Windows
Analysis Report
Salary 2025- workers-v1.xls
Overview
General Information
Detection
Score: | 52 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- EXCEL.EXE (PID: 5452 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" "C:\ Users\user \Desktop\S alary 2025 - workers- v1.xls" MD5: 4A871771235598812032C822E6F68F19) - splwow64.exe (PID: 4592 cmdline:
C:\Windows \splwow64. exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
- cleanup
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T09:18:18.089586+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.16 | 49716 | 13.107.246.42 | 443 | TCP |
2024-11-20T09:18:22.918256+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.16 | 49717 | 13.107.246.42 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Joe Sandbox ML: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Memory has grown: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | OLE, VBA macro line: | |||
Source: | OLE, VBA macro line: |
Source: | OLE indicator, VBA macros: | ||
Source: | OLE indicator, VBA macros: |
Source: | OLE stream indicators for Word, Excel, PowerPoint, and Visio: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: | ||
Source: | OLE indicator, Workbook stream: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 2 Scripting | Valid Accounts | 2 Exploitation for Client Execution | 2 Scripting | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Extra Window Memory Injection | 1 Virtualization/Sandbox Evasion | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Extra Window Memory Injection | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 2 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 1 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/Macro.Downloader.MRACS.Gen | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0014.t-0009.t-msedge.net | 13.107.246.42 | true | false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.107.246.42 | s-part-0014.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1559179 |
Start date and time: | 2024-11-20 09:16:42 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 14 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Salary 2025- workers-v1.xls |
Detection: | MAL |
Classification: | mal52.winXLS@3/4@0/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.109.32.97, 52.109.28.47, 52.113.194.132, 184.28.90.27, 13.89.179.8
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, eur.roaming1.live.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, ukw-azsc-config.officeapps.live.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, osiprod-uks-buff-azsc-000.uksouth.cloudapp.azure.com, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, uks-azsc-000.roaming.officeapps.live.com, s-0005.s-msedge.net, config.officeapps.live.com, onedscolprdcus06.centralus.cloudapp.azure.com, azureedge-t-prod.trafficmanager.net, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.n
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: Salary 2025- workers-v1.xls
Time | Type | Description |
---|---|---|
03:18:32 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
13.107.246.42 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0014.t-0009.t-msedge.net | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | HtmlDropper, HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 3.12078184246611 |
Encrypted: | false |
SSDEEP: | 96:MlHY1GpNnyn3ajMDxZoPay/9beX98Qy1vDp+fp4YgA6PrYhZ9p6Ka7is:MlzytCDRC+Sl6PUhTAKa |
MD5: | 50F83308869E593040C36F7BB477E559 |
SHA1: | E60766ADF2F3883DA5114FF664D2B77BCAB0E198 |
SHA-256: | 0E8B54B36E1DBDC206D1BAB37E17CDDEC0BA764818E68905275C744C72232E46 |
SHA-512: | E970288A8E0EF225934A0C54B49A1C42E826CF62C029184223F55563DD12D8D426BE1701E8E8015C63B5EBDE74CE4CCC93AB499D0EB283F26A22A192EB38C9B5 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 2.3470112157064933 |
Encrypted: | false |
SSDEEP: | 192:jvKruKW9J43AgdLSUX7qIF4kBez2CWeXjV1RKjc1uHQJib0tG/9gpUOgGMb9H39T:zKrDFhF4PnuTWCGt |
MD5: | 92D85E1B6A3465F0170B75D492EAAA74 |
SHA1: | 814183DA7E9D34A1750B13AA25BF69F4DB7FC8F7 |
SHA-256: | 4F6CCFB8CF96E8558BF8EC13656BE3D79F1B0A15997F3979A3CE6FE549E0A27F |
SHA-512: | F70C70F3A0CC56DDDB7E77CB66E59D20A4B59E186341470238986C22A2538F1861698BB27580D5D486C4692F3F6AD7A43EE74646F141C50A6625C7E50E4FD7DF |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 128000 |
Entropy (8bit): | 4.772147427746537 |
Encrypted: | false |
SSDEEP: | 3072:yCzbkJxEtjPOtioVjDGUU1qfDlaGGx+cx18gUsAeHSwpbNXnLwGyjsCHVwOu4AXS:wxEtjPOtioVjDGUU1qfDlavx+818gUsE |
MD5: | DA370E238F05B56EE96BFF20C28DAB53 |
SHA1: | 8AD4472721DCE0DAE7A1E0732BAE6F9DF6493A60 |
SHA-256: | F6D7F10348EC09341AEAF6F346E81A1BE09B210F241AAD9F4C71490AED13FF79 |
SHA-512: | 6A11DFC830E05CD423149E6D2FF20B361F6E1A0D9510F41EFF96D5DC4AA167B2B037EF010D8991C691195B8BA6947581843BFC1B475098B087E8336BA89D3859 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.3520167401771568 |
Encrypted: | false |
SSDEEP: | 3:8Nultln:X1n |
MD5: | 9AC4D67F6E514F452D4A1DB79CE3B2E8 |
SHA1: | 33F8C665ECBB81275D2E49D48F2565A58A282043 |
SHA-256: | 407E1D871964C93DBDBD4D00613CD0A9E30D3ED6352D8052C58E7A252D52FC5A |
SHA-512: | 018D0F54AB0AB01F27E9FB870A128F2F581A58487399DD7FB56A94EC4AAEC6874708A5AD5650F362485E45E2C6A557ED08524C5B8335F83F240E0962281A0F1A |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 4.776274699794475 |
TrID: |
|
File name: | Salary 2025- workers-v1.xls |
File size: | 124'416 bytes |
MD5: | db0d2d8342343528bb33649e91bb6f3d |
SHA1: | 7e00d44d5b05912a2e42c5408fefed8396710b24 |
SHA256: | abd87359790b24e8ac8464d3af8688b08248ca84c14dd97f1b6f33e8c297a3b8 |
SHA512: | fb842d348c99fc2a5a995f2ab9f37de69c05177acfe4a360367b7c2a46f192e0b96c453ef45a98a305e50ecf53d48efe79935e5d5a1f8d537b7371acddcd5f8b |
SSDEEP: | 3072:iKrDS+xEtjPOtioVjDGUU1qfDlaGGx+cx18gUsAeeSwpbNXnLwHMj2iGOPdLimAH:hxEtjPOtioVjDGUU1qfDlavx+818gUsZ |
TLSH: | A1C3A652F79B8C88F969C73ABDD707606731EC91ABB29307638873185EB79805A33741 |
File Content Preview: | ........................>.......................................................b.............................................................................................................................................................................. |
Icon Hash: | 35ed8e920e8c81b5 |
