Windows
Analysis Report
Week13.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Week13.exe (PID: 4712 cmdline:
"C:\Users\ user\Deskt op\Week13. exe" MD5: A1B8FA53A47B1991EE76A46EE8685B7D) - oneetx.exe (PID: 6160 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\cb7ae7 01b3\oneet x.exe" MD5: A1B8FA53A47B1991EE76A46EE8685B7D) - schtasks.exe (PID: 6592 cmdline:
"C:\Window s\System32 \schtasks. exe" /Crea te /SC MIN UTE /MO 1 /TN oneetx .exe /TR " C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe" /F MD5: 48C2FE20575769DE916F48EF0676A965) - conhost.exe (PID: 1252 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 5024 cmdline:
"C:\Window s\System32 \cmd.exe" /k echo Y| CACLS "one etx.exe" / P "user:N" &&CACLS "o neetx.exe" /P "user: R" /E&&ech o Y|CACLS "..\cb7ae7 01b3" /P " user:N"&&C ACLS "..\c b7ae701b3" /P "user: R" /E&&Exi t MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6620 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 5332 cmdline:
C:\Windows \system32\ cmd.exe /S /D /c" ec ho Y" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - cacls.exe (PID: 2276 cmdline:
CACLS "one etx.exe" / P "user:N" MD5: 00BAAE10C69DAD58F169A3ED638D6C59) - cacls.exe (PID: 6584 cmdline:
CACLS "one etx.exe" / P "user:R" /E MD5: 00BAAE10C69DAD58F169A3ED638D6C59) - cmd.exe (PID: 5008 cmdline:
C:\Windows \system32\ cmd.exe /S /D /c" ec ho Y" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - cacls.exe (PID: 6628 cmdline:
CACLS "..\ cb7ae701b3 " /P "user :N" MD5: 00BAAE10C69DAD58F169A3ED638D6C59) - cacls.exe (PID: 1120 cmdline:
CACLS "..\ cb7ae701b3 " /P "user :R" /E MD5: 00BAAE10C69DAD58F169A3ED638D6C59)
- oneetx.exe (PID: 3788 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
- oneetx.exe (PID: 5068 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
- oneetx.exe (PID: 4204 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
- oneetx.exe (PID: 5820 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
- oneetx.exe (PID: 6464 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\cb7ae70 1b3\oneetx .exe MD5: A1B8FA53A47B1991EE76A46EE8685B7D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Amadey | Amadey is a botnet that appeared around October 2018 and is being sold for about $500 on Russian-speaking hacking forums. It periodically sends information about the system and installed AV software to its C2 server and polls to receive orders from it. Its main functionality is that it can load other payloads (called "tasks") for all or specifically targeted computers compromised by the malware. | No Attribution |
{"C2 url": "193.3.19.154/store/games/index.php", "Version": "3.80", "Install Folder": "cb7ae701b3", "Install File": "oneetx.exe"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Amadey | Yara detected Amadey bot | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security | ||
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security | ||
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security | ||
JoeSecurity_Amadey | Yara detected Amadey bot | Joe Security | ||
JoeSecurity_Amadey_2 | Yara detected Amadey\'s stealer DLL | Joe Security | ||
Click to see the 14 entries |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T20:52:56.688685+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50036 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:04.143083+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49705 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:08.382363+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49706 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626323+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49707 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:16.860879+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49709 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095201+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49712 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:25.313904+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49722 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579693+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49733 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:33.829480+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49741 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073084+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49752 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:42.313889+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49764 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532660+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49775 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:50.782734+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49787 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:55.042480+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49794 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:59.298221+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49804 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:03.548223+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49815 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:07.798356+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49826 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:12.048318+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49837 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:16.282841+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49848 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:20.533150+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49859 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:24.851912+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49867 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:29.157698+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49878 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:33.560630+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49887 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:37.814020+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49898 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:42.064285+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49909 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:46.314044+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49920 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:50.563900+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49930 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:54.816557+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49940 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:57.550787+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49950 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:01.782905+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49958 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:06.032766+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49967 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:10.291064+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49976 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:14.517087+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49987 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:18.770958+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 49998 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:23.026943+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50009 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:27.284604+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50016 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:31.534796+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50017 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:35.782914+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50018 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:40.001425+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50019 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:44.236221+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50020 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:48.526834+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50021 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:52.784639+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50022 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:57.136097+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50023 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:01.438981+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50024 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:05.680904+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50025 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:09.923228+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50026 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:14.164217+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50027 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:18.455177+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50028 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:22.706673+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50029 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:26.956810+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50030 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:31.204734+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50031 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:35.454542+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50032 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:39.694587+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50033 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:43.907721+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50034 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:48.157989+0100 | 2027700 | 1 | Malware Command and Control Activity Detected | 192.168.2.5 | 50035 | 193.3.19.154 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T20:52:56.688685+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50036 