 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484011889 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484078884 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484088898 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484096050 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484114885 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484123945 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484131098 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484141111 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484252930 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484263897 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484277010 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484293938 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484302998 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484313965 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484385967 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484395027 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484404087 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484412909 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484424114 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484447002 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484469891 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484479904 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.484517097 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488264084 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488275051 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488306999 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488316059 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488325119 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488334894 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488363981 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488378048 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488387108 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488394976 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488410950 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488420010 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488435984 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488445044 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488460064 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.488466978 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488476038 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488502979 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488518000 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.488518953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488533974 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488543987 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488555908 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488590002 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488599062 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488606930 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488630056 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488639116 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488646030 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488661051 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488689899 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488698959 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488707066 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488723993 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488733053 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488742113 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488820076 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488828897 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488837957 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488899946 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488909960 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488919020 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488929033 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488979101 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488987923 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.488997936 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489063978 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489088058 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489129066 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489177942 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489187002 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489232063 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489242077 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489248991 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.489259005 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493397951 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493458033 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493469954 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493483067 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493551016 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493561983 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493585110 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493592024 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.493599892 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493613005 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493632078 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493643999 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493652105 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.493670940 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493720055 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493730068 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493740082 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493762016 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493771076 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493801117 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493809938 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493858099 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493866920 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493889093 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493897915 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493932962 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493942976 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493984938 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.493994951 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494039059 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494050980 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494164944 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494175911 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494199991 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494211912 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494230032 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494282007 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494292974 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494301081 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494312048 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494343996 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494353056 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494360924 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494375944 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494388103 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494398117 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494410038 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494452953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494467020 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494478941 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494488001 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494532108 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494540930 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494554043 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.494571924 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498442888 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498454094 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498464108 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498472929 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498507977 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498531103 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498539925 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498549938 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498605013 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498615026 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498615980 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.498672962 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498682976 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498683929 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.498692036 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498701096 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498709917 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498718977 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498743057 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498750925 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498760939 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498770952 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498797894 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498806953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498815060 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498828888 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498889923 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498903990 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498913050 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498922110 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498934984 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498944044 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498954058 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498979092 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498989105 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.498996973 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499039888 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499049902 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499058008 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499066114 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499075890 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499116898 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499125957 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499140978 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499150038 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499190092 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499200106 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499219894 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499229908 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499237061 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499255896 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499267101 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499274969 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499296904 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.499305964 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503642082 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503652096 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503689051 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503699064 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503712893 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503724098 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503731966 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503859043 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503870010 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503879070 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503890038 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.503922939 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503932953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503941059 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.503950119 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.503994942 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504004002 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504008055 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504012108 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504070044 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504080057 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504087925 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504098892 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504142046 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504151106 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504159927 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504199028 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504208088 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504218102 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504283905 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504292965 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504302025 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.504311085 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.550216913 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:57.550513983 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.550611019 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.550611019 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.550643921 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Nov 12, 2024 14:55:57.598068953 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:58.310973883 CET | 6677 | 49711 | 4.251.123.83 | 192.168.2.6 |
Nov 12, 2024 14:55:58.348325014 CET | 49711 | 6677 | 192.168.2.6 | 4.251.123.83 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 12, 2024 14:56:08.142393112 CET | 1.1.1.1 | 192.168.2.6 | 0x9d76 | No error (0) | fp2e7a.wpc.phicdn.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 12, 2024 14:56:08.142393112 CET | 1.1.1.1 | 192.168.2.6 | 0x9d76 | No error (0) | 192.229.221.95 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 08:55:50 |
Start date: | 12/11/2024 |
Path: | C:\Users\user\Desktop\VJoillkb6X.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x460000 |
File size: | 346'112 bytes |
MD5 hash: | C9B68B9567CC9067794E32999C02BFA7 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 18.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 9 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD343816B3 Relevance: 1.0, Instructions: 990COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B3299 Relevance: .3, Instructions: 317COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0F4F Relevance: .3, Instructions: 316COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0DF5 Relevance: .3, Instructions: 314COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B1EDE Relevance: .3, Instructions: 297COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD343822EB Relevance: .3, Instructions: 286COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2FF0 Relevance: .3, Instructions: 278COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B15AE Relevance: .3, Instructions: 262COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2E90 Relevance: .3, Instructions: 257COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3438D189 Relevance: .2, Instructions: 246COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B1F71 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B1E4F Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3438C331 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3438031D Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0A52 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B30D0 Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B334A Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B275A Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2CBD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD343804FD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD343806E0 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34382119 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0D01 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD343807CE Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B3775 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2EE0 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2FA8 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0850 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B21F9 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2F08 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0D99 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2D68 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B2D70 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD342B0873 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|