Windows
Analysis Report
08e2VwqyI0.dll
Overview
General Information
Sample name: | 08e2VwqyI0.dllrenamed because original name is a hash value |
Original sample name: | dba9c2268b1ee590b4b3b456642c6c7aa6993b9d.dll |
Analysis ID: | 1558497 |
MD5: | 129a4a5be1e9cff7a54ebf6b80793986 |
SHA1: | dba9c2268b1ee590b4b3b456642c6c7aa6993b9d |
SHA256: | a80d66f921a6f59756560ae3c3afd26fdd43e26f30ecabdd729c80301a8d08ce |
Tags: | dlluser-NDA0E |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- loaddll32.exe (PID: 1996 cmdline:
loaddll32. exe "C:\Us ers\user\D esktop\08e 2VwqyI0.dl l" MD5: 51E6071F9CBA48E79F10C84515AAE618) - conhost.exe (PID: 1992 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 5540 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\08e 2VwqyI0.dl l",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - rundll32.exe (PID: 3580 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\08e2 VwqyI0.dll ",#1 MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1160 cmdline:
rundll32.e xe C:\User s\user\Des ktop\08e2V wqyI0.dll, DoAddToFav Dlg MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 6720 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6408 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 344 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12) - rundll32.exe (PID: 1308 cmdline:
rundll32.e xe C:\User s\user\Des ktop\08e2V wqyI0.dll, InputFile MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 1976 cmdline:
rundll32.e xe C:\User s\user\Des ktop\08e2V wqyI0.dll, PrintFile MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 5784 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 1 976 -s 672 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 5280 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\08e2 VwqyI0.dll ",DoAddToF avDlg MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 2100 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 740 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 4648 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12) - rundll32.exe (PID: 3404 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\08e2 VwqyI0.dll ",InputFil e MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 4032 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\08e2 VwqyI0.dll ",PrintFil e MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 6676 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 4 032 -s 668 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- rundll32.exe (PID: 3396 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\08 e2VwqyI0.d ll",DoAddT oFavDlg MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 5736 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 760 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 4580 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- rundll32.exe (PID: 2300 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\08 e2VwqyI0.d ll",DoAddT oFavDlg MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 1160 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 1308 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 2848 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- cleanup
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 4_2_10007F3E |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Process created: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 4_2_10003F41 |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Static PE information: |
Source: | Process Stats: |
Source: | Code function: | 4_2_10008AAD |
Source: | Code function: | 4_2_10003F63 | |
Source: | Code function: | 11_2_10003F63 | |
Source: | Code function: | 19_2_10003F63 |
Source: | Code function: | 0_2_024500CD | |
Source: | Code function: | 3_2_026B00CD | |
Source: | Code function: | 4_2_1000B224 | |
Source: | Code function: | 4_2_1000B70D | |
Source: | Code function: | 4_2_100121ED | |
Source: | Code function: | 4_2_1000AEC0 | |
Source: | Code function: | 4_2_033900CD | |
Source: | Code function: | 10_2_047100CD | |
Source: | Code function: | 11_2_1000B224 | |
Source: | Code function: | 11_2_1000B70D | |
Source: | Code function: | 11_2_100121ED | |
Source: | Code function: | 11_2_1000AEC0 | |
Source: | Code function: | 17_2_030600CD | |
Source: | Code function: | 18_2_049C00CD | |
Source: | Code function: | 19_2_1000B224 | |
Source: | Code function: | 19_2_1000B70D | |
Source: | Code function: | 19_2_100121ED | |
Source: | Code function: | 19_2_1000AEC0 | |
Source: | Code function: | 19_2_049400CD | |
Source: | Code function: | 26_2_02D900CD |
Source: | Process created: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 4_2_1000404F | |
Source: | Code function: | 11_2_1000404F | |
Source: | Code function: | 19_2_1000404F |
Source: | Code function: | 4_2_10003FB7 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_02450E9F |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 4_2_1003901C | |
Source: | Code function: | 4_2_1002A254 | |
Source: | Code function: | 4_2_1002F036 | |
Source: | Code function: | 4_2_10027C71 | |
Source: | Code function: | 4_2_10029046 | |
Source: | Code function: | 4_2_1003B061 | |
Source: | Code function: | 4_2_1002F051 | |
Source: | Code function: | 4_2_1002F068 | |
Source: | Code function: | 4_2_100351D7 | |
Source: | Code function: | 4_2_1003307F | |
Source: | Code function: | 4_2_1003307F | |
Source: | Code function: | 4_2_1002D08D | |
Source: | Code function: | 4_2_10031095 | |
Source: | Code function: | 4_2_1002FD0B | |
Source: | Code function: | 4_2_1002FD4E | |
Source: | Code function: | 4_2_10023093 | |
Source: | Code function: | 4_2_100230B3 | |
Source: | Code function: | 4_2_1002B78C | |
Source: | Code function: | 4_2_1003B2DF | |
Source: | Code function: | 4_2_1002F874 | |
Source: | Code function: | 4_2_1002AD33 | |
Source: | Code function: | 4_2_1003408E | |
Source: | Code function: | 4_2_1002F0EF | |
Source: | Code function: | 4_2_100282E3 | |
Source: | Code function: | 4_2_100338DA | |
Source: | Code function: | 4_2_10035102 | |
Source: | Code function: | 4_2_100250F0 | |
Source: | Code function: | 4_2_1002B0FD | |
Source: | Code function: | 4_2_1002D116 | |
Source: | Code function: | 4_2_1002B0FD | |
Source: | Code function: | 4_2_10039116 |
Source: | Static PE information: |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | Evasive API call chain: | graph_4-17729 |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Code function: | 4_2_1001E1FE |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 4_2_10007F3E |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-384 | ||
Source: | API call chain: | graph_0-395 | ||
Source: | API call chain: | graph_3-404 | ||
Source: | API call chain: | graph_3-393 | ||
Source: | API call chain: | graph_4-17642 | ||
Source: | API call chain: | graph_4-17631 | ||
Source: | API call chain: | graph_10-395 | ||
Source: | API call chain: | graph_10-384 | ||
Source: | API call chain: | graph_17-401 | ||
Source: | API call chain: | graph_17-390 | ||
Source: | API call chain: | graph_18-392 | ||
Source: | API call chain: | graph_18-381 | ||
Source: | API call chain: | graph_19-17332 | ||
Source: | API call chain: | graph_19-17321 | ||
Source: | API call chain: | graph_26-392 | ||
Source: | API call chain: | graph_26-381 |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | |||
Source: | Process queried: |
Source: | Code function: | 4_2_1001E1FE |
Source: | Code function: | 11_2_1000CCF2 |
Source: | Code function: | 0_2_02450E9F |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 11 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 3 Obfuscated Files or Information | LSASS Memory | 111 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 111 Process Injection | 2 Software Packing | Security Account Manager | 31 Security Software Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 11 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 1 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | 1 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 31 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | 1 Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 111 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Rundll32 | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
97% | ReversingLabs | Win32.Backdoor.Zegost | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
blogx.sina.com.cn | 202.108.0.52 | true | false | high | |
host123.zz.am | unknown | unknown | false | high | |
blog.sina.com.cn | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
202.108.0.52 | blogx.sina.com.cn | China | 4808 | CHINA169-BJChinaUnicomBeijingProvinceNetworkCN | false | |
107.163.56.110 | unknown | United States | 20248 | TAKE2US | true | |
107.160.131.253 | unknown | United States | 40676 | AS40676US | true | |
107.160.131.254 | unknown | United States | 40676 | AS40676US | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1558497 |
Start date and time: | 2024-11-19 14:23:42 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 37 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 08e2VwqyI0.dllrenamed because original name is a hash value |
Original Sample Name: | dba9c2268b1ee590b4b3b456642c6c7aa6993b9d.dll |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winDLL@42/10@58/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.168.117.172, 20.42.73.29
- Excluded domains from analysis (whitelisted): onedsblobprdeus07.eastus.cloudapp.azure.com, login.live.com, otelrules.azureedge.net, slscr.update.microsoft.com, blobcollector.events.data.trafficmanager.net, onedsblobprdeus15.eastus.cloudapp.azure.com, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com
- Execution Graph export aborted for target rundll32.exe, PID 1976 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 08e2VwqyI0.dll
Time | Type | Description |
---|---|---|
08:24:38 | API Interceptor | |
08:24:45 | API Interceptor | |
08:27:24 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
202.108.0.52 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
107.163.56.110 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
107.160.131.253 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
107.160.131.254 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
blogx.sina.com.cn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AS40676US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mint Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mint Stealer | Browse |
| ||
AS40676US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mint Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mint Stealer | Browse |
| ||
CHINA169-BJChinaUnicomBeijingProvinceNetworkCN | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TAKE2US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 721 |
Entropy (8bit): | 4.519220738257457 |
Encrypted: | false |
SSDEEP: | 12:8GGdzrn7oce9UcdY7xjIaGwwwwwwwwwwwwwwwwwwwwP:8G4n7o39U0YVje |
MD5: | 1A2142B706CA0E422BE413C718EF7308 |
SHA1: | 655BF7399BB4BD75695AC5D5BEAB6963DC6ECAF3 |
SHA-256: | A7A39269A451A173BA8509B63AAFF9D2419FDDB7DF981FAB27DA0F2855CEAC84 |
SHA-512: | C895FA7C8857079EDD5A75CC8810DF08DBB091408E48E96AAFC48E84CD955F71401B9F54B3D2FAF29C862DA3E82F07E450DECF42A19E379D8CAA23C0631EA16A |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_d2d6a05f617930bde2d4c76b2a5555e299272ba9_7522e4b5_43694ddf-2812-4925-b8af-347e7aeab431\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.950696993679653 |
Encrypted: | false |
SSDEEP: | 192:yQJijOE30BU/wjeT7WaZYzuiFUZ24IO8dci:TJiqEEBU/wjevbYzuiFUY4IO8dci |
MD5: | 26E7BC64706BE716A2352C1183C34F48 |
SHA1: | BF2D620B1F7A9314E30A51E2A31BE65EB00A9B0D |
SHA-256: | D6774B23692B023AB2F404283C8DDBED6322484A9C3B9836EFB2891CDD4EA4E2 |
