Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7524 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 66B03D1AFF27D81E62B53FC108806211) - powershell.exe (PID: 7708 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" Add-MpPref erence -Ex clusionPat h "C:\User s\user\Des ktop\file. exe" MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 7724 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - WmiPrvSE.exe (PID: 7856 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) - file.exe (PID: 7716 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: 66B03D1AFF27D81E62B53FC108806211)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Loki Password Stealer (PWS), LokiBot | "Loki Bot is a commodity malware sold on underground sites which is designed to steal private data from infected machines, and then submit that info to a command and control host via HTTP POST. This private data includes stored passwords, login credential information from Web browsers, and a variety of cryptocurrency wallets." - PhishMeLoki-Bot employs function hashing to obfuscate the libraries utilized. While not all functions are hashed, a vast majority of them are.Loki-Bot accepts a single argument/switch of -u that simply delays execution (sleeps) for 10 seconds. This is used when Loki-Bot is upgrading itself.The Mutex generated is the result of MD5 hashing the Machine GUID and trimming to 24-characters. For example: B7E1C2CC98066B250DDB2123.Loki-Bot creates a hidden folder within the %APPDATA% directory whose name is supplied by the 8th thru 13th characters of the Mutex. For example: %APPDATA%\ C98066\.There can be four files within the hidden %APPDATA% directory at any given time: .exe, .lck, .hdb and .kdb. They will be named after characters 13 thru 18 of the Mutex. For example: 6B250D. Below is the explanation of their purpose:FILE EXTENSIONFILE DESCRIPTION.exeA copy of the malware that will execute every time the user account is logged into.lckA lock file created when either decrypting Windows Credentials or Keylogging to prevent resource conflicts.hdbA database of hashes for data that has already been exfiltrated to the C2 server.kdbA database of keylogger data that has yet to be sent to the C2 serverIf the user is privileged, Loki-Bot sets up persistence within the registry under HKEY_LOCAL_MACHINE. If not, it sets up persistence under HKEY_CURRENT_USER.The first packet transmitted by Loki-Bot contains application data.The second packet transmitted by Loki-Bot contains decrypted Windows credentials.The third packet transmitted by Loki-Bot is the malware requesting C2 commands from the C2 server. By default, Loki-Bot will send this request out every 10 minutes after the initial packet it sent.Communications to the C2 server from the compromised host contain information about the user and system including the username, hostname, domain, screen resolution, privilege level, system architecture, and Operating System.The first WORD of the HTTP Payload represents the Loki-Bot version.The second WORD of the HTTP Payload is the Payload Type. Below is the table of identified payload types:BYTEPAYLOAD TYPE0x26Stolen Cryptocurrency Wallet0x27Stolen Application Data0x28Get C2 Commands from C2 Server0x29Stolen File0x2APOS (Point of Sale?)0x2BKeylogger Data0x2CScreenshotThe 11th byte of the HTTP Payload begins the Binary ID. This might be useful in tracking campaigns or specific threat actors. This value value is typically ckav.ru. If you come across a Binary ID that is different from this, take note!Loki-Bot encrypts both the URL and the registry key used for persistence using Triple DES encryption.The Content-Key HTTP Header value is the result of hashing the HTTP Header values that precede it. This is likely used as a protection against researchers who wish to poke and prod at Loki-Bots C2 infrastructure.Loki-Bot can accept the following instructions from the C2 Server:BYTEINSTRUCTION DESCRIPTION0x00Download EXE & Execute0x01Download DLL & Load #10x02Download DLL & Load #20x08Delete HDB File0x09Start Keylogger0x0AMine & Steal Data0x0EExit Loki-Bot0x0FUpgrade Loki-Bot0x10Change C2 Polling Frequency0x11Delete Executables & ExitSuricata SignaturesRULE SIDRULE NAME2024311ET TROJAN Loki Bot Cryptocurrency Wallet Exfiltration Detected2024312ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M12024313ET TROJAN Loki Bot Request for C2 Commands Detected M12024314ET TROJAN Loki Bot File Exfiltration Detected2024315ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M12024316ET TROJAN Loki Bot Screenshot Exfiltration Detected2024317ET TROJAN Loki Bot Application/Credential Data Exfiltration Detected M22024318ET TROJAN Loki Bot Request for C2 Commands Detected M22024319ET TROJAN Loki Bot Keylogger Data Exfiltration Detected M2 |
{"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php", "94.156.177.41/maxzi/five/fre.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Lokibot_1 | Yara detected Lokibot | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | ||
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Windows_Trojan_Lokibot_1f885282 | unknown | unknown |
| |
Windows_Trojan_Lokibot_0f421617 | unknown | unknown |
| |
Click to see the 30 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
Windows_Trojan_Lokibot_1f885282 | unknown | unknown |
| |
Windows_Trojan_Lokibot_0f421617 | unknown | unknown |
| |
Loki_1 | Loki Payload | kevoreilly |
| |
Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group |
| |
Click to see the 37 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:21.673105+0100 | 2024312 | 1 | A Network Trojan was detected | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.332524+0100 | 2024312 | 1 | A Network Trojan was detected | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:20.385794+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.419739+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:27.183872+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:29.035149+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.844447+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.663838+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.331046+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:36.401062+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:38.111286+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.948025+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.659082+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.413430+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:45.199702+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.970645+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.693877+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.493985+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.309427+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:54.159922+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:56.007119+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.847693+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.730255+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.391645+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:03.187495+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.874345+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.624697+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:08.251882+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:10.075035+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.694205+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.452854+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:15.106129+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.873576+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.772634+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.515914+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.314600+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:24.067071+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.697513+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.435691+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.277428+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.980502+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.779202+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.454700+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.638264+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.319161+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:40.156593+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.832002+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.599899+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.307094+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:47.159997+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:49.169189+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.892509+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.742489+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.532238+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:56.154638+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.905221+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.617555+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.461227+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:03.120405+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.910450+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.653374+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.480379+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.283380+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.940390+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.780404+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.455772+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:17.167831+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.923857+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.873102+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.672655+0100 | 2025381 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:18.696905+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 50000 | TCP |
2024-11-22T17:38:25.060056+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49736 | TCP |
2024-11-22T17:38:26.901213+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49738 | TCP |
2024-11-22T17:38:28.759253+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49739 | TCP |
2024-11-22T17:38:30.564948+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49740 | TCP |
2024-11-22T17:38:32.375028+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49741 | TCP |
2024-11-22T17:38:34.060918+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49743 | TCP |
2024-11-22T17:38:35.862948+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49745 | TCP |
2024-11-22T17:38:37.847124+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49748 | TCP |
2024-11-22T17:38:39.689057+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49749 | TCP |
2024-11-22T17:38:41.388207+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49751 | TCP |
2024-11-22T17:38:43.138286+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49753 | TCP |
2024-11-22T17:38:44.941143+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49754 | TCP |
2024-11-22T17:38:46.707141+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49755 | TCP |
2024-11-22T17:38:48.418123+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49756 | TCP |
2024-11-22T17:38:50.222754+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49757 | TCP |
2024-11-22T17:38:52.042226+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49758 | TCP |
2024-11-22T17:38:53.883990+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49759 | TCP |
2024-11-22T17:38:55.733469+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49760 | TCP |
2024-11-22T17:38:57.577179+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49762 | TCP |
2024-11-22T17:38:59.426546+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49768 | TCP |
2024-11-22T17:39:01.131407+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49769 | TCP |
2024-11-22T17:39:02.920927+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49775 | TCP |
2024-11-22T17:39:04.600571+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49781 | TCP |
2024-11-22T17:39:06.355478+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49787 | TCP |
2024-11-22T17:39:07.980188+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49788 | TCP |
2024-11-22T17:39:09.802909+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49794 | TCP |
2024-11-22T17:39:11.424821+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49800 | TCP |
2024-11-22T17:39:13.174861+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49806 | TCP |
2024-11-22T17:39:14.848103+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49807 | TCP |
2024-11-22T17:39:16.600800+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49814 | TCP |
2024-11-22T17:39:18.412865+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49820 | TCP |
2024-11-22T17:39:20.251127+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49826 | TCP |
2024-11-22T17:39:22.044326+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49830 | TCP |
2024-11-22T17:39:23.796270+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49834 | TCP |
2024-11-22T17:39:25.422629+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49839 | TCP |
2024-11-22T17:39:27.173859+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49845 | TCP |
2024-11-22T17:39:29.008704+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49851 | TCP |
2024-11-22T17:39:30.723332+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49853 | TCP |
2024-11-22T17:39:32.439587+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49858 | TCP |
2024-11-22T17:39:34.184105+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49864 | TCP |
2024-11-22T17:39:36.030123+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49869 | TCP |
2024-11-22T17:39:38.031130+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49875 | TCP |
2024-11-22T17:39:39.893944+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49878 | TCP |
2024-11-22T17:39:41.556669+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49883 | TCP |
2024-11-22T17:39:43.330266+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49889 | TCP |
2024-11-22T17:39:45.051310+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49894 | TCP |
2024-11-22T17:39:46.887092+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49898 | TCP |
2024-11-22T17:39:48.686602+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49902 | TCP |
2024-11-22T17:39:50.616894+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49907 | TCP |
2024-11-22T17:39:52.461465+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49913 | TCP |
2024-11-22T17:39:54.273217+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49917 | TCP |
2024-11-22T17:39:55.885986+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49922 | TCP |
2024-11-22T17:39:57.636701+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49926 | TCP |
2024-11-22T17:39:59.348827+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49932 | TCP |
2024-11-22T17:40:01.189433+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49937 | TCP |
2024-11-22T17:40:02.986093+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49942 | TCP |
2024-11-22T17:40:04.646103+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49945 | TCP |
2024-11-22T17:40:06.389791+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49951 | TCP |
2024-11-22T17:40:08.225755+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49957 | TCP |
2024-11-22T17:40:10.011540+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49961 | TCP |
2024-11-22T17:40:11.677531+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49965 | TCP |
2024-11-22T17:40:13.513836+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49970 | TCP |
2024-11-22T17:40:15.188463+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49976 | TCP |
2024-11-22T17:40:16.897699+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49981 | TCP |
2024-11-22T17:40:18.649027+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49984 | TCP |
2024-11-22T17:40:20.449796+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49990 | TCP |