Document Type: | OLE |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | Microsoft Excel |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | True |
Code Page: | 1258 |
Author: | |
Last Saved By: | |
Create Time: | 2021-01-11 08:46:49 |
Last Saved Time: | 2024-11-20 08:05:33 |
Creating Application: | |
Security: | 0 |
Document Code Page: | 1258 |
Thumbnail Scaling Desired: | False |
Contains Dirty Links: | False |
Shared Document: | False |
Changed Hyperlinks: | False |
Application Version: | 1048576 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/Kangatang |
VBA File Name: | Kangatang |
Stream Size: | 2955 |
Data ASCII: | . . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . 1 n . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . M E . . . . . . . . . . . . . . . . . . . . . P . . . . . 6 . . . . . . . . . . . . . . . . . L . . . . . L . . . . . L . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 01 16 01 00 06 f0 00 00 00 bc 04 00 00 d4 00 00 00 d8 01 00 00 ff ff ff ff 7b 05 00 00 87 09 00 00 01 00 00 00 01 00 00 00 31 a8 6e bd 00 00 ff ff 03 00 00 00 00 00 00 00 b6 00 ff ff 01 01 00 00 00 00 ff ff ff ff 00 00 00 00 ff ff 04 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 |
|
General | |
Stream Path: | \x1CompObj |
CLSID: | |
File Type: | data |
Stream Size: | 108 |
Entropy: | 4.188499988527259 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . . . . . . . . . . F . . . . M i c r o s o f t E x c e l 2 0 0 3 W o r k s h e e t . . . . . B i f f 8 . . . . . E x c e l . S h e e t . 8 . 9 q . . . . . . . . . . . . |
Data Raw: | 01 00 fe ff 03 0a 00 00 ff ff ff ff 20 08 02 00 00 00 00 00 c0 00 00 00 00 00 00 46 20 00 00 00 1e 4d 69 63 72 6f 73 6f 66 74 20 45 78 63 65 6c 20 32 30 30 33 20 57 6f 72 6b 73 68 65 65 74 00 06 00 00 00 42 69 66 66 38 00 0e 00 00 00 45 78 63 65 6c 2e 53 68 65 65 74 2e 38 00 f4 39 b2 71 00 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | \x5DocumentSummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 236 |
Entropy: | 2.7640880482745716 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . + , 0 . . . . . . . . . . . . . . H . . . . . . . P . . . . . . . X . . . . . . . ` . . . . . . . h . . . . . . . p . . . . . . . x . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S h e e t 1 . . . . . S h e e t 3 . . . . . . . . . . . . . . . . . W o r k s h e e t s . . . . . . . . . . . . |
Data Raw: | fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 02 d5 cd d5 9c 2e 1b 10 93 97 08 00 2b 2c f9 ae 30 00 00 00 bc 00 00 00 08 00 00 00 01 00 00 00 48 00 00 00 17 00 00 00 50 00 00 00 0b 00 00 00 58 00 00 00 10 00 00 00 60 00 00 00 13 00 00 00 68 00 00 00 16 00 00 00 70 00 00 00 0d 00 00 00 78 00 00 00 0c 00 00 00 96 00 00 00 02 00 00 00 ea 04 00 00 |
General | |
Stream Path: | \x5SummaryInformation |
CLSID: | |
File Type: | data |
Stream Size: | 216 |
Entropy: | 3.721686438120175 |
Base64 Encoded: | False |
Data ASCII: | . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . + ' 0 . . . . . . . . . . . . . . @ . . . . . . . H . . . . . . . \\ . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . S M & Y o u . . . . . . . . . . . . T H A N G U Y E N . . . . . . . . . . M i c r o s o f t E x c e l . @ . . . L . @ . . . " ; . . . . . . . . . |
Data Raw: | fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 a8 00 00 00 07 00 00 00 01 00 00 00 40 00 00 00 04 00 00 00 48 00 00 00 08 00 00 00 5c 00 00 00 12 00 00 00 70 00 00 00 0c 00 00 00 88 00 00 00 0d 00 00 00 94 00 00 00 13 00 00 00 a0 00 00 00 02 00 00 00 ea 04 00 00 1e 00 00 00 0c 00 00 00 |
General | |
Stream Path: | Workbook |
CLSID: | |
File Type: | Applesoft BASIC program data, first line number 16 |
Stream Size: | 109758 |
Entropy: | 4.820077150727378 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . Z O . . . . . . . . . . . . . . . . . . . . \\ . p . . . . T H A N G U Y E N B . . . . a . . . . . . . . = . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . = . . . . P . P 8 " 8 . . . . . . . X . @ . . . . . . . . . . " . . . . . . . . . . . . . . . . . . |
Data Raw: | 09 08 10 00 00 06 05 00 5a 4f cd 07 c9 00 02 00 06 08 00 00 e1 00 02 00 b0 04 c1 00 02 00 00 00 e2 00 00 00 5c 00 70 00 0a 00 00 54 48 41 20 4e 47 55 59 45 4e 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 20 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECT |
CLSID: | |
File Type: | ASCII text, with CRLF line terminators |
Stream Size: | 309 |
Entropy: | 5.244459014114699 |
Base64 Encoded: | True |
Data ASCII: | I D = " { 2 7 7 2 3 D 3 E - 1 1 1 9 - 4 7 6 9 - A 7 3 7 - A 2 8 7 3 B F 0 C C E 4 } " . . M o d u l e = K a n g a t a n g . . N a m e = " V B A P r o j e c t " . . H e l p C o n t e x t I D = " 0 " . . V e r s i o n C o m p a t i b l e 3 2 = " 3 9 3 2 2 2 0 0 0 " . . C M G = " 1 3 1 1 D 2 C 1 E 1 C 5 E 1 C 5 E 1 C 5 E 1 C 5 " . . D P B = " 2 6 2 4 E 7 F 6 E 9 1 A F D 1 B F D 1 B F D " . . G C = " 3 9 3 B F 8 F D F 9 F D F 9 0 2 " . . . . [ H o s t E x t e n d e r I n f o ] . . & H 0 0 0 0 0 0 0 1 = { 3 |
Data Raw: | 49 44 3d 22 7b 32 37 37 32 33 44 33 45 2d 31 31 31 39 2d 34 37 36 39 2d 41 37 33 37 2d 41 32 38 37 33 42 46 30 43 43 45 34 7d 22 0d 0a 4d 6f 64 75 6c 65 3d 4b 61 6e 67 61 74 61 6e 67 0d 0a 4e 61 6d 65 3d 22 56 42 41 50 72 6f 6a 65 63 74 22 0d 0a 48 65 6c 70 43 6f 6e 74 65 78 74 49 44 3d 22 30 22 0d 0a 56 65 72 73 69 6f 6e 43 6f 6d 70 61 74 69 62 6c 65 33 32 3d 22 33 39 33 32 32 32 |
General | |
Stream Path: | _VBA_PROJECT_CUR/PROJECTwm |
CLSID: | |
File Type: | data |
Stream Size: | 32 |
Entropy: | 2.224601752714581 |
Base64 Encoded: | False |
Data ASCII: | K a n g a t a n g . K . a . n . g . a . t . a . n . g . . . . . |
Data Raw: | 4b 61 6e 67 61 74 61 6e 67 00 4b 00 61 00 6e 00 67 00 61 00 74 00 61 00 6e 00 67 00 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/_VBA_PROJECT |
CLSID: | |
File Type: | data |
Stream Size: | 2603 |
Entropy: | 4.257434479295426 |
Base64 Encoded: | False |
Data ASCII: | a . . . . . . . . . . . . . . . . . . . . . . . . . . . . . , . * . \\ . G . { . 0 . 0 . 0 . 2 . 0 . 4 . E . F . - . 0 . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . - . C . 0 . 0 . 0 . - . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 0 . 4 . 6 . } . # . 4 . . . 2 . # . 9 . # . C . : . \\ . P . r . o . g . r . a . m . . F . i . l . e . s . . ( . x . 8 . 6 . ) . \\ . C . o . m . m . o . n . . F . i . l . e . s . \\ . M . i . c . r . o . s . o . f . t . . S . h . a . r . e . d . \\ . V . B . A . \\ . V . B . A . 7 . . . 1 . \\ . |