SHA-512: | 468A4EA4796C06D6E6DA750E683D6D49520929DCCC06D181780414F1BE1D29DF921A88005F86EBE2BFFDA01AEF0603A983A9719DC289052D7364B8194FCCA867 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_d2d6a05f617930bde2d4c76b2a5555e299272ba9_7522e4b5_a5abc924-2452-4abb-81bb-5fc932c8c5b9\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.95056249331519 |
Encrypted: | false |
SSDEEP: | 192:KHA3iZOB30BU/wjeTbWaZYzuiFUZ24IO8dci:CA3iwBEBU/wjePbYzuiFUY4IO8dci |
MD5: | A10B880963DCCE0D113EE9CF80E61AAD |
SHA1: | 9864B6C9C4F9292F397CD34F1D96B5F0E093689F |
SHA-256: | E7D150DEA7847B95978F5597CEBAEC5543847F0D9D67B8E165CD3431D913A49E |
SHA-512: | 5ABFA95DB8D874D178A4E9A58DFFFB0C06E43A08B332832A6233B815F8A13AD2D11A96A65FD1464E4F83F4019710EDA73F6E351FBFFAB691173F3C0E15EBE444 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 45268 |
Entropy (8bit): | 2.02092739146417 |
Encrypted: | false |
SSDEEP: | 192:DW/EkZHVXpXvUO5H4ysmv1qd/Ar/4+BTdh1Ky:i/bZHf5HTs4cd/Az4+Bo |
MD5: | 424149B97758D42A94955AD99241655B |
SHA1: | CAD007CA26DCB111296BFDAA7351297C1A0C8C8E |
SHA-256: | 16D4F48C5A0F75C90D3921FD6B3724C6601FFE4C81633EF2B69847439C300F97 |
SHA-512: | 55725C8B040781F45A368DB5F2CEE916A1B03F347924CCA940E95C0F4FBB19303DBF6F64C9D45E3F2B591433AD33716A3B3212C43ACD1BD92DFF28941CD38CAF |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8272 |
Entropy (8bit): | 3.6952229836293027 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJcC626YdE6RgmfTZaYprw89btnsf0GPm:R6lXJB626YO6RgmfTZaQtsfC |
MD5: | 879A11CAF691ECDDB382FE396C073BF7 |
SHA1: | 1541960D059A3A92F99858715F56015346649080 |
SHA-256: | BE18C4E2335D1E5932298AD2E132965AB7F581C97EC0FD0D8055DC83358533C0 |
SHA-512: | 87C5E0901CA84F11F9C40CE1E6780C765DA7DC2979F21E25FB5EB822509EB10A488B48133AAC8BDB0BA122C13EC65AA715EDB7C7B81CB9D358F423FD39798044 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.461892195265477 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsyJg77aI9QzWpW8VYoFoYm8M4JCdPSFW+q8/AxGScSpd:uIjfAI76C7VhFFJupJ3pd |
MD5: | 308064529445FB5EBE61928086FE9A07 |
SHA1: | 0AFF5318E6D0934F184B81272C653814EB450A32 |
SHA-256: | 22A2AE01AAA0DE08893C3AA84CEF06351CDA97A89C5A28E280C1C4AE31DFAC39 |
SHA-512: | D8494E209F011E9384B1578A18E843F82236B120795C398C9E43C6C5FA04420BCCC1834D2A50E2B5884C339E6E298B830D19EBFFD21FEF5FEA11209FC65EBC71 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 45966 |
Entropy (8bit): | 1.9951415072130652 |
Encrypted: | false |
SSDEEP: | 192:WYLWZHVXpX1cO5H4iheT/YI5a9O/3mihgYZYE:XqZH15HDheT/YDZiT |
MD5: | CA3FEAEDFD8EF261BC1D2BEC7A3F9476 |
SHA1: | 962088D07A9513B038E500888F7E54BC5C28A5EA |
SHA-256: | 5EB74BEDB95BAA11A7A1AD48C65F4A1889C150B4B072541EE0902711A974C53F |
SHA-512: | 67670C28AF5FC898C7B061FC8B942A3ADB75ED79A23E54B345284F5CD215F1CC1FC2F4574DF11925720015BB62BB754A0CD585AC53299452F4AB9033DC6EBCF6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8270 |
Entropy (8bit): | 3.6906602209919854 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJYjR6r76YVQV6SgmfTZaYprO89bAJsfCRAm:R6lXJSR6r76YWV6SgmfTZaaAifCD |
MD5: | BEF443A886833269E99CE65CC29364E7 |
SHA1: | A9E7C89485E18782FC937EAEC858553E39EB22EB |
SHA-256: | 173FEF31ED2AFBEDB79F1CE2BEADB1732000F4EDFFFC63A22F0064C42D8D2154 |
SHA-512: | EA2A68CBD84D1F62040A3D7135400CC1C4D24B0514EA4BA86CDAC3A7FE29D4296EEACF54B3D374FF3F657B6059D75711058E1C62BC6349F3498E2BAF7CA2AA06 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.459899340293469 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsyJg77aI9QzWpW8VYbYm8M4JCdPSFWI+q8/ARnGScSxd:uIjfAI76C7V7JeIZnJ3xd |
MD5: | A193261BAA3A3DB7A69582B510883A45 |
SHA1: | EE5095ECB5AF904AB215277C1A45536899159DF1 |
SHA-256: | 8AD42BD44F393249AAC6E7B8CC71A0C688AB251FC4C0C1A9C0104D8E1ED27A9C |
SHA-512: | E844381F719155373A8A0DE24E356B740D4AD56627764F04DD3E29FBC56FC6A39355BEE681ED853944708058C7C7A26882218D2B5A348D073E6EBA127743D6ED |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.37287043948001 |
Encrypted: | false |
SSDEEP: | 6144:OFVfpi6ceLP/9skLmb0ayWWSPtaJG8nAge35OlMMhA2AX4WABlguNEiL:eV1QyWWI/glMM6kF7Kq |
MD5: | D1B051EC99383A0FFE404B622C2A78EF |
SHA1: | 909FA24353C4C9E66F6EAE63EDFF9625B33F37DB |
SHA-256: | 864B62E91ABE3D173BDCDE74F889C67D1527158F8EB6443A575FF626BE410A19 |
SHA-512: | E9A2EB95378586915BCD4D830D1DA3C541332F403CB74B0EC220ED65587876D860982BC0E014115E28914E1393D108F03CBDEE85F947A59DFEAEE08893A3F96D |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.960894639958724 |
TrID: |
|
File name: | 08e2VwqyI0.dll |
File size: | 175'321 bytes |
MD5: | 129a4a5be1e9cff7a54ebf6b80793986 |
SHA1: | dba9c2268b1ee590b4b3b456642c6c7aa6993b9d |
SHA256: | a80d66f921a6f59756560ae3c3afd26fdd43e26f30ecabdd729c80301a8d08ce |
SHA512: | 2d71d88ff8c8854bacbd6689abd54e739c482b5605295bd9ffea1b06078b4e9f1f6f1072bb03b9cf255cd50a8f28da9bd762c3c3ca950d7165932e89940611fd |
SSDEEP: | 3072:R2Iz9CI8mUOtDDPwLkBLXLDFkKmvzXBpLHYmmO1QezRd7UcPa1xMjM7A:Rjz9X8mXGUXVPmr9mOzRd7UcPKoMk |
TLSH: | 100412B0F3F98B59F0A716770831597CC97638816329277FC2889A6EAC5442FF18D764 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......... B..N...N...N...B...N.F.....N.......N.......N.......N...@...N.m.D...N...O.^.N.m.E...N.=.H...N.m.J...N.Rich..N................ |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x1004fe9b |
Entrypoint Section: | .rsrc |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL |
DLL Characteristics: | |
Time Stamp: | 0x565C7C9C [Mon Nov 30 16:43:08 2015 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | bb6e4ad1ce3cf53a77a13b1c6fafb901 |
Instruction |
---|
mov eax, 10050CB4h |
push eax |
push dword ptr fs:[00000000h] |
mov dword ptr fs:[00000000h], esp |
xor eax, eax |
mov dword ptr [eax], ecx |
push eax |
inc ebp |
inc ebx |
outsd |
insd |
jo 00007F7A3CF38A23h |
arpl word ptr [edx+esi+00h], si |
add byte ptr [eax], al |
or byte ptr [eax+eax], cl |
dec eax |
loope 00007F7A3CF389C3h |
push esi |
push edi |
push ebx |
push ebp |
mov ebx, dword ptr [esp+1Ch] |
test ebx, ebx |
je 00007F79FADBAB71h |
push cs |
out 60h, al |
or eax, 72656B0Bh |
outsb |
insb |
xor esi, dword ptr [edx] |
adc al, 44h |
push es |
mov eax, C08513FFh |
cmp byte ptr [edi+0CE8F08Bh], cl |
xor eax, dword ptr [esi+6900ECE3h] |
jc 00007F7A3CF38A36h |
jne 00007F7A3CF38A23h |
insb |
inc esi |
sbb bh, bh |
push ebx |
add al, 3Eh |
mov dword ptr [8BFFC4D0h], eax |
call 00007F79E034A537h |
xor eax, dword ptr [edi+636F6E15h] |
sbb al, 58h |
mov esp, dword ptr [esp+edx] |
jl 00007F7A3CF38951h |
sar ecx, FFFFFFA1h |
sbb byte ptr [edx+68h], ch |
adc byte ptr [eax-01h], cl |
pushad |
clc |
cmp dword ptr [ecx], 3F33D008h |
mov ebx, eax |
push eax |
push esp |
jbe 00007F7A3CF389C6h |
push edi |
or byte ptr [eax], cl |
lea eax, dword ptr [esi+0Fh] |
inc edx |
aad C9h |
stc |
mov dh, 0Ch |
add eax, FF0C300Dh |
adc dword ptr [esi], ecx |
push eax |
push ebx |
call 00007F7A017732E8h |
sub byte ptr [edx+58h], bl |
je 00007F7A3CF389C5h |
int3 |
adc dword ptr [edx], esi |
jne 00007F7A3CF389F5h |
dec eax |
push eax |
add byte ptr [eax+53h], FFFFFFD5h |
pop eax |
push eax |
add byte ptr [edx], cl |
push eax |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x4fb24 | 0x68 | .rsrc |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x4fc14 | 0x2eb | .rsrc |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4f000 | 0xb10 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x51000 | 0x18 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4e000 | 0x28800 | 616e4770cbaa1701277e430d81cefbf7 | False | 0.9978238329475309 | data | 7.997797944306588 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x4f000 | 0x2000 | 0x1e00 | 4178e173c28267cb5211773428c4940e | False | 0.6875 | data | 6.368056297656816 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x51000 | 0x1000 | 0x200 | aa11e7584102ed6962d8c933636a8bad | False | 0.0625 | data | 0.2162069074398449 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_STRING | 0x4b000 | 0x16c | empty | English | United States | 0 |
RT_STRING | 0x4b170 | 0x86 | empty | English | United States | 0 |
RT_STRING | 0x4b1f8 | 0x56 | empty | English | United States | 0 |
RT_STRING | 0x4b250 | 0x16e | empty | English | United States | 0 |
RT_STRING | 0x4b3c0 | 0x128 | empty | English | United States | 0 |
RT_STRING | 0x4b4e8 | 0xd2 | empty | English | United States | 0 |
RT_STRING | 0x4b5c0 | 0x6a | empty | English | United States | 0 |
RT_STRING | 0x4b630 | 0xc8 | empty | English | United States | 0 |
RT_STRING | 0x4b6f8 | 0x200 | empty | English | United States | 0 |
RT_STRING | 0x4b8f8 | 0x23e | empty | English | United States | 0 |
RT_STRING | 0x4bb38 | 0x12e | empty | English | United States | 0 |
RT_STRING | 0x4bc68 | 0xca | empty | English | United States | 0 |
RT_STRING | 0x4bd38 | 0x252 | empty | English | United States | 0 |
RT_STRING | 0x4bf90 | 0x28e | empty | English | United States | 0 |
RT_STRING | 0x4c220 | 0xce | empty | English | United States | 0 |
RT_STRING | 0x4c2f0 | 0x15c | empty | English | United States | 0 |
RT_STRING | 0x4c450 | 0x398 | empty | English | United States | 0 |
RT_STRING | 0x4c7e8 | 0x2ae | empty | English | United States | 0 |
RT_STRING | 0x4ca98 | 0x42 | empty | English | United States | 0 |
RT_STRING | 0x4cae0 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cb00 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cb20 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cb40 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cb60 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cb80 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cba0 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cbc0 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cbe0 | 0x7a | empty | English | United States | 0 |
RT_STRING | 0x4cc60 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cc80 | 0x20 | empty | English | United States | 0 |
RT_STRING | 0x4cca0 | 0x13a | empty | English | United States | 0 |
RT_STRING | 0x4cde0 | 0x19a | empty | English | United States | 0 |
RT_STRING | 0x4cf80 | 0x9a | empty | English | United States | 0 |
RT_STRING | 0x4d020 | 0xa8 | empty | English | United States | 0 |
RT_STRING | 0x4d0c8 | 0x20 | empty | English | United States | 0 |
RT_VERSION | 0x4f7f0 | 0x31c | data | English | United States | 0.4296482412060301 |
RT_HTML | 0x4d0e8 | 0x49 | empty | English | United States | 0 |
RT_HTML | 0x4d138 | 0xd | empty | English | United States | 0 |
RT_HTML | 0x4d148 | 0x6be | empty | English | United States | 0 |
DLL | Import |
---|---|
kernel32.dll | LoadLibraryA, GetProcAddress, VirtualAlloc, VirtualFree |
MFC42.DLL | |
MSVCRT.dll | _strcmpi |
USER32.dll | GetDesktopWindow |
ADVAPI32.dll | RegDeleteValueA |
WS2_32.dll | htons |
SHLWAPI.dll | PathIsDirectoryA |
ole32.dll | CoUninitialize |
OLEAUT32.dll | SafeArrayGetVartype |
MSVCP60.dll | ?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z |
NETAPI32.dll | Netbios |
Name | Ordinal | Address |
---|---|---|
DoAddToFavDlg | 1 | 0x10008645 |
InputFile | 2 | 0x1000678b |
PrintFile | 3 | 0x1000443d |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 14:24:40.615721941 CET | 49707 | 18530 | 192.168.2.8 | 107.163.56.110 |
Nov 19, 2024 14:24:40.615811110 CET | 49706 | 18659 | 192.168.2.8 | 107.160.131.253 |
Nov 19, 2024 14:24:41.625773907 CET | 49707 | 18530 | 192.168.2.8 | 107.163.56.110 |
Nov 19, 2024 14:24:41.625785112 CET | 49706 | 18659 | 192.168.2.8 | 107.160.131.253 |
Nov 19, 2024 14:24:43.641510963 CET | 49707 | 18530 | 192.168.2.8 | 107.163.56.110 |
Nov 19, 2024 14:24:43.641535044 CET | 49706 | 18659 | 192.168.2.8 | 107.160.131.253 |
Nov 19, 2024 14:24:47.641448975 CET | 49707 | 18530 | 192.168.2.8 | 107.163.56.110 |
Nov 19, 2024 14:24:47.641721010 CET | 49706 | 18659 | 192.168.2.8 | 107.160.131.253 |
Nov 19, 2024 14:24:55.657119989 CET | 49706 | 18659 | 192.168.2.8 | 107.160.131.253 |
Nov 19, 2024 14:24:55.657161951 CET | 49707 | 18530 | 192.168.2.8 | 107.163.56.110 |