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:04.143083+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49705 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:08.382363+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49706 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626323+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49707 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:16.860879+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49709 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095201+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49712 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:25.313904+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49722 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579693+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49733 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:33.829480+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49741 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073084+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49752 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:42.313889+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49764 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532660+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49775 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:50.782734+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49787 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:55.042480+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49794 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:59.298221+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49804 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:03.548223+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49815 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:07.798356+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49826 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:12.048318+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49837 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:16.282841+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49848 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:20.533150+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49859 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:24.851912+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49867 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:29.157698+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49878 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:33.560630+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49887 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:37.814020+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49898 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:42.064285+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49909 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:46.314044+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49920 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:50.563900+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49930 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:54.816557+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49940 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:57.550787+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49950 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:01.782905+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49958 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:06.032766+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49967 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:10.291064+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49976 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:14.517087+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49987 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:18.770958+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 49998 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:23.026943+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50009 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:27.284604+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50016 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:31.534796+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50017 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:35.782914+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50018 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:40.001425+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50019 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:44.236221+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50020 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:48.526834+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50021 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:52.784639+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50022 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:57.136097+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50023 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:01.438981+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50024 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:05.680904+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50025 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:09.923228+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50026 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:14.164217+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50027 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:18.455177+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50028 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:22.706673+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50029 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:26.956810+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50030 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:31.204734+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50031 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:35.454542+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50032 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:39.694587+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50033 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:43.907721+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50034 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:48.157989+0100 | 2045751 | 1 | A Network Trojan was detected | 192.168.2.5 | 50035 | 193.3.19.154 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T20:53:04.143141+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49704 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626276+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49708 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095122+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49714 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579645+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49735 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073133+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49754 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532797+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.5 | 49776 | 193.3.19.154 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | IPs: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Persistence and Installation Behavior |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Key value created or modified: | Jump to behavior | ||
Source: | Key value created or modified: | Jump to behavior |
Source: | Process created: |
Source: | Process created: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 11 Process Injection | 1 Masquerading | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Scheduled Task/Job | 21 Virtualization/Sandbox Evasion | LSASS Memory | 21 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 Services File Permissions Weakness | 1 Registry Run Keys / Startup Folder | 11 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 12 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 1 DLL Side-Loading | 1 Services File Permissions Weakness | 1 Services File Permissions Weakness | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | 1 DLL Side-Loading | 1 DLL Side-Loading | LSA Secrets | 12 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
92% | ReversingLabs | Win32.Trojan.Amadey | ||
100% | Avira | HEUR/AGEN.1317762 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1317762 | ||
100% | Joe Sandbox ML | |||
92% | ReversingLabs | Win32.Trojan.Amadey |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.3.19.154 | unknown | Denmark | 2107 | ARNES-NETAcademicandResearchNetworkofSloveniaSI | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1561581 |
Start date and time: | 2024-11-23 20:52:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 13s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 20 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Week13.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.winEXE@26/6@0/1 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: Week13.exe
Time | Type | Description |
---|---|---|
14:52:58 | API Interceptor | |
20:52:57 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.3.19.154 | Get hash | malicious | Amadey, Healer AV Disabler, PureLog Stealer, RedLine | Browse |
| |
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
| ||
Get hash | malicious | Amadey, RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ARNES-NETAcademicandResearchNetworkofSloveniaSI | Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| |
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Amadey, Healer AV Disabler, PureLog Stealer, RedLine | Browse |
|
Process: | C:\Users\user\Desktop\Week13.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 209950 |
Entropy (8bit): | 6.342521487985493 |
Encrypted: | false |