Data Raw: | cc 61 b2 00 00 01 00 ff 09 04 00 00 09 04 00 00 e4 04 01 00 00 00 00 00 00 00 00 00 01 00 04 00 02 00 2c 01 2a 00 5c 00 47 00 7b 00 30 00 30 00 30 00 32 00 30 00 34 00 45 00 46 00 2d 00 30 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 2d 00 43 00 30 00 30 00 30 00 2d 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 30 00 34 00 36 00 7d 00 23 00 34 00 2e 00 32 00 23 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/__SRP_0 |
CLSID: | |
File Type: | data |
Stream Size: | 1336 |
Entropy: | 3.952411484964291 |
Base64 Encoded: | False |
Data ASCII: | K * . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . r U . . . . . . . . . . . . . . . . ~ . . . ~ . . . ~ . . . ~ . . . ~ . . . ~ . . . ~ m . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ] . . L O E > . . . . . . . . . . . . . . . . . . . . . . a . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . |
Data Raw: | 93 4b 2a b2 01 00 10 00 00 00 ff ff 00 00 00 00 01 00 02 00 ff ff 00 00 00 00 01 00 00 00 00 00 00 00 00 00 01 00 02 00 00 00 00 00 00 00 01 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 05 00 00 00 72 55 00 01 00 00 80 00 00 00 80 00 00 00 80 00 00 00 04 00 00 7e 01 00 00 7e 01 00 00 7e 01 00 00 7e 01 00 00 7e 02 00 00 7e 01 00 00 7e 6d 00 00 7f 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/__SRP_1 |
CLSID: | |
File Type: | data |
Stream Size: | 66 |
Entropy: | 1.7549422714340965 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . t . . . . . . . |
Data Raw: | 72 55 80 00 00 00 00 00 00 00 80 00 00 00 80 00 00 00 00 00 00 00 0a 00 00 00 09 00 00 00 00 00 00 00 ff ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 09 00 00 00 00 00 03 00 74 00 00 7f 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/__SRP_2 |
CLSID: | |
File Type: | data |
Stream Size: | 822 |
Entropy: | 3.9272228834115355 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . ~ | . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . A . . . . . . . . . . . . . . . i . . . . . . . . . . . . . . . . . . . . . . . . . . . . 9 . . . . . . . Q . . . . . . . X . . . . . . . . . . % . . . . . . . . . x . . . $ . . . . . . . . x . < . . . . x . " . . . . . . x . . . $ . . . . . . . . x . . . . . x . . K . \\ . t . . . . . x . . . . . . . $ . . . . . . . x . 0 . . . l t . l . . . . . p . . . $ . . . . . . . . |
Data Raw: | 72 55 80 00 00 00 80 00 00 00 80 00 00 00 80 00 00 00 02 00 00 7e 7c 00 00 7f 00 00 00 00 0e 00 00 00 09 00 00 00 00 00 00 00 09 00 00 00 00 00 03 00 08 00 00 00 00 00 02 00 02 00 02 00 09 00 00 00 c9 07 00 00 00 00 00 00 41 06 00 00 00 00 00 00 19 06 00 00 00 00 00 00 69 06 00 00 00 00 00 00 91 06 00 00 00 00 00 00 b9 06 00 00 00 00 00 00 e1 06 00 00 00 00 00 00 39 07 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/__SRP_3 |
CLSID: | |
File Type: | data |
Stream Size: | 140 |
Entropy: | 1.963193181149096 |
Base64 Encoded: | False |
Data ASCII: | r U . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . . . . . ` . . . . . . . . . . . $ . . . . . . . . . . . ` . . . . . . . . . . . . . . . . . n . . . . . . . |
Data Raw: | 72 55 80 00 00 00 00 00 00 00 80 00 00 00 80 00 00 00 00 00 00 00 10 00 00 00 09 00 00 00 00 00 02 00 ff ff ff ff ff ff ff ff 00 00 00 00 08 00 00 00 04 00 24 00 81 00 00 00 00 00 02 00 00 00 00 60 00 00 fd ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 24 00 a9 00 00 00 00 00 02 00 01 00 00 60 00 00 fd ff ff ff ff ff ff ff ff ff ff ff 00 00 00 00 00 00 00 00 00 00 00 |
General | |
Stream Path: | _VBA_PROJECT_CUR/VBA/dir |
CLSID: | |
File Type: | data |
Stream Size: | 474 |
Entropy: | 6.186533047263901 |
Base64 Encoded: | True |
Data ASCII: | . . . . . . . . . . 0 J . . . H . . H . . " . . H . . . . d . . . . . . . V B A P @ r o j e c t . . D . @ . & . . . . . = . . . . r . . . . . . . . 5 M i . . . . J . < . . . . 9 s t d o . l e > . . s . t . . d . o . l . e . ( . . h . % ^ . . * \\ . G { 0 0 0 2 0 4 3 0 - . . . . C . . . . . . . 0 0 4 6 } # 2 . . 0 # 0 # C : \\ . W i n d o w s \\ . S y s W O W 6 4 . \\ . e 2 . t l b # . O L E A u t o m a t i o n . 0 . . A E O f f i c E O D . f . i . c E . . . E 2 D F 8 . D 0 4 C - 5 B F . A - 1 0 1 B - B H D E |
Data Raw: | 01 d6 b1 80 01 00 04 00 00 00 01 00 30 aa 4a 02 90 05 00 48 02 02 48 09 00 c0 22 14 06 48 03 00 02 00 64 e4 04 08 04 00 0a 00 1c 56 42 41 50 40 72 6f 6a 65 63 74 01 bc 00 44 00 40 00 26 00 00 06 02 0a 3d ad 02 0a 07 02 72 01 14 08 06 12 09 02 12 80 c2 35 4d 69 05 00 0c 02 4a 0a 3c 02 0a 16 02 39 73 74 64 6f 08 6c 65 3e 02 19 73 00 74 00 00 64 00 6f 00 6c 00 65 00 28 0d 00 68 00 25 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T09:18:18.089586+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.16 | 49716 | 13.107.246.42 | 443 | TCP |
2024-11-20T09:18:22.918256+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.16 | 49717 | 13.107.246.42 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 09:18:17.435281992 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:17.435354948 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:17.435446024 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:17.435770988 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:17.435790062 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.089193106 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.089586020 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.091348886 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.091358900 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.091670990 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.093786001 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.135324001 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.204123020 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.204180956 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.204224110 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.204282045 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.204298019 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.204319000 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.204415083 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.281267881 