Nov 19, 2024 14:25:05.726532936 CET | 49740 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:05.726566076 CET | 49741 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:06.735306978 CET | 49740 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:06.735321999 CET | 49741 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:08.735232115 CET | 49741 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:08.735275030 CET | 49740 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:08.853775024 CET | 49772 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:09.743359089 CET | 49781 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:09.848402977 CET | 49783 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:09.848583937 CET | 49784 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:10.750876904 CET | 49781 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:10.860253096 CET | 49784 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:10.860351086 CET | 49783 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:12.750935078 CET | 49781 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:12.860301018 CET | 49783 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:12.860312939 CET | 49784 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:13.790194035 CET | 49813 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:13.897733927 CET | 49814 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:13.898276091 CET | 49815 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:14.797770023 CET | 49813 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:14.907170057 CET | 49814 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:14.909013033 CET | 49815 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:16.798535109 CET | 49813 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:16.907171965 CET | 49814 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:16.909497976 CET | 49815 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:17.800687075 CET | 49850 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:17.913883924 CET | 49852 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:17.914828062 CET | 49853 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:18.813447952 CET | 49850 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:18.925156116 CET | 49853 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:18.925334930 CET | 49852 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:20.813430071 CET | 49850 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:20.938417912 CET | 49853 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:20.939026117 CET | 49852 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:21.814012051 CET | 49882 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:21.928117037 CET | 49884 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:21.928790092 CET | 49885 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:22.829083920 CET | 49882 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:22.922780037 CET | 49884 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:22.922832012 CET | 49885 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:24.891526937 CET | 49882 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:24.938426018 CET | 49885 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:24.938426018 CET | 49884 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:25.830224037 CET | 49917 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:25.943288088 CET | 49919 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:25.943824053 CET | 49920 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:26.844660044 CET | 49917 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:26.954107046 CET | 49920 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:26.985322952 CET | 49919 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:28.860316038 CET | 49917 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:28.955022097 CET | 49920 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:29.094696045 CET | 49919 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:29.872823000 CET | 49953 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:29.998346090 CET | 49955 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:30.377155066 CET | 49959 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:30.891599894 CET | 49953 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:31.000979900 CET | 49955 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:31.391597986 CET | 49959 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:32.985482931 CET | 49953 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:33.001010895 CET | 49955 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:33.391635895 CET | 49959 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:33.861284971 CET | 49990 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:33.975883007 CET | 49992 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:33.977057934 CET | 49993 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:34.876353979 CET | 49990 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:34.985382080 CET | 49992 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:34.985404015 CET | 49993 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:36.875955105 CET | 49990 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:36.985368013 CET | 49992 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:36.985446930 CET | 49993 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:37.876288891 CET | 50021 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:38.455117941 CET | 50023 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:38.456125021 CET | 50024 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:38.891649961 CET | 50021 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:39.469863892 CET | 50023 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:39.469891071 CET | 50024 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:40.891657114 CET | 50021 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:41.485347986 CET | 50024 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:41.485465050 CET | 50023 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:41.892653942 CET | 50056 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:42.007720947 CET | 50058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:42.008347988 CET | 50059 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:42.891611099 CET | 50056 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:43.016781092 CET | 50058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:43.016849995 CET | 50059 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:44.907248974 CET | 50056 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:45.032244921 CET | 50058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:45.035104990 CET | 50059 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:45.907807112 CET | 50098 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:46.019923925 CET | 50100 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:46.020697117 CET | 50101 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:46.922863007 CET | 50098 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:47.032294035 CET | 50100 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:47.035080910 CET | 50101 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:48.938508987 CET | 50098 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:49.032263041 CET | 50100 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:49.035095930 CET | 50101 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:49.925606012 CET | 50144 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:50.035718918 CET | 50146 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:50.036628008 CET | 50147 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:50.938514948 CET | 50144 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:51.047877073 CET | 50146 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:51.049134970 CET | 50147 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:52.954145908 CET | 50144 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:53.047916889 CET | 50146 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:53.048105001 CET | 50147 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:53.939373016 CET | 50192 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:54.053328037 CET | 50194 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:54.054531097 CET | 50195 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:54.938524961 CET | 50192 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:55.047931910 CET | 50194 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:55.051212072 CET | 50195 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:56.938529015 CET | 50192 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:57.047936916 CET | 50194 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:57.051140070 CET | 50195 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:57.970362902 CET | 50251 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:58.084568977 CET | 50253 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:58.085148096 CET | 50254 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:25:58.985445023 CET | 50251 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:59.094801903 CET | 50253 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:25:59.094911098 CET | 50254 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:00.985413074 CET | 50251 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:01.094901085 CET | 50253 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:01.110502005 CET | 50254 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:01.970464945 CET | 50316 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:02.122955084 CET | 50320 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:02.123651981 CET | 50321 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:02.985455036 CET | 50316 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:03.110642910 CET | 50320 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:03.110646009 CET | 50321 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:04.985410929 CET | 50316 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:05.126163960 CET | 50320 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:05.129594088 CET | 50321 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:05.987163067 CET | 50393 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:06.099972963 CET | 50396 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:06.100513935 CET | 50397 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:07.001123905 CET | 50393 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:07.110411882 CET | 50396 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:07.110421896 CET | 50397 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:09.001092911 CET | 50393 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:09.110553026 CET | 50396 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:09.110641956 CET | 50397 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:10.002002001 CET | 50452 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:10.117201090 CET | 50456 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:10.117883921 CET | 50457 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:11.016805887 CET | 50452 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:11.110445023 CET | 50456 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:11.110455036 CET | 50457 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:13.016756058 CET | 50452 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:13.110630035 CET | 50456 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:13.110630989 CET | 50457 