2024-11-22T17:40:22.401027+0100 | 2025483 | 1 | A Network Trojan was detected | 94.156.177.41 | 80 | 192.168.2.4 | 49995 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:24.937744+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:26.773102+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:28.639683+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.444496+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.251170+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:33.940877+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:35.739391+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:37.721603+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.565166+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.267831+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.017979+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:44.821525+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.587354+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.298382+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.103232+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:51.916181+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:53.761108+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:55.610382+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.457422+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.302710+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.010755+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:02.801173+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.480951+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.235877+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:07.860411+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:09.682146+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.305204+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.054807+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:14.727841+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.481024+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.289205+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.131550+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:21.922262+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:23.676175+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.302977+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.054176+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:28.889019+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.602180+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.319975+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.064527+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:35.909915+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:37.911435+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:39.774405+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.435946+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.209941+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:44.928389+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:46.764115+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:48.566331+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.496975+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.341897+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.151907+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:55.765985+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.517015+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.228879+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.069978+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:02.745174+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.526328+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.269586+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.104776+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:09.891749+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.557939+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.394137+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.065652+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:16.777601+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.529455+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.330214+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.279856+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:24.138359+0100 | 2024313 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:24.937744+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:26.773102+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:28.639683+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.444496+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.251170+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:33.940877+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:35.739391+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:37.721603+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.565166+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.267831+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.017979+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:44.821525+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.587354+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.298382+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.103232+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:51.916181+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:53.761108+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:55.610382+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.457422+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.302710+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.010755+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:02.801173+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.480951+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.235877+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:07.860411+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:09.682146+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.305204+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.054807+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:14.727841+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.481024+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.289205+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.131550+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:21.922262+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:23.676175+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.302977+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.054176+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:28.889019+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.602180+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.319975+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.064527+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:35.909915+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:37.911435+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:39.774405+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.435946+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.209941+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:44.928389+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:46.764115+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:48.566331+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.496975+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.341897+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.151907+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:55.765985+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.517015+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.228879+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.069978+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:02.745174+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.526328+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.269586+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.104776+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:09.891749+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.557939+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.394137+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.065652+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:16.777601+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.529455+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.330214+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.279856+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:24.138359+0100 | 2024318 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:20.385794+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.419739+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:27.183872+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:29.035149+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.844447+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.663838+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.331046+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:36.401062+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:38.111286+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.948025+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.659082+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.413430+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:45.199702+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.970645+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.693877+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.493985+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.309427+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:54.159922+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:56.007119+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.847693+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.730255+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.391645+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:03.187495+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.874345+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.624697+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:08.251882+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:10.075035+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.694205+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.452854+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:15.106129+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.873576+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.772634+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.515914+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.314600+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:24.067071+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.697513+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.435691+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.277428+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.980502+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.779202+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.454700+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.638264+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.319161+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:40.156593+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.832002+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.599899+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.307094+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:47.159997+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:49.169189+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.892509+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.742489+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.532238+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:56.154638+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.905221+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.617555+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.461227+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:03.120405+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.910450+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.653374+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.480379+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.283380+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.940390+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.780404+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.455772+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:17.167831+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.923857+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.873102+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.672655+0100 | 2021641 | 1 | A Network Trojan was detected | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:20.385794+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.419739+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:27.183872+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:29.035149+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.844447+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.663838+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.331046+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:36.401062+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:38.111286+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.948025+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.659082+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.413430+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:45.199702+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.970645+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.693877+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.493985+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.309427+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:54.159922+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:56.007119+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.847693+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.730255+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.391645+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:03.187495+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.874345+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.624697+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:08.251882+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:10.075035+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.694205+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.452854+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:15.106129+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.873576+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.772634+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.515914+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.314600+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:24.067071+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.697513+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.435691+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.277428+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.980502+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.779202+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.454700+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.638264+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.319161+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:40.156593+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.832002+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.599899+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.307094+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:47.159997+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:49.169189+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.892509+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.742489+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.532238+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:56.154638+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.905221+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.617555+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.461227+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:03.120405+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.910450+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.653374+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.480379+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.283380+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.940390+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.780404+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.455772+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:17.167831+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.923857+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.873102+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.672655+0100 | 2825766 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 3_2_00403D74 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 3_2_00404ED4 |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_0246D51C | |
Source: | Code function: | 0_2_04B16FE8 | |
Source: | Code function: | 0_2_04B10006 | |
Source: | Code function: | 0_2_04B10040 | |
Source: | Code function: | 0_2_04B16FD8 | |
Source: | Code function: | 0_2_0674B328 | |
Source: | Code function: | 0_2_06747660 | |
Source: | Code function: | 0_2_067456B0 | |
Source: | Code function: | 0_2_06745F20 | |
Source: | Code function: | 0_2_06745278 | |
Source: | Code function: | 0_2_06745AE8 | |
Source: | Code function: | 3_2_0040549C | |
Source: | Code function: | 3_2_004029D4 |
Source: | Code function: | ||
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Code function: | 3_2_0040650A |
Source: | Code function: | 3_2_0040434D |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_06748A91 | |
Source: | Code function: | 0_2_06748A99 | |
Source: | Code function: | 3_2_00402AD4 | |
Source: | Code function: | 3_2_00402AFC |
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 3_2_00403D74 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 3_2_0040317B |
Source: | Code function: | 3_2_00402B7C |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 3_2_0040D069 | |
Source: | Code function: | 3_2_0040D069 |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Access Token Manipulation | 1 Masquerading | 2 OS Credential Dumping | 11 Security Software Discovery | Remote Services | 1 Email Collection | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 111 Process Injection | 11 Disable or Modify Tools | 2 Credentials in Registry | 1 Process Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | 2 Data from Local System | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 112 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 111 Process Injection | LSA Secrets | 2 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Deobfuscate/Decode Files or Information | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 3 Obfuscated Files or Information | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 12 Software Packing | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 DLL Side-Loading | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
71% | ReversingLabs | ByteCode-MSIL.Trojan.Taskun | ||
100% | Avira | HEUR/AGEN.1306899 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
94.156.177.41 | unknown | Bulgaria | 43561 | NET1-ASBG | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1561052 |
Start date and time: | 2024-11-22 17:37:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 39s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@7/8@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
11:38:16 | API Interceptor | |
11:38:19 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
94.156.177.41 | Get hash | malicious | HTMLPhisher, Lokibot | Browse |
| |
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Cobalt Strike, Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Cobalt Strike, HTMLPhisher, Lokibot | Browse |
| ||
Get hash | malicious | HTMLPhisher, Lokibot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NET1-ASBG | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | DarkTortilla, SmokeLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Cobalt Strike, Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Lokibot | Browse |
| ||
Get hash | malicious | Cobalt Strike, HTMLPhisher, Lokibot | Browse |
| ||
Get hash | malicious | HTMLPhisher, Lokibot | Browse |
|
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1216 |
Entropy (8bit): | 5.34331486778365 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4KH1qE4qXKDE4KhKiKhPKIE4oKNzKoZAE4Kze0E4x84j:MIHK5HKH1qHiYHKh3oPtHo6hAHKze0HJ |
MD5: | 1330C80CAAC9A0FB172F202485E9B1E8 |
SHA1: | 86BAFDA4E4AE68C7C3012714A33D85D2B6E1A492 |
SHA-256: | B6C63ECE799A8F7E497C2A158B1FFC2F5CB4F745A2F8E585F794572B7CF03560 |