SSDEEP: | 3072:c/frTDzurT1S3CzpdmnATE55zjExkKGruONMvhu5QTXzeJX2vkMfSDPwU:Wfrnzurs3Czpexj2kGOIu5QTyJMKk |
MD5: | A1B8FA53A47B1991EE76A46EE8685B7D |
SHA1: | 4002A9CFFCDE9F7F44633457457792564A63BF5D |
SHA-256: | E472FD69B5A891059F44206124BAF829CB7583890E2C8E288E311359A2249871 |
SHA-512: | F685FEF174DED44E2ECA9DF2F75F858611B45672E4DE5D81C868BB7441F476BC20AB8421AE48E2D004B960672C35190C2F4F6B9975A67596DE204918C6E52613 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Week13.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Windows\SysWOW64\cacls.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15 |
Entropy (8bit): | 3.240223928941852 |
Encrypted: | false |
SSDEEP: | 3:o3F:o1 |
MD5: | 509B054634B6DE74F111C3E646BC80FD |
SHA1: | 99B4C0F39144A92FE42E22473A2A2552FB16BD13 |
SHA-256: | 07C7C151ADD6D955F3C876359C0E2A3A3FB0C519DD1E574413F0B68B345D8C36 |
SHA-512: | A9C2D23947DBE09D5ECFBF6B3109F3CF8409E43176AE10C18083446EDE006E60E41C3EA2D2765036A967FC81B085D5F271686606AED4154AE45287D412CF6D40 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 6.342521487985493 |
TrID: |
|
File name: | Week13.exe |
File size: | 209'950 bytes |
MD5: | a1b8fa53a47b1991ee76a46ee8685b7d |
SHA1: | 4002a9cffcde9f7f44633457457792564a63bf5d |
SHA256: | e472fd69b5a891059f44206124baf829cb7583890e2c8e288e311359a2249871 |
SHA512: | f685fef174ded44e2eca9df2f75f858611b45672e4de5d81c868bb7441f476bc20ab8421ae48e2d004b960672c35190c2f4f6b9975a67596de204918c6e52613 |
SSDEEP: | 3072:c/frTDzurT1S3CzpdmnATE55zjExkKGruONMvhu5QTXzeJX2vkMfSDPwU:Wfrnzurs3Czpexj2kGOIu5QTyJMKk |
TLSH: | F524F6257D12C032D561A1B619F5BFF2C59CA828A7B049DB7B800F77DA122F73960E39 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......]..M.o...o...o..B....o..B....o..B....o.......o.......o......5o..B....o...o...o.......o....m..o.......o..Rich.o................. |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x41552f |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6442E0B0 [Fri Apr 21 19:14:56 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | f8cc61ade86cb7277d0ab974de6323cb |
Instruction |
---|
call 00007F4174B0CD79h |
jmp 00007F4174B0C769h |
jmp 00007F4174B0F8B9h |
push ebp |
mov ebp, esp |
sub esp, 00000324h |
push ebx |
push 00000017h |
call 00007F4174B1B8C9h |
test eax, eax |
je 00007F4174B0C8F7h |
mov ecx, dword ptr [ebp+08h] |
int 29h |
push 00000003h |
call 00007F4174B0CA9Bh |
mov dword ptr [esp], 000002CCh |
lea eax, dword ptr [ebp-00000324h] |
push 00000000h |
push eax |
call 00007F4174B0D241h |
add esp, 0Ch |
mov dword ptr [ebp-00000274h], eax |
mov dword ptr [ebp-00000278h], ecx |
mov dword ptr [ebp-0000027Ch], edx |
mov dword ptr [ebp-00000280h], ebx |
mov dword ptr [ebp-00000284h], esi |
mov dword ptr [ebp-00000288h], edi |
mov word ptr [ebp-0000025Ch], ss |
mov word ptr [ebp-00000268h], cs |
mov word ptr [ebp-0000028Ch], ds |
mov word ptr [ebp-00000290h], es |
mov word ptr [ebp-00000294h], fs |
mov word ptr [ebp-00000298h], gs |
pushfd |
pop dword ptr [ebp-00000264h] |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [ebp-0000026Ch], eax |
lea eax, dword ptr [ebp+04h] |
mov dword ptr [ebp-00000260h], eax |
mov dword ptr [ebp-00000324h], 00010001h |
mov eax, dword ptr [eax-04h] |
push 00000050h |
mov dword ptr [ebp-00000270h], eax |
lea eax, dword ptr [ebp-58h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x300d8 | 0x64 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x34000 | 0x1e0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x35000 | 0x208c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x2f360 | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x2f474 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x2f3d0 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x29000 | 0x204 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2722d | 0x27400 | f8a1f275d950abfb13b70d936b801360 | False | 0.4442426353503185 | data | 6.4362141478020645 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x29000 | 0x7c74 | 0x7e00 | a9c9e415c77aeb6ff53c4ca6792ae320 | False | 0.4195808531746032 | data | 4.991773718102028 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x31000 | 0x2728 | 0x1800 | 214e19b3a3a6d8354fa90e8a17cf746e | False | 0.08658854166666667 | data | 1.3673078527283469 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x34000 | 0x1e0 | 0x200 | 1b99276507c6356b24a31f63887375df | False | 0.52734375 | data | 4.7176788329467545 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x35000 | 0x208c | 0x2200 | 1f9afe88c86e7b78ae326a57253f65d5 | False | 0.7651654411764706 | data | 6.522595049005223 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x34060 | 0x17d | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5931758530183727 |
DLL | Import |
---|---|
KERNEL32.dll | GetFileAttributesA, CreateFileA, CloseHandle, GetSystemInfo, CreateThread, HeapAlloc, GetThreadContext, GetProcAddress, VirtualAllocEx, LocalFree, GetLastError, ReadProcessMemory, GetProcessHeap, CreateProcessA, CreateDirectoryA, SetThreadContext, WriteConsoleW, ReadConsoleW, SetEndOfFile, SetFilePointerEx, GetTempPathA, Sleep, SetCurrentDirectoryA, GetModuleHandleA, GetComputerNameExW, ResumeThread, GetVersionExW, CreateMutexA, VirtualAlloc, WriteFile, VirtualFree, HeapFree, WriteProcessMemory, GetModuleFileNameA, RemoveDirectoryA, ReadFile, HeapReAlloc, HeapSize, GetTimeZoneInformation, GetConsoleMode, GetConsoleCP, FlushFileBuffers, GetStringTypeW, SetEnvironmentVariableW, FreeEnvironmentStringsW, GetEnvironmentStringsW, WideCharToMultiByte, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, FindNextFileW, FindFirstFileExW, FindClose, SetStdHandle, GetFullPathNameW, GetCurrentDirectoryW, DeleteFileW, LCMapStringW, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, SetEvent, ResetEvent, WaitForSingleObjectEx, CreateEventW, GetModuleHandleW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, IsProcessorFeaturePresent, IsDebuggerPresent, GetStartupInfoW, QueryPerformanceCounter, GetCurrentProcessId, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, RaiseException, SetLastError, RtlUnwind, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, FreeLibrary, LoadLibraryExW, ExitProcess, GetModuleHandleExW, CreateFileW, GetDriveTypeW, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, GetModuleFileNameW, GetStdHandle, GetCommandLineA, GetCommandLineW, MultiByteToWideChar, CompareStringW, DecodePointer |
ADVAPI32.dll | RegCloseKey, RegQueryValueExA, GetUserNameA, RegSetValueExA, RegOpenKeyExA, ConvertSidToStringSidW, GetUserNameW, LookupAccountNameW |
SHELL32.dll | SHGetFolderPathA, ShellExecuteA, SHFileOperationA |
WININET.dll | HttpOpenRequestA, InternetReadFile, InternetConnectA, HttpSendRequestA, InternetCloseHandle, InternetOpenA, InternetOpenW, InternetOpenUrlA |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-23T20:52:56.688685+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50036 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:52:56.688685+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50036 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:04.143083+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49705 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:04.143083+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49705 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:04.143141+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49704 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:08.382363+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49706 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:08.382363+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49706 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626276+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49708 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626323+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49707 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:12.626323+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49707 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:16.860879+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49709 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:16.860879+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49709 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095122+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49714 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095201+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49712 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:21.095201+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49712 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:25.313904+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49722 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:25.313904+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49722 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579645+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49735 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579693+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49733 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:29.579693+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49733 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:33.829480+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49741 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:33.829480+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49741 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073084+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49752 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073084+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49752 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:38.073133+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49754 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:42.313889+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49764 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:42.313889+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49764 