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:14.002032042 CET | 50555 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:14.116729975 CET | 50559 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:14.117393970 CET | 50560 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:15.016726017 CET | 50555 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:15.126080036 CET | 50559 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:15.126080036 CET | 50560 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:17.016719103 CET | 50555 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:17.126133919 CET | 50560 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:17.126200914 CET | 50559 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:18.022039890 CET | 50650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:18.134448051 CET | 50654 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:18.134533882 CET | 50655 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:19.032381058 CET | 50650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:19.141714096 CET | 50655 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:19.141721964 CET | 50654 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:21.032349110 CET | 50650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:21.157393932 CET | 50655 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:21.159169912 CET | 50654 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:22.034920931 CET | 50820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:22.153125048 CET | 50828 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:22.153687000 CET | 50829 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:23.032393932 CET | 50820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:23.188607931 CET | 50829 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:23.189886093 CET | 50828 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:25.032401085 CET | 50820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:25.188607931 CET | 50829 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:25.188616037 CET | 50828 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:26.051171064 CET | 51035 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:26.237404108 CET | 51043 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:26.239666939 CET | 51044 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:27.079231977 CET | 51035 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:27.251101971 CET | 51043 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:27.391735077 CET | 51044 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:29.079251051 CET | 51035 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:29.266752005 CET | 51043 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:29.399588108 CET | 51044 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:30.168665886 CET | 51267 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:30.169061899 CET | 51268 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:30.647553921 CET | 51298 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:31.282362938 CET | 51267 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:31.282757998 CET | 51268 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:31.782365084 CET | 51298 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:33.289228916 CET | 51448 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:33.305258036 CET | 51450 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:33.309498072 CET | 51451 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:34.342844009 CET | 51448 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:34.391746998 CET | 51451 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:34.391820908 CET | 51450 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:36.391760111 CET | 51451 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:36.391772985 CET | 51450 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:36.487304926 CET | 51448 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:37.331753969 CET | 52264 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:37.458865881 CET | 52353 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:37.459856033 CET | 52354 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:38.376151085 CET | 52264 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:38.485522985 CET | 52353 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:38.579678059 CET | 52354 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:40.485533953 CET | 52264 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:40.485573053 CET | 52353 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:40.579309940 CET | 52354 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:41.354407072 CET | 54475 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:41.479357004 CET | 54525 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:41.481875896 CET | 54526 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:42.376142979 CET | 54475 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:42.486022949 CET | 54526 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:42.579286098 CET | 54525 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:44.376147985 CET | 54475 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:44.487242937 CET | 54526 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:44.579406023 CET | 54525 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:45.480082989 CET | 57083 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:45.481848955 CET | 57085 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:45.482141972 CET | 57086 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:46.485570908 CET | 57086 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:46.579299927 CET | 57083 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:46.579668999 CET | 57085 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:48.490139961 CET | 57086 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:48.579298973 CET | 57083 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:48.579298973 CET | 57085 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:49.487488985 CET | 59733 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:49.606384993 CET | 59827 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:49.609586954 CET | 59828 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:50.594918966 CET | 59733 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:50.594973087 CET | 59828 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:50.688668013 CET | 59827 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:52.688692093 CET | 59733 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:52.688698053 CET | 59828 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:52.688775063 CET | 59827 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:53.502202988 CET | 62592 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:53.633871078 CET | 62644 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:53.636389971 CET | 62646 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:54.688687086 CET | 62592 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:54.688776016 CET | 62646 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:54.688776970 CET | 62644 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:56.688708067 CET | 62592 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:56.688782930 CET | 62646 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:56.688781023 CET | 62644 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:57.503460884 CET | 64939 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:57.619721889 CET | 65000 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:57.620663881 CET | 65001 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:26:58.579349995 CET | 64939 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:58.688714027 CET | 65000 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:26:58.688723087 CET | 65001 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:00.688707113 CET | 64939 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:00.688729048 CET | 65000 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:00.688729048 CET | 65001 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:01.518512964 CET | 51280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:01.633598089 CET | 51385 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:01.637638092 CET | 51387 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:02.579363108 CET | 51280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:02.688705921 CET | 51385 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:02.688709021 CET | 51387 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:04.579341888 CET | 51280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:04.688705921 CET | 51385 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:04.688724995 CET | 51387 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:05.519896030 CET | 53282 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:05.639990091 CET | 53342 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:05.693483114 CET | 53385 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:06.579467058 CET | 53282 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:06.688720942 CET | 53342 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:06.876663923 CET | 53385 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:08.579668999 CET | 53282 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:08.691274881 CET | 53342 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:08.876363039 CET | 53385 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:09.534600973 CET | 56273 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:09.662786961 CET | 56331 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:09.665492058 CET | 56333 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:10.579500914 CET | 56273 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:10.688755035 CET | 56333 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:10.688762903 CET | 56331 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:12.688757896 CET | 56273 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:12.688761950 CET | 56333 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:12.688766003 CET | 56331 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:13.550123930 CET | 59046 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:13.665581942 CET | 59091 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:13.667083979 CET | 59092 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:14.579478025 CET | 59046 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:14.688765049 CET | 59091 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:14.689791918 CET | 59092 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:16.579472065 CET | 59046 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:16.688816071 CET | 59092 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:16.782510996 CET | 59091 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:17.571221113 CET | 61468 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:17.684721947 CET | 61538 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:17.685092926 CET | 61539 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:18.581572056 CET | 61468 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:18.688780069 CET | 61538 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:18.688780069 CET | 61539 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:20.579550028 CET | 61468 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:20.688770056 CET | 61538 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:20.688805103 