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.281301022 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.281433105 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.281457901 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.281625986 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.283852100 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.283870935 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.285365105 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.285372019 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.285459995 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.367724895 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.367752075 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.367861032 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.367885113 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.367993116 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.369100094 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.369117022 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.370795965 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.370865107 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.370865107 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.370877981 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.372565031 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.372581959 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.372641087 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.372641087 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.372648001 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.419667006 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.457814932 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.457842112 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.457917929 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.457946062 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.458044052 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.458693981 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.458712101 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.458766937 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.458781958 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.458867073 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.459975004 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.459991932 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.460050106 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.460064888 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.460203886 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.461750031 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.461769104 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.461847067 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.461847067 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.461858034 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.462863922 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.462882042 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.462918997 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.462918997 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.462928057 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.462990046 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.462990046 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.464129925 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.464144945 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.464401960 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.464411974 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.464514971 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.466207027 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.466223955 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.466279984 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.466298103 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.466404915 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.534385920 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.534471989 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.534495115 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.534513950 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.534554005 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.542685986 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.542721987 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.542772055 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.542789936 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.542829990 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.542829990 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.543543100 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.543560982 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.543613911 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.543627024 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.543711901 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.544475079 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.544491053 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.544545889 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.544559002 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.544648886 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.545236111 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.545250893 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.545305967 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.545317888 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.545393944 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.550451994 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.550476074 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.550545931 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.550553083 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.550663948 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551194906 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551238060 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551276922 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551281929 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551311016 