SHA-512: | 75A17AB129FE97BBAB36AA2BD66D59F41DB5AFF44A705EF3E4D094EC5FCD056A3ED59992A0AC96C9D0D40E490F8596B07DCA9B60E606B67223867B061D9D0EB2 |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2232 |
Entropy (8bit): | 5.379736180876081 |
Encrypted: | false |
SSDEEP: | 48:tWSU4y4RQmFoUeWmfgZ9tK8NPZHUm7u1iMuge//ZeUyus:tLHyIFKL3IZ2KRH9Ougos |
MD5: | 9D384A9EBEABB083763926A2E63505A6 |
SHA1: | 3AB2DD8F7518A36D7E22EFD76FF25F3DFA25D889 |
SHA-256: | 801BC488523F40135A2F58EE86844AD3AFD2EFD0AF5DD0F7DE40978E7EDE92DD |
SHA-512: | 03941519E7F748E7A151CDEFC2E6D98A19B2E077AB09C48822B3882D8BA39C8427A9766C26B3F28DB419385FD7F030C3A7D5FE5ADE4F796AE876921042F5FED9 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-2246122658-3693405117-2476756634-1002\bc49718863ee53e026d805ec372039e9_9e146be9-c76a-4720-bcdb-53011b87bd06
Download File
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | modified |
Size (bytes): | 46 |
Entropy (8bit): | 1.0424600748477153 |
Encrypted: | false |
SSDEEP: | 3:/lbq:4 |
MD5: | 8CB7B7F28464C3FCBAE8A10C46204572 |
SHA1: | 767FE80969EC2E67F54CC1B6D383C76E7859E2DE |
SHA-256: | ED5E3DCEB0A1D68803745084985051C1ED41E11AC611DF8600B1A471F3752E96 |
SHA-512: | 9BA84225FDB6C0FD69AD99B69824EC5B8D2B8FD3BB4610576DB4AD79ADF381F7F82C4C9522EC89F7171907577FAF1B4E70B82364F516CF8BBFED99D2ADEA43AF |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.913749036393697 |
TrID: |
|
File name: | file.exe |
File size: | 600'576 bytes |
MD5: | 66b03d1aff27d81e62b53fc108806211 |
SHA1: | 2557ec8b32d0b42cac9cabde199d31c5d4e40041 |
SHA256: | 59586e753c54629f428a6b880f6aff09f67af0ace76823af3627dda2281532e4 |
SHA512: | 9f8ef3dd8c482debb535b1e7c9155e4ab33a04f8c4f31ade9e70adbd5598362033785438d5d60c536a801e134e09fcd1bc80fc7aed2d167af7f531a81f12e43d |
SSDEEP: | 12288:VrOj+Ri3AgFdZeDZskwkzA0+7xUNq4KC73vUECPnsSnR83PdB0:xQ3AgSskwZNeEqdCPssS3F |
TLSH: | DFD423C93776E127D8BCD330A76250A287752D7BDB0CD65D09C9269ACFA6388C052F87 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:=g..............0...... .......&... ...@....@.. ....................................`................................ |
Icon Hash: | 8bdb4b414d656d61 |
Entrypoint: | 0x4926e6 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x673D3AED [Wed Nov 20 01:27:09 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x92694 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x94000 | 0x1d7c | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x96000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x906ec | 0x90800 | d9d07ddc2146889bed0094cb505c9d7b | False | 0.948473656466263 | data | 7.9227520273220895 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x94000 | 0x1d7c | 0x1e00 | 189959de2daf17a1a19aa0679201b63f | False | 0.80625 | data | 7.321945731144507 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x96000 | 0xc | 0x200 | 6d98c7473e47d9fd8de69fea995f2518 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x94100 | 0x1733 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.9151372284896447 | ||
RT_GROUP_ICON | 0x95844 | 0x14 | data | 1.05 | ||
RT_VERSION | 0x95868 | 0x314 | data | 0.43274111675126903 | ||
RT_MANIFEST | 0x95b8c | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-22T17:38:18.696905+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 50000 | TCP |
2024-11-22T17:38:20.385794+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:20.385794+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:20.385794+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:21.673105+0100 | 2024312 | ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M1 | 1 | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:22.053197+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.332524+0100 | 2024312 | ET MALWARE LokiBot Application/Credential Data Exfiltration Detected M1 | 1 | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:23.667763+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:24.937744+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:24.937744+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.060056+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49736 | TCP |
2024-11-22T17:38:25.419739+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.419739+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:25.419739+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:26.773102+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:26.773102+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:26.901213+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49738 | TCP |
2024-11-22T17:38:27.183872+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:27.183872+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:27.183872+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:28.639683+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:28.639683+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:28.759253+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49739 | TCP |
2024-11-22T17:38:29.035149+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:29.035149+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:29.035149+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.444496+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.444496+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.564948+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49740 | TCP |
2024-11-22T17:38:30.844447+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.844447+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:30.844447+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.251170+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.251170+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.375028+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49741 | TCP |
2024-11-22T17:38:32.663838+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.663838+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:32.663838+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:33.940877+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:33.940877+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.060918+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49743 | TCP |
2024-11-22T17:38:34.331046+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.331046+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:34.331046+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:35.739391+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:35.739391+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:35.862948+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49745 | TCP |
2024-11-22T17:38:36.401062+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:36.401062+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:36.401062+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:37.721603+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:37.721603+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:37.847124+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49748 | TCP |
2024-11-22T17:38:38.111286+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:38.111286+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:38.111286+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.565166+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.565166+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.689057+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49749 | TCP |
2024-11-22T17:38:39.948025+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.948025+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:39.948025+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.267831+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.267831+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.388207+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49751 | TCP |
2024-11-22T17:38:41.659082+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.659082+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:41.659082+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.017979+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.017979+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.138286+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49753 | TCP |
2024-11-22T17:38:43.413430+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.413430+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:43.413430+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:44.821525+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:44.821525+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:44.941143+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49754 | TCP |
2024-11-22T17:38:45.199702+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:45.199702+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:45.199702+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.587354+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.587354+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.707141+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49755 | TCP |
2024-11-22T17:38:46.970645+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.970645+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:46.970645+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.298382+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.298382+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.418123+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49756 | TCP |
2024-11-22T17:38:48.693877+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.693877+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:48.693877+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.103232+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.103232+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.222754+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49757 | TCP |
2024-11-22T17:38:50.493985+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.493985+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:50.493985+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:51.916181+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:51.916181+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.042226+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49758 | TCP |
2024-11-22T17:38:52.309427+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.309427+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:52.309427+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:53.761108+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:53.761108+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:53.883990+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49759 | TCP |
2024-11-22T17:38:54.159922+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:54.159922+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:54.159922+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:55.610382+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:55.610382+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:55.733469+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49760 | TCP |
2024-11-22T17:38:56.007119+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:56.007119+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:56.007119+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.457422+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.457422+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.577179+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49762 | TCP |
2024-11-22T17:38:57.847693+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.847693+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:57.847693+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.302710+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.302710+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.426546+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49768 | TCP |
2024-11-22T17:38:59.730255+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.730255+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:38:59.730255+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.010755+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.010755+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.131407+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49769 | TCP |
2024-11-22T17:39:01.391645+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.391645+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:01.391645+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:02.801173+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:02.801173+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:02.920927+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49775 | TCP |
2024-11-22T17:39:03.187495+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:03.187495+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:03.187495+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.480951+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.480951+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.600571+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49781 | TCP |
2024-11-22T17:39:04.874345+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.874345+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:04.874345+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.235877+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.235877+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.355478+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49787 | TCP |
2024-11-22T17:39:06.624697+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.624697+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:06.624697+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:07.860411+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:07.860411+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:07.980188+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49788 | TCP |
2024-11-22T17:39:08.251882+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:08.251882+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:08.251882+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:09.682146+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:09.682146+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:09.802909+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49794 | TCP |
2024-11-22T17:39:10.075035+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:10.075035+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:10.075035+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.305204+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.305204+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.424821+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49800 | TCP |
2024-11-22T17:39:11.694205+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.694205+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:11.694205+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.054807+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.054807+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.174861+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49806 | TCP |
2024-11-22T17:39:13.452854+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.452854+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:13.452854+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:14.727841+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:14.727841+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:14.848103+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49807 | TCP |
2024-11-22T17:39:15.106129+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:15.106129+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:15.106129+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.481024+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.481024+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.600800+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49814 | TCP |
2024-11-22T17:39:16.873576+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.873576+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:16.873576+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.289205+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.289205+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.412865+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49820 | TCP |
2024-11-22T17:39:18.772634+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.772634+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:18.772634+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.131550+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.131550+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.251127+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49826 | TCP |
2024-11-22T17:39:20.515914+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.515914+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:20.515914+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:21.922262+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:21.922262+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.044326+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49830 | TCP |
2024-11-22T17:39:22.314600+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.314600+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:22.314600+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:23.676175+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:23.676175+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:23.796270+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49834 | TCP |
2024-11-22T17:39:24.067071+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:24.067071+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:24.067071+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.302977+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.302977+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.422629+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49839 | TCP |
2024-11-22T17:39:25.697513+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.697513+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:25.697513+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.054176+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.054176+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.173859+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49845 | TCP |
2024-11-22T17:39:27.435691+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.435691+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:27.435691+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:28.889019+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:28.889019+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.008704+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49851 | TCP |