CET | 61539 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:21.584034920 CET | 64314 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:21.697453022 CET | 64340 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:21.699865103 CET | 64341 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:22.579834938 CET | 64314 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:22.688770056 CET | 64341 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:22.891901016 CET | 64340 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:24.688782930 CET | 64314 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:24.688782930 CET | 64341 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:24.891907930 CET | 64340 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:25.708920002 CET | 50715 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:25.711210966 CET | 50716 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:25.730297089 CET | 50719 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:26.876280069 CET | 50719 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:26.891935110 CET | 50715 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:26.891957045 CET | 50716 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:28.876291990 CET | 50719 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:28.891906023 CET | 50715 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:28.893352032 CET | 50716 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:29.706254959 CET | 53174 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:29.823767900 CET | 53241 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:29.828819036 CET | 53243 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:30.876286983 CET | 53241 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:30.876584053 CET | 53243 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:30.894825935 CET | 53174 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:32.876311064 CET | 53243 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:32.876310110 CET | 53241 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:33.079502106 CET | 53174 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:33.722116947 CET | 55701 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:33.842988968 CET | 55749 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:33.853442907 CET | 55756 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:34.876313925 CET | 55749 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:34.891946077 CET | 55701 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:34.891988039 CET | 55756 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:36.876482010 CET | 55749 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:36.891963005 CET | 55756 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:36.892138958 CET | 55701 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:37.737807989 CET | 58199 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:37.853638887 CET | 58255 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:37.855684042 CET | 58256 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:38.876311064 CET | 58255 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:38.891944885 CET | 58199 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:38.892086983 CET | 58256 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:40.879108906 CET | 58255 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:40.891974926 CET | 58199 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:40.891977072 CET | 58256 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:41.742420912 CET | 61154 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:41.854506969 CET | 61193 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:41.857969046 CET | 61194 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:42.876327038 CET | 61193 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:42.891963959 CET | 61154 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:42.895358086 CET | 61194 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:44.876343012 CET | 61193 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:44.891971111 CET | 61154 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:44.891973972 CET | 61194 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:45.753154993 CET | 63604 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:45.869000912 CET | 63650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:45.871989965 CET | 63651 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:46.782814026 CET | 63604 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:46.876339912 CET | 63650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:46.876442909 CET | 63651 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:48.787369013 CET | 63604 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:48.876368999 CET | 63650 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:48.879753113 CET | 63651 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:49.768950939 CET | 49759 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:49.885262012 CET | 49810 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:49.887161016 CET | 49811 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:50.892050982 CET | 49759 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:50.985714912 CET | 49810 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:50.985944033 CET | 49811 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:52.891973019 CET | 49759 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:52.985709906 CET | 49810 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:52.985723019 CET | 49811 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:53.785599947 CET | 52025 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:53.979168892 CET | 52058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:53.983279943 CET | 52060 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:54.891977072 CET | 52025 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:54.985748053 CET | 52058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:54.985837936 CET | 52060 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:56.892059088 CET | 52025 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:56.985723972 CET | 52058 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:56.988734961 CET | 52060 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:57.809887886 CET | 54186 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:57.935857058 CET | 54196 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:57.943892002 CET | 54198 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:27:58.893523932 CET | 54186 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:58.985755920 CET | 54196 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:27:58.985759020 CET | 54198 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:00.895406961 CET | 54186 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:00.985743999 CET | 54196 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:00.986145020 CET | 54198 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:01.818099022 CET | 56776 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:01.932241917 CET | 56820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:01.935075998 CET | 56821 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:02.883416891 CET | 56776 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:03.079662085 CET | 56821 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:03.079663992 CET | 56820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:04.876396894 CET | 56776 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:05.079550028 CET | 56820 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:05.079616070 CET | 56821 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:05.836056948 CET | 59032 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:05.959243059 CET | 59077 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:05.964421034 CET | 59078 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:06.892033100 CET | 59032 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:06.987431049 CET | 59078 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:07.083461046 CET | 59077 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:08.892007113 CET | 59032 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:08.985789061 CET | 59078 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:09.188894033 CET | 59077 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:09.841046095 CET | 61280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:09.961762905 CET | 61388 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:10.892193079 CET | 61280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:10.985776901 CET | 61388 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:12.892016888 CET | 61280 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:12.985788107 CET | 61388 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:13.847321987 CET | 59350 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:13.973267078 CET | 59429 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:14.892014027 CET | 59350 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:15.095474958 CET | 59429 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:16.892029047 CET | 59350 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:17.095176935 CET | 59429 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:17.871402025 CET | 61975 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:18.380880117 CET | 61978 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:18.892025948 CET | 61975 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:19.392050982 CET | 61978 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:20.574270010 CET | 63061 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:20.892103910 CET | 61975 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:21.392050028 CET | 61978 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:21.579560995 CET | 63061 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:21.875798941 CET | 63697 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:21.994311094 CET | 63768 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:21.994909048 CET | 63769 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:22.907994032 CET | 63697 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:23.079560041 CET | 63768 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:23.080167055 CET | 63769 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:25.019185066 CET | 63697 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:25.079544067 CET | 63768 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:25.079560995 CET | 63769 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:25.878392935 CET | 49160 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:26.017760992 CET | 49254 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:26.019459009 CET | 49255 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:26.892057896 CET | 49160 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:27.138370037 CET | 49254 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:27.138442039 CET | 49255 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:28.892065048 CET | 49160 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:29.149811983 CET | 49254 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:29.149903059 CET | 49255 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:29.924071074 CET | 51840 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:30.040077925 CET | 51877 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:30.041276932 CET | 51879 