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532660+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49775 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532660+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49775 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:46.532797+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.5 | 49776 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:50.782734+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49787 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:50.782734+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49787 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:55.042480+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49794 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:55.042480+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49794 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:59.298221+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49804 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:53:59.298221+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49804 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:03.548223+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49815 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:03.548223+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49815 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:07.798356+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49826 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:07.798356+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49826 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:12.048318+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49837 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:12.048318+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49837 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:16.282841+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49848 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:16.282841+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49848 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:20.533150+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49859 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:20.533150+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49859 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:24.851912+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49867 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:24.851912+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49867 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:29.157698+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49878 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:29.157698+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49878 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:33.560630+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49887 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:33.560630+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49887 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:37.814020+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49898 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:37.814020+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49898 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:42.064285+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49909 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:42.064285+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49909 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:46.314044+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49920 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:46.314044+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49920 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:50.563900+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49930 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:50.563900+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49930 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:54.816557+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49940 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:54.816557+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49940 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:57.550787+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49950 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:54:57.550787+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49950 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:01.782905+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49958 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:01.782905+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49958 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:06.032766+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49967 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:06.032766+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49967 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:10.291064+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49976 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:10.291064+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49976 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:14.517087+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49987 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:14.517087+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49987 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:18.770958+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 49998 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:18.770958+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 49998 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:23.026943+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50009 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:23.026943+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50009 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:27.284604+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50016 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:27.284604+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50016 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:31.534796+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50017 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:31.534796+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50017 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:35.782914+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50018 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:35.782914+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50018 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:40.001425+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50019 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:40.001425+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50019 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:44.236221+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50020 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:44.236221+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50020 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:48.526834+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50021 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:48.526834+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50021 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:52.784639+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50022 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:52.784639+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50022 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:57.136097+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50023 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:55:57.136097+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50023 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:01.438981+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50024 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:01.438981+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50024 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:05.680904+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50025 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:05.680904+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50025 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:09.923228+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50026 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:09.923228+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50026 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:14.164217+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50027 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:14.164217+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50027 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:18.455177+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50028 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:18.455177+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50028 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:22.706673+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50029 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:22.706673+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50029 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:26.956810+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50030 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:26.956810+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50030 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:31.204734+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50031 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:31.204734+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50031 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:35.454542+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50032 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:35.454542+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50032 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:39.694587+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50033 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:39.694587+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50033 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:43.907721+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50034 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:43.907721+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50034 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:48.157989+0100 | 2027700 | ET MALWARE Amadey CnC Check-In | 1 | 192.168.2.5 | 50035 | 193.3.19.154 | 80 | TCP |