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551330090 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551791906 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551821947 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551856041 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551867008 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.551915884 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.551915884 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.621922016 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.621947050 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.622075081 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.622102976 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.622256041 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.630199909 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630222082 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630294085 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.630320072 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630372047 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.630703926 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630719900 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630759954 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.630772114 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.630816936 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.630816936 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.631444931 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.631469011 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.631536007 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.631550074 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.631644011 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.631901026 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.631916046 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.631964922 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.631977081 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.632061005 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.632618904 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.632637978 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.632690907 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.632704973 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.632788897 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.633112907 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.633126974 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.633171082 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.633182049 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.633265972 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.634001970 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.634016991 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.634072065 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.634083033 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.634169102 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.707834005 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.707865953 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.708158016 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.708169937 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.708226919 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.716269016 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716290951 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716377974 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.716391087 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716614008 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716634989 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716670990 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.716670990 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.716677904 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.716739893 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.716739893 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717073917 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717089891 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717174053 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717180014 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717222929 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717468023 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717483997 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717547894 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717559099 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717611074 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717892885 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717912912 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.717976093 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.717988014 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718367100 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.718466997 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718485117 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718549967 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.718561888 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718661070 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.718825102 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718841076 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.718903065 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.718914986 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.719003916 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.794648886 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.794677973 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.794778109 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.794790983 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.794831038 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803028107 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803045988 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803137064 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803143024 