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:31.079632998 CET | 51877 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:31.079633951 CET | 51840 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:31.079709053 CET | 51879 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:33.079588890 CET | 51877 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:33.079597950 CET | 51879 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:33.113887072 CET | 51840 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:33.943373919 CET | 54552 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:34.056288958 CET | 54679 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:34.056289911 CET | 54680 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:34.985831976 CET | 54552 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:35.079586983 CET | 54679 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:35.079612017 CET | 54680 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:36.985846043 CET | 54552 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:37.079605103 CET | 54679 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:37.079618931 CET | 54680 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:37.956382036 CET | 57187 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:38.084666967 CET | 57240 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:38.084669113 CET | 57242 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:38.985863924 CET | 57187 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:39.087794065 CET | 57240 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:39.087802887 CET | 57242 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:40.985831976 CET | 57187 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:41.152759075 CET | 57240 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:41.152913094 CET | 57242 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:42.045383930 CET | 58891 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:42.324048996 CET | 58894 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:42.324541092 CET | 58895 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:43.079623938 CET | 58891 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:43.392088890 CET | 58894 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:43.392098904 CET | 58895 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:45.079659939 CET | 58891 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:45.392220020 CET | 58894 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:45.392225027 CET | 58895 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:49.079623938 CET | 58891 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:49.392111063 CET | 58894 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:49.392184973 CET | 58895 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:57.079668045 CET | 58891 | 23588 | 192.168.2.8 | 107.160.131.254 |
Nov 19, 2024 14:28:57.392128944 CET | 58894 | 80 | 192.168.2.8 | 202.108.0.52 |
Nov 19, 2024 14:28:57.393249989 CET | 58895 | 23588 | 192.168.2.8 | 107.160.131.254 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 19, 2024 14:25:02.682295084 CET | 61561 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:02.689649105 CET | 53 | 61561 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:07.439935923 CET | 57022 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:07.448739052 CET | 53 | 57022 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:08.844156981 CET | 59402 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:08.851649046 CET | 53 | 59402 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:12.424705982 CET | 60275 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:12.927687883 CET | 53 | 60275 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:17.460808039 CET | 52991 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:17.468424082 CET | 53 | 52991 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:22.455702066 CET | 60711 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:22.463224888 CET | 53 | 60711 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:27.518908024 CET | 51252 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:27.526247025 CET | 53 | 51252 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:30.001863956 CET | 53239 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:30.322807074 CET | 53 | 53239 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:32.443738937 CET | 64770 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:32.451770067 CET | 53 | 64770 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:37.533169031 CET | 59582 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:38.046952963 CET | 53 | 59582 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:42.439436913 CET | 64357 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:42.447223902 CET | 53 | 64357 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:47.486337900 CET | 63486 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:47.493582964 CET | 53 | 63486 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:52.471498013 CET | 56591 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:52.479806900 CET | 53 | 56591 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:25:57.455539942 CET | 49932 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:25:57.462965012 CET | 53 | 49932 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:02.468851089 CET | 54461 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:02.476084948 CET | 53 | 54461 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:07.424005985 CET | 51684 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:07.967272997 CET | 53 | 51684 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:12.528201103 CET | 56158 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:12.535715103 CET | 53 | 56158 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:17.432022095 CET | 53253 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:17.439743996 CET | 53 | 53253 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:22.426475048 CET | 63557 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:22.433978081 CET | 53 | 63557 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:27.425965071 CET | 54117 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:27.434043884 CET | 53 | 54117 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:30.168071985 CET | 51835 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:30.646616936 CET | 53 | 51835 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:32.432154894 CET | 63013 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:32.439722061 CET | 53 | 63013 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:37.426999092 CET | 63081 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:37.434618950 CET | 53 | 63081 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:42.427570105 CET | 65056 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:42.437283993 CET | 53 | 65056 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:47.424005032 CET | 62102 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:47.431242943 CET | 53 | 62102 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:52.437810898 CET | 54386 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:52.446202993 CET | 53 | 54386 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:26:57.423410892 CET | 58306 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:26:57.430773020 CET | 53 | 58306 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:02.435044050 CET | 57071 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:02.442382097 CET | 53 | 57071 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:07.423933983 CET | 60156 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:07.431350946 CET | 53 | 60156 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:12.424355984 CET | 62615 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:12.431884050 CET | 53 | 62615 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:17.480093956 CET | 62247 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:17.487660885 CET | 53 | 62247 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:22.423556089 CET | 63585 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:22.431140900 CET | 53 | 63585 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:27.425457954 CET | 57524 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:27.433211088 CET | 53 | 57524 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:32.425044060 CET | 51844 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:32.432256937 CET | 53 | 51844 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:33.844614029 CET | 49710 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:33.852269888 CET | 53 | 49710 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:37.429163933 CET | 52470 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:37.436516047 CET | 53 | 52470 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:42.424137115 CET | 63749 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:42.973465919 CET | 53 | 63749 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:47.427387953 CET | 53177 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:47.436167955 CET | 53 | 53177 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:52.425645113 CET | 58124 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:52.540406942 CET | 53 | 58124 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:27:57.424582958 CET | 58525 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:27:57.431771994 CET | 53 | 58525 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:02.423815012 CET | 63086 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:02.432440042 CET | 53 | 63086 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:07.451950073 CET | 63968 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:07.459525108 CET | 53 | 63968 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:09.964345932 CET | 62800 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:09.986568928 CET | 62800 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:09.993688107 CET | 53 | 62800 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:10.437556982 CET | 53 | 62800 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:12.424608946 CET | 64072 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:12.431502104 CET | 53 | 64072 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:17.423834085 CET | 63188 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:17.454699039 CET | 63188 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:17.935024977 CET | 53 | 63188 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:17.935071945 CET | 53 | 63188 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:20.149029970 CET | 58800 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:20.174072981 CET | 58800 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:20.565541983 CET | 53 | 58800 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:20.565623999 CET | 53 | 58800 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:22.424654007 CET | 59162 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:22.454890966 CET | 59162 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:23.611974955 CET | 59162 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:23.952347040 CET | 53 | 59162 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:23.952363968 CET | 53 | 59162 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:23.952373028 CET | 53 | 59162 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:27.423804998 CET | 56893 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:27.431349993 CET | 53 | 56893 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:32.424931049 CET | 58113 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:32.432806969 CET | 53 | 58113 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:37.425646067 CET | 50006 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:37.455241919 CET | 50006 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:37.947464943 CET | 53 | 50006 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:37.947490931 CET | 53 | 50006 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:42.516774893 CET | 65158 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:42.551462889 CET | 65158 | 53 | 192.168.2.8 | 1.1.1.1 |