2024-11-23T20:56:48.157989+0100 | 2045751 | ET MALWARE Win32/Amadey Bot Activity (POST) M2 | 1 | 192.168.2.5 | 50035 | 193.3.19.154 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 23, 2024 20:53:00.002206087 CET | 49704 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.010263920 CET | 49705 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.124864101 CET | 80 | 49704 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:00.126138926 CET | 49704 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.133295059 CET | 80 | 49705 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:00.133389950 CET | 49705 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.134437084 CET | 49705 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.156812906 CET | 49704 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:00.260898113 CET | 80 | 49705 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:00.283392906 CET | 80 | 49704 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:04.143083096 CET | 49705 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:04.143141031 CET | 49704 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:04.252187967 CET | 49706 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:04.371838093 CET | 80 | 49706 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:04.372108936 CET | 49706 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:04.372400045 CET | 49706 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:04.491997957 CET | 80 | 49706 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:08.382363081 CET | 49706 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:08.489516973 CET | 49707 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:08.612205982 CET | 80 | 49707 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:08.612313986 CET | 49707 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:08.615879059 CET | 49707 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:08.739934921 CET | 80 | 49707 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:09.158493996 CET | 49708 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:09.280980110 CET | 80 | 49708 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:09.281224012 CET | 49708 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:09.281379938 CET | 49708 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:09.401662111 CET | 80 | 49708 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:12.626276016 CET | 49708 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:12.626322985 CET | 49707 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:12.738591909 CET | 49709 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:12.858773947 CET | 80 | 49709 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:12.858923912 CET | 49709 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:12.859211922 CET | 49709 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:12.978961945 CET | 80 | 49709 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:16.860878944 CET | 49709 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:16.972708941 CET | 49712 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.093209982 CET | 80 | 49712 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:17.093353987 CET | 49712 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.093691111 CET | 49712 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.213599920 CET | 80 | 49712 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:17.642725945 CET | 49714 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.762764931 CET | 80 | 49714 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:17.762995958 CET | 49714 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.763102055 CET | 49714 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:17.883232117 CET | 80 | 49714 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:21.095122099 CET | 49714 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:21.095201015 CET | 49712 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:21.205379963 CET | 49722 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:21.325506926 CET | 80 | 49722 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:21.325592041 CET | 49722 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:21.325753927 CET | 49722 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:21.446183920 CET | 80 | 49722 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:25.313904047 CET | 49722 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:25.426434994 CET | 49733 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:25.581192970 CET | 80 | 49733 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:25.581295967 CET | 49733 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:25.581552029 CET | 49733 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:25.701292992 CET | 80 | 49733 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:26.112663984 CET | 49735 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:26.236144066 CET | 80 | 49735 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:26.236242056 CET | 49735 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:26.236412048 CET | 49735 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:26.362917900 CET | 80 | 49735 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:29.579644918 CET | 49735 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:29.579693079 CET | 49733 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:29.689541101 CET | 49741 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:29.815486908 CET | 80 | 49741 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:29.815574884 CET | 49741 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:29.815764904 CET | 49741 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:29.935518026 CET | 80 | 49741 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:33.829479933 CET | 49741 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:33.941314936 CET | 49752 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.065119982 CET | 80 | 49752 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:34.065262079 CET | 49752 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.065401077 CET | 49752 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.191620111 CET | 80 | 49752 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:34.595963955 CET | 49754 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.715733051 CET | 80 | 49754 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:34.715802908 CET | 49754 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.715946913 CET | 49754 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:34.835439920 CET | 80 | 49754 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:38.073084116 CET | 49752 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:38.073132992 CET | 49754 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:38.192760944 CET | 49764 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:38.313626051 CET | 80 | 49764 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:38.313788891 CET | 49764 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:38.322386980 CET | 49764 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:38.444483042 CET | 80 | 49764 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:42.313889027 CET | 49764 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:42.425879002 CET | 49775 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:42.546495914 CET | 80 | 49775 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:42.546619892 CET | 49775 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:42.546869040 CET | 49775 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:42.671483994 CET | 80 | 49775 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:43.080255032 CET | 49776 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:43.200009108 CET | 80 | 49776 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:43.200149059 CET | 49776 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:43.200330019 CET | 49776 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:43.320007086 CET | 80 | 49776 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:46.532660007 CET | 49775 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:46.532797098 CET | 49776 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:46.643244982 CET | 49787 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:46.768717051 CET | 80 | 49787 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:46.768811941 CET | 49787 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:46.769010067 CET | 49787 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:46.892851114 CET | 80 | 49787 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:50.782733917 CET | 49787 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:50.894567966 CET | 49794 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:51.020188093 CET | 80 | 49794 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:51.020323038 CET | 49794 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:51.020618916 CET | 49794 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:51.147005081 CET | 80 | 49794 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:55.042479992 CET | 49794 