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803196907 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803386927 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803401947 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803463936 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803469896 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803564072 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803797960 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803812027 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803858995 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.803864002 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.803905964 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.804409027 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.804425955 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.804481983 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.804487944 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.804524899 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808094025 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808121920 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808187008 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808195114 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808217049 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808239937 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808315039 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808331013 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808384895 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808391094 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808440924 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808479071 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808494091 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808552027 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808559895 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.808574915 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.808631897 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.881788969 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.881817102 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.881926060 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.881939888 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.881978989 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.891527891 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.891551018 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.891665936 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.891679049 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.891731977 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.892152071 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892168999 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892220020 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.892225027 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892257929 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.892690897 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892707109 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892744064 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.892749071 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.892776966 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.892798901 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.893083096 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893101931 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893156052 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.893161058 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893203020 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.893755913 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893774033 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893812895 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.893822908 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.893848896 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.893870115 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.894104958 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894123077 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894177914 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.894182920 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894226074 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.894622087 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894639015 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894696951 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.894702911 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.894748926 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.970006943 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.970041037 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.970156908 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.970170021 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.970215082 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.978826046 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.978852987 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.978951931 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.978961945 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979011059 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.979362011 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979378939 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979432106 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.979439020 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979480982 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.979882002 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979902983 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.979969978 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.979975939 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.980082989 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.980211020 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.980227947 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.980304003 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.980310917 