Nov 19, 2024 14:28:43.032388926 CET | 53 | 65158 | 1.1.1.1 | 192.168.2.8 |
Nov 19, 2024 14:28:43.032435894 CET | 53 | 65158 | 1.1.1.1 | 192.168.2.8 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 19, 2024 14:25:02.682295084 CET | 192.168.2.8 | 1.1.1.1 | 0x931f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:07.439935923 CET | 192.168.2.8 | 1.1.1.1 | 0x6294 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:08.844156981 CET | 192.168.2.8 | 1.1.1.1 | 0xda9f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:12.424705982 CET | 192.168.2.8 | 1.1.1.1 | 0xd3bd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:17.460808039 CET | 192.168.2.8 | 1.1.1.1 | 0xaa20 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:22.455702066 CET | 192.168.2.8 | 1.1.1.1 | 0xe791 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:27.518908024 CET | 192.168.2.8 | 1.1.1.1 | 0x546d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:30.001863956 CET | 192.168.2.8 | 1.1.1.1 | 0xa115 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:32.443738937 CET | 192.168.2.8 | 1.1.1.1 | 0x5527 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:37.533169031 CET | 192.168.2.8 | 1.1.1.1 | 0xfc96 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:42.439436913 CET | 192.168.2.8 | 1.1.1.1 | 0xc200 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:47.486337900 CET | 192.168.2.8 | 1.1.1.1 | 0xa38c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:52.471498013 CET | 192.168.2.8 | 1.1.1.1 | 0x444f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:57.455539942 CET | 192.168.2.8 | 1.1.1.1 | 0xa039 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:02.468851089 CET | 192.168.2.8 | 1.1.1.1 | 0x5e9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:07.424005985 CET | 192.168.2.8 | 1.1.1.1 | 0x4c6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:12.528201103 CET | 192.168.2.8 | 1.1.1.1 | 0x1675 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:17.432022095 CET | 192.168.2.8 | 1.1.1.1 | 0xfa92 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:22.426475048 CET | 192.168.2.8 | 1.1.1.1 | 0xd09c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:27.425965071 CET | 192.168.2.8 | 1.1.1.1 | 0xbf37 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:30.168071985 CET | 192.168.2.8 | 1.1.1.1 | 0x4b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:32.432154894 CET | 192.168.2.8 | 1.1.1.1 | 0x7bb8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:37.426999092 CET | 192.168.2.8 | 1.1.1.1 | 0x1449 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:42.427570105 CET | 192.168.2.8 | 1.1.1.1 | 0x1db2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:47.424005032 CET | 192.168.2.8 | 1.1.1.1 | 0x563a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:52.437810898 CET | 192.168.2.8 | 1.1.1.1 | 0x6ffd | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:57.423410892 CET | 192.168.2.8 | 1.1.1.1 | 0x8e10 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:02.435044050 CET | 192.168.2.8 | 1.1.1.1 | 0x374f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:07.423933983 CET | 192.168.2.8 | 1.1.1.1 | 0xd437 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:12.424355984 CET | 192.168.2.8 | 1.1.1.1 | 0xa916 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:17.480093956 CET | 192.168.2.8 | 1.1.1.1 | 0x11fa | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:22.423556089 CET | 192.168.2.8 | 1.1.1.1 | 0x2fbe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:27.425457954 CET | 192.168.2.8 | 1.1.1.1 | 0xda4a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:32.425044060 CET | 192.168.2.8 | 1.1.1.1 | 0x3f00 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:33.844614029 CET | 192.168.2.8 | 1.1.1.1 | 0xca17 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:37.429163933 CET | 192.168.2.8 | 1.1.1.1 | 0xd739 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:42.424137115 CET | 192.168.2.8 | 1.1.1.1 | 0xe3c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:47.427387953 CET | 192.168.2.8 | 1.1.1.1 | 0x9e02 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:52.425645113 CET | 192.168.2.8 | 1.1.1.1 | 0x7a18 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:57.424582958 CET | 192.168.2.8 | 1.1.1.1 | 0x9d95 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:02.423815012 CET | 192.168.2.8 | 1.1.1.1 | 0x4638 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:07.451950073 CET | 192.168.2.8 | 1.1.1.1 | 0x9830 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:09.964345932 CET | 192.168.2.8 | 1.1.1.1 | 0x566 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:09.986568928 CET | 192.168.2.8 | 1.1.1.1 | 0x566 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:12.424608946 CET | 192.168.2.8 | 1.1.1.1 | 0x15a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:17.423834085 CET | 192.168.2.8 | 1.1.1.1 | 0x3434 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:17.454699039 CET | 192.168.2.8 | 1.1.1.1 | 0x3434 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:20.149029970 CET | 192.168.2.8 | 1.1.1.1 | 0x7e0d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:20.174072981 CET | 192.168.2.8 | 1.1.1.1 | 0x7e0d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:22.424654007 CET | 192.168.2.8 | 1.1.1.1 | 0x1bde | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:22.454890966 CET | 192.168.2.8 | 1.1.1.1 | 0x1bde | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:23.611974955 CET | 192.168.2.8 | 1.1.1.1 | 0x1bde | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:27.423804998 CET | 192.168.2.8 | 1.1.1.1 | 0xff5c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:32.424931049 CET | 192.168.2.8 | 1.1.1.1 | 0x1ef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:37.425646067 CET | 192.168.2.8 | 1.1.1.1 | 0xba38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:37.455241919 CET | 192.168.2.8 | 1.1.1.1 | 0xba38 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:42.516774893 CET | 192.168.2.8 | 1.1.1.1 | 0xc19e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:42.551462889 CET | 192.168.2.8 | 1.1.1.1 | 0xc19e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 19, 2024 14:25:02.689649105 CET | 1.1.1.1 | 192.168.2.8 | 0x931f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:07.448739052 CET | 1.1.1.1 | 192.168.2.8 | 0x6294 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:08.851649046 CET | 1.1.1.1 | 192.168.2.8 | 0xda9f | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:25:08.851649046 CET | 1.1.1.1 | 192.168.2.8 | 0xda9f | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:25:12.927687883 CET | 1.1.1.1 | 192.168.2.8 | 0xd3bd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:17.468424082 CET | 1.1.1.1 | 192.168.2.8 | 0xaa20 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:22.463224888 CET | 1.1.1.1 | 192.168.2.8 | 0xe791 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:27.526247025 CET | 1.1.1.1 | 192.168.2.8 | 0x546d | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:30.322807074 CET | 1.1.1.1 | 192.168.2.8 | 0xa115 | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:25:30.322807074 CET | 1.1.1.1 | 192.168.2.8 | 0xa115 | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:25:32.451770067 CET | 1.1.1.1 | 192.168.2.8 | 0x5527 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:38.046952963 CET | 1.1.1.1 | 192.168.2.8 | 0xfc96 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:42.447223902 CET | 1.1.1.1 | 192.168.2.8 | 0xc200 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:47.493582964 CET | 1.1.1.1 | 192.168.2.8 | 0xa38c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:52.479806900 CET | 1.1.1.1 | 192.168.2.8 | 0x444f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:25:57.462965012 CET | 1.1.1.1 | 192.168.2.8 | 0xa039 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:02.476084948 CET | 1.1.1.1 | 192.168.2.8 | 0x5e9e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:07.967272997 CET | 1.1.1.1 | 192.168.2.8 | 0x4c6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:12.535715103 CET | 1.1.1.1 | 192.168.2.8 | 0x1675 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:17.439743996 CET | 1.1.1.1 | 192.168.2.8 | 0xfa92 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:22.433978081 CET | 1.1.1.1 | 192.168.2.8 | 0xd09c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:27.434043884 CET | 1.1.1.1 | 192.168.2.8 | 0xbf37 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:30.646616936 CET | 1.1.1.1 | 192.168.2.8 | 0x4b6 | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:26:30.646616936 CET | 1.1.1.1 | 192.168.2.8 | 0x4b6 | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:26:32.439722061 CET | 1.1.1.1 | 192.168.2.8 | 0x7bb8 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:37.434618950 CET | 1.1.1.1 | 192.168.2.8 | 0x1449 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:42.437283993 CET | 1.1.1.1 | 192.168.2.8 | 0x1db2 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:47.431242943 CET | 1.1.1.1 | 192.168.2.8 | 0x563a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:52.446202993 CET | 1.1.1.1 | 192.168.2.8 | 0x6ffd | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:26:57.430773020 CET | 1.1.1.1 | 192.168.2.8 | 0x8e10 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:02.442382097 CET | 1.1.1.1 | 192.168.2.8 | 0x374f | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:07.431350946 CET | 1.1.1.1 | 192.168.2.8 | 0xd437 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:12.431884050 CET | 1.1.1.1 | 192.168.2.8 | 0xa916 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:17.487660885 CET | 1.1.1.1 | 192.168.2.8 | 0x11fa | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:22.431140900 CET | 1.1.1.1 | 192.168.2.8 | 0x2fbe | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:27.433211088 CET | 1.1.1.1 | 192.168.2.8 | 0xda4a | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:32.432256937 CET | 1.1.1.1 | 192.168.2.8 | 0x3f00 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:33.852269888 CET | 1.1.1.1 | 192.168.2.8 | 0xca17 | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:27:33.852269888 CET | 1.1.1.1 | 192.168.2.8 | 0xca17 | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:27:37.436516047 CET | 1.1.1.1 | 192.168.2.8 | 0xd739 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:42.973465919 CET | 1.1.1.1 | 192.168.2.8 | 0xe3c1 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:47.436167955 CET | 1.1.1.1 | 192.168.2.8 | 0x9e02 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:52.540406942 CET | 1.1.1.1 | 192.168.2.8 | 0x7a18 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:27:57.431771994 CET | 1.1.1.1 | 192.168.2.8 | 0x9d95 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:02.432440042 CET | 1.1.1.1 | 192.168.2.8 | 0x4638 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:07.459525108 CET | 1.1.1.1 | 192.168.2.8 | 0x9830 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:10.437556982 CET | 1.1.1.1 | 192.168.2.8 | 0x566 | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:10.437556982 CET | 1.1.1.1 | 192.168.2.8 | 0x566 | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:12.431502104 CET | 1.1.1.1 | 192.168.2.8 | 0x15a6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:17.935024977 CET | 1.1.1.1 | 192.168.2.8 | 0x3434 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:17.935071945 CET | 1.1.1.1 | 192.168.2.8 | 0x3434 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:20.565541983 CET | 1.1.1.1 | 192.168.2.8 | 0x7e0d | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:20.565541983 CET | 1.1.1.1 | 192.168.2.8 | 0x7e0d | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:20.565623999 CET | 1.1.1.1 | 192.168.2.8 | 0x7e0d | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:20.565623999 CET | 1.1.1.1 | 192.168.2.8 | 0x7e0d | No error (0) | 202.108.0.52 | A (IP address) | IN (0x0001) | false | ||
Nov 19, 2024 14:28:23.952347040 CET | 1.1.1.1 | 192.168.2.8 | 0x1bde | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:23.952363968 CET | 1.1.1.1 | 192.168.2.8 | 0x1bde | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:23.952373028 CET | 1.1.1.1 | 192.168.2.8 | 0x1bde | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:27.431349993 CET | 1.1.1.1 | 192.168.2.8 | 0xff5c | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:32.432806969 CET | 1.1.1.1 | 192.168.2.8 | 0x1ef | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:37.947464943 CET | 1.1.1.1 | 192.168.2.8 | 0xba38 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:37.947490931 CET | 1.1.1.1 | 192.168.2.8 | 0xba38 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:43.032388926 CET | 1.1.1.1 | 192.168.2.8 | 0xc19e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Nov 19, 2024 14:28:43.032435894 CET | 1.1.1.1 | 192.168.2.8 | 0xc19e | Name error (3) | none | none | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\loaddll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x170000 |
File size: | 126'464 bytes |
MD5 hash: | 51E6071F9CBA48E79F10C84515AAE618 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 2 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa40000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa40000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 08:24:36 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc80000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 08:24:39 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 08:24:42 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 08:24:42 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x90000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa40000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x90000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 24 |
Start time: | 08:24:45 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc80000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 26 |
Start time: | 08:25:08 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 08:25:09 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa40000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 28 |
Start time: | 08:25:09 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 29 |
Start time: | 08:25:09 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc80000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 30 |
Start time: | 08:25:16 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x5d0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 31 |
Start time: | 08:25:17 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa40000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 32 |
Start time: | 08:25:17 |
Start date: | 19/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ee680000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 33 |
Start time: | 08:25:17 |
Start date: | 19/11/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc80000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 11.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 7.9% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 02450C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02450CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02450D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 024514C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02450063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0245002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 024500CD Relevance: .8, Instructions: 823COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.1% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 026B0C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 026B0CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 026B0D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 026B14C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 026B0063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 026B002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 4.5% |
Dynamic/Decrypted Code Coverage: | 11% |
Signature Coverage: | 1.1% |
Total number of Nodes: | 282 |
Total number of Limit Nodes: | 12 |
Graph
Control-flow Graph
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FB7 Relevance: 1.5, APIs: 1, Instructions: 4processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006EDE Relevance: 21.2, APIs: 5, Strings: 7, Instructions: 174sleepfileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006499 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 272timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03390C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03390CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 116timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03390D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 72timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 145sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 58sleepthreadCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008567 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 79sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000841C Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 119sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10007101 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 95sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100081F7 Relevance: 3.0, APIs: 1, Strings: 1, Instructions: 48sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 033914C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03390063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F0A Relevance: 1.5, APIs: 1, Instructions: 10networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FF7 Relevance: 1.5, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004104 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004115 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000400A Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004092 Relevance: 1.5, APIs: 1, Instructions: 3registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003EB4 Relevance: 1.5, APIs: 1, Instructions: 3networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F72 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0339002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F63 Relevance: 1.5, APIs: 1, Instructions: 4shutdownCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008AAD Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1001E1FE Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 102filethreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 179sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004351 Relevance: 9.1, APIs: 2, Strings: 4, Instructions: 64sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100087F4 Relevance: 6.0, APIs: 2, Strings: 2, Instructions: 32sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.3% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 04710C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04710CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04710D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 047114C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04710063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0471002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000CCF2 Relevance: 1.3, Strings: 1, Instructions: 2COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006EDE Relevance: 21.2, APIs: 5, Strings: 7, Instructions: 174sleepfileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 102filethreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 179sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006499 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 272timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 116timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 145sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 58sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008567 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 79sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000841C Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 119sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.4% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 03060C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03060CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03060D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030614C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03060063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0306002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 049C0C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049C0CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049C0D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049C14C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049C0063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049C002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 1.3% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 31 |
Total number of Limit Nodes: | 2 |
Graph
Function 04940C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04940CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04940D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 049414C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04940063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0494002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006EDE Relevance: 21.2, APIs: 5, Strings: 7, Instructions: 174sleepfileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 102filethreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 179sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006499 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 272timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 116timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 145sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 58sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008567 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 79sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000841C Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 119sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 63 |
Total number of Limit Nodes: | 3 |
Graph
Callgraph
Function 02D90C8D Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 179memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D90CF9 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 136memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D90D32 Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 115memorywindowCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D914C0 Relevance: 3.0, APIs: 2, Instructions: 35memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D90063 Relevance: 2.6, APIs: 2, Instructions: 50memoryCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02D9002A Relevance: 1.3, APIs: 1, Instructions: 39COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|