Windows
Analysis Report
I2BJhmJou4.exe
Overview
General Information
Sample name: | I2BJhmJou4.exerenamed because original name is a hash value |
Original sample name: | 16f4ab4f0ba6ebd746bcc6b032346ffb80f88814e78e103739af0e5569fee962.exe |
Analysis ID: | 1555044 |
MD5: | c847cb3090530ec9ae2e82805a03360d |
SHA1: | a7f075ba37961545ae0a819bda5d2be28618d60d |
SHA256: | 16f4ab4f0ba6ebd746bcc6b032346ffb80f88814e78e103739af0e5569fee962 |
Tags: | 94-158-244-69exeuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- I2BJhmJou4.exe (PID: 7500 cmdline:
"C:\Users\ user\Deskt op\I2BJhmJ ou4.exe" MD5: C847CB3090530EC9AE2E82805A03360D) - WerFault.exe (PID: 3712 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 7 500 -s 170 8 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- cleanup
{"C2 url": "http://94.158.244.69/c2sock", "Build Version": "LummaC2, Build 20233101"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer_1 | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_LummaCStealer_3 | Yara detected LummaC Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_RedLineStealer_ed346e4c | unknown | unknown |
| |
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-13T10:54:22.079039+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.8 | 49706 | TCP |
2024-11-13T10:54:59.967146+0100 | 2022930 | 1 | A Network Trojan was detected | 4.245.163.56 | 443 | 192.168.2.8 | 49711 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-13T10:53:30.089830+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49713 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:53:30.089830+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49708 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:54:34.362378+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49707 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:54:53.135143+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49709 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:02.213728+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49710 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:10.989197+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49712 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:29.613117+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49714 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:30.349548+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49715 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:48.326883+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49716 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:57.094150+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49717 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:06.203781+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49718 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:15.057549+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49719 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:23.838414+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49720 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:32.618908+0100 | 2043206 | 1 | A Network Trojan was detected | 192.168.2.8 | 49721 | 94.158.244.69 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-13T10:55:30.349548+0100 | 2843864 | 1 | A Network Trojan was detected | 192.168.2.8 | 49715 | 94.158.244.69 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 0_2_004052D9 |
Compliance |
---|
Source: | Unpacked PE file: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_00451F08 | |
Source: | Code function: | 0_2_00451FBC | |
Source: | Code function: | 0_2_02F22223 | |
Source: | Code function: | 0_2_02F2216F |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_0040B81C | |
Source: | Code function: | 0_2_00422177 | |
Source: | Code function: | 0_2_0040A928 | |
Source: | Code function: | 0_2_0040B129 | |
Source: | Code function: | 0_2_0042F1C2 | |
Source: | Code function: | 0_2_0041F9A4 | |
Source: | Code function: | 0_2_004244E4 | |
Source: | Code function: | 0_2_004224A3 | |
Source: | Code function: | 0_2_004245EC | |
Source: | Code function: | 0_2_00421EEB | |
Source: | Code function: | 0_2_0040B7BB | |
Source: | Code function: | 0_2_0040B7F5 |
Source: | Code function: | 0_2_0040B81C | |
Source: | Code function: | 0_2_0042C0DA | |
Source: | Code function: | 0_2_00434080 | |
Source: | Code function: | 0_2_0040E14E | |
Source: | Code function: | 0_2_0040A928 | |
Source: | Code function: | 0_2_0040B129 | |
Source: | Code function: | 0_2_0042B9C5 | |
Source: | Code function: | 0_2_004069A1 | |
Source: | Code function: | 0_2_0041F9A4 | |
Source: | Code function: | 0_2_0041C270 | |
Source: | Code function: | 0_2_0042F278 | |
Source: | Code function: | 0_2_0040620B | |
Source: | Code function: | 0_2_00430228 | |
Source: | Code function: | 0_2_004052D9 | |
Source: | Code function: | 0_2_00436ADC | |
Source: | Code function: | 0_2_00405AAA | |
Source: | Code function: | 0_2_0043B362 | |
Source: | Code function: | 0_2_00402476 | |
Source: | Code function: | 0_2_0042FD35 | |
Source: | Code function: | 0_2_0042AD82 | |
Source: | Code function: | 0_2_0042D658 | |
Source: | Code function: | 0_2_00430E6C | |
Source: | Code function: | 0_2_00438E28 | |
Source: | Code function: | 0_2_0042CFBA | |
Source: | Code function: | 0_2_0041204D | |
Source: | Code function: | 0_2_00441057 | |
Source: | Code function: | 0_2_00415070 | |
Source: | Code function: | 0_2_00448800 | |
Source: | Code function: | 0_2_0043D8D0 | |
Source: | Code function: | 0_2_0041E083 | |
Source: | Code function: | 0_2_0044915B | |
Source: | Code function: | 0_2_0045D15A | |
Source: | Code function: | 0_2_0041316D | |
Source: | Code function: | 0_2_0040112C | |
Source: | Code function: | 0_2_004279E0 | |
Source: | Code function: | 0_2_0041D1E9 | |
Source: | Code function: | 0_2_004109FC | |
Source: | Code function: | 0_2_0040D994 | |
Source: | Code function: | 0_2_0044F244 | |
Source: | Code function: | 0_2_0041AA49 | |
Source: | Code function: | 0_2_0041B251 | |
Source: | Code function: | 0_2_00429A5B | |
Source: | Code function: | 0_2_00410218 | |
Source: | Code function: | 0_2_00410A33 | |
Source: | Code function: | 0_2_00414A83 | |
Source: | Code function: | 0_2_0044234A | |
Source: | Code function: | 0_2_0040136E | |
Source: | Code function: | 0_2_00457B30 | |
Source: | Code function: | 0_2_00428334 | |
Source: | Code function: | 0_2_0041EBEB | |
Source: | Code function: | 0_2_00415C7E | |
Source: | Code function: | 0_2_00418413 | |
Source: | Code function: | 0_2_0043A4FE | |
Source: | Code function: | 0_2_00424C8D | |
Source: | Code function: | 0_2_0043BCA4 | |
Source: | Code function: | 0_2_00416548 | |
Source: | Code function: | 0_2_00439535 | |
Source: | Code function: | 0_2_0041764A | |
Source: | Code function: | 0_2_0043D600 | |
Source: | Code function: | 0_2_004126B9 | |
Source: | Code function: | 0_2_00429730 | |
Source: | Code function: | 0_2_00434FAC | |
Source: | Code function: | 0_2_02EEE2EA | |
Source: | Code function: | 0_2_02F042E7 | |
Source: | Code function: | 0_2_02EF9ADA | |
Source: | Code function: | 0_2_02EE52D7 | |
Source: | Code function: | 0_2_02F112BE | |
Source: | Code function: | 0_2_02EE22B4 | |
Source: | Code function: | 0_2_02EDBA83 | |
Source: | Code function: | 0_2_02F18A67 | |
Source: | Code function: | 0_2_02EFD221 | |
Source: | Code function: | 0_2_02F05213 | |
Source: | Code function: | 0_2_02F003F5 | |
Source: | Code function: | 0_2_02EDDBFB | |
Source: | Code function: | 0_2_02F2D3C1 | |
Source: | Code function: | 0_2_02F193C2 | |
Source: | Code function: | 0_2_02EE33D4 | |
Source: | Code function: | 0_2_02EDE3B5 | |
Source: | Code function: | 0_2_02EDAB8F | |
Source: | Code function: | 0_2_02EDB390 | |
Source: | Code function: | 0_2_02EFC341 | |
Source: | Code function: | 0_2_02F0DB37 | |
Source: | Code function: | 0_2_02F010D3 | |
Source: | Code function: | 0_2_02EFD8BF | |
Source: | Code function: | 0_2_02EE78B1 | |
Source: | Code function: | 0_2_02F0908F | |
Source: | Code function: | 0_2_02F0D867 | |
Source: | Code function: | 0_2_02EF9997 | |
Source: | Code function: | 0_2_02EE2920 | |
Source: | Code function: | 0_2_02EE5EE5 | |
Source: | Code function: | 0_2_02EF9EE2 | |
Source: | Code function: | 0_2_02EF4EF4 | |
Source: | Code function: | 0_2_02ED26DD | |
Source: | Code function: | 0_2_02EE867A | |
Source: | Code function: | 0_2_02EEEE52 | |
Source: | Code function: | 0_2_02EFAFE9 | |
Source: | Code function: | 0_2_02EE67AF | |
Source: | Code function: | 0_2_02F0979C | |
Source: | Code function: | 0_2_02F0A765 | |
Source: | Code function: | 0_2_02F0BF0B | |
Source: | Code function: | 0_2_02EF9CC2 | |
Source: | Code function: | 0_2_02EFF4DF | |
Source: | Code function: | 0_2_02EEC4D7 | |
Source: | Code function: | 0_2_02EEB4B8 | |
Source: | Code function: | 0_2_02F1F4AB | |
Source: | Code function: | 0_2_02EEACB0 | |
Source: | Code function: | 0_2_02F0048F | |
Source: | Code function: | 0_2_02EE047F | |
Source: | Code function: | 0_2_02ED6472 | |
Source: | Code function: | 0_2_02EF7C47 | |
Source: | Code function: | 0_2_02EED450 | |
Source: | Code function: | 0_2_02EFBC2C | |
Source: | Code function: | 0_2_02ED6C08 | |
Source: | Code function: | 0_2_02EEFC0B | |
Source: | Code function: | 0_2_02F0B5C9 | |
Source: | Code function: | 0_2_02EFA5D4 | |
Source: | Code function: | 0_2_02F125B1 | |
Source: | Code function: | 0_2_02EF859B | |
Source: | Code function: | 0_2_02ED5540 | |
Source: | Code function: | 0_2_02F06D43 | |
Source: | Code function: | 0_2_02ED5D11 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_02F69F2E |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | System information queried: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | Unpacked PE file: |
Source: | Code function: | 0_2_00464079 | |
Source: | Code function: | 0_2_00463CB6 | |
Source: | Code function: | 0_2_00403D71 | |
Source: | Code function: | 0_2_0045277B | |
Source: | Code function: | 0_2_02F229E2 | |
Source: | Code function: | 0_2_02ED3FD8 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Code function: | 0_2_00401FF9 | |
Source: | Code function: | 0_2_00401FF9 | |
Source: | Code function: | 0_2_02ED2260 |
Source: | Evasive API call chain: | graph_0-74297 | ||
Source: | Evasive API call chain: | graph_0-74297 |
Source: | System information queried: | Jump to behavior |
Source: | Code function: | 0_2_00429EF7 |
Source: | Code function: | 0_2_0041F9A4 |
Source: | Evasive API call chain: | graph_0-74312 |
Source: | Code function: | 0_2_00451F08 | |
Source: | Code function: | 0_2_00451FBC | |
Source: | Code function: | 0_2_02F22223 | |
Source: | Code function: | 0_2_02F2216F |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-74210 |
Anti Debugging |
---|
Source: | Code function: | 0_2_004244E4 |
Source: | Debugger detection routine: | graph_0-74296 |
Source: | Thread information set: | Jump to behavior |
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_00429EF7 |
Source: | Code function: | 0_2_0044E33B |
Source: | Code function: | 0_2_0041F9A4 |
Source: | Code function: | 0_2_00422177 | |
Source: | Code function: | 0_2_00443998 | |
Source: | Code function: | 0_2_0041F9A4 | |
Source: | Code function: | 0_2_004262A1 | |
Source: | Code function: | 0_2_0043B362 | |