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:55.183239937 CET | 49804 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:55.305100918 CET | 80 | 49804 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:55.305166006 CET | 49804 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:55.310513020 CET | 49804 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:55.430382013 CET | 80 | 49804 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:59.298221111 CET | 49804 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:59.411309958 CET | 49815 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:59.532593966 CET | 80 | 49815 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:53:59.532694101 CET | 49815 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:59.532934904 CET | 49815 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:53:59.691047907 CET | 80 | 49815 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:03.548223019 CET | 49815 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:03.660164118 CET | 49826 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:03.786046982 CET | 80 | 49826 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:03.786185026 CET | 49826 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:03.786379099 CET | 49826 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:03.905863047 CET | 80 | 49826 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:07.798356056 CET | 49826 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:07.926301003 CET | 49837 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:08.046344042 CET | 80 | 49837 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:08.046516895 CET | 49837 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:08.046710014 CET | 49837 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:08.167445898 CET | 80 | 49837 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:12.048317909 CET | 49837 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:12.160501957 CET | 49848 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:12.280471087 CET | 80 | 49848 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:12.280692101 CET | 49848 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:12.280874014 CET | 49848 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:12.400686979 CET | 80 | 49848 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:16.282840967 CET | 49848 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:16.395031929 CET | 49859 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:16.514506102 CET | 80 | 49859 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:16.514682055 CET | 49859 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:16.532166004 CET | 49859 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:16.652009010 CET | 80 | 49859 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:20.533149958 CET | 49859 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:20.663415909 CET | 49867 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:20.789742947 CET | 80 | 49867 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:20.790651083 CET | 49867 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:20.790802956 CET | 49867 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:20.912870884 CET | 80 | 49867 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:24.851912022 CET | 49867 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:24.996495008 CET | 49878 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:25.117372036 CET | 80 | 49878 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:25.117521048 CET | 49878 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:25.131287098 CET | 49878 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:25.255280972 CET | 80 | 49878 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:29.157697916 CET | 49878 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:29.269805908 CET | 49887 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:29.402349949 CET | 80 | 49887 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:29.402704000 CET | 49887 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:29.402793884 CET | 49887 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:29.522439003 CET | 80 | 49887 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:33.560630083 CET | 49887 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:33.691617966 CET | 49898 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:33.813066006 CET | 80 | 49898 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:33.813146114 CET | 49898 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:33.813493967 CET | 49898 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:34.092799902 CET | 80 | 49898 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:37.814019918 CET | 49898 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:37.927474976 CET | 49909 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:38.049320936 CET | 80 | 49909 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:38.049408913 CET | 49909 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:38.049715996 CET | 49909 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:38.169197083 CET | 80 | 49909 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:42.064285040 CET | 49909 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:42.175811052 CET | 49920 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:42.298598051 CET | 80 | 49920 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:42.298685074 CET | 49920 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:42.298825026 CET | 49920 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:42.419357061 CET | 80 | 49920 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:46.314043999 CET | 49920 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:46.425678968 CET | 49930 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:46.549834013 CET | 80 | 49930 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:46.549961090 CET | 49930 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:46.556485891 CET | 49930 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:46.680821896 CET | 80 | 49930 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:50.563899994 CET | 49930 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:50.675829887 CET | 49940 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:50.799247980 CET | 80 | 49940 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:50.800801039 CET | 49940 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:50.800801039 CET | 49940 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:50.927278042 CET | 80 | 49940 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:54.816556931 CET | 49940 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:54.928177118 CET | 49950 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:55.048604965 CET | 80 | 49950 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:55.048691034 CET | 49950 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:55.048923969 CET | 49950 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:55.169949055 CET | 80 | 49950 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:57.550786972 CET | 49950 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:57.660074949 CET | 49958 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:57.780625105 CET | 80 | 49958 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:54:57.780713081 CET | 49958 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:57.781066895 CET | 49958 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:54:57.907393932 CET | 80 | 49958 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:01.782905102 CET | 49958 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:01.895857096 CET | 49967 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:02.020486116 CET | 80 | 49967 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:02.020572901 CET | 49967 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:02.021011114 CET | 49967 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:02.140578032 CET | 80 | 49967 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:06.032766104 CET | 49967 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:06.156371117 CET | 49976 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:06.276398897 CET | 80 | 49976 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:06.276474953 CET | 49976 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:06.276736021 CET | 49976 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:06.396256924 CET | 80 | 49976 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:10.291064024 CET | 49976 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:10.394263029 CET | 49987 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:10.513916016 CET | 80 | 49987 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:10.514005899 CET | 49987 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:10.514265060 CET | 49987 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:10.633970022 CET | 80 | 49987 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:14.517086983 CET | 49987 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:14.630228996 CET | 49998 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:14.751076937 CET | 80 | 49998 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:14.752810955 CET | 49998 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:14.752942085 CET | 49998 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:14.877484083 CET | 80 | 49998 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:18.770957947 CET | 49998 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:18.881467104 CET | 50009 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:19.004756927 CET | 80 | 50009 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:19.004856110 CET | 50009 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:19.005067110 CET | 50009 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:19.130290031 CET | 80 | 50009 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:23.026942968 CET | 50009 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:23.147197008 CET | 50016 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:23.266874075 CET | 80 | 50016 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:23.267155886 CET | 50016 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:23.267354965 CET | 50016 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:23.387819052 CET | 80 | 50016 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:27.284604073 CET | 50016 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:27.396590948 CET | 50017 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:27.519185066 CET | 80 | 50017 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:27.520701885 CET | 50017 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:27.524590969 CET | 50017 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:27.644126892 CET | 80 | 50017 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:31.534796000 CET | 50017 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:31.646648884 CET | 50018 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:31.768959045 CET | 80 | 50018 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:31.769076109 CET | 50018 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:31.769241095 CET | 50018 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:31.888921976 CET | 80 | 50018 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:35.782913923 CET | 50018 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:35.895593882 CET | 50019 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:36.015454054 CET | 80 | 50019 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:36.015582085 CET | 50019 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:36.015755892 CET | 50019 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:36.135890961 CET | 80 | 50019 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:40.001425028 CET | 50019 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:40.114579916 CET | 50020 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:40.236881018 CET | 80 | 50020 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:40.236968040 CET | 50020 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:40.237325907 CET | 50020 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:40.359134912 CET | 80 | 50020 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:44.236221075 CET | 50020 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:44.347963095 CET | 50021 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:44.468381882 CET | 80 | 50021 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:44.468463898 CET | 50021 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:44.468620062 CET | 50021 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:44.588114023 CET | 80 | 50021 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:48.526834011 CET | 50021 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:48.650610924 CET | 50022 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:48.772303104 CET | 80 | 50022 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:48.772412062 CET | 50022 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:48.775316954 CET | 50022 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:48.894989967 CET | 80 | 50022 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:52.784638882 CET | 50022 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:52.896639109 CET | 50023 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:53.016299963 CET | 80 | 50023 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:53.016719103 CET | 50023 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:53.018945932 CET | 50023 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:53.139497995 CET | 80 | 50023 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:57.136096954 CET | 50023 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:57.300864935 CET | 50024 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:57.424350977 CET | 80 | 50024 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:55:57.424740076 CET | 50024 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:57.425158978 CET | 50024 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:55:57.547476053 CET | 80 | 50024 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:01.438981056 CET | 50024 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:01.550828934 CET | 50025 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:01.671396017 CET | 80 | 50025 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:01.671538115 CET | 50025 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:01.674710989 CET | 50025 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:01.797806025 CET | 80 | 50025 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:05.680903912 CET | 50025 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:05.801099062 CET | 50026 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:05.920730114 CET | 80 | 50026 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:05.920859098 CET | 50026 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:05.921580076 CET | 50026 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:06.041557074 CET | 80 | 50026 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:09.923228025 CET | 50026 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:10.034737110 CET | 50027 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:10.154762030 CET | 80 | 50027 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:10.154865980 CET | 50027 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:10.155056953 CET | 50027 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:10.275922060 CET | 80 | 50027 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:14.164216995 CET | 50027 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:14.309473038 CET | 50028 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:14.429255009 CET | 80 | 50028 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:14.429358959 CET | 50028 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:14.447710991 CET | 50028 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:14.567240000 CET | 80 | 50028 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:18.455177069 CET | 50028 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:18.566900015 CET | 50029 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:18.693553925 CET | 80 | 50029 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:18.693641901 CET | 50029 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:18.693800926 CET | 50029 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:18.816591024 CET | 80 | 50029 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:22.706672907 CET | 50029 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:22.819727898 CET | 50030 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:22.940217972 CET | 80 | 50030 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:22.945043087 CET | 50030 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:22.945043087 CET | 50030 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:23.069458961 CET | 80 | 50030 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:26.956809998 CET | 50030 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:27.068814039 CET | 50031 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:27.188440084 CET | 80 | 50031 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:27.188760996 CET | 50031 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:27.188958883 CET | 50031 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:27.310029030 CET | 80 | 50031 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:31.204734087 CET | 50031 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:31.324182034 CET | 50032 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:31.449716091 CET | 80 | 50032 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:31.449810982 CET | 50032 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:31.450035095 CET | 50032 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:31.569895029 CET | 80 | 50032 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:35.454541922 CET | 50032 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:35.566035032 CET | 50033 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:35.690761089 CET | 80 | 50033 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:35.694916964 CET | 50033 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:35.698836088 CET | 50033 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:35.822062016 CET | 80 | 50033 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:39.694586992 CET | 50033 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:39.800750971 CET | 50034 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:39.921848059 CET | 80 | 50034 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:39.921938896 CET | 50034 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:39.922708988 CET | 50034 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:40.048729897 CET | 80 | 50034 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:43.907721043 CET | 50034 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:44.021300077 CET | 50035 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:44.144025087 CET | 80 | 50035 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:44.144121885 CET | 50035 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:44.144380093 CET | 50035 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:44.266232014 CET | 80 | 50035 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:48.157989025 CET | 50035 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:48.285547018 CET | 50036 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:48.409069061 CET | 80 | 50036 | 193.3.19.154 | 192.168.2.5 |
Nov 23, 2024 20:56:48.409148932 CET | 50036 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:48.409323931 CET | 50036 | 80 | 192.168.2.5 | 193.3.19.154 |