2024-11-22T17:39:29.277428+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.277428+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:29.277428+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.602180+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.602180+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.723332+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49853 | TCP |
2024-11-22T17:39:30.980502+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.980502+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:30.980502+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.319975+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.319975+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.439587+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49858 | TCP |
2024-11-22T17:39:32.779202+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.779202+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:32.779202+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.064527+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.064527+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.184105+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49864 | TCP |
2024-11-22T17:39:34.454700+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.454700+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:34.454700+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:35.909915+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:35.909915+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.030123+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49869 | TCP |
2024-11-22T17:39:36.638264+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.638264+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:36.638264+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:37.911435+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:37.911435+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.031130+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49875 | TCP |
2024-11-22T17:39:38.319161+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.319161+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:38.319161+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:39.774405+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:39.774405+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:39.893944+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49878 | TCP |
2024-11-22T17:39:40.156593+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:40.156593+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:40.156593+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.435946+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.435946+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.556669+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49883 | TCP |
2024-11-22T17:39:41.832002+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.832002+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:41.832002+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.209941+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.209941+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.330266+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49889 | TCP |
2024-11-22T17:39:43.599899+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.599899+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:43.599899+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:44.928389+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:44.928389+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.051310+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49894 | TCP |
2024-11-22T17:39:45.307094+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.307094+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:45.307094+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:46.764115+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:46.764115+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:46.887092+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49898 | TCP |
2024-11-22T17:39:47.159997+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:47.159997+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:47.159997+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:48.566331+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:48.566331+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:48.686602+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49902 | TCP |
2024-11-22T17:39:49.169189+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:49.169189+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:49.169189+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.496975+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.496975+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.616894+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49907 | TCP |
2024-11-22T17:39:50.892509+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.892509+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:50.892509+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.341897+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.341897+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.461465+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49913 | TCP |
2024-11-22T17:39:52.742489+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.742489+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:52.742489+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.151907+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.151907+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.273217+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49917 | TCP |
2024-11-22T17:39:54.532238+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.532238+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:54.532238+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:55.765985+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:55.765985+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:55.885986+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49922 | TCP |
2024-11-22T17:39:56.154638+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:56.154638+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:56.154638+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.517015+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.517015+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.636701+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49926 | TCP |
2024-11-22T17:39:57.905221+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.905221+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:57.905221+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.228879+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.228879+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.348827+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49932 | TCP |
2024-11-22T17:39:59.617555+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.617555+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:39:59.617555+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.069978+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.069978+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.189433+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49937 | TCP |
2024-11-22T17:40:01.461227+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.461227+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:01.461227+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:02.745174+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:02.745174+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:02.986093+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49942 | TCP |
2024-11-22T17:40:03.120405+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:03.120405+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:03.120405+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.526328+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.526328+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.646103+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49945 | TCP |
2024-11-22T17:40:04.910450+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.910450+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:04.910450+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.269586+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.269586+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.389791+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49951 | TCP |
2024-11-22T17:40:06.653374+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.653374+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:06.653374+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.104776+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.104776+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.225755+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49957 | TCP |
2024-11-22T17:40:08.480379+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.480379+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:08.480379+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:09.891749+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:09.891749+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.011540+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49961 | TCP |
2024-11-22T17:40:10.283380+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.283380+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:10.283380+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.557939+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.557939+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.677531+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49965 | TCP |
2024-11-22T17:40:11.940390+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.940390+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:11.940390+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.394137+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.394137+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.513836+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49970 | TCP |
2024-11-22T17:40:13.780404+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.780404+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:13.780404+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.065652+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.065652+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.188463+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49976 | TCP |
2024-11-22T17:40:15.455772+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.455772+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:15.455772+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:16.777601+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:16.777601+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:16.897699+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49981 | TCP |
2024-11-22T17:40:17.167831+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:17.167831+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:17.167831+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.529455+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.529455+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.649027+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49984 | TCP |
2024-11-22T17:40:18.923857+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.923857+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:18.923857+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.330214+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.330214+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.449796+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49990 | TCP |
2024-11-22T17:40:20.873102+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.873102+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:20.873102+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.279856+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.279856+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.401027+0100 | 2025483 | ET MALWARE LokiBot Fake 404 Response | 1 | 94.156.177.41 | 80 | 192.168.2.4 | 49995 | TCP |
2024-11-22T17:40:22.672655+0100 | 2021641 | ET MALWARE LokiBot User-Agent (Charon/Inferno) | 1 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.672655+0100 | 2025381 | ET MALWARE LokiBot Checkin | 1 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:22.672655+0100 | 2825766 | ETPRO MALWARE LokiBot Checkin M2 | 1 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:24.138359+0100 | 2024313 | ET MALWARE LokiBot Request for C2 Commands Detected M1 | 1 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
2024-11-22T17:40:24.138359+0100 | 2024318 | ET MALWARE LokiBot Request for C2 Commands Detected M2 | 1 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 22, 2024 17:38:20.137862921 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:20.260165930 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:20.260262966 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:20.262320042 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:20.381899118 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:20.385793924 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:20.506242037 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:21.672959089 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:21.673105001 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:21.673769951 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:21.673820972 CET | 49733 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:21.794495106 CET | 80 | 49733 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:21.808927059 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:21.930843115 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:21.930949926 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:21.933479071 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:22.053076029 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:22.053196907 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:22.172765970 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.332376003 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.332487106 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.332524061 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.332729101 CET | 49735 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.418351889 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.452244997 CET | 80 | 49735 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.538078070 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.538388014 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.543745041 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.664089918 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:23.667762995 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:23.788616896 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:24.937561989 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:24.937700987 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:24.937743902 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:24.937743902 CET | 49736 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:25.060055971 CET | 80 | 49736 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:25.100286961 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:25.294733047 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:25.294951916 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:25.299732924 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:25.419250965 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:25.419739008 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:25.539408922 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:26.772850990 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:26.773046017 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:26.773102045 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:26.777545929 CET | 49738 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:26.901212931 CET | 80 | 49738 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:26.930571079 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:27.056574106 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:27.056672096 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:27.059416056 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:27.183681965 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:27.183871984 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:27.303469896 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:28.639436007 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:28.639604092 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:28.639683008 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:28.639683008 CET | 49739 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:28.759253025 CET | 80 | 49739 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:28.791460037 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:28.911700010 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:28.911786079 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:28.914505005 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:29.035039902 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:29.035149097 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:29.155675888 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.444330931 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.444484949 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.444495916 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.444556952 CET | 49740 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.564948082 CET | 80 | 49740 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.601917028 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.722234964 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.722369909 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.724769115 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.844373941 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:30.844446898 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:30.967636108 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.251027107 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.251152992 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.251169920 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.251214027 CET | 49741 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.375027895 CET | 80 | 49741 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.416835070 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.536413908 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.536786079 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.538633108 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.660919905 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:32.663837910 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:32.783415079 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:33.940777063 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:33.940817118 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:33.940876961 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:33.940916061 CET | 49743 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:34.060918093 CET | 80 | 49743 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:34.088253975 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:34.207823992 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:34.207920074 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:34.211275101 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:34.330879927 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:34.331046104 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:34.450628996 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:35.739247084 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:35.739339113 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:35.739391088 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:35.739444971 CET | 49745 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:35.862947941 CET | 80 | 49745 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:35.883506060 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:36.007707119 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:36.007818937 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:36.009876966 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:36.394360065 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:36.400959969 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:36.401062012 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:36.515647888 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:36.521666050 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:37.721430063 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:37.721477032 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:37.721602917 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:37.725712061 CET | 49748 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:37.847124100 CET | 80 | 49748 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:37.869770050 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:37.989345074 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:37.989429951 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:37.991627932 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:38.111229897 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:38.111285925 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:38.231889009 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.565046072 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.565068960 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.565165997 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:39.565165997 CET | 49749 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:39.689057112 CET | 80 | 49749 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.706327915 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:39.826114893 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.826231956 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:39.828217983 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:39.947945118 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:39.948024988 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:40.067854881 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.267765045 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.267779112 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.267831087 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.268070936 CET | 49751 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.388206959 CET | 80 | 49751 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.413249969 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.535583973 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.535676956 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.537769079 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.658865929 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:41.659081936 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:41.778654099 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.017709017 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.017901897 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.017978907 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.018102884 CET | 49753 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.138286114 CET | 80 | 49753 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.170975924 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.290558100 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.290704012 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.293705940 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.413337946 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:43.413429976 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:43.534756899 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:44.821378946 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:44.821525097 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:44.821686983 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:44.821751118 CET | 49754 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:44.941143036 CET | 80 | 49754 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:44.957221985 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:45.077297926 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:45.077439070 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:45.079622030 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:45.199644089 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:45.199702024 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:45.319600105 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.587224960 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.587265015 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.587353945 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:46.587394953 CET | 49755 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:46.707140923 CET | 80 | 49755 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.725450993 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:46.846040010 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.846203089 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:46.848512888 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:46.970364094 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:46.970644951 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:47.095890999 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.298242092 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.298368931 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.298382044 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.298453093 CET | 49756 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.418123007 CET | 80 | 49756 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.447061062 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.566957951 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.567092896 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.569140911 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.693805933 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:48.693876982 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:48.819236994 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.103084087 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.103179932 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.103231907 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.103554010 CET | 49757 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.222754002 CET | 80 | 49757 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.252827883 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.372426033 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.372561932 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.374321938 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.493808985 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:50.493984938 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:50.615389109 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:51.915977001 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:51.916115999 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:51.916181087 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:51.922749043 CET | 49758 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:52.042226076 CET | 80 | 49758 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:52.068408966 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:52.188014030 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:52.188101053 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:52.189835072 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:52.309343100 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:52.309427023 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:52.428996086 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:53.760936022 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:53.761030912 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:53.761107922 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:53.761153936 CET | 49759 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:53.883990049 CET | 80 | 49759 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:53.909797907 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:54.034085989 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:54.035665035 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:54.037755966 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:54.157320976 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:54.159921885 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:54.280143023 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:55.610198021 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:55.610382080 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:55.610382080 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:55.610471010 CET | 49760 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:55.733469009 CET | 80 | 49760 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:55.763942957 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:55.884566069 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:55.884691000 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:55.886729002 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:56.007050991 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:56.007118940 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:56.128679037 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.457268953 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.457422018 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.457474947 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.457541943 CET | 49762 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.577178955 CET | 80 | 49762 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.605179071 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.725462914 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.725872993 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.727844954 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.847414017 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:57.847692966 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:57.968549013 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.302567005 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.302710056 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.302737951 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.302794933 CET | 49768 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.426546097 CET | 80 | 49768 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.440942049 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.608441114 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.608582020 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.610678911 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.730158091 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:38:59.730254889 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:38:59.850593090 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.010632992 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.010755062 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.010855913 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.010906935 CET | 49769 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.131407022 CET | 80 | 49769 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.149786949 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.269344091 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.269783020 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.271894932 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.391530991 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:01.391644955 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:01.512151957 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:02.801037073 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:02.801172972 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:02.801379919 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:02.801434040 CET | 49775 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:02.920927048 CET | 80 | 49775 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:02.945754051 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:03.065608978 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:03.065876961 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:03.067959070 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:03.187405109 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:03.187494993 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:03.307110071 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.480725050 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.480839968 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.480951071 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.481015921 CET | 49781 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.600570917 CET | 80 | 49781 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.628365040 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.748048067 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.750089884 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.751878023 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.873462915 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:04.874345064 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:04.994447947 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.235555887 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.235800982 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.235877037 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.235929966 CET | 49787 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.355478048 CET | 80 | 49787 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.378495932 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.499408007 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.499619007 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.501547098 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.624631882 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:06.624696970 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:06.745925903 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:07.860249996 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:07.860367060 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:07.860410929 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:07.860447884 CET | 49788 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:07.980187893 CET | 80 | 49788 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:08.004100084 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:08.125183105 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:08.125297070 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:08.127332926 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:08.248356104 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:08.251882076 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:08.373492002 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:09.681982994 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:09.682146072 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:09.682370901 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:09.682441950 CET | 49794 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:09.802908897 CET | 80 | 49794 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:09.832218885 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:09.951980114 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:09.952083111 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:09.955069065 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:10.074831009 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:10.075035095 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:10.195442915 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.305012941 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.305165052 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.305203915 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.305252075 CET | 49800 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.424820900 CET | 80 | 49800 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.451225996 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.570990086 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.571108103 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.574165106 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.694134951 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:11.694205046 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:11.816440105 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.054687023 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.054754972 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.054806948 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.054968119 CET | 49806 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.174860954 CET | 80 | 49806 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.207679987 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.327430964 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.327531099 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.330580950 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.452759027 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:13.452853918 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:13.572524071 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:14.727401018 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:14.727694988 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:14.727840900 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:14.727955103 CET | 49807 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:14.848103046 CET | 80 | 49807 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:14.862828970 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:14.982588053 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:14.982724905 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:14.984954119 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:15.106004953 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:15.106128931 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:15.225786924 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.480851889 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.480959892 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.481024027 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.481060982 CET | 49814 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.600800037 CET | 80 | 49814 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.630595922 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.750190973 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.751986027 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.753679037 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.873368979 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:16.873575926 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:16.993340969 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.289005995 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.289077044 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.289205074 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.289644957 CET | 49820 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.412864923 CET | 80 | 49820 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.529416084 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.650351048 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.650458097 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.652259111 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.772546053 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:18.772634029 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:18.892538071 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.131437063 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.131473064 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.131550074 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.131692886 CET | 49826 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.251127005 CET | 80 | 49826 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.269785881 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.389367104 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.391848087 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.393621922 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.513151884 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:20.515913963 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:20.636499882 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:21.922034025 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:21.922180891 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:21.922261953 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:21.922321081 CET | 49830 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:22.044326067 CET | 80 | 49830 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:22.066808939 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:22.186733007 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:22.186948061 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:22.188827991 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:22.314522982 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:22.314599991 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:22.439863920 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:23.676054955 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:23.676175117 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:23.676268101 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:23.676318884 CET | 49834 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:23.796269894 CET | 80 | 49834 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:23.824381113 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:23.944221020 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:23.944381952 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:23.947361946 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:24.067006111 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:24.067070961 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:24.186597109 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.302767992 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.302884102 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.302977085 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.303193092 CET | 49839 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.422629118 CET | 80 | 49839 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.454355955 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.574307919 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.574544907 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.577486992 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.697432995 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:25.697513103 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:25.817264080 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.054007053 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.054131985 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.054176092 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.054210901 CET | 49845 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.173858881 CET | 80 | 49845 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.193262100 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.313162088 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.313330889 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.315241098 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.435455084 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:27.435691118 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:27.555305004 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:28.888890028 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:28.889019012 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:28.889079094 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:28.889134884 CET | 49851 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:29.008703947 CET | 80 | 49851 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:29.035540104 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:29.155242920 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:29.155498981 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:29.157468081 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:29.277345896 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:29.277427912 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:29.397070885 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.602054119 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.602082014 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.602180004 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:30.602238894 CET | 49853 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:30.723331928 CET | 80 | 49853 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.738857031 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:30.858542919 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.858638048 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:30.860815048 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:30.980386972 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:30.980501890 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:31.100344896 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.319843054 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.319974899 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.320007086 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.320063114 CET | 49858 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.439587116 CET | 80 | 49858 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.460311890 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.580173016 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.580312967 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.582351923 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.779086113 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:32.779201984 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:32.934107065 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.064419031 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.064527035 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.064604044 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.064646006 CET | 49864 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.184104919 CET | 80 | 49864 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.212327003 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.331859112 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.331958055 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.334594965 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.454606056 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:34.454699993 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:34.574393988 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:35.909826040 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:35.909848928 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:35.909914970 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:35.910069942 CET | 49869 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:36.030122995 CET | 80 | 49869 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:36.391951084 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:36.511449099 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:36.511543036 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:36.518543959 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:36.638083935 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:36.638263941 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:36.757836103 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:37.911163092 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:37.911422968 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:37.911434889 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:37.911483049 CET | 49875 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:38.031130075 CET | 80 | 49875 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:38.073164940 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:38.192841053 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:38.195971966 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:38.199114084 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:38.319088936 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:38.319160938 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:38.438910961 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:39.774283886 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:39.774358034 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:39.774405003 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:39.774466991 CET | 49878 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:39.893944025 CET | 80 | 49878 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:39.911514997 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:40.031264067 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:40.031404018 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:40.033540964 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:40.156470060 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:40.156593084 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:40.276273966 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.435794115 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.435904026 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.435945988 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.435991049 CET | 49883 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.556668997 CET | 80 | 49883 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.590384960 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.709949017 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.710035086 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.712372065 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.831861019 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:41.832001925 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:41.951833963 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.209742069 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.209940910 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.211462021 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.211534023 CET | 49889 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.330265999 CET | 80 | 49889 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.356964111 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.476849079 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.476964951 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.480339050 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.599814892 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:43.599899054 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:43.719422102 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:44.928255081 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:44.928389072 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:44.928430080 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:44.928484917 CET | 49894 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:45.051310062 CET | 80 | 49894 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:45.065685034 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:45.185334921 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:45.185427904 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:45.187427044 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:45.307025909 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:45.307094097 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:45.426630974 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:46.763998985 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:46.764098883 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:46.764115095 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:46.764152050 CET | 49898 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:46.887092113 CET | 80 | 49898 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:46.910146952 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:47.032720089 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:47.032844067 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:47.035160065 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:47.159826040 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:47.159996986 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:47.284257889 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:48.566066980 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:48.566159964 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:48.566330910 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:48.566330910 CET | 49902 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:48.686602116 CET | 80 | 49902 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:48.927112103 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:49.046622992 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:49.046719074 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:49.049055099 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:49.169121981 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:49.169188976 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:49.290102005 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.496753931 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.496933937 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.496974945 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:50.497009993 CET | 49907 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:50.616894007 CET | 80 | 49907 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.651004076 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:50.770690918 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.770804882 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:50.772958040 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:50.892405033 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:50.892508984 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:51.012083054 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.341576099 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.341768980 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.341897011 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.341897011 CET | 49913 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.461464882 CET | 80 | 49913 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.500437021 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.620732069 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.620826006 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.622878075 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.742398977 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:52.742489100 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:52.862409115 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.151818037 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.151843071 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.151906967 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.151931047 CET | 49917 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.273216963 CET | 80 | 49917 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.290039062 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.409564972 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.409774065 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.411840916 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.532161951 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:54.532238007 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:54.655554056 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:55.765755892 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:55.765846014 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:55.765985012 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:55.766098022 CET | 49922 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:55.885986090 CET | 80 | 49922 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:55.910949945 CET | 49926 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:56.031737089 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:56.031858921 CET | 49926 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:56.034006119 CET | 49926 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:56.154486895 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:56.154638052 CET | 49926 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:56.274411917 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.516748905 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.516896963 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.517014980 CET | 49926 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:57.636701107 CET | 80 | 49926 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.660712004 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:57.781261921 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.781424046 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:57.783540010 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:57.905011892 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:57.905220985 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:58.024755955 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.228705883 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.228878975 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.228926897 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.228987932 CET | 49932 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.348826885 CET | 80 | 49932 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.371396065 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.492074966 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.492219925 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.497380018 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.617477894 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:39:59.617554903 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:39:59.737829924 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.069856882 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.069950104 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.069977999 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.070010900 CET | 49937 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.189433098 CET | 80 | 49937 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.218647003 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.338296890 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.338401079 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.341367960 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.461124897 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:01.461226940 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:01.580817938 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:02.745074987 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:02.745093107 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:02.745173931 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:02.745208979 CET | 49942 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:02.878787994 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:02.986093044 CET | 80 | 49942 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:02.998406887 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:02.998523951 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:03.000669003 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:03.120337009 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:03.120404959 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:03.240005016 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.526101112 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.526233912 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.526328087 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:04.526328087 CET | 49945 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:04.646102905 CET | 80 | 49945 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.665785074 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:04.785433054 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.785701036 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:04.788348913 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:04.910341978 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:04.910449982 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:05.030009985 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.269392967 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.269452095 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.269586086 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.269684076 CET | 49951 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.389791012 CET | 80 | 49951 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.409576893 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.529684067 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.529804945 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.531886101 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.653244972 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:06.653373957 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:06.773073912 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.104639053 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.104744911 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.104775906 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.104819059 CET | 49957 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.225754976 CET | 80 | 49957 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.237373114 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.357147932 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.357280016 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.359375000 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.480283976 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:08.480379105 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:08.599953890 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:09.891527891 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:09.891618013 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:09.891748905 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:09.891750097 CET | 49961 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:10.011539936 CET | 80 | 49961 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:10.039467096 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:10.159194946 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:10.159285069 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:10.162188053 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:10.283293962 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:10.283380032 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:10.402885914 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.557749987 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.557939053 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:11.557984114 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.558062077 CET | 49965 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:11.677531004 CET | 80 | 49965 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.698425055 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:11.818003893 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.818142891 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:11.820862055 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:11.940304041 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:11.940390110 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:12.059907913 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.393899918 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.393992901 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.394136906 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.394186020 CET | 49970 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.513835907 CET | 80 | 49970 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.538705111 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.658473015 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.658709049 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.660808086 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.780323029 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:13.780404091 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:13.901499033 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.065463066 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.065615892 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.065651894 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.065686941 CET | 49976 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.188462973 CET | 80 | 49976 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.213808060 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.333775997 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.333883047 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.336205959 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.455688000 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:15.455771923 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:15.575445890 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:16.777442932 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:16.777518034 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:16.777601004 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:16.777636051 CET | 49981 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:16.897699118 CET | 80 | 49981 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:16.923423052 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:17.042998075 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:17.044049025 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:17.046169043 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:17.165817976 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:17.167830944 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:17.287533998 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.529325008 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.529454947 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:18.529480934 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.529545069 CET | 49984 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:18.649027109 CET | 80 | 49984 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.682302952 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:18.802068949 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.802206993 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:18.804296017 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:18.923772097 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:18.923856974 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:19.043404102 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.330070019 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.330144882 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.330214024 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.331954002 CET | 49990 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.449795961 CET | 80 | 49990 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.630951881 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.750711918 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.750821114 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.753468990 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.873039007 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:20.873101950 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:20.994288921 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.279743910 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.279778004 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.279855967 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.279881001 CET | 49995 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.401026964 CET | 80 | 49995 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.427679062 CET | 50000 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.547498941 CET | 80 | 50000 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.547760010 CET | 50000 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.549735069 CET | 50000 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.672595978 CET | 80 | 50000 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:22.672655106 CET | 50000 | 80 | 192.168.2.4 | 94.156.177.41 |
Nov 22, 2024 17:40:22.794616938 CET | 80 | 50000 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:24.138025999 CET | 80 | 50000 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:24.138267040 CET | 80 | 50000 | 94.156.177.41 | 192.168.2.4 |
Nov 22, 2024 17:40:24.138359070 CET | 50000 | 80 | 192.168.2.4 | 94.156.177.41 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49733 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:20.262320042 CET | 244 | OUT | |
Nov 22, 2024 17:38:20.385793924 CET | 176 | OUT | |
Nov 22, 2024 17:38:21.672959089 CET | 185 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49735 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:21.933479071 CET | 244 | OUT | |
Nov 22, 2024 17:38:22.053196907 CET | 176 | OUT | |
Nov 22, 2024 17:38:23.332376003 CET | 185 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49736 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:23.543745041 CET | 244 | OUT | |
Nov 22, 2024 17:38:23.667762995 CET | 149 | OUT | |
Nov 22, 2024 17:38:24.937561989 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49738 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:25.299732924 CET | 244 | OUT | |
Nov 22, 2024 17:38:25.419739008 CET | 149 | OUT | |
Nov 22, 2024 17:38:26.772850990 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49739 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:27.059416056 CET | 244 | OUT | |
Nov 22, 2024 17:38:27.183871984 CET | 149 | OUT | |
Nov 22, 2024 17:38:28.639436007 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49740 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:28.914505005 CET | 244 | OUT | |
Nov 22, 2024 17:38:29.035149097 CET | 149 | OUT | |
Nov 22, 2024 17:38:30.444330931 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49741 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:30.724769115 CET | 244 | OUT | |
Nov 22, 2024 17:38:30.844446898 CET | 149 | OUT | |
Nov 22, 2024 17:38:32.251027107 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49743 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:32.538633108 CET | 244 | OUT | |
Nov 22, 2024 17:38:32.663837910 CET | 149 | OUT | |
Nov 22, 2024 17:38:33.940777063 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49745 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:34.211275101 CET | 244 | OUT | |
Nov 22, 2024 17:38:34.331046104 CET | 149 | OUT | |
Nov 22, 2024 17:38:35.739247084 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49748 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:36.009876966 CET | 244 | OUT | |
Nov 22, 2024 17:38:36.394360065 CET | 393 | OUT | |
Nov 22, 2024 17:38:36.401062012 CET | 149 | OUT | |
Nov 22, 2024 17:38:37.721430063 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49749 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:37.991627932 CET | 244 | OUT | |
Nov 22, 2024 17:38:38.111285925 CET | 149 | OUT | |
Nov 22, 2024 17:38:39.565046072 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49751 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:39.828217983 CET | 244 | OUT | |
Nov 22, 2024 17:38:39.948024988 CET | 149 | OUT | |
Nov 22, 2024 17:38:41.267765045 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49753 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:41.537769079 CET | 244 | OUT | |
Nov 22, 2024 17:38:41.659081936 CET | 149 | OUT | |
Nov 22, 2024 17:38:43.017709017 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49754 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:43.293705940 CET | 244 | OUT | |
Nov 22, 2024 17:38:43.413429976 CET | 149 | OUT | |
Nov 22, 2024 17:38:44.821378946 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49755 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:45.079622030 CET | 244 | OUT | |
Nov 22, 2024 17:38:45.199702024 CET | 149 | OUT | |
Nov 22, 2024 17:38:46.587224960 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49756 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:46.848512888 CET | 244 | OUT | |
Nov 22, 2024 17:38:46.970644951 CET | 149 | OUT | |
Nov 22, 2024 17:38:48.298242092 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49757 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:48.569140911 CET | 244 | OUT | |
Nov 22, 2024 17:38:48.693876982 CET | 149 | OUT | |
Nov 22, 2024 17:38:50.103084087 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49758 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:50.374321938 CET | 244 | OUT | |
Nov 22, 2024 17:38:50.493984938 CET | 149 | OUT | |
Nov 22, 2024 17:38:51.915977001 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49759 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:52.189835072 CET | 244 | OUT | |
Nov 22, 2024 17:38:52.309427023 CET | 149 | OUT | |
Nov 22, 2024 17:38:53.760936022 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49760 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:54.037755966 CET | 244 | OUT | |
Nov 22, 2024 17:38:54.159921885 CET | 149 | OUT | |
Nov 22, 2024 17:38:55.610198021 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49762 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:55.886729002 CET | 244 | OUT | |
Nov 22, 2024 17:38:56.007118940 CET | 149 | OUT | |
Nov 22, 2024 17:38:57.457268953 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49768 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:57.727844954 CET | 244 | OUT | |
Nov 22, 2024 17:38:57.847692966 CET | 149 | OUT | |
Nov 22, 2024 17:38:59.302567005 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49769 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:38:59.610678911 CET | 244 | OUT | |
Nov 22, 2024 17:38:59.730254889 CET | 149 | OUT | |
Nov 22, 2024 17:39:01.010632992 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49775 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:01.271894932 CET | 244 | OUT | |
Nov 22, 2024 17:39:01.391644955 CET | 149 | OUT | |
Nov 22, 2024 17:39:02.801037073 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49781 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:03.067959070 CET | 244 | OUT | |
Nov 22, 2024 17:39:03.187494993 CET | 149 | OUT | |
Nov 22, 2024 17:39:04.480725050 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49787 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:04.751878023 CET | 244 | OUT | |
Nov 22, 2024 17:39:04.874345064 CET | 149 | OUT | |
Nov 22, 2024 17:39:06.235555887 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49788 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:06.501547098 CET | 244 | OUT | |
Nov 22, 2024 17:39:06.624696970 CET | 149 | OUT | |
Nov 22, 2024 17:39:07.860249996 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49794 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:08.127332926 CET | 244 | OUT | |
Nov 22, 2024 17:39:08.251882076 CET | 149 | OUT | |
Nov 22, 2024 17:39:09.681982994 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49800 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:09.955069065 CET | 244 | OUT | |
Nov 22, 2024 17:39:10.075035095 CET | 149 | OUT | |
Nov 22, 2024 17:39:11.305012941 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49806 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:11.574165106 CET | 244 | OUT | |
Nov 22, 2024 17:39:11.694205046 CET | 149 | OUT | |
Nov 22, 2024 17:39:13.054687023 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49807 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:13.330580950 CET | 244 | OUT | |
Nov 22, 2024 17:39:13.452853918 CET | 149 | OUT | |
Nov 22, 2024 17:39:14.727401018 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49814 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:14.984954119 CET | 244 | OUT | |
Nov 22, 2024 17:39:15.106128931 CET | 149 | OUT | |
Nov 22, 2024 17:39:16.480851889 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49820 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:16.753679037 CET | 244 | OUT | |
Nov 22, 2024 17:39:16.873575926 CET | 149 | OUT | |
Nov 22, 2024 17:39:18.289005995 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49826 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:18.652259111 CET | 244 | OUT | |
Nov 22, 2024 17:39:18.772634029 CET | 149 | OUT | |
Nov 22, 2024 17:39:20.131437063 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49830 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:20.393621922 CET | 244 | OUT | |
Nov 22, 2024 17:39:20.515913963 CET | 149 | OUT | |
Nov 22, 2024 17:39:21.922034025 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49834 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:22.188827991 CET | 244 | OUT | |
Nov 22, 2024 17:39:22.314599991 CET | 149 | OUT | |
Nov 22, 2024 17:39:23.676054955 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49839 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:23.947361946 CET | 244 | OUT | |
Nov 22, 2024 17:39:24.067070961 CET | 149 | OUT | |
Nov 22, 2024 17:39:25.302767992 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49845 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:25.577486992 CET | 244 | OUT | |
Nov 22, 2024 17:39:25.697513103 CET | 149 | OUT | |
Nov 22, 2024 17:39:27.054007053 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49851 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:27.315241098 CET | 244 | OUT | |
Nov 22, 2024 17:39:27.435691118 CET | 149 | OUT | |
Nov 22, 2024 17:39:28.888890028 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49853 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:29.157468081 CET | 244 | OUT | |
Nov 22, 2024 17:39:29.277427912 CET | 149 | OUT | |
Nov 22, 2024 17:39:30.602054119 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49858 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:30.860815048 CET | 244 | OUT | |
Nov 22, 2024 17:39:30.980501890 CET | 149 | OUT | |
Nov 22, 2024 17:39:32.319843054 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49864 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:32.582351923 CET | 244 | OUT | |
Nov 22, 2024 17:39:32.779201984 CET | 149 | OUT | |
Nov 22, 2024 17:39:34.064419031 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49869 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:34.334594965 CET | 244 | OUT | |
Nov 22, 2024 17:39:34.454699993 CET | 149 | OUT | |
Nov 22, 2024 17:39:35.909826040 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49875 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:36.518543959 CET | 244 | OUT | |
Nov 22, 2024 17:39:36.638263941 CET | 149 | OUT | |
Nov 22, 2024 17:39:37.911163092 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49878 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:38.199114084 CET | 244 | OUT | |
Nov 22, 2024 17:39:38.319160938 CET | 149 | OUT | |
Nov 22, 2024 17:39:39.774283886 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49883 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:40.033540964 CET | 244 | OUT | |
Nov 22, 2024 17:39:40.156593084 CET | 149 | OUT | |
Nov 22, 2024 17:39:41.435794115 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49889 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:41.712372065 CET | 244 | OUT | |
Nov 22, 2024 17:39:41.832001925 CET | 149 | OUT | |
Nov 22, 2024 17:39:43.209742069 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 49894 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:43.480339050 CET | 244 | OUT | |
Nov 22, 2024 17:39:43.599899054 CET | 149 | OUT | |
Nov 22, 2024 17:39:44.928255081 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 49898 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:45.187427044 CET | 244 | OUT | |
Nov 22, 2024 17:39:45.307094097 CET | 149 | OUT | |
Nov 22, 2024 17:39:46.763998985 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 49902 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:47.035160065 CET | 244 | OUT | |
Nov 22, 2024 17:39:47.159996986 CET | 149 | OUT | |
Nov 22, 2024 17:39:48.566066980 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 49907 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:49.049055099 CET | 244 | OUT | |
Nov 22, 2024 17:39:49.169188976 CET | 149 | OUT | |
Nov 22, 2024 17:39:50.496753931 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 49913 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:50.772958040 CET | 244 | OUT | |
Nov 22, 2024 17:39:50.892508984 CET | 149 | OUT | |
Nov 22, 2024 17:39:52.341576099 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 49917 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:52.622878075 CET | 244 | OUT | |
Nov 22, 2024 17:39:52.742489100 CET | 149 | OUT | |
Nov 22, 2024 17:39:54.151818037 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 49922 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:54.411840916 CET | 244 | OUT | |
Nov 22, 2024 17:39:54.532238007 CET | 149 | OUT | |
Nov 22, 2024 17:39:55.765755892 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 49926 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:56.034006119 CET | 244 | OUT | |
Nov 22, 2024 17:39:56.154638052 CET | 149 | OUT | |
Nov 22, 2024 17:39:57.516748905 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 49932 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:57.783540010 CET | 244 | OUT | |
Nov 22, 2024 17:39:57.905220985 CET | 149 | OUT | |
Nov 22, 2024 17:39:59.228705883 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 49937 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:39:59.497380018 CET | 244 | OUT | |
Nov 22, 2024 17:39:59.617554903 CET | 149 | OUT | |
Nov 22, 2024 17:40:01.069856882 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.4 | 49942 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:01.341367960 CET | 244 | OUT | |
Nov 22, 2024 17:40:01.461226940 CET | 149 | OUT | |
Nov 22, 2024 17:40:02.745074987 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.4 | 49945 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:03.000669003 CET | 244 | OUT | |
Nov 22, 2024 17:40:03.120404959 CET | 149 | OUT | |
Nov 22, 2024 17:40:04.526101112 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.4 | 49951 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:04.788348913 CET | 244 | OUT | |
Nov 22, 2024 17:40:04.910449982 CET | 149 | OUT | |
Nov 22, 2024 17:40:06.269392967 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.4 | 49957 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:06.531886101 CET | 244 | OUT | |
Nov 22, 2024 17:40:06.653373957 CET | 149 | OUT | |
Nov 22, 2024 17:40:08.104639053 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.4 | 49961 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:08.359375000 CET | 244 | OUT | |
Nov 22, 2024 17:40:08.480379105 CET | 149 | OUT | |
Nov 22, 2024 17:40:09.891527891 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.4 | 49965 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:10.162188053 CET | 244 | OUT | |
Nov 22, 2024 17:40:10.283380032 CET | 149 | OUT | |
Nov 22, 2024 17:40:11.557749987 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.4 | 49970 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:11.820862055 CET | 244 | OUT | |
Nov 22, 2024 17:40:11.940390110 CET | 149 | OUT | |
Nov 22, 2024 17:40:13.393899918 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.4 | 49976 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:13.660808086 CET | 244 | OUT | |
Nov 22, 2024 17:40:13.780404091 CET | 149 | OUT | |
Nov 22, 2024 17:40:15.065463066 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.4 | 49981 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:15.336205959 CET | 244 | OUT | |
Nov 22, 2024 17:40:15.455771923 CET | 149 | OUT | |
Nov 22, 2024 17:40:16.777442932 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.4 | 49984 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:17.046169043 CET | 244 | OUT | |
Nov 22, 2024 17:40:17.167830944 CET | 149 | OUT | |
Nov 22, 2024 17:40:18.529325008 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.4 | 49990 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:18.804296017 CET | 244 | OUT | |
Nov 22, 2024 17:40:18.923856974 CET | 149 | OUT | |
Nov 22, 2024 17:40:20.330070019 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.4 | 49995 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:20.753468990 CET | 244 | OUT | |
Nov 22, 2024 17:40:20.873101950 CET | 149 | OUT | |
Nov 22, 2024 17:40:22.279743910 CET | 193 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.4 | 50000 | 94.156.177.41 | 80 | 7716 | C:\Users\user\Desktop\file.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 22, 2024 17:40:22.549735069 CET | 244 | OUT | |
Nov 22, 2024 17:40:22.672655106 CET | 149 | OUT | |
Nov 22, 2024 17:40:24.138025999 CET | 193 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:38:15 |
Start date: | 22/11/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1f0000 |
File size: | 600'576 bytes |
MD5 hash: | 66B03D1AFF27D81E62B53FC108806211 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:38:18 |
Start date: | 22/11/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x310000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:38:18 |
Start date: | 22/11/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbf0000 |
File size: | 600'576 bytes |
MD5 hash: | 66B03D1AFF27D81E62B53FC108806211 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 4 |
Start time: | 11:38:18 |
Start date: | 22/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:38:20 |
Start date: | 22/11/2024 |
Path: | C:\Windows\System32\wbem\WmiPrvSE.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff693ab0000 |
File size: | 496'640 bytes |
MD5 hash: | 60FF40CFD7FB8FE41EE4FE9AE5FE1C51 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 10.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 185 |
Total number of Limit Nodes: | 11 |
Graph
Function 04B16FE8 Relevance: 18.4, Strings: 14, Instructions: 878COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04B16FD8 Relevance: 18.3, Strings: 14, Instructions: 809COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0674B328 Relevance: .6, Instructions: 628COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0246AD08 Relevance: 1.7, APIs: 1, Instructions: 197COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 024658EC Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 024644B0 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04B14040 Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747D18 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0246D1DC Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747A92 Relevance: 1.6, APIs: 1, Instructions: 64threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0246D5E9 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747D20 Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747A98 Relevance: 1.6, APIs: 1, Instructions: 63threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747B68 Relevance: 1.6, APIs: 1, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747B70 Relevance: 1.6, APIs: 1, Instructions: 53memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067475A8 Relevance: 1.6, APIs: 1, Instructions: 51threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067475B0 Relevance: 1.5, APIs: 1, Instructions: 49threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0674A6B8 Relevance: 1.5, APIs: 1, Instructions: 48windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06744818 Relevance: 1.5, APIs: 1, Instructions: 47windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0246AEF8 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067475B7 Relevance: 1.5, APIs: 1, Instructions: 46threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0232D4C4 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0233D1D4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0233D01C Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0233D006 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0232D4BF Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0233D1CF Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06747660 Relevance: 1.6, Strings: 1, Instructions: 312COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 067456B0 Relevance: 1.6, Strings: 1, Instructions: 312COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06745AE8 Relevance: 1.6, Strings: 1, Instructions: 312COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04B10040 Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06745F20 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06745278 Relevance: .3, Instructions: 312COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0246D51C Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 04B10006 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 31.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 4.4% |
Total number of Nodes: | 1846 |
Total number of Limit Nodes: | 94 |
Graph
Function 00403D74 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 200fileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402B7C Relevance: 3.0, APIs: 2, Instructions: 20memoryCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404ED4 Relevance: 1.5, APIs: 1, Instructions: 9networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404E17 Relevance: 7.6, APIs: 5, Instructions: 72networkCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004040BB Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 129filememoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004042CF Relevance: 4.6, APIs: 3, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00412D31 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 178threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402C03 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 13libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004060BD Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403C62 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040642C Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404EEA Relevance: 1.5, APIs: 1, Instructions: 16networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403BD0 Relevance: 1.5, APIs: 1, Instructions: 14COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404DF3 Relevance: 1.5, APIs: 1, Instructions: 13networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040427D Relevance: 1.5, APIs: 1, Instructions: 13COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403C08 Relevance: 1.5, APIs: 1, Instructions: 12fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402C1F Relevance: 1.5, APIs: 1, Instructions: 12libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403BEF Relevance: 1.5, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403BB7 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403B64 Relevance: 1.5, APIs: 1, Instructions: 11COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00404DE5 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403F9E Relevance: 1.3, APIs: 1, Instructions: 16COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00403C40 Relevance: 1.3, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00406472 Relevance: 1.3, APIs: 1, Instructions: 12sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004058EA Relevance: 1.3, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00405924 Relevance: 1.3, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040D069 Relevance: 12.6, Strings: 10, Instructions: 138COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040317B Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|