Source: | Code function: | 0_2_0044FB15 | |
Source: | Code function: | 0_2_004244E4 | |
Source: | Code function: | 0_2_004224A3 | |
Source: | Code function: | 0_2_004245EC | |
Source: | Code function: | 0_2_00421EEB | |
Source: | Code function: | 0_2_00422817 | |
Source: | Code function: | 0_2_0041F916 | |
Source: | Code function: | 0_2_004269E4 | |
Source: | Code function: | 0_2_00424995 | |
Source: | Code function: | 0_2_00424995 | |
Source: | Code function: | 0_2_00426A42 | |
Source: | Code function: | 0_2_0042F265 | |
Source: | Code function: | 0_2_00424B24 | |
Source: | Code function: | 0_2_0041EBEB | |
Source: | Code function: | 0_2_00424BED | |
Source: | Code function: | 0_2_00424C8D | |
Source: | Code function: | 0_2_0041E6F0 | |
Source: | Code function: | 0_2_00429EF7 | |
Source: | Code function: | 0_2_02EF2A7E | |
Source: | Code function: | 0_2_02F13BFF | |
Source: | Code function: | 0_2_02EF4BFC | |
Source: | Code function: | 0_2_02EF4BFC | |
Source: | Code function: | 0_2_02EF23DE | |
Source: | Code function: | 0_2_02EEFB7D | |
Source: | Code function: | 0_2_02EF4853 | |
Source: | Code function: | 0_2_02EFA15E | |
Source: | Code function: | 0_2_02EEE957 | |
Source: | Code function: | 0_2_02EF2152 | |
Source: | Code function: | 0_2_02ED092B | |
Source: | Code function: | 0_2_02EF4EF4 | |
Source: | Code function: | 0_2_02EF4E54 | |
Source: | Code function: | 0_2_02EEEE52 | |
Source: | Code function: | 0_2_02EF474B | |
Source: | Code function: | 0_2_02EF270A | |
Source: | Code function: | 0_2_02EFF4CC | |
Source: | Code function: | 0_2_02EF6CA9 | |
Source: | Code function: | 0_2_02EF6C4B | |
Source: | Code function: | 0_2_02EEFC0B | |
Source: | Code function: | 0_2_02F0B5C9 | |
Source: | Code function: | 0_2_02EF4D8B | |
Source: | Code function: | 0_2_02ED0D90 | |
Source: | Code function: | 0_2_02F1FD7C | |
Source: | Code function: | 0_2_02EF6508 | |
Source: | Code function: | 0_2_02F6980B |
Source: | Code function: | 0_2_0043323B |
Source: | Code function: | 0_2_0044E33B | |
Source: | Code function: | 0_2_0043D3A0 | |
Source: | Code function: | 0_2_0043CE89 | |
Source: | Code function: | 0_2_0043CE95 | |
Source: | Code function: | 0_2_02F0D0F0 | |
Source: | Code function: | 0_2_02F0D0FC | |
Source: | Code function: | 0_2_02F0D607 | |
Source: | Code function: | 0_2_02F1E5A2 |
Source: | Code function: | 0_2_0043D0B8 |
Source: | Code function: | 0_2_0044614F |
Source: | Code function: | 0_2_00402476 |
Source: | Code function: | 0_2_00453BC4 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior |
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Native API | 1 LSASS Driver | 1 Process Injection | 32 Virtualization/Sandbox Evasion | 1 OS Credential Dumping | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 1 LSASS Driver | 1 Process Injection | LSASS Memory | 471 Security Software Discovery | Remote Desktop Protocol | 31 Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | Security Account Manager | 32 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 2 Obfuscated Files or Information | NTDS | 2 Process Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Software Packing | LSA Secrets | 1 Account Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 1 System Owner/User Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 11 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 13 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
84% | ReversingLabs | Win32.Trojan.Smokeloader | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
94.158.244.69 | unknown | Moldova Republic of | 39798 | MIVOCLOUDMD | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1555044 |
Start date and time: | 2024-11-13 10:52:40 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | I2BJhmJou4.exerenamed because original name is a hash value |
Original Sample Name: | 16f4ab4f0ba6ebd746bcc6b032346ffb80f88814e78e103739af0e5569fee962.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@2/5@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 20.42.65.92
- Excluded domains from analysis (whitelisted): onedsblobprdeus17.eastus.cloudapp.azure.com, slscr.update.microsoft.com, login.live.com, blobcollector.events.data.trafficmanager.net, umwatson.events.data.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: I2BJhmJou4.exe
Time | Type | Description |
---|---|---|
04:56:38 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
94.158.244.69 | Get hash | malicious | LummaC Stealer | Browse |
| |
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MIVOCLOUDMD | Get hash | malicious | LummaC Stealer | Browse |
| |
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_I2BJhmJou4.exe_7abd4b2ffccb829face88ca1d1d9f1e903b9_37ce086c_ac1319ab-d779-4ed1-ae4c-b7b64b7db42d\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.8423482439830231 |
Encrypted: | false |
SSDEEP: | 96:HEyYA3haHCslA4hclAS7Zf2QXIDcQqc6acEVcw3ZOeOO+HbHg/PB6HeaOy1EoqzV:kyYfCMYb0UevojGdzuiF8Z24IO8QLC |
MD5: | 7E20C02C760B970A272638D3132B1F18 |
SHA1: | DC4E32AD39F5DE08EA777235407803FBE3299D54 |
SHA-256: | C4DEC0AD2909B6C6D565324ED07123129CBBE832F68AE3D1D3EDFD813DFD603A |
SHA-512: | 74156CEE6DF706CCE73A40480F0D2C8FDF06E3D8B90B3847B3EAD7EACD38BC39F6D04592AF9108FF9754F4DC847ACE58BE498A61888C81633572E4AAB878446B |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41968 |
Entropy (8bit): | 2.4935738305279456 |
Encrypted: | false |
SSDEEP: | 192:fyQX3wNBFlgOSbfHJnfoFlD67/BbT+h/ar3HPLx4Nqn:LwTFpSbfHFgDuBi/aLvLwa |
MD5: | 8B78AC2ED0F69C319E060BADFE213524 |
SHA1: | 601739C05ABC194E87C7460788438799CBF52279 |
SHA-256: | FF8E4F672902C473E4280A314A6DF5D5E5B6F4E49ECDD95DFC54BE1BCDB1F486 |
SHA-512: | 24AD49F347FB655AFE6B623D8B91878472F8F9559300CD58EBE5208F155219CD6C70D7839F379E515E5F33CD54915F4C7595F22C86C3C7B5ED723FE0FEDDFEDB |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8336 |
Entropy (8bit): | 3.7024715539745583 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJRI6aY26YSqSUdgmfdYpDy89bvEsf0FFm:R6lXJ+6ah6YvSUdgmfdev3fT |
MD5: | 5A0CF5FBCD8F402C4DF17AED5075F114 |
SHA1: | 1E6FDE590E3DFB54753CF31FE1D5432D231D3B54 |
SHA-256: | A3E1E476F62630AA35B84FAD76C8DEF4C2B9835377FF249287B5726481AC308C |
SHA-512: | 79DC2E4BA0B79F7673F747D0A4FAC5818DB53521C871D2A17C09AB57CFE0F521724C16AD6FD3CC7FB461045BFED6FF679E39ED3A8C4F48EC62D7D3771A4AC760 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4579 |
Entropy (8bit): | 4.473223919125026 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsSJg77aI9nMWpW8VYuYm8M4J9tFwjV+q8+BScqId:uIjfgI7xl7VGJSVxzqId |
MD5: | A9DE4FB8DFEFBECA1EDB7075BAAB6942 |
SHA1: | E9492D8EC00AA32349719DDA47300D3126FCC182 |
SHA-256: | 254298481A1AA0446D17019EB4A7D0F48209075DC955F7C6BAC550AA0983EE6B |
SHA-512: | 0746F6A96935320BE3AE6038EC8892C628DC74F4CC5A0EDAFDB7922021FB40AE2BEFCBB3CC292CFDA00CAD88AFDA0EBD91E7B9ACD863BA52F5153C200E9BB9B1 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.372088739129614 |
Encrypted: | false |
SSDEEP: | 6144:sFVfpi6ceLP/9skLmb0ayWWSPtaJG8nAge35OlMMhA2AX4WABlguN2iL5:cV1QyWWI/glMM6kF7Uq |
MD5: | B83EF58CD4FEE920D622AC23A56F77CB |
SHA1: | 19A8F49E9246F62FEC7BAEB73CCE1E249139E9C9 |
SHA-256: | EA9E5BBC0B046BCF8D75AD6F787A7F901114BB10DDCB6E663A9A97085515546B |
SHA-512: | 1FB5AF3352DF4A009AE92C7839AA8E41D861C386B572F718255C9654A00C735AC3C1B7F4BE99BA437A1C9AD2F4BF12F554B62D2FD573F30A570B940361E011F2 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 7.161752093231944 |
TrID: |
|
File name: | I2BJhmJou4.exe |
File size: | 474'624 bytes |
MD5: | c847cb3090530ec9ae2e82805a03360d |
SHA1: | a7f075ba37961545ae0a819bda5d2be28618d60d |
SHA256: | 16f4ab4f0ba6ebd746bcc6b032346ffb80f88814e78e103739af0e5569fee962 |
SHA512: | d8640e1ef34c4679215d515ef9594c39a9db51a672897489926a6a2b60cb2376beb0634808c11b72104a02c26c1cacd9dc9d98c78862b2411f3cc4bbe72ea32c |
SSDEEP: | 12288:YALM9byCGBIH114+JbdWBOCGDInCDuz3gTR9:YAebZG2H11NJb4G0nBOR |
TLSH: | 2CA49D4353A1BD59EB254B729E1EC6F8361DF9518F093B7A720C6E2F06B0872C1A7711 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........y...............n.......n<......n=......`...............n9......n.......n......Rich............PE..L...+..a................... |
Icon Hash: | 4a183e435119984a |
Entrypoint: | 0x405c58 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x61B51A2B [Sat Dec 11 21:37:47 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | f1a2f8d8b54600da323a01db4f49195d |
Instruction |
---|
call 00007FD5A1155F57h |
jmp 00007FD5A11523AEh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 20h |
mov eax, dword ptr [ebp+08h] |
push esi |
push edi |
push 00000008h |
pop ecx |
mov esi, 00401294h |
lea edi, dword ptr [ebp-20h] |
rep movsd |
mov dword ptr [ebp-08h], eax |
mov eax, dword ptr [ebp+0Ch] |
pop edi |
mov dword ptr [ebp-04h], eax |
pop esi |
test eax, eax |
je 00007FD5A115252Eh |
test byte ptr [eax], 00000008h |
je 00007FD5A1152529h |
mov dword ptr [ebp-0Ch], 01994000h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
push dword ptr [ebp-10h] |
push dword ptr [ebp-1Ch] |
push dword ptr [ebp-20h] |
call dword ptr [004010FCh] |
leave |
retn 0008h |
mov edi, edi |
push ebp |
mov ebp, esp |
mov edx, dword ptr [ebp+08h] |
push esi |
push edi |
test edx, edx |
je 00007FD5A1152529h |
mov edi, dword ptr [ebp+0Ch] |
test edi, edi |
jne 00007FD5A1152535h |
call 00007FD5A115274Dh |
push 00000016h |
pop esi |
mov dword ptr [eax], esi |
call 00007FD5A1153560h |
mov eax, esi |
jmp 00007FD5A1152555h |
mov eax, dword ptr [ebp+10h] |
test eax, eax |
jne 00007FD5A1152526h |
mov byte ptr [edx], al |
jmp 00007FD5A1152504h |
mov esi, edx |
sub esi, eax |
mov cl, byte ptr [eax] |
mov byte ptr [esi+eax], cl |
inc eax |
test cl, cl |
je 00007FD5A1152525h |
dec edi |
jne 00007FD5A1152515h |
test edi, edi |
jne 00007FD5A1152533h |
mov byte ptr [edx], 00000000h |
call 00007FD5A1152717h |
push 00000022h |
pop ecx |
mov dword ptr [eax], ecx |
mov esi, ecx |
jmp 00007FD5A11524E8h |
xor eax, eax |
pop edi |
pop esi |
pop ebp |
ret |
int3 |
int3 |
int3 |
mov ecx, dword ptr [esp+04h] |
test ecx, 00000003h |
je 00007FD5A1152546h |
mov al, byte ptr [ecx] |
add ecx, 00000000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1233c | 0x3c | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x28fe000 | 0x1bc18 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x3998 | 0x40 | .text |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x1000 | 0x1c0 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x11da0 | 0x11e00 | b76206d2d320499f3ff13cf1c189d29e | False | 0.5574874344405595 | data | 6.463633330803623 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x13000 | 0x28ead04 | 0x45e00 | 4822dc0d5f14f6436350a2de158cfe65 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x28fe000 | 0x1bc18 | 0x1be00 | 07946ee195931bcc383a16c4df6a010e | False | 0.3036627662556054 | data | 3.8590886530682353 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0x2917050 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.7598684210526315 | ||
RT_CURSOR | 0x2917198 | 0x130 | Device independent bitmap graphic, 32 x 64 x 1, image size 0 | 0.4473684210526316 | ||
RT_CURSOR | 0x29172c8 | 0xf0 | Device independent bitmap graphic, 24 x 48 x 1, image size 0 | 0.4625 | ||
RT_CURSOR | 0x29173b8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | 0.08583489681050657 | ||
RT_CURSOR | 0x2918490 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | 0.3407039711191336 | ||
RT_ICON | 0x28fea80 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.3986175115207373 |
RT_ICON | 0x28fea80 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.3986175115207373 |
RT_ICON | 0x28ff148 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.3908959537572254 |
RT_ICON | 0x28ff148 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.3908959537572254 |
RT_ICON | 0x28ff6b0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.27790806754221387 |
RT_ICON | 0x28ff6b0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.27790806754221387 |
RT_ICON | 0x2900758 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.3421985815602837 |
RT_ICON | 0x2900758 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.3421985815602837 |
RT_ICON | 0x2900c00 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | India | 0.39981949458483756 |
RT_ICON | 0x2900c00 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Tamil | Sri Lanka | 0.39981949458483756 |
RT_ICON | 0x29014a8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.4498847926267281 |
RT_ICON | 0x29014a8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.4498847926267281 |
RT_ICON | 0x2901b70 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.4226878612716763 |
RT_ICON | 0x2901b70 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.4226878612716763 |
RT_ICON | 0x29020d8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.2767354596622889 |
RT_ICON | 0x29020d8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.2767354596622889 |
RT_ICON | 0x2903180 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.28114754098360656 |
RT_ICON | 0x2903180 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.28114754098360656 |
RT_ICON | 0x2903b08 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.3191489361702128 |
RT_ICON | 0x2903b08 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.3191489361702128 |
RT_ICON | 0x2903fd0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | India | 0.3715351812366738 |
RT_ICON | 0x2903fd0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | Sri Lanka | 0.3715351812366738 |
RT_ICON | 0x2904e78 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | India | 0.48104693140794225 |
RT_ICON | 0x2904e78 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | Sri Lanka | 0.48104693140794225 |
RT_ICON | 0x2905720 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | India | 0.5247695852534562 |
RT_ICON | 0x2905720 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | Sri Lanka | 0.5247695852534562 |
RT_ICON | 0x2905de8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | India | 0.5513005780346821 |
RT_ICON | 0x2905de8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | Sri Lanka | 0.5513005780346821 |
RT_ICON | 0x2906350 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | India | 0.20342323651452282 |
RT_ICON | 0x2906350 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | Sri Lanka | 0.20342323651452282 |
RT_ICON | 0x29088f8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | India | 0.2347560975609756 |
RT_ICON | 0x29088f8 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | Sri Lanka | 0.2347560975609756 |
RT_ICON | 0x29099a0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | India | 0.25163934426229506 |
RT_ICON | 0x29099a0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | Sri Lanka | 0.25163934426229506 |
RT_ICON | 0x290a328 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | India | 0.3067375886524823 |
RT_ICON | 0x290a328 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | Sri Lanka | 0.3067375886524823 |
RT_ICON | 0x290a808 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | India | 0.28251599147121537 |
RT_ICON | 0x290a808 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Tamil | Sri Lanka | 0.28251599147121537 |
RT_ICON | 0x290b6b0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | India | 0.3934331797235023 |
RT_ICON | 0x290b6b0 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Tamil | Sri Lanka | 0.3934331797235023 |
RT_ICON | 0x290bd78 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | India | 0.39739884393063585 |
RT_ICON | 0x290bd78 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Tamil | Sri Lanka | 0.39739884393063585 |
RT_ICON | 0x290c2e0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | India | 0.2233402489626556 |
RT_ICON | 0x290c2e0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Tamil | Sri Lanka | 0.2233402489626556 |
RT_ICON | 0x290e888 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | India | 0.2795497185741088 |
RT_ICON | 0x290e888 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Tamil | Sri Lanka | 0.2795497185741088 |
RT_ICON | 0x290f930 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | India | 0.3016393442622951 |
RT_ICON | 0x290f930 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Tamil | Sri Lanka | 0.3016393442622951 |
RT_ICON | 0x29102b8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | India | 0.3395390070921986 |
RT_ICON | 0x29102b8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Tamil | Sri Lanka | 0.3395390070921986 |
RT_ICON | 0x2910788 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | India | 0.31369936034115137 |
RT_ICON | 0x2910788 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Tamil | Sri Lanka | 0.31369936034115137 |
RT_ICON | 0x2911630 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | India | 0.3813176895306859 |
RT_ICON | 0x2911630 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Tamil | Sri Lanka | 0.3813176895306859 |
RT_ICON | 0x2911ed8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | India | 0.42223502304147464 |
RT_ICON | 0x2911ed8 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Tamil | Sri Lanka | 0.42223502304147464 |
RT_ICON | 0x29125a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | India | 0.3872832369942196 |
RT_ICON | 0x29125a0 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Tamil | Sri Lanka | 0.3872832369942196 |
RT_ICON | 0x2912b08 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | India | 0.23921161825726142 |
RT_ICON | 0x2912b08 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | Tamil | Sri Lanka | 0.23921161825726142 |
RT_ICON | 0x29150b0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | India | 0.2774390243902439 |
RT_ICON | 0x29150b0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | Tamil | Sri Lanka | 0.2774390243902439 |
RT_ICON | 0x2916158 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | India | 0.27991803278688526 |
RT_ICON | 0x2916158 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2400 | Tamil | Sri Lanka | 0.27991803278688526 |
RT_ICON | 0x2916ae0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | India | 0.32269503546099293 |
RT_ICON | 0x2916ae0 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | Tamil | Sri Lanka | 0.32269503546099293 |
RT_STRING | 0x2918f78 | 0x502 | data | Tamil | India | 0.4391575663026521 |
RT_STRING | 0x2918f78 | 0x502 | data | Tamil | Sri Lanka | 0.4391575663026521 |
RT_STRING | 0x2919480 | 0x394 | data | Tamil | India | 0.4606986899563319 |
RT_STRING | 0x2919480 | 0x394 | data | Tamil | Sri Lanka | 0.4606986899563319 |
RT_STRING | 0x2919818 | 0x396 | Matlab v4 mat-file (little endian) o, numeric, rows 0, columns 0 | Tamil | India | 0.46187363834422657 |
RT_STRING | 0x2919818 | 0x396 | Matlab v4 mat-file (little endian) o, numeric, rows 0, columns 0 | Tamil | Sri Lanka | 0.46187363834422657 |
RT_STRING | 0x2919bb0 | 0x64 | data | Tamil | India | 0.65 |
RT_STRING | 0x2919bb0 | 0x64 | data | Tamil | Sri Lanka | 0.65 |
RT_ACCELERATOR | 0x2916fc0 | 0x90 | data | Tamil | India | 0.6944444444444444 |
RT_ACCELERATOR | 0x2916fc0 | 0x90 | data | Tamil | Sri Lanka | 0.6944444444444444 |
RT_GROUP_CURSOR | 0x2917180 | 0x14 | data | 1.15 | ||
RT_GROUP_CURSOR | 0x2918d38 | 0x14 | data | 1.25 | ||
RT_GROUP_CURSOR | 0x2918460 | 0x30 | data | 1.0 | ||
RT_GROUP_ICON | 0x290a790 | 0x76 | data | Tamil | India | 0.6779661016949152 |
RT_GROUP_ICON | 0x290a790 | 0x76 | data | Tamil | Sri Lanka | 0.6779661016949152 |
RT_GROUP_ICON | 0x2900bc0 | 0x3e | data | Tamil | India | 0.8387096774193549 |
RT_GROUP_ICON | 0x2900bc0 | 0x3e | data | Tamil | Sri Lanka | 0.8387096774193549 |
RT_GROUP_ICON | 0x2903f70 | 0x5a | data | Tamil | India | 0.7222222222222222 |
RT_GROUP_ICON | 0x2903f70 | 0x5a | data | Tamil | Sri Lanka | 0.7222222222222222 |
RT_GROUP_ICON | 0x2910720 | 0x68 | data | Tamil | India | 0.7211538461538461 |
RT_GROUP_ICON | 0x2910720 | 0x68 | data | Tamil | Sri Lanka | 0.7211538461538461 |
RT_GROUP_ICON | 0x2916f48 | 0x76 | data | Tamil | India | 0.6864406779661016 |
RT_GROUP_ICON | 0x2916f48 | 0x76 | data | Tamil | Sri Lanka | 0.6864406779661016 |
RT_VERSION | 0x2918d50 | 0x228 | data | 0.5670289855072463 |
DLL | Import |
---|---|
KERNEL32.dll | GetProfileIntW, BuildCommDCBAndTimeoutsA, InterlockedIncrement, InterlockedDecrement, SetMailslotInfo, GetSystemWindowsDirectoryW, FreeEnvironmentStringsA, GetProcessPriorityBoost, EnumCalendarInfoExW, WaitNamedPipeW, EnumTimeFormatsW, GetDriveTypeA, GetProcessTimes, GetVolumePathNameW, GetCalendarInfoA, GetConsoleAliasExesLengthW, GetFileAttributesA, WriteConsoleW, SetSystemPowerState, GetModuleFileNameW, CompareStringW, GetShortPathNameA, EnumSystemLocalesA, SearchPathW, DeleteFiber, GetLastError, GetProcAddress, AttachConsole, HeapSize, SetComputerNameA, EnterCriticalSection, OpenWaitableTimerA, LoadLibraryA, GetProcessId, LocalAlloc, SetCalendarInfoW, IsSystemResumeAutomatic, AddAtomA, OpenJobObjectW, GetPrivateProfileStructA, FindFirstVolumeMountPointA, EnumDateFormatsA, CreateIoCompletionPort, GetModuleHandleA, CancelTimerQueueTimer, FreeEnvironmentStringsW, FindNextFileW, SetFileShortNameA, AreFileApisANSI, HeapCompact, GetPrivateProfileIntW, GetVolumeNameForVolumeMountPointA, HeapFree, HeapAlloc, DeleteFileA, WideCharToMultiByte, HeapReAlloc, GetCommandLineA, HeapSetInformation, GetStartupInfoW, RaiseException, IsProcessorFeaturePresent, HeapCreate, GetModuleHandleW, ExitProcess, DecodePointer, WriteFile, GetStdHandle, EncodePointer, LeaveCriticalSection, SetFilePointer, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, DeleteCriticalSection, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetCurrentProcess, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, GetModuleFileNameA, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LoadLibraryW, Sleep, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, RtlUnwind, LCMapStringW, MultiByteToWideChar, GetStringTypeW, CloseHandle, CreateFileW |
GDI32.dll | GetCharABCWidthsA, SelectObject |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Tamil | India | |
Tamil | Sri Lanka |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-13T10:53:30.089830+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49713 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:53:30.089830+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49708 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:54:22.079039+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.8 | 49706 | TCP |
2024-11-13T10:54:34.362378+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49707 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:54:53.135143+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49709 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:54:59.967146+0100 | 2022930 | ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow | 1 | 4.245.163.56 | 443 | 192.168.2.8 | 49711 | TCP |
2024-11-13T10:55:02.213728+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49710 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:10.989197+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49712 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:29.613117+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49714 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:30.349548+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49715 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:30.349548+0100 | 2843864 | ETPRO MALWARE Suspicious Zipped Filename in Outbound POST Request (screen.) M2 | 1 | 192.168.2.8 | 49715 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:48.326883+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49716 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:55:57.094150+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49717 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:06.203781+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49718 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:15.057549+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49719 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:23.838414+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49720 | 94.158.244.69 | 80 | TCP |
2024-11-13T10:56:32.618908+0100 | 2043206 | ET MALWARE Win32/Lumma Stealer Data Exfiltration Attempt M2 | 1 | 192.168.2.8 | 49721 | 94.158.244.69 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 13, 2024 10:54:25.867844105 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.872735023 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.872829914 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.872971058 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.873425007 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.877752066 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.877830982 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.878293991 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878304958 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878357887 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:25.878405094 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878416061 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878423929 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878433943 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878443003 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878451109 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.878459930 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.882742882 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.883294106 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.883327007 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.883337021 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:25.883344889 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.362256050 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.362377882 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.362993956 CET | 49707 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.367850065 CET | 80 | 49707 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.817794085 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.823041916 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.823142052 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.823267937 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.824714899 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.828685045 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.828789949 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.829607010 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829623938 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829637051 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829663992 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829677105 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829689980 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829700947 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829701900 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.829737902 CET | 49708 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:34.829849958 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.829863071 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.833641052 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.834511995 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.834527969 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.834563017 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.834589958 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.834603071 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:34.877552986 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:43.303020000 CET | 80 | 49708 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:44.307792902 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:44.482095957 CET | 80 | 49709 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:44.482758999 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:44.482758999 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:44.484832048 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:44.487656116 CET | 80 | 49709 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:44.489751101 CET | 80 | 49709 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:53.135071993 CET | 80 | 49709 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:53.135143042 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.135479927 CET | 49709 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.140507936 CET | 80 | 49709 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:53.722238064 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.727291107 CET | 80 | 49710 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:53.727447033 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.728033066 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.728033066 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:54:53.732846975 CET | 80 | 49710 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:54:53.732882977 CET | 80 | 49710 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:02.213565111 CET | 80 | 49710 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:02.213727951 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.213769913 CET | 49710 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.218744040 CET | 80 | 49710 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:02.503761053 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.510034084 CET | 80 | 49712 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:02.510107040 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.510430098 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.510850906 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:02.515261889 CET | 80 | 49712 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:02.515707016 CET | 80 | 49712 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:10.989110947 CET | 80 | 49712 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:10.989197016 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:10.989314079 CET | 49712 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:10.994087934 CET | 80 | 49712 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:11.536524057 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.140552044 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.140711069 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.140882969 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.141294956 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.145725012 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.145782948 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.146177053 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146184921 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146226883 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.146230936 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146240950 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146249056 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146281004 CET | 49713 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:12.146434069 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146442890 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.146450043 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.150326967 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.150582075 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.151034117 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.151041985 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.151051998 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.151148081 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.151155949 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:12.193475962 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:20.623872995 CET | 80 | 49713 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:21.131783009 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:21.136784077 CET | 80 | 49714 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:21.136852980 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:21.137038946 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:21.137424946 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:21.141801119 CET | 80 | 49714 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:21.142283916 CET | 80 | 49714 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:29.613034964 CET | 80 | 49714 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:29.613116980 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:29.613262892 CET | 49714 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:29.618233919 CET | 80 | 49714 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.291652918 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.296725035 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.296834946 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.297111988 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.297679901 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.301911116 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.301961899 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302596092 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302606106 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302619934 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302638054 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302680969 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302700043 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302720070 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302721977 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302731037 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302757978 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302759886 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302769899 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302772045 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302793980 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302797079 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.302813053 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.302830935 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.306926012 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.306967974 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.307461977 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.307497025 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.307531118 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.307540894 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.307585001 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.307611942 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.307674885 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.307683945 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.307707071 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.307729959 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.349405050 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.349548101 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.397583008 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.397711039 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.445492983 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.445720911 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.493462086 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.493673086 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.541448116 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.541601896 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.589736938 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.589852095 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.637814045 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.638456106 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.685653925 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.685720921 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.733722925 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.733776093 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.789863110 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.789956093 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.837680101 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.837796926 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.889766932 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.889898062 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.941819906 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.941910028 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:30.989837885 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:30.989959955 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.037894011 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.038005114 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.085778952 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.085937023 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.133856058 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.134032965 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.181941032 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.182086945 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.233573914 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.233721018 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.281909943 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.282004118 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.329576969 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.329735041 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.377865076 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.377928972 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.425841093 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.425905943 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.475281954 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.475409031 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.522768974 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.522890091 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.569875002 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.569986105 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.618604898 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.618735075 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.665704012 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.665812969 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.718069077 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.718204021 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.769758940 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.769848108 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.817666054 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.817945004 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.865817070 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.865966082 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.913568020 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.913753033 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:31.961848974 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:31.961936951 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.010013103 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.010097980 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.066004038 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.066211939 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.117748976 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.117917061 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.169507980 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.169826031 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.221766949 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.221888065 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.273679972 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.273845911 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.329716921 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.329860926 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.377836943 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.377971888 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.426208019 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.426299095 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.478693008 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.478797913 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.525818110 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.525945902 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.574251890 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.574316978 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.623384953 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.623460054 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.675578117 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.675695896 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.727227926 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.727322102 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.779911995 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.780097961 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.831491947 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.831617117 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.877656937 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.877785921 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.925707102 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.925787926 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:32.973805904 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:32.973922014 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.025806904 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.025993109 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.073609114 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.073734999 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.125701904 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.125840902 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.177690983 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.177798986 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.229795933 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.229871988 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.277514935 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.277582884 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.325741053 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.325798988 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.377716064 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.377861977 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.425654888 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.425759077 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.473603964 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.473932981 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.521555901 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.521666050 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.569483995 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.569561005 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.617465019 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.617567062 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.665632963 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.665746927 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.713617086 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.713735104 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.765733004 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.765994072 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.813690901 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.813829899 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.861609936 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.861701012 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.913518906 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.913657904 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:33.965544939 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:33.965610027 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.013698101 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.013811111 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.061541080 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.061738968 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.109529972 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.109608889 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.157587051 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.157876968 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.205861092 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.206125975 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.253453970 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.253562927 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.301587105 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.301660061 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.353949070 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.354094982 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.406111956 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.406259060 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.453567028 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.453676939 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.501481056 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.501528025 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.550652027 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.550715923 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.598159075 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.598285913 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.649688005 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.649779081 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.703100920 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.703222036 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.749491930 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.749645948 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.808661938 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.808734894 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.860554934 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.860610008 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.913536072 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.913605928 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:34.984792948 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:34.984859943 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.042498112 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.042587996 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.090212107 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.090291023 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.141807079 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.141882896 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.190093040 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.190167904 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.237761974 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.238054037 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.285773993 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.286053896 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.334119081 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.334228039 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.385787010 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.385931015 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.437597036 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.437715054 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.486393929 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.486555099 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.533603907 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.533729076 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.581623077 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.581692934 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.629690886 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.629792929 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.687733889 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.687834024 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.755968094 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.756047964 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.804630995 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.804706097 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.856118917 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.856311083 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.905597925 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.905850887 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:35.962383986 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:35.962466955 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.012538910 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.012675047 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.061717033 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.061861992 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.109647036 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.109786987 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.159933090 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.160048008 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.209794998 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.209896088 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.258187056 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.258394957 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.312061071 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.312257051 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.365536928 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.365632057 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.417045116 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.417110920 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.465673923 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.465779066 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.518044949 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.518131971 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.570043087 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.570240974 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.618827105 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.619035959 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.666529894 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.666702032 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.713618994 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.713711977 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.765539885 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.765721083 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.813925028 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.813994884 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.865546942 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.865647078 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.919538975 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.919706106 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:36.971240997 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:36.971378088 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.019296885 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.019352913 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.066090107 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.066169024 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.115348101 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.115544081 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.171571016 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.171783924 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.224251032 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.224348068 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.285722017 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.285900116 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.336052895 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.336143970 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.391911983 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.391989946 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.437589884 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.437670946 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.486743927 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.486866951 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.535474062 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.535540104 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.585720062 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.585773945 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.645737886 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.645807028 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.712234974 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.712368011 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.769706964 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.769819021 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.836467981 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.836596012 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.888592005 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.888761044 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.938942909 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.939045906 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:37.985641956 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:37.985738039 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.034513950 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.034662962 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.081949949 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.082094908 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.129697084 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.129793882 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.178145885 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.178222895 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.225814104 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.225872040 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.273592949 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.273663998 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.324330091 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.324449062 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.373800039 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.373945951 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.427356005 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.427448034 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.473905087 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.474026918 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.523894072 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.523988962 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.570918083 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.571166992 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.621869087 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.621942043 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.671084881 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.671147108 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.717699051 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.717758894 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.765822887 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:38.765928984 CET | 49715 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:38.786639929 CET | 80 | 49715 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:39.820585012 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:39.827023029 CET | 80 | 49716 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:39.827326059 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:39.827390909 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:39.827801943 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:39.832604885 CET | 80 | 49716 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:39.832813978 CET | 80 | 49716 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:48.326785088 CET | 80 | 49716 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:48.326883078 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.327023029 CET | 49716 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.335414886 CET | 80 | 49716 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:48.608906984 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.615736961 CET | 80 | 49717 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:48.616281986 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.616439104 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.616862059 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:48.622174978 CET | 80 | 49717 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:48.622984886 CET | 80 | 49717 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:57.094016075 CET | 80 | 49717 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:57.094150066 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.094232082 CET | 49717 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.099153042 CET | 80 | 49717 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:57.500457048 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.724580050 CET | 80 | 49718 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:57.724706888 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.724904060 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.725347042 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:55:57.729938984 CET | 80 | 49718 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:55:57.730076075 CET | 80 | 49718 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:06.203653097 CET | 80 | 49718 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:06.203780890 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.203780890 CET | 49718 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.208606958 CET | 80 | 49718 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:06.574736118 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.579714060 CET | 80 | 49719 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:06.579811096 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.579957008 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.580327034 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:06.584723949 CET | 80 | 49719 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:06.585133076 CET | 80 | 49719 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:15.057467937 CET | 80 | 49719 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:15.057549000 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.057626009 CET | 49719 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.062511921 CET | 80 | 49719 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:15.353727102 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.359919071 CET | 80 | 49720 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:15.360023022 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.360138893 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.360508919 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:15.366242886 CET | 80 | 49720 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:15.366858006 CET | 80 | 49720 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:23.838267088 CET | 80 | 49720 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:23.838413954 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:23.838460922 CET | 49720 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:23.843358994 CET | 80 | 49720 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:24.122925043 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:24.127931118 CET | 80 | 49721 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:24.127994061 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:24.128138065 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:24.128518105 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:24.133198023 CET | 80 | 49721 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:24.133855104 CET | 80 | 49721 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:32.618824005 CET | 80 | 49721 | 94.158.244.69 | 192.168.2.8 |
Nov 13, 2024 10:56:32.618907928 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:32.618973017 CET | 49721 | 80 | 192.168.2.8 | 94.158.244.69 |
Nov 13, 2024 10:56:32.624000072 CET | 80 | 49721 | 94.158.244.69 | 192.168.2.8 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.8 | 49707 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:54:25.872971058 CET | 190 | OUT | |
Nov 13, 2024 10:54:25.873425007 CET | 11124 | OUT | |
Nov 13, 2024 10:54:25.877830982 CET | 1236 | OUT | |
Nov 13, 2024 10:54:25.878357887 CET | 4105 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.8 | 49708 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:54:34.823267937 CET | 190 | OUT | |
Nov 13, 2024 10:54:34.824714899 CET | 11124 | OUT | |
Nov 13, 2024 10:54:34.828789949 CET | 1236 | OUT | |
Nov 13, 2024 10:54:34.829701900 CET | 2472 | OUT | |
Nov 13, 2024 10:54:34.829737902 CET | 4181 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.8 | 49709 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:54:44.482758999 CET | 188 | OUT | |
Nov 13, 2024 10:54:44.484832048 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.8 | 49710 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:54:53.728033066 CET | 188 | OUT | |
Nov 13, 2024 10:54:53.728033066 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.8 | 49712 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:02.510430098 CET | 188 | OUT | |
Nov 13, 2024 10:55:02.510850906 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.8 | 49713 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:12.140882969 CET | 190 | OUT | |
Nov 13, 2024 10:55:12.141294956 CET | 11124 | OUT | |
Nov 13, 2024 10:55:12.145782948 CET | 1236 | OUT | |
Nov 13, 2024 10:55:12.146226883 CET | 4944 | OUT | |
Nov 13, 2024 10:55:12.146281004 CET | 2870 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.8 | 49714 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:21.137038946 CET | 189 | OUT | |
Nov 13, 2024 10:55:21.137424946 CET | 1136 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.8 | 49715 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:30.297111988 CET | 191 | OUT | |
Nov 13, 2024 10:55:30.297679901 CET | 11124 | OUT | |
Nov 13, 2024 10:55:30.301961899 CET | 1236 | OUT | |
Nov 13, 2024 10:55:30.302638054 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302700043 CET | 4944 | OUT | |
Nov 13, 2024 10:55:30.302721977 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302759886 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302772045 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302793980 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302813053 CET | 2472 | OUT | |
Nov 13, 2024 10:55:30.302830935 CET | 1236 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.8 | 49716 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:39.827390909 CET | 188 | OUT | |
Nov 13, 2024 10:55:39.827801943 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.8 | 49717 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:48.616439104 CET | 188 | OUT | |
Nov 13, 2024 10:55:48.616862059 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.8 | 49718 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:55:57.724904060 CET | 188 | OUT | |
Nov 13, 2024 10:55:57.725347042 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.8 | 49719 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:56:06.579957008 CET | 188 | OUT | |
Nov 13, 2024 10:56:06.580327034 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.8 | 49720 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:56:15.360138893 CET | 188 | OUT | |
Nov 13, 2024 10:56:15.360508919 CET | 440 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.8 | 49721 | 94.158.244.69 | 80 | 7500 | C:\Users\user\Desktop\I2BJhmJou4.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 13, 2024 10:56:24.128138065 CET | 188 | OUT | |
Nov 13, 2024 10:56:24.128518105 CET | 440 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:53:35 |
Start date: | 13/11/2024 |
Path: | C:\Users\user\Desktop\I2BJhmJou4.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 474'624 bytes |
MD5 hash: | C847CB3090530EC9AE2E82805A03360D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 04:56:32 |
Start date: | 13/11/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 4% |
Dynamic/Decrypted Code Coverage: | 10.1% |
Signature Coverage: | 52.5% |
Total number of Nodes: | 774 |
Total number of Limit Nodes: | 25 |
Graph
Function 004069A1 Relevance: 208.6, APIs: 6, Strings: 112, Instructions: 2052stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00436ADC Relevance: 91.3, APIs: 22, Strings: 29, Instructions: 2004COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B81C Relevance: 70.2, APIs: 17, Strings: 22, Instructions: 1922stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040E14E Relevance: 40.3, APIs: 6, Strings: 16, Instructions: 1822stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00430E6C Relevance: 39.9, APIs: 14, Strings: 8, Instructions: 1432memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00434080 Relevance: 39.4, APIs: 10, Strings: 12, Instructions: 872registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042AD82 Relevance: 25.7, Strings: 20, Instructions: 749COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00405AAA Relevance: 24.9, APIs: 8, Strings: 6, Instructions: 448stringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040620B Relevance: 21.4, APIs: 8, Strings: 4, Instructions: 445stringCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042B9C5 Relevance: 16.7, Strings: 13, Instructions: 436COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040A928 Relevance: 14.5, APIs: 5, Strings: 3, Instructions: 475stringCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042FD35 Relevance: 14.1, Strings: 11, Instructions: 308COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004262A1 Relevance: 12.6, APIs: 2, Strings: 5, Instructions: 391libraryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B129 Relevance: 9.1, APIs: 2, Strings: 3, Instructions: 375nativefileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00422177 Relevance: 8.9, APIs: 1, Strings: 4, Instructions: 183nativeCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401FF9 Relevance: 7.3, APIs: 2, Strings: 2, Instructions: 254sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004224A3 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 201nativeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042C0DA Relevance: 6.8, Strings: 5, Instructions: 552COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043B362 Relevance: 6.6, APIs: 1, Strings: 3, Instructions: 550stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00430228 Relevance: 5.7, Strings: 4, Instructions: 717COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004052D9 Relevance: 5.7, APIs: 1, Strings: 2, Instructions: 467encryptionCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042F278 Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 222stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042CFBA Relevance: 5.4, Strings: 4, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00453BC4 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 116timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B7BB Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 40nativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040B7F5 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 16nativeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F69F2E Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004245EC Relevance: 1.7, APIs: 1, Instructions: 207nativeCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00421EEB Relevance: 1.7, APIs: 1, Instructions: 153nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042F1C2 Relevance: 1.5, APIs: 1, Instructions: 32nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044FB15 Relevance: .0, Instructions: 22COMMONLIBRARYCODE
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00443998 Relevance: .0, Instructions: 12COMMONLIBRARYCODE
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042F625 Relevance: 24.9, APIs: 8, Strings: 6, Instructions: 418stringCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02ED003C Relevance: 12.8, APIs: 5, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00432718 Relevance: 10.7, APIs: 7, Instructions: 234COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044CF15 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 74COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044575F Relevance: 9.3, APIs: 6, Instructions: 269COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402FCC Relevance: 7.3, APIs: 2, Strings: 2, Instructions: 283libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00453B82 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 140timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044E224 Relevance: 3.0, APIs: 2, Instructions: 22memoryCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02ED0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00418BA2 Relevance: 1.8, APIs: 1, Instructions: 313COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0045699F Relevance: 1.5, APIs: 1, Instructions: 44memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450330 Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044EB6F Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F69BED Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EDBA83 Relevance: 42.2, APIs: 5, Strings: 18, Instructions: 1922stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F042E7 Relevance: 25.4, APIs: 7, Strings: 7, Instructions: 872registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EDE3B5 Relevance: 20.6, Strings: 15, Instructions: 1822COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00439535 Relevance: 10.9, Strings: 8, Instructions: 905COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00428334 Relevance: 9.8, Strings: 7, Instructions: 1067COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00424C8D Relevance: 7.4, Strings: 5, Instructions: 1174COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02ED2260 Relevance: 7.3, APIs: 2, Strings: 2, Instructions: 254sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041EBEB Relevance: 6.8, Strings: 5, Instructions: 537COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F003F5 Relevance: 6.6, Strings: 5, Instructions: 301COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EDAB8F Relevance: 6.5, APIs: 4, Instructions: 475stringCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044F244 Relevance: 6.3, APIs: 4, Instructions: 337COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00451FBC Relevance: 6.1, APIs: 4, Instructions: 129fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F22223 Relevance: 6.1, APIs: 4, Instructions: 129fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043CE95 Relevance: 6.1, APIs: 4, Instructions: 73COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EFD221 Relevance: 5.4, Strings: 4, Instructions: 405COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EF23DE Relevance: 5.2, Strings: 4, Instructions: 183COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00424BED Relevance: 4.5, APIs: 3, Instructions: 32fileCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00448800 Relevance: 3.4, APIs: 2, Instructions: 449COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F18A67 Relevance: 3.4, APIs: 2, Instructions: 449COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043BCA4 Relevance: 3.1, Strings: 2, Instructions: 611COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043D600 Relevance: 3.1, APIs: 2, Instructions: 92COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044614F Relevance: 3.0, APIs: 2, Instructions: 44timeCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004279E0 Relevance: 1.8, Strings: 1, Instructions: 509COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00415070 Relevance: 1.7, Strings: 1, Instructions: 471COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EE52D7 Relevance: 1.7, Strings: 1, Instructions: 471COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00451F08 Relevance: 1.7, APIs: 1, Instructions: 158fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043D0B8 Relevance: 1.6, APIs: 1, Instructions: 147COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00414A83 Relevance: 1.6, Strings: 1, Instructions: 352COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F112BE Relevance: 1.6, Strings: 1, Instructions: 344COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040136E Relevance: 1.6, Strings: 1, Instructions: 318COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041F916 Relevance: 1.6, APIs: 1, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00424B24 Relevance: 1.5, APIs: 1, Instructions: 47memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043CE89 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E6F0 Relevance: 1.5, Strings: 1, Instructions: 232COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004126B9 Relevance: .8, Instructions: 751COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041D1E9 Relevance: .5, Instructions: 492COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041204D Relevance: .5, Instructions: 486COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EE22B4 Relevance: .5, Instructions: 486COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040D994 Relevance: .5, Instructions: 464COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EDDBFB Relevance: .5, Instructions: 464COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041316D Relevance: .4, Instructions: 440COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EE33D4 Relevance: .4, Instructions: 440COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E083 Relevance: .4, Instructions: 379COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EEE2EA Relevance: .4, Instructions: 379COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00429A5B Relevance: .3, Instructions: 346COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00441057 Relevance: .3, Instructions: 344COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044234A Relevance: .3, Instructions: 344COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00410A33 Relevance: .3, Instructions: 313COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00418413 Relevance: .3, Instructions: 279COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00429730 Relevance: .2, Instructions: 246COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004109FC Relevance: .2, Instructions: 210COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044915B Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F193C2 Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EF9ADA Relevance: .2, Instructions: 151COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00424995 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EF4BFC Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0043D8D0 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00422817 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02EF2A7E Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00426A42 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00410218 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00429EF7 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 02F13BFF Relevance: .0, Instructions: 12COMMONLIBRARYCODE
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004269E4 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0042F265 Relevance: .0, Instructions: 5COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0045999F Relevance: 14.3, APIs: 4, Strings: 4, Instructions: 303COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0045C793 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 147COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044C5A0 Relevance: 9.3, APIs: 6, Instructions: 275COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00443916 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 42libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044623D Relevance: 7.6, APIs: 5, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00446CD2 Relevance: 7.6, APIs: 5, Instructions: 143pipeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00459DC4 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 118COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00456D31 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 27libraryCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004537D0 Relevance: 6.1, APIs: 4, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0044C89A Relevance: 6.1, APIs: 4, Instructions: 109COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00450F41 Relevance: 6.1, APIs: 4, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00455DA6 Relevance: 6.0, APIs: 4, Instructions: 42COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00455E0C Relevance: 6.0, APIs: 4, Instructions: 42COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0045962F Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 97COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|