Nov 23, 2024 20:56:48.531388998 CET | 80 | 50036 | 193.3.19.154 | 192.168.2.5 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:00.134437084 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49704 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:00.156812906 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49706 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:04.372400045 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49707 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:08.615879059 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49708 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:09.281379938 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49709 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:12.859211922 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49712 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:17.093691111 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49714 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:17.763102055 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49722 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:21.325753927 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49733 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:25.581552029 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.5 | 49735 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:26.236412048 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.5 | 49741 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:29.815764904 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.5 | 49752 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:34.065401077 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.5 | 49754 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:34.715946913 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.5 | 49764 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:38.322386980 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.5 | 49775 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:42.546869040 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.5 | 49776 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:43.200330019 CET | 68 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.5 | 49787 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:46.769010067 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.5 | 49794 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:51.020618916 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.5 | 49804 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:55.310513020 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.5 | 49815 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:53:59.532934904 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.5 | 49826 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:03.786379099 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.5 | 49837 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:08.046710014 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.5 | 49848 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:12.280874014 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.5 | 49859 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:16.532166004 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.5 | 49867 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:20.790802956 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.5 | 49878 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:25.131287098 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.5 | 49887 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:29.402793884 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.5 | 49898 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:33.813493967 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.5 | 49909 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:38.049715996 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.5 | 49920 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:42.298825026 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.5 | 49930 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:46.556485891 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.5 | 49940 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:50.800801039 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.5 | 49950 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:55.048923969 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.5 | 49958 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:54:57.781066895 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.5 | 49967 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:02.021011114 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.5 | 49976 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:06.276736021 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.5 | 49987 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:10.514265060 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.5 | 49998 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:14.752942085 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.5 | 50009 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:19.005067110 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.5 | 50016 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:23.267354965 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.5 | 50017 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:27.524590969 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.5 | 50018 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:31.769241095 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.5 | 50019 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:36.015755892 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.5 | 50020 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:40.237325907 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.5 | 50021 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:44.468620062 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.5 | 50022 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:48.775316954 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.5 | 50023 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:53.018945932 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.5 | 50024 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:55:57.425158978 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.5 | 50025 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:01.674710989 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.5 | 50026 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:05.921580076 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.5 | 50027 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:10.155056953 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.5 | 50028 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:14.447710991 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.5 | 50029 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:18.693800926 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.5 | 50030 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:22.945043087 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.5 | 50031 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:27.188958883 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.5 | 50032 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:31.450035095 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.5 | 50033 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:35.698836088 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.5 | 50034 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:39.922708988 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.5 | 50035 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:44.144380093 CET | 242 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.5 | 50036 | 193.3.19.154 | 80 | 6160 | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 23, 2024 20:56:48.409323931 CET | 242 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 14:52:56 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\Desktop\Week13.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x610000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\schtasks.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x650000 |
File size: | 187'904 bytes |
MD5 hash: | 48C2FE20575769DE916F48EF0676A965 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cacls.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe20000 |
File size: | 27'648 bytes |
MD5 hash: | 00BAAE10C69DAD58F169A3ED638D6C59 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cacls.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe20000 |
File size: | 27'648 bytes |
MD5 hash: | 00BAAE10C69DAD58F169A3ED638D6C59 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cacls.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe20000 |
File size: | 27'648 bytes |
MD5 hash: | 00BAAE10C69DAD58F169A3ED638D6C59 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 14:52:57 |
Start date: | 23/11/2024 |
Path: | C:\Windows\SysWOW64\cacls.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe20000 |
File size: | 27'648 bytes |
MD5 hash: | 00BAAE10C69DAD58F169A3ED638D6C59 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 13 |
Start time: | 14:53:01 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Target ID: | 16 |
Start time: | 14:54:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Target ID: | 17 |
Start time: | 14:55:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Target ID: | 18 |
Start time: | 14:56:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |
Target ID: | 19 |
Start time: | 14:57:00 |
Start date: | 23/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\cb7ae701b3\oneetx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x890000 |
File size: | 209'950 bytes |
MD5 hash: | A1B8FA53A47B1991EE76A46EE8685B7D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Has exited: | true |