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.980353117 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981182098 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981225014 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981250048 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981256008 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981281042 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981300116 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981509924 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981551886 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981580973 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981586933 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981615067 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981638908 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981895924 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981940031 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.981975079 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.981981039 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:18.982000113 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:18.982026100 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.056082010 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.056138039 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.056205034 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.056222916 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.056248903 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.056267023 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.064551115 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.064591885 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.064621925 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.064637899 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.064656973 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.064673901 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.064945936 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.064986944 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065020084 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065026999 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065047026 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065066099 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065416098 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065460920 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065479994 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065488100 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065530062 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065670013 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065726995 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065742970 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.065751076 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.065792084 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066163063 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.066206932 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.066226959 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066235065 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.066252947 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066359997 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066365957 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.066385984 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066418886 CET | 49716 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:19.066422939 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:19.066438913 CET | 443 | 49716 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:22.277700901 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:22.277749062 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:22.277852058 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:22.278083086 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:22.278095961 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:22.917623043 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:22.918256044 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:22.918298006 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:22.919092894 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:22.919106007 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:23.021819115 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:23.021879911 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:23.021975994 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:23.022042036 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:23.022264004 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:23.022264004 CET | 49717 | 443 | 192.168.2.16 | 13.107.246.42 |
Nov 20, 2024 09:18:23.022289991 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Nov 20, 2024 09:18:23.022341967 CET | 443 | 49717 | 13.107.246.42 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 09:18:17.434052944 CET | 1.1.1.1 | 192.168.2.16 | 0x995 | No error (0) | s-part-0014.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Nov 20, 2024 09:18:17.434052944 CET | 1.1.1.1 | 192.168.2.16 | 0x995 | No error (0) | 13.107.246.42 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49716 | 13.107.246.42 | 443 | 5452 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 08:18:18 UTC | 219 | OUT | |
2024-11-20 08:18:18 UTC | 493 | IN | |
2024-11-20 08:18:18 UTC | 15891 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN | |
2024-11-20 08:18:18 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.16 | 49717 | 13.107.246.42 | 443 | 5452 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 08:18:22 UTC | 207 | OUT | |
2024-11-20 08:18:23 UTC | 515 | IN | |
2024-11-20 08:18:23 UTC | 2128 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 03:17:12 |
Start date: | 20/11/2024 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe60000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 03:18:32 |
Start date: | 20/11/2024 |
Path: | C:\Windows\splwow64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b8af0000 |
File size: | 163'840 bytes |
MD5 hash: | 77DE7761B037061C7C112FD3C5B91E73 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |