Windows
Analysis Report
3WaqgS34S7.exe
Overview
General Information
Sample name: | 3WaqgS34S7.exerenamed because original name is a hash value |
Original sample name: | F99E6584C274E6814B81BE68C0F2EE47.exe |
Analysis ID: | 1565628 |
MD5: | f99e6584c274e6814b81be68c0f2ee47 |
SHA1: | 56c3838e6f68404b1309291639b3a300292a46b1 |
SHA256: | 8e430af53d8eb61a39239d6537b7e8a2b99efb0852f8814ce1a5ebd7ace53fd4 |
Tags: | exeSocks5Systemzuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 3WaqgS34S7.exe (PID: 6516 cmdline:
"C:\Users\ user\Deskt op\3WaqgS3 4S7.exe" MD5: F99E6584C274E6814B81BE68C0F2EE47) - explorer.exe (PID: 2580 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5) - 7E95.exe (PID: 5084 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\7E95.ex e MD5: C56489FED27114B3EAD6D98FAD967C15)
- vdhivcv (PID: 6764 cmdline:
C:\Users\u ser\AppDat a\Roaming\ vdhivcv MD5: F99E6584C274E6814B81BE68C0F2EE47)
- wrhivcv (PID: 4048 cmdline:
C:\Users\u ser\AppDat a\Roaming\ wrhivcv MD5: C56489FED27114B3EAD6D98FAD967C15)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://obozintsev.ru/tmp/index.php", "http://olovge.at/tmp/index.php", "http://nuxc.cc/tmp/index.php", "http://piratekings.online/tmp/index.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 14 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-30T11:11:50.241243+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.4 | 50064 | 103.35.190.240 | 443 | TCP |
2024-11-30T11:13:12.097931+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.4 | 49791 | 23.145.40.181 | 443 | TCP |
2024-11-30T11:13:44.395105+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.4 | 49875 | 23.145.40.181 | 443 | TCP |
2024-11-30T11:14:56.054784+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.4 | 49949 | 207.246.75.248 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-30T11:12:26.661625+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49736 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:28.539115+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49737 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:30.464957+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49738 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:32.393771+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49739 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:34.315997+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49740 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:36.283892+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49741 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:38.493730+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49742 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:40.415342+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49743 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:42.336279+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49744 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:44.476603+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49745 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:46.397930+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49746 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:48.544489+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49747 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:50.425797+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49748 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:52.340198+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49749 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:54.211867+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49750 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:56.083759+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49752 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:57.964234+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49754 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:59.830749+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49755 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:01.802938+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49761 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:03.676363+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49767 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:05.644767+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49773 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:07.570894+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49778 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:09.507541+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49780 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:15.257748+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49797 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:17.454825+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49803 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:19.374519+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49809 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:21.288923+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49815 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:23.209112+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49819 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:25.128970+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49823 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:27.270542+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49828 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:29.204841+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49834 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:31.076893+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49840 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:33.046649+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49842 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:34.998162+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49847 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:36.925631+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49853 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:39.051723+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49859 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:41.033201+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49865 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:42.994728+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49869 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:47.602500+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49881 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:49.522920+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49887 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:51.429121+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49890 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:53.395941+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49896 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:55.345806+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49902 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:57.270618+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49908 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:59.357155+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49912 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:01.341053+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49915 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:03.218592+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49921 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:05.094798+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49927 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:07.246905+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49932 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:09.171651+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49937 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:11.136134+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49941 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:13.297021+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49946 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:15.211720+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49953 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:17.129851+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 49959 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:15:29.907269+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50061 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:15:39.774346+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50062 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:15:50.872341+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50065 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:16:02.791232+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.4 | 50066 | 123.213.233.131 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 8_2_0041D240 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00401546 | |
Source: | Code function: | 0_2_00403135 | |
Source: | Code function: | 0_2_00401545 | |
Source: | Code function: | 0_2_00401551 | |
Source: | Code function: | 0_2_00401652 | |
Source: | Code function: | 0_2_0040165E | |
Source: | Code function: | 0_2_00401563 | |
Source: | Code function: | 0_2_0040166A | |
Source: | Code function: | 0_2_0040227B | |
Source: | Code function: | 0_2_0040327E | |
Source: | Code function: | 0_2_00401617 | |
Source: | Code function: | 0_2_00401582 | |
Source: | Code function: | 0_2_0040158C | |
Source: | Code function: | 0_2_00401590 | |
Source: | Code function: | 0_2_00401691 | |
Source: | Code function: | 0_2_004025B8 | |
Source: | Code function: | 5_2_00401546 | |
Source: | Code function: | 5_2_00403135 | |
Source: | Code function: | 5_2_00401545 | |
Source: | Code function: | 5_2_00401551 | |
Source: | Code function: | 5_2_00401652 | |
Source: | Code function: | 5_2_0040165E | |
Source: | Code function: | 5_2_00401563 | |
Source: | Code function: | 5_2_0040166A | |
Source: | Code function: | 5_2_0040227B | |
Source: | Code function: | 5_2_0040327E | |
Source: | Code function: | 5_2_00401617 | |
Source: | Code function: | 5_2_00401582 | |
Source: | Code function: | 5_2_0040158C | |
Source: | Code function: | 5_2_00401590 | |
Source: | Code function: | 5_2_00401691 | |
Source: | Code function: | 5_2_004025B8 | |
Source: | Code function: | 7_2_00402F78 | |
Source: | Code function: | 7_2_0040151A | |
Source: | Code function: | 7_2_00401543 | |
Source: | Code function: | 7_2_00401547 | |
Source: | Code function: | 7_2_0040154A | |
Source: | Code function: | 7_2_00401558 | |
Source: | Code function: | 7_2_00403306 | |
Source: | Code function: | 7_2_00401707 | |
Source: | Code function: | 7_2_00401525 | |
Source: | Code function: | 7_2_00403127 | |
Source: | Code function: | 7_2_00401539 | |
Source: | Code function: | 7_2_00402FD6 | |
Source: | Code function: | 7_2_004014DC |
Source: | Code function: | 0_2_004025B8 | |
Source: | Code function: | 0_2_0041C110 | |
Source: | Code function: | 5_2_004025B8 | |
Source: | Code function: | 5_2_0041C110 | |
Source: | Code function: | 7_2_00403306 | |
Source: | Code function: | 7_2_0041D240 | |
Source: | Code function: | 8_2_0041D240 | |
Source: | Code function: | 8_2_0040217E |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_009F0939 |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Code function: | 8_2_004050FA |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00401B89 | |
Source: | Code function: | 0_2_00401B89 | |
Source: | Code function: | 0_2_00401B89 | |
Source: | Code function: | 0_2_009A1BF0 | |
Source: | Code function: | 0_2_009A1BF0 | |
Source: | Code function: | 0_2_009A1BF0 | |
Source: | Code function: | 0_2_009F8500 | |
Source: | Code function: | 0_2_009F3365 | |
Source: | Code function: | 0_2_009F1E7D | |
Source: | Code function: | 0_2_009F5C4E | |
Source: | Code function: | 0_2_009F5C7F | |
Source: | Code function: | 5_2_00401B89 | |
Source: | Code function: | 5_2_00401B89 | |
Source: | Code function: | 5_2_00401B89 | |
Source: | Code function: | 5_2_009A1BF0 | |
Source: | Code function: | 5_2_009A1BF0 | |
Source: | Code function: | 5_2_009A1BF0 | |
Source: | Code function: | 5_2_00A82055 | |
Source: | Code function: | 5_2_00A871F0 | |
Source: | Code function: | 5_2_00A8493E | |
Source: | Code function: | 5_2_00A80B6D | |
Source: | Code function: | 5_2_00A8496F | |
Source: | Code function: | 7_2_004036A6 | |
Source: | Code function: | 7_2_00882EF4 | |
Source: | Code function: | 7_2_00A44F94 | |
Source: | Code function: | 7_2_00A46BAA | |
Source: | Code function: | 7_2_00A44B72 | |
Source: | Code function: | 8_2_0040279C |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Evasive API call chain: | graph_0-5408 | ||
Source: | Evasive API call chain: | graph_5-5417 | ||
Source: | Evasive API call chain: | graph_8-4774 |
Source: | Evasive API call chain: | graph_8-3986 | ||
Source: | Evasive API call chain: | graph_8-4377 |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 8_2_0041D240 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_8-4379 |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 8_2_00401000 |
Source: | Code function: | 8_2_004050FA |
Source: | Code function: | 0_2_009A0D90 | |
Source: | Code function: | 0_2_009A092B | |
Source: | Code function: | 0_2_009F0216 | |
Source: | Code function: | 5_2_009A0D90 | |
Source: | Code function: | 5_2_009A092B | |
Source: | Code function: | 5_2_00A7EF06 | |
Source: | Code function: | 7_2_00880D90 | |
Source: | Code function: | 7_2_0088092B | |
Source: | Code function: | 7_2_00A3F268 |
Source: | Code function: | 8_2_00401000 | |
Source: | Code function: | 8_2_004030A9 | |
Source: | Code function: | 8_2_00404569 | |
Source: | Code function: | 8_2_0040656A |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_0041C110 | |
Source: | Code function: | 5_2_0041C110 | |
Source: | Code function: | 7_2_0041D240 | |
Source: | Code function: | 8_2_0041D240 | |
Source: | Code function: | 8_2_0040836B |
Source: | Code function: | 0_2_0041C110 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Native API | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 521 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 115 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 2 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 113 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | Win32.Trojan.Zenpak | ||
51% | Virustotal | Browse | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
55% | ReversingLabs | Win32.Trojan.Stealc | ||
63% | ReversingLabs | Win32.Trojan.Zenpak | ||
55% | ReversingLabs | Win32.Trojan.Stealc |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
1% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
jamforvaise.com | 207.246.75.248 | true | true |
| unknown |
telphboardline.com | 103.35.190.240 | true | true | unknown | |
midginvineco.com | 23.145.40.181 | true | true | unknown | |
obozintsev.ru | 189.163.166.52 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
103.35.190.240 | telphboardline.com | Japan | 2519 | VECTANTARTERIANetworksCorporationJP | true | |
123.213.233.131 | unknown | Korea Republic of | 9318 | SKB-ASSKBroadbandCoLtdKR | true | |
207.246.75.248 | jamforvaise.com | United States | 20473 | AS-CHOOPAUS | true | |
23.145.40.181 | midginvineco.com | Reserved | 22631 | SURFAIRWIRELESS-IN-01US | true | |
189.163.166.52 | obozintsev.ru | Mexico | 8151 | UninetSAdeCVMX | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1565628 |
Start date and time: | 2024-11-30 11:11:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 3WaqgS34S7.exerenamed because original name is a hash value |
Original Sample Name: | F99E6584C274E6814B81BE68C0F2EE47.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@6/5@9/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 20.190.147.7, 20.190.177.22, 20.190.147.3, 20.190.147.10, 20.190.147.0, 20.190.147.1, 20.190.177.147, 20.190.147.9
- Excluded domains from analysis (whitelisted): prdv4a.aadg.msidentity.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, login.live.com, www.tm.v4.a.prd.aadg.akadns.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
05:12:19 | API Interceptor | |
10:12:19 | Task Scheduler | |
10:14:11 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
123.213.233.131 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | LummaC, Babuk, Clipboard Hijacker, Djvu, Glupteba, LummaC Stealer, Mars Stealer | Browse |
| ||
Get hash | malicious | Glupteba, Petite Virus, Raccoon Stealer v2, RedLine, SmokeLoader, Socks5Systemz | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Glupteba, Petite Virus, RedLine, SmokeLoader, Socks5Systemz | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
obozintsev.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AS-CHOOPAUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
SKB-ASSKBroadbandCoLtdKR | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
VECTANTARTERIANetworksCorporationJP | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | LummaC Stealer | Browse |
| |
Get hash | malicious | Amadey, Cryptbot, LummaC Stealer, Nymaim, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Amadey, Credential Flusher, Cryptbot, LummaC Stealer, Nymaim, Stealc | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | Amadey, Credential Flusher, LummaC Stealer, Stealc | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 196096 |
Entropy (8bit): | 5.525135459216088 |
Encrypted: | false |
SSDEEP: | 1536:NcfrYGHh+PsO+qHk4iansXMWlJ3tejju4Zc2e0wS0jQCOTJNeDAq5FFw4BW5s2lR:NcKVinXMWlJ3t4Z1nCQpJcDAq53wo8d |
MD5: | C56489FED27114B3EAD6D98FAD967C15 |
SHA1: | 17304BB7935ED01B2A11BE735BDEAE0941CB0A31 |
SHA-256: | 71D2EE1B2C6BCA8C88161090430A78DA0CD067211DE0BE16FE82E35262B1411A |
SHA-512: | 31121768CD12FFEEC1CF87BE976107CDEE726CD252A323E4E42CD62F4E40E7BDB27354E2A9693A253D914F57B79FD8B9B9A649DE3FAC1304013B6CE66B83F778 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 183865 |
Entropy (8bit): | 5.5889564554089555 |
Encrypted: | false |
SSDEEP: | 1536:NcfrYGHh+PsO+qHk4iansXMWlJ3tejju4Zc2e0wS0jQCOTJNeDAq5FFw4BW5s2lw:NcKVinXMWlJ3t4Z1nCQpJcDAq53wo8c |
MD5: | 6596269561EB94BB69E30912C9B9EF10 |
SHA1: | 78CABE6DF2A9903AADEC1C542949DE050459A2D4 |
SHA-256: | 8436A23073927F51208D94B4C99B18EDE8B68ADF3B2E65FBA1A97EEB65B1E1D6 |
SHA-512: | 46CA35DE765540F4D9890323FEC3A787A5E18FBA92BB7BAD8BCC29F4CFE4FB81E5EC2BFCB0E614ABCE0C3F126376E864DCED1C8726703BF07B0DD6A359C2B8B9 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 193536 |
Entropy (8bit): | 5.486955260182578 |
Encrypted: | false |
SSDEEP: | 3072:+FEJ0B5aRXtU49eLUoblr435Gz569C4UgO6:dJYClefz |
MD5: | F99E6584C274E6814B81BE68C0F2EE47 |
SHA1: | 56C3838E6F68404B1309291639B3A300292A46B1 |
SHA-256: | 8E430AF53D8EB61A39239D6537B7E8A2B99EFB0852F8814CE1A5EBD7ACE53FD4 |
SHA-512: | 1B94AD9C88FCC335368E79FAA70A878EAF78FD34F192CCDBA20D2FE0024B441AA372983BC132510D7C9727FB800509BC5F98E1AE2BA38A521F8C5C74361460EB |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 196096 |
Entropy (8bit): | 5.525135459216088 |
Encrypted: | false |
SSDEEP: | 1536:NcfrYGHh+PsO+qHk4iansXMWlJ3tejju4Zc2e0wS0jQCOTJNeDAq5FFw4BW5s2lR:NcKVinXMWlJ3t4Z1nCQpJcDAq53wo8d |
MD5: | C56489FED27114B3EAD6D98FAD967C15 |
SHA1: | 17304BB7935ED01B2A11BE735BDEAE0941CB0A31 |
SHA-256: | 71D2EE1B2C6BCA8C88161090430A78DA0CD067211DE0BE16FE82E35262B1411A |
SHA-512: | 31121768CD12FFEEC1CF87BE976107CDEE726CD252A323E4E42CD62F4E40E7BDB27354E2A9693A253D914F57B79FD8B9B9A649DE3FAC1304013B6CE66B83F778 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.486955260182578 |
TrID: |
|
File name: | 3WaqgS34S7.exe |
File size: | 193'536 bytes |
MD5: | f99e6584c274e6814b81be68c0f2ee47 |
SHA1: | 56c3838e6f68404b1309291639b3a300292a46b1 |
SHA256: | 8e430af53d8eb61a39239d6537b7e8a2b99efb0852f8814ce1a5ebd7ace53fd4 |
SHA512: | 1b94ad9c88fcc335368e79faa70a878eaf78fd34f192ccdba20d2fe0024b441aa372983bc132510d7c9727fb800509bc5f98e1ae2ba38a521f8c5c74361460eb |
SSDEEP: | 3072:+FEJ0B5aRXtU49eLUoblr435Gz569C4UgO6:dJYClefz |
TLSH: | 7C146C117AF65026F3F78A746970A6945E3BBCA37B79809E1110126F3D336D08E6DB23 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........v......................................xc.....................................Rich............PE..L...~..e................... |
Icon Hash: | 0323252521170f17 |
Entrypoint: | 0x4016eb |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x65D9F07E [Sat Feb 24 13:34:54 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | 0b72f9871877c1429fc389a1eb1f1d2b |
Instruction |
---|
call 00007FEC98861DA9h |
jmp 00007FEC9885F06Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [00420208h], eax |
mov dword ptr [00420204h], ecx |
mov dword ptr [00420200h], edx |
mov dword ptr [004201FCh], ebx |
mov dword ptr [004201F8h], esi |
mov dword ptr [004201F4h], edi |
mov word ptr [00420220h], ss |
mov word ptr [00420214h], cs |
mov word ptr [004201F0h], ds |
mov word ptr [004201ECh], es |
mov word ptr [004201E8h], fs |
mov word ptr [004201E4h], gs |
pushfd |
pop dword ptr [00420218h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [0042020Ch], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [00420210h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [0042021Ch], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [00420158h], 00010001h |
mov eax, dword ptr [00420210h] |
mov dword ptr [0042010Ch], eax |
mov dword ptr [00420100h], C0000409h |
mov dword ptr [00420104h], 00000001h |
mov eax, dword ptr [0041F008h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [0041F00Ch] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000C4h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1e634 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x40e000 | 0xc390 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x1d000 | 0x178 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1b500 | 0x1b600 | c173ea61c5b8c95b8dd9fe083e692a0b | False | 0.626007776826484 | data | 6.26371473137505 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x1d000 | 0x1f02 | 0x2000 | dcf31f9faad9936987278a6744061b17 | False | 0.3560791015625 | data | 5.5063636226432084 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x1f000 | 0x3e77bc | 0x1200 | 5067901f9f416eaf5f2e13f92c7e71b2 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.voheba | 0x407000 | 0x4948 | 0x3e00 | 51596dda30fc38f0df3556d6f115256d | False | 0.0023941532258064517 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.yovu | 0x40c000 | 0x400 | 0x400 | 0f343b0931126a20f133d67c2b018a3b | False | 0.0166015625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.lobudib | 0x40d000 | 0xc | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x40e000 | 0xc390 | 0xc400 | a4912bf414f73e5b56a1f03fa5cae900 | False | 0.4240672831632653 | data | 4.406680623692904 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x40e540 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Spanish | Peru | 0.3723347547974414 |
RT_ICON | 0x40f3e8 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Spanish | Peru | 0.47382671480144406 |
RT_ICON | 0x40fc90 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Spanish | Peru | 0.5213133640552995 |
RT_ICON | 0x410358 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Spanish | Peru | 0.536849710982659 |
RT_ICON | 0x4108c0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Spanish | Peru | 0.39927385892116185 |
RT_ICON | 0x412e68 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Spanish | Peru | 0.4148686679174484 |
RT_ICON | 0x413f10 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Spanish | Peru | 0.46557377049180326 |
RT_ICON | 0x414898 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Spanish | Peru | 0.46808510638297873 |
RT_STRING | 0x414f40 | 0x55a | data | 0.44452554744525546 | ||
RT_STRING | 0x4154a0 | 0x43a | data | 0.4676524953789279 | ||
RT_STRING | 0x4158e0 | 0x130 | data | 0.5032894736842105 | ||
RT_STRING | 0x415a10 | 0x73c | data | 0.4195464362850972 | ||
RT_STRING | 0x416150 | 0x686 | data | 0.4353293413173653 | ||
RT_STRING | 0x4167d8 | 0x840 | data | 0.4237689393939394 | ||
RT_STRING | 0x417018 | 0x768 | data | 0.4240506329113924 | ||
RT_STRING | 0x417780 | 0x8c4 | data | 0.4180035650623886 | ||
RT_STRING | 0x418048 | 0x7bc | data | 0.41919191919191917 | ||
RT_STRING | 0x418808 | 0x612 | data | 0.4395109395109395 | ||
RT_STRING | 0x418e20 | 0x7e6 | data | 0.4228486646884273 | ||
RT_STRING | 0x419608 | 0x672 | data | 0.43575757575757573 | ||
RT_STRING | 0x419c80 | 0x53e | data | 0.4493293591654247 | ||
RT_STRING | 0x41a1c0 | 0x1d0 | data | 0.5086206896551724 | ||
RT_ACCELERATOR | 0x414d78 | 0x18 | data | 1.3333333333333333 | ||
RT_GROUP_ICON | 0x414d00 | 0x76 | data | Spanish | Peru | 0.6610169491525424 |
RT_VERSION | 0x414d90 | 0x1ac | data | 0.5794392523364486 |
DLL | Import |
---|---|
KERNEL32.dll | WriteConsoleOutputCharacterW, GetConsoleAliasExesLengthA, InterlockedDecrement, GetLogicalDriveStringsW, SetDefaultCommConfigW, GetSystemWindowsDirectoryW, GetEnvironmentStringsW, InterlockedCompareExchange, GetTimeFormatA, GetModuleHandleW, GetConsoleAliasesA, ReadConsoleOutputA, GetCommandLineA, GetVolumePathNameW, GlobalAlloc, LoadLibraryW, GetLocaleInfoW, GetProcessHandleCount, GetConsoleAliasW, GetModuleFileNameW, GetFileSize, GetStringTypeExA, GetLastError, GetProcAddress, MoveFileW, BuildCommDCBW, OpenWaitableTimerA, WriteConsoleA, GetModuleFileNameA, GetModuleHandleA, QueryMemoryResourceNotification, GetShortPathNameW, SetThreadAffinityMask, FindAtomW, OpenFileMappingA, GetSystemTime, DisconnectNamedPipe, GetThreadContext, HeapFree, HeapAlloc, Sleep, ExitProcess, GetStartupInfoA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, HeapReAlloc, WriteFile, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, LoadLibraryA, InitializeCriticalSectionAndSpinCount, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, SetHandleCount, GetFileType, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapSize, GetLocaleInfoA, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW |
USER32.dll | GetMonitorInfoA, GetClassLongW |
ADVAPI32.dll | GetAce |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Spanish | Peru |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-11-30T11:11:50.241243+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.4 | 50064 | 103.35.190.240 | 443 | TCP |
2024-11-30T11:12:26.661625+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49736 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:28.539115+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49737 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:30.464957+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49738 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:32.393771+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49739 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:34.315997+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49740 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:36.283892+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49741 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:38.493730+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49742 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:40.415342+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49743 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:42.336279+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49744 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:44.476603+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49745 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:46.397930+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49746 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:48.544489+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49747 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:50.425797+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49748 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:52.340198+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49749 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:54.211867+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49750 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:56.083759+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49752 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:57.964234+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49754 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:12:59.830749+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49755 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:01.802938+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49761 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:03.676363+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49767 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:05.644767+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49773 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:07.570894+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49778 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:09.507541+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49780 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:12.097931+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.4 | 49791 | 23.145.40.181 | 443 | TCP |
2024-11-30T11:13:15.257748+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49797 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:17.454825+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49803 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:19.374519+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49809 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:21.288923+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49815 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:23.209112+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49819 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:25.128970+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49823 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:27.270542+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49828 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:29.204841+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49834 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:31.076893+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49840 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:33.046649+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49842 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:34.998162+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49847 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:36.925631+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49853 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:39.051723+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49859 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:41.033201+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49865 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:42.994728+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49869 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:44.395105+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.4 | 49875 | 23.145.40.181 | 443 | TCP |
2024-11-30T11:13:47.602500+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49881 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:49.522920+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49887 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:51.429121+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49890 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:53.395941+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49896 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:55.345806+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49902 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:57.270618+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49908 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:13:59.357155+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49912 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:01.341053+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49915 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:03.218592+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49921 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:05.094798+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49927 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:07.246905+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49932 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:09.171651+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49937 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:11.136134+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49941 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:13.297021+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49946 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:15.211720+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49953 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:17.129851+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 49959 | 189.163.166.52 | 80 | TCP |
2024-11-30T11:14:56.054784+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.4 | 49949 | 207.246.75.248 | 443 | TCP |
2024-11-30T11:15:29.907269+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50061 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:15:39.774346+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50062 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:15:50.872341+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50065 | 123.213.233.131 | 80 | TCP |
2024-11-30T11:16:02.791232+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.4 | 50066 | 123.213.233.131 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 30, 2024 11:12:24.786530018 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:24.907808065 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:24.907888889 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:24.908046961 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:24.908066034 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:25.027981997 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:25.028008938 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.650377035 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.661560059 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.661624908 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.662062883 CET | 49736 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.664829969 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.782062054 CET | 80 | 49736 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.784884930 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.785077095 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.785270929 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.785303116 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:26.905157089 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:26.906296015 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.533607960 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.539052010 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.539114952 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.539167881 CET | 49737 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.542660952 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.659298897 CET | 80 | 49737 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.662678003 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.662743092 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.662853003 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.662890911 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:28.782820940 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:28.782876968 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.464797974 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.464907885 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.464956999 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.465029001 CET | 49738 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.467318058 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.585114002 CET | 80 | 49738 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.587481976 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.587569952 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.587718010 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.587743998 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:30.708878040 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:30.708906889 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.393549919 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.393630981 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.393770933 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.393804073 CET | 49739 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.396136045 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.513982058 CET | 80 | 49739 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.516309023 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.516407967 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.517201900 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.517262936 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:32.637135983 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:32.637257099 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.315684080 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.315912008 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.315996885 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.335463047 CET | 49740 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.369910002 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.455459118 CET | 80 | 49740 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.490037918 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.490101099 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.490216017 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.490226030 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:34.610347986 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:34.610409975 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.283663034 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.283819914 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.283891916 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.284030914 CET | 49741 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.286278963 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.404022932 CET | 80 | 49741 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.406249046 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.406349897 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.406519890 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.406564951 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:36.527091026 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:36.527527094 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.493619919 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.493659973 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.493730068 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.493901968 CET | 49742 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.496118069 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.614129066 CET | 80 | 49742 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.616069078 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.616153955 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.616270065 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.616338015 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:38.736273050 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:38.736319065 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.403886080 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.415250063 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.415342093 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.415376902 CET | 49743 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.418051958 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.536046028 CET | 80 | 49743 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.538872004 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.538949966 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.539100885 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.539115906 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:40.659393072 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:40.659476042 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.335429907 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.336205959 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.336278915 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.336317062 CET | 49744 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.338871002 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.459860086 CET | 80 | 49744 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.461201906 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.461308956 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.461447954 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.461447954 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:42.583837032 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:42.585999966 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.476198912 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.476545095 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.476603031 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.476634026 CET | 49745 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.479034901 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.598704100 CET | 80 | 49745 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.601094007 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.601171017 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.601337910 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.601353884 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:44.723973989 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:44.724148989 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.397649050 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.397878885 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.397929907 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.400681973 CET | 49746 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.407629013 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.520601988 CET | 80 | 49746 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.527987957 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.528069019 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.529252052 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.529280901 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:46.649240017 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:46.649282932 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.544128895 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.544383049 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.544488907 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.544488907 CET | 49747 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.546755075 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.664453983 CET | 80 | 49747 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.666644096 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.666712999 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.667563915 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.667592049 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:48.787628889 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:48.787643909 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.425718069 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.425745964 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.425796986 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.425940990 CET | 49748 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.428491116 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.545840025 CET | 80 | 49748 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.548418045 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.548593044 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.548768997 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.548789024 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:50.668653965 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:50.668756962 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.340101957 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.340122938 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.340198040 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.340341091 CET | 49749 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.342854023 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.460235119 CET | 80 | 49749 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.462905884 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.462977886 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.463105917 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.463133097 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:52.583766937 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:52.583868027 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.211771011 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.211802006 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.211867094 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.211978912 CET | 49750 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.215408087 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.332532883 CET | 80 | 49750 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.336149931 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.336229086 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.339349985 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.339375019 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:54.459330082 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:54.459343910 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.079293966 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.083652020 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.083759069 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.084434986 CET | 49752 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.086777925 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.204425097 CET | 80 | 49752 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.206814051 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.206898928 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.207856894 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.207885027 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:56.328816891 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:56.328835011 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:57.958450079 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:57.964160919 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:57.964234114 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:57.964301109 CET | 49754 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:57.966617107 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:58.084218025 CET | 80 | 49754 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:58.086549997 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:58.086636066 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:58.086781979 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:58.086811066 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:58.206857920 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:58.206990004 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:59.830614090 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:59.830696106 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:59.830749035 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:59.830873013 CET | 49755 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:59.833554983 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:59.950865030 CET | 80 | 49755 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:59.953535080 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:12:59.953635931 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:59.953778028 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:12:59.953802109 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:00.073817968 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:00.073831081 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:01.802746058 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:01.802768946 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:01.802937984 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:01.803212881 CET | 49761 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:01.805500031 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:01.923430920 CET | 80 | 49761 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:01.925647974 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:01.925818920 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:01.925877094 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:01.925900936 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:02.045850992 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:02.045876980 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.676213026 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.676316023 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.676362991 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.676420927 CET | 49767 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.679007053 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.796830893 CET | 80 | 49767 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.799277067 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.799349070 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.799493074 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.799519062 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:03.919440031 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:03.919512033 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.639331102 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.644725084 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.644767046 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.644813061 CET | 49773 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.647500992 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.764673948 CET | 80 | 49773 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.767364025 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.767432928 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.767579079 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.767607927 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:05.887546062 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:05.887691975 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.570679903 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.570805073 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.570894003 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.571094036 CET | 49778 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.573508978 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.690982103 CET | 80 | 49778 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.693438053 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.693505049 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.693670988 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.693706036 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:07.813981056 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:07.813993931 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:09.507329941 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:09.507489920 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:09.507540941 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:09.507682085 CET | 49780 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:09.627659082 CET | 80 | 49780 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:10.656449080 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:10.656478882 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:10.656543970 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:10.656896114 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:10.656909943 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.097831011 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.097930908 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.104140997 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.104152918 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.104409933 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.122706890 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.167330027 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.622001886 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.622026920 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.622185946 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.622204065 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.663271904 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.832181931 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.832191944 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.832268953 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.853069067 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.853076935 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.853133917 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.878456116 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.878463984 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.878561020 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:12.899914026 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:12.899980068 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.042807102 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.042902946 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.055180073 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.055345058 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.070139885 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.070305109 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.084928036 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.085100889 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.098143101 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.098221064 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.108097076 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.108275890 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.118201971 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.118272066 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.128158092 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.128261089 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.253307104 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.253633022 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.261033058 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.261112928 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.270540953 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.270622015 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.280006886 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.280081987 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.292457104 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.292515993 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.297405005 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.297470093 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.302448988 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.302522898 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.307471037 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.307552099 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.314027071 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.314122915 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.319175959 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.319255114 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.320849895 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.320899963 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.320950031 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.320980072 CET | 49791 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:13.320992947 CET | 443 | 49791 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:13.341000080 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:13.461041927 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:13.461112022 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:13.461258888 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:13.461287975 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:13.581319094 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:13.581343889 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.257535934 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.257600069 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.257747889 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.262013912 CET | 49797 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.270701885 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.381953955 CET | 80 | 49797 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.390645027 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.390754938 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.396183014 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.396204948 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:15.516215086 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:15.516267061 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.454736948 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.454768896 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.454824924 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.455091953 CET | 49803 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.458414078 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.574975014 CET | 80 | 49803 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.578366041 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.578476906 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.578808069 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.578838110 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:17.699543953 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:17.699687004 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.368659019 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.374459028 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.374519110 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.374558926 CET | 49809 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.377026081 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.494515896 CET | 80 | 49809 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.496925116 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.496989012 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.497152090 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.497152090 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:19.617201090 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:19.617300987 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.288722992 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.288827896 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.288923025 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.289062023 CET | 49815 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.292443991 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.410607100 CET | 80 | 49815 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.414350986 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.415646076 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.415868998 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.415903091 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:21.536211014 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:21.536299944 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.208852053 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.208998919 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.209111929 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.209139109 CET | 49819 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.211651087 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.329133987 CET | 80 | 49819 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.331640005 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.331847906 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.331949949 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.331978083 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:23.452244997 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:23.452259064 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.128737926 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.128890991 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.128969908 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.133466005 CET | 49823 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.253410101 CET | 80 | 49823 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.333441973 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.453382969 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.453447104 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.453610897 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.453622103 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:25.573756933 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:25.573811054 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.262444973 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.267971992 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.270541906 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.270606041 CET | 49828 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.274652004 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.390757084 CET | 80 | 49828 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.394556999 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.394622087 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.394815922 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.394829035 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:27.514995098 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:27.515011072 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.204399109 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.204462051 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.204840899 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.204891920 CET | 49834 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.208331108 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.325155973 CET | 80 | 49834 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.328253984 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.328340054 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.328526020 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.328557014 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:29.448401928 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:29.448518038 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.076697111 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.076710939 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.076893091 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.082050085 CET | 49840 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.117103100 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.202124119 CET | 80 | 49840 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.237075090 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.237195015 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.237323999 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.237354040 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:31.357218981 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:31.357250929 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.046477079 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.046586037 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.046648979 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.049777985 CET | 49842 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.069211006 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.169724941 CET | 80 | 49842 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.189162016 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.189308882 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.190927982 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.191423893 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:33.310832977 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:33.311260939 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:34.992533922 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:34.998097897 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:34.998162031 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:34.998189926 CET | 49847 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:35.002702951 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:35.118506908 CET | 80 | 49847 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:35.122852087 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:35.122921944 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:35.123045921 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:35.123065948 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:35.243290901 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:35.243300915 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:36.925482988 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:36.925565958 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:36.925631046 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:36.925756931 CET | 49853 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:36.936717033 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:37.048157930 CET | 80 | 49853 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:37.060597897 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:37.060755968 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:37.061934948 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:37.062011957 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:37.181859970 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:37.181925058 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.051615000 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.051630974 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.051723003 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.052114964 CET | 49859 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.071980000 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.172099113 CET | 80 | 49859 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.191998005 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.192066908 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.192209005 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.192223072 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:39.313098907 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:39.313483000 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.033102989 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.033148050 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.033200979 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.033334017 CET | 49865 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.037738085 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.153423071 CET | 80 | 49865 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.157671928 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.157762051 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.157958984 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.157991886 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:41.277848959 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:41.277909994 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:42.994563103 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:42.994646072 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:42.994728088 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:42.994843960 CET | 49869 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:42.999183893 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:42.999212980 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:42.999284983 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:42.999620914 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:42.999634981 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:43.114943981 CET | 80 | 49869 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:44.395034075 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.395104885 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:44.396581888 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:44.396590948 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.396817923 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.466403008 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:44.507338047 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.904937029 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.904957056 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.904963970 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.904992104 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.905039072 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:44.905072927 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:44.905088902 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.069667101 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.105983973 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.105992079 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.106019020 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.106051922 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.106084108 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.127209902 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.127218962 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.127249956 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.127279043 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.127320051 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.152353048 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.152360916 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.152384043 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.152435064 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.152461052 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.181938887 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.181946993 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.181968927 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.182010889 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.182025909 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.307254076 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.307260990 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.307352066 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.318859100 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.318866968 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.318932056 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.337935925 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.337948084 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.338020086 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.352530956 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.352539062 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.352611065 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.363850117 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.363857985 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.363936901 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.377230883 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.377341032 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.387007952 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.387072086 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.509632111 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.509728909 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.518107891 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.518201113 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.525870085 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.525959969 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.533555984 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.533633947 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.543673038 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.543765068 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.551388979 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.551462889 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.559123993 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.559200048 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.566880941 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.566956997 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.577050924 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.577131987 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.584661007 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.584755898 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.593556881 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.593641996 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.601476908 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.601546049 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.606430054 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.606493950 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.606523991 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.606550932 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.612706900 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.612726927 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.612740040 CET | 49875 | 443 | 192.168.2.4 | 23.145.40.181 |
Nov 30, 2024 11:13:45.612746954 CET | 443 | 49875 | 23.145.40.181 | 192.168.2.4 |
Nov 30, 2024 11:13:45.689131975 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:45.809137106 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:45.809245110 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:45.809374094 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:45.809393883 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:45.929372072 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:45.929387093 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.602294922 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.602447987 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.602499962 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.602538109 CET | 49881 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.609795094 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.722481966 CET | 80 | 49881 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.729754925 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.729823112 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.730003119 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.730045080 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:47.849956036 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:47.849994898 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.522645950 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.522849083 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.522919893 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.523132086 CET | 49887 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.542083025 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.642961025 CET | 80 | 49887 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.662313938 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.662581921 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.662631989 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.662646055 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:49.782804966 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:49.782815933 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.422012091 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.427697897 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.429121017 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.429121017 CET | 49890 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.436868906 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.549068928 CET | 80 | 49890 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.556869030 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.556941986 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.558331013 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.558353901 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:51.678440094 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:51.678498030 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.395775080 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.395889044 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.395941019 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.396045923 CET | 49896 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.424197912 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.515949965 CET | 80 | 49896 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.544214010 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.544353962 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.544500113 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.544539928 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:53.664407969 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:53.664509058 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.339034081 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.344430923 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.345805883 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.345805883 CET | 49902 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.349319935 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.465792894 CET | 80 | 49902 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.469377041 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.469580889 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.469620943 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.469635963 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:55.589540958 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:55.589567900 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.270198107 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.270549059 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.270617962 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.326015949 CET | 49908 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.443669081 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.448033094 CET | 80 | 49908 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.565768003 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.565831900 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.566004038 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.566135883 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:57.686988115 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:57.687486887 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.350991964 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.357084990 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.357155085 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.357687950 CET | 49912 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.381295919 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.477587938 CET | 80 | 49912 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.501455069 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.501543999 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.501769066 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.501805067 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:13:59.621680975 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:13:59.621706963 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.340970039 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.341001034 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.341053009 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.341243029 CET | 49915 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.346306086 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.461103916 CET | 80 | 49915 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.467358112 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.467824936 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.467909098 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.467921019 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:01.589167118 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:01.589180946 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.218429089 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.218518019 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.218591928 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.218740940 CET | 49921 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.225835085 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.338684082 CET | 80 | 49921 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.345861912 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.345951080 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.346157074 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.346194983 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:03.466226101 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:03.466249943 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.094419003 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.094733000 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.094798088 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.094893932 CET | 49927 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.101079941 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.217745066 CET | 80 | 49927 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.221620083 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.221695900 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.221851110 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.221868992 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:05.343334913 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:05.344007969 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.246759892 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.246849060 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.246905088 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.247052908 CET | 49932 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.255489111 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.367266893 CET | 80 | 49932 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.375477076 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.375555992 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.375758886 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.375781059 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:07.496345043 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:07.496392965 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.165790081 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.171569109 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.171650887 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.171828985 CET | 49937 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.175662041 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.291863918 CET | 80 | 49937 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.295599937 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.295778990 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.295814037 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.295829058 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:09.416037083 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:09.416090965 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.135932922 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.136074066 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.136133909 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.136172056 CET | 49941 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.145404100 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.256122112 CET | 80 | 49941 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.265588045 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.265682936 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.306545019 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.306545019 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:11.426549911 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.426609039 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:11.867687941 CET | 49949 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:11.867718935 CET | 443 | 49949 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:14:11.867811918 CET | 49949 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:11.868218899 CET | 49949 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:11.868230104 CET | 443 | 49949 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:14:13.296889067 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:13.296952009 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:13.297020912 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.297283888 CET | 49946 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.305887938 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.417155027 CET | 80 | 49946 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:13.425812006 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:13.425889969 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.426032066 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.426074028 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:13.545979023 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:13.546071053 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.211502075 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.211560965 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.211719990 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.211853981 CET | 49953 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.216741085 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.332180977 CET | 80 | 49953 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.336693048 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.336791039 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.336947918 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.336958885 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:15.457818985 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:15.457832098 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:17.129673004 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:17.129772902 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:17.129851103 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:17.131385088 CET | 49959 | 80 | 192.168.2.4 | 189.163.166.52 |
Nov 30, 2024 11:14:17.251997948 CET | 80 | 49959 | 189.163.166.52 | 192.168.2.4 |
Nov 30, 2024 11:14:56.054718971 CET | 443 | 49949 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:14:56.054784060 CET | 49949 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:56.054831028 CET | 49949 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:56.054841995 CET | 443 | 49949 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:14:56.055386066 CET | 50046 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:56.055448055 CET | 443 | 50046 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:14:56.055511951 CET | 50046 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:56.055958986 CET | 50046 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:14:56.055989027 CET | 443 | 50046 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:15:27.606290102 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:27.726496935 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:27.726646900 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:27.765614033 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:27.765676975 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:27.885701895 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:27.885715961 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:29.907083035 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:29.907196045 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:29.907269001 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:29.907381058 CET | 50061 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:30.027416945 CET | 80 | 50061 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:37.599111080 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:37.719223022 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:37.719434977 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:37.719506025 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:37.719540119 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:37.839412928 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:37.839538097 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:39.773937941 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:39.773993969 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:39.774346113 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:39.774346113 CET | 50062 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:39.894500971 CET | 80 | 50062 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:40.087188959 CET | 443 | 50046 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:15:40.087292910 CET | 50046 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.087393999 CET | 50046 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.087438107 CET | 443 | 50046 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:15:40.097280025 CET | 50063 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.097316980 CET | 443 | 50063 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:15:40.097376108 CET | 50063 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.098084927 CET | 50063 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.098135948 CET | 443 | 50063 | 207.246.75.248 | 192.168.2.4 |
Nov 30, 2024 11:15:40.098187923 CET | 50063 | 443 | 192.168.2.4 | 207.246.75.248 |
Nov 30, 2024 11:15:40.515969992 CET | 50064 | 443 | 192.168.2.4 | 103.35.190.240 |
Nov 30, 2024 11:15:40.515994072 CET | 443 | 50064 | 103.35.190.240 | 192.168.2.4 |
Nov 30, 2024 11:15:40.516072989 CET | 50064 | 443 | 192.168.2.4 | 103.35.190.240 |
Nov 30, 2024 11:15:40.516452074 CET | 50064 | 443 | 192.168.2.4 | 103.35.190.240 |
Nov 30, 2024 11:15:40.516464949 CET | 443 | 50064 | 103.35.190.240 | 192.168.2.4 |
Nov 30, 2024 11:15:48.662132978 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:48.782183886 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:48.782263041 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:48.782426119 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:48.782447100 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:48.902309895 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:48.902446985 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:50.871936083 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:50.872126102 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:15:50.872340918 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:50.872340918 CET | 50065 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:15:50.992364883 CET | 80 | 50065 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:00.493751049 CET | 50066 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:16:00.614087105 CET | 80 | 50066 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:00.614168882 CET | 50066 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:16:00.614301920 CET | 50066 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:16:00.614326000 CET | 50066 | 80 | 192.168.2.4 | 123.213.233.131 |
Nov 30, 2024 11:16:00.735229969 CET | 80 | 50066 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:00.735362053 CET | 80 | 50066 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:02.791148901 CET | 80 | 50066 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:02.791171074 CET | 80 | 50066 | 123.213.233.131 | 192.168.2.4 |
Nov 30, 2024 11:16:02.791232109 CET | 50066 | 80 | 192.168.2.4 | 123.213.233.131 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 30, 2024 11:12:20.192096949 CET | 55162 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:12:21.211153030 CET | 55162 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:12:22.238938093 CET | 55162 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:12:24.241425991 CET | 55162 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:12:24.784635067 CET | 53 | 55162 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:12:24.784678936 CET | 53 | 55162 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:12:24.784686089 CET | 53 | 55162 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:12:24.784727097 CET | 53 | 55162 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:13:09.509634972 CET | 56155 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:13:10.522713900 CET | 56155 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:13:10.655658960 CET | 53 | 56155 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:13:10.660612106 CET | 53 | 56155 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:14:11.102834940 CET | 53334 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:14:11.850492001 CET | 53 | 53334 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:15:26.713681936 CET | 64618 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:15:27.596349955 CET | 53 | 64618 | 1.1.1.1 | 192.168.2.4 |
Nov 30, 2024 11:15:40.128400087 CET | 56154 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 30, 2024 11:15:40.508466005 CET | 53 | 56154 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 30, 2024 11:12:20.192096949 CET | 192.168.2.4 | 1.1.1.1 | 0xb2de | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:12:21.211153030 CET | 192.168.2.4 | 1.1.1.1 | 0xb2de | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:12:22.238938093 CET | 192.168.2.4 | 1.1.1.1 | 0xb2de | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:12:24.241425991 CET | 192.168.2.4 | 1.1.1.1 | 0xb2de | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:13:09.509634972 CET | 192.168.2.4 | 1.1.1.1 | 0x11f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:13:10.522713900 CET | 192.168.2.4 | 1.1.1.1 | 0x11f5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:14:11.102834940 CET | 192.168.2.4 | 1.1.1.1 | 0x1e61 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:15:26.713681936 CET | 192.168.2.4 | 1.1.1.1 | 0xd2c1 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 30, 2024 11:15:40.128400087 CET | 192.168.2.4 | 1.1.1.1 | 0x2fb3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.163.166.52 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 119.194.160.37 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 201.103.72.35 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.143.204.110 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784635067 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.163.166.52 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 119.194.160.37 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 201.103.72.35 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.143.204.110 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784678936 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.163.166.52 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 119.194.160.37 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 201.103.72.35 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.143.204.110 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784686089 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.163.166.52 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 119.194.160.37 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 201.103.72.35 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 189.143.204.110 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:12:24.784727097 CET | 1.1.1.1 | 192.168.2.4 | 0xb2de | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:13:10.655658960 CET | 1.1.1.1 | 192.168.2.4 | 0x11f5 | No error (0) | 23.145.40.181 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:13:10.660612106 CET | 1.1.1.1 | 192.168.2.4 | 0x11f5 | No error (0) | 23.145.40.181 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:14:11.850492001 CET | 1.1.1.1 | 192.168.2.4 | 0x1e61 | No error (0) | 207.246.75.248 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 123.213.233.131 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 119.194.160.37 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 186.137.126.27 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 58.151.148.90 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 200.45.93.45 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 201.103.72.35 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 78.89.199.216 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 189.143.204.110 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 123.212.43.225 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:27.596349955 CET | 1.1.1.1 | 192.168.2.4 | 0xd2c1 | No error (0) | 189.163.166.52 | A (IP address) | IN (0x0001) | false | ||
Nov 30, 2024 11:15:40.508466005 CET | 1.1.1.1 | 192.168.2.4 | 0x2fb3 | No error (0) | 103.35.190.240 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:24.908046961 CET | 283 | OUT | |
Nov 30, 2024 11:12:24.908066034 CET | 287 | OUT | |
Nov 30, 2024 11:12:26.650377035 CET | 152 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:26.785270929 CET | 282 | OUT | |
Nov 30, 2024 11:12:26.785303116 CET | 335 | OUT | |
Nov 30, 2024 11:12:28.533607960 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49738 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:28.662853003 CET | 284 | OUT | |
Nov 30, 2024 11:12:28.662890911 CET | 203 | OUT | |
Nov 30, 2024 11:12:30.464797974 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49739 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:30.587718010 CET | 284 | OUT | |
Nov 30, 2024 11:12:30.587743998 CET | 345 | OUT | |
Nov 30, 2024 11:12:32.393549919 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49740 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:32.517201900 CET | 283 | OUT | |
Nov 30, 2024 11:12:32.517262936 CET | 253 | OUT | |
Nov 30, 2024 11:12:34.315684080 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49741 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:34.490216017 CET | 286 | OUT | |
Nov 30, 2024 11:12:34.490226030 CET | 160 | OUT | |
Nov 30, 2024 11:12:36.283663034 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49742 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:36.406519890 CET | 286 | OUT | |
Nov 30, 2024 11:12:36.406564951 CET | 122 | OUT | |
Nov 30, 2024 11:12:38.493619919 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49743 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:38.616270065 CET | 283 | OUT | |
Nov 30, 2024 11:12:38.616338015 CET | 126 | OUT | |
Nov 30, 2024 11:12:40.403886080 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49744 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:40.539100885 CET | 283 | OUT | |
Nov 30, 2024 11:12:40.539115906 CET | 169 | OUT | |
Nov 30, 2024 11:12:42.335429907 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49745 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:42.461447954 CET | 286 | OUT | |
Nov 30, 2024 11:12:42.461447954 CET | 262 | OUT | |
Nov 30, 2024 11:12:44.476198912 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49746 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:44.601337910 CET | 283 | OUT | |
Nov 30, 2024 11:12:44.601353884 CET | 271 | OUT | |
Nov 30, 2024 11:12:46.397649050 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49747 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:46.529252052 CET | 285 | OUT | |
Nov 30, 2024 11:12:46.529280901 CET | 130 | OUT | |
Nov 30, 2024 11:12:48.544128895 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49748 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:48.667563915 CET | 285 | OUT | |
Nov 30, 2024 11:12:48.667592049 CET | 364 | OUT | |
Nov 30, 2024 11:12:50.425718069 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49749 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:50.548768997 CET | 284 | OUT | |
Nov 30, 2024 11:12:50.548789024 CET | 112 | OUT | |
Nov 30, 2024 11:12:52.340101957 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49750 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:52.463105917 CET | 285 | OUT | |
Nov 30, 2024 11:12:52.463133097 CET | 272 | OUT | |
Nov 30, 2024 11:12:54.211771011 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49752 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:54.339349985 CET | 284 | OUT | |
Nov 30, 2024 11:12:54.339375019 CET | 358 | OUT | |
Nov 30, 2024 11:12:56.079293966 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49754 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:56.207856894 CET | 284 | OUT | |
Nov 30, 2024 11:12:56.207885027 CET | 359 | OUT | |
Nov 30, 2024 11:12:57.958450079 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49755 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:58.086781979 CET | 283 | OUT | |
Nov 30, 2024 11:12:58.086811066 CET | 275 | OUT | |
Nov 30, 2024 11:12:59.830614090 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49761 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:12:59.953778028 CET | 285 | OUT | |
Nov 30, 2024 11:12:59.953802109 CET | 135 | OUT | |
Nov 30, 2024 11:13:01.802746058 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49767 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:01.925877094 CET | 285 | OUT | |
Nov 30, 2024 11:13:01.925900936 CET | 149 | OUT | |
Nov 30, 2024 11:13:03.676213026 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49773 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:03.799493074 CET | 282 | OUT | |
Nov 30, 2024 11:13:03.799519062 CET | 211 | OUT | |
Nov 30, 2024 11:13:05.639331102 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49778 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:05.767579079 CET | 287 | OUT | |
Nov 30, 2024 11:13:05.767607927 CET | 264 | OUT | |
Nov 30, 2024 11:13:07.570679903 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49780 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:07.693670988 CET | 287 | OUT | |
Nov 30, 2024 11:13:07.693706036 CET | 338 | OUT | |
Nov 30, 2024 11:13:09.507329941 CET | 194 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49797 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:13.461258888 CET | 285 | OUT | |
Nov 30, 2024 11:13:13.461287975 CET | 327 | OUT | |
Nov 30, 2024 11:13:15.257535934 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49803 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:15.396183014 CET | 282 | OUT | |
Nov 30, 2024 11:13:15.396204948 CET | 118 | OUT | |
Nov 30, 2024 11:13:17.454736948 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49809 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:17.578808069 CET | 287 | OUT | |
Nov 30, 2024 11:13:17.578838110 CET | 363 | OUT | |
Nov 30, 2024 11:13:19.368659019 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49815 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:19.497152090 CET | 285 | OUT | |
Nov 30, 2024 11:13:19.497152090 CET | 204 | OUT | |
Nov 30, 2024 11:13:21.288722992 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49819 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:21.415868998 CET | 287 | OUT | |
Nov 30, 2024 11:13:21.415903091 CET | 295 | OUT | |
Nov 30, 2024 11:13:23.208852053 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49823 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:23.331949949 CET | 286 | OUT | |
Nov 30, 2024 11:13:23.331978083 CET | 327 | OUT | |
Nov 30, 2024 11:13:25.128737926 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49828 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:25.453610897 CET | 284 | OUT | |
Nov 30, 2024 11:13:25.453622103 CET | 153 | OUT | |
Nov 30, 2024 11:13:27.262444973 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49834 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:27.394815922 CET | 285 | OUT | |
Nov 30, 2024 11:13:27.394829035 CET | 284 | OUT | |
Nov 30, 2024 11:13:29.204399109 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49840 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:29.328526020 CET | 286 | OUT | |
Nov 30, 2024 11:13:29.328557014 CET | 279 | OUT | |
Nov 30, 2024 11:13:31.076697111 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49842 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:31.237323999 CET | 283 | OUT | |
Nov 30, 2024 11:13:31.237354040 CET | 355 | OUT | |
Nov 30, 2024 11:13:33.046477079 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49847 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:33.190927982 CET | 285 | OUT | |
Nov 30, 2024 11:13:33.191423893 CET | 318 | OUT | |
Nov 30, 2024 11:13:34.992533922 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49853 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:35.123045921 CET | 285 | OUT | |
Nov 30, 2024 11:13:35.123065948 CET | 319 | OUT | |
Nov 30, 2024 11:13:36.925482988 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49859 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:37.061934948 CET | 287 | OUT | |
Nov 30, 2024 11:13:37.062011957 CET | 183 | OUT | |
Nov 30, 2024 11:13:39.051615000 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49865 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:39.192209005 CET | 283 | OUT | |
Nov 30, 2024 11:13:39.192223072 CET | 177 | OUT | |
Nov 30, 2024 11:13:41.033102989 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49869 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:41.157958984 CET | 282 | OUT | |
Nov 30, 2024 11:13:41.157991886 CET | 363 | OUT | |
Nov 30, 2024 11:13:42.994563103 CET | 194 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49881 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:45.809374094 CET | 284 | OUT | |
Nov 30, 2024 11:13:45.809393883 CET | 318 | OUT | |
Nov 30, 2024 11:13:47.602294922 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49887 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:47.730003119 CET | 282 | OUT | |
Nov 30, 2024 11:13:47.730045080 CET | 191 | OUT | |
Nov 30, 2024 11:13:49.522645950 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49890 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:49.662631989 CET | 287 | OUT | |
Nov 30, 2024 11:13:49.662646055 CET | 177 | OUT | |
Nov 30, 2024 11:13:51.422012091 CET | 137 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49896 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:51.558331013 CET | 287 | OUT | |
Nov 30, 2024 11:13:51.558353901 CET | 305 | OUT | |
Nov 30, 2024 11:13:53.395775080 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49902 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:53.544500113 CET | 283 | OUT | |
Nov 30, 2024 11:13:53.544539928 CET | 164 | OUT | |
Nov 30, 2024 11:13:55.339034081 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49908 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:55.469620943 CET | 284 | OUT | |
Nov 30, 2024 11:13:55.469635963 CET | 228 | OUT | |
Nov 30, 2024 11:13:57.270198107 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49912 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:57.566004038 CET | 286 | OUT | |
Nov 30, 2024 11:13:57.566135883 CET | 203 | OUT | |
Nov 30, 2024 11:13:59.350991964 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49915 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:13:59.501769066 CET | 283 | OUT | |
Nov 30, 2024 11:13:59.501805067 CET | 169 | OUT | |
Nov 30, 2024 11:14:01.340970039 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49921 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:01.467909098 CET | 286 | OUT | |
Nov 30, 2024 11:14:01.467921019 CET | 358 | OUT | |
Nov 30, 2024 11:14:03.218429089 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 49927 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:03.346157074 CET | 286 | OUT | |
Nov 30, 2024 11:14:03.346194983 CET | 215 | OUT | |
Nov 30, 2024 11:14:05.094419003 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 49932 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:05.221851110 CET | 286 | OUT | |
Nov 30, 2024 11:14:05.221868992 CET | 232 | OUT | |
Nov 30, 2024 11:14:07.246759892 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 49937 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:07.375758886 CET | 283 | OUT | |
Nov 30, 2024 11:14:07.375781059 CET | 265 | OUT | |
Nov 30, 2024 11:14:09.165790081 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 49941 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:09.295814037 CET | 283 | OUT | |
Nov 30, 2024 11:14:09.295829058 CET | 157 | OUT | |
Nov 30, 2024 11:14:11.135932922 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 49946 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:11.306545019 CET | 284 | OUT | |
Nov 30, 2024 11:14:11.306545019 CET | 158 | OUT | |
Nov 30, 2024 11:14:13.296889067 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 49953 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:13.426032066 CET | 283 | OUT | |
Nov 30, 2024 11:14:13.426074028 CET | 228 | OUT | |
Nov 30, 2024 11:14:15.211502075 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 49959 | 189.163.166.52 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:14:15.336947918 CET | 284 | OUT | |
Nov 30, 2024 11:14:15.336958885 CET | 149 | OUT | |
Nov 30, 2024 11:14:17.129673004 CET | 484 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 50061 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:15:27.765614033 CET | 282 | OUT | |
Nov 30, 2024 11:15:27.765676975 CET | 281 | OUT | |
Nov 30, 2024 11:15:29.907083035 CET | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 50062 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:15:37.719506025 CET | 287 | OUT | |
Nov 30, 2024 11:15:37.719540119 CET | 112 | OUT | |
Nov 30, 2024 11:15:39.773937941 CET | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 50065 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:15:48.782426119 CET | 283 | OUT | |
Nov 30, 2024 11:15:48.782447100 CET | 114 | OUT | |
Nov 30, 2024 11:15:50.871936083 CET | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.4 | 50066 | 123.213.233.131 | 80 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Nov 30, 2024 11:16:00.614301920 CET | 282 | OUT | |
Nov 30, 2024 11:16:00.614326000 CET | 347 | OUT | |
Nov 30, 2024 11:16:02.791148901 CET | 151 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49791 | 23.145.40.181 | 443 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-30 10:13:12 UTC | 167 | OUT | |
2024-11-30 10:13:12 UTC | 327 | IN | |
2024-11-30 10:13:12 UTC | 7865 | IN | |
2024-11-30 10:13:12 UTC | 8000 | IN | |
2024-11-30 10:13:12 UTC | 8000 | IN | |
2024-11-30 10:13:12 UTC | 8000 | IN | |
2024-11-30 10:13:12 UTC | 8000 | IN | |
2024-11-30 10:13:13 UTC | 8000 | IN | |
2024-11-30 10:13:13 UTC | 8000 | IN | |
2024-11-30 10:13:13 UTC | 8000 | IN | |
2024-11-30 10:13:13 UTC | 8000 | IN | |
2024-11-30 10:13:13 UTC | 8000 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49875 | 23.145.40.181 | 443 | 2580 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-11-30 10:13:44 UTC | 167 | OUT | |
2024-11-30 10:13:44 UTC | 327 | IN | |
2024-11-30 10:13:44 UTC | 7865 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN | |
2024-11-30 10:13:45 UTC | 8000 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 05:11:53 |
Start date: | 30/11/2024 |
Path: | C:\Users\user\Desktop\3WaqgS34S7.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 193'536 bytes |
MD5 hash: | F99E6584C274E6814B81BE68C0F2EE47 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 05:12:00 |
Start date: | 30/11/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff72b770000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 05:12:19 |
Start date: | 30/11/2024 |
Path: | C:\Users\user\AppData\Roaming\vdhivcv |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 193'536 bytes |
MD5 hash: | F99E6584C274E6814B81BE68C0F2EE47 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 05:13:44 |
Start date: | 30/11/2024 |
Path: | C:\Users\user\AppData\Local\Temp\7E95.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 196'096 bytes |
MD5 hash: | C56489FED27114B3EAD6D98FAD967C15 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 05:14:11 |
Start date: | 30/11/2024 |
Path: | C:\Users\user\AppData\Roaming\wrhivcv |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 196'096 bytes |
MD5 hash: | C56489FED27114B3EAD6D98FAD967C15 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 6.4% |
Dynamic/Decrypted Code Coverage: | 17.5% |
Signature Coverage: | 52% |
Total number of Nodes: | 177 |
Total number of Limit Nodes: | 8 |
Graph
Function 00401546 Relevance: 10.8, APIs: 7, Instructions: 295COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040327E Relevance: 3.1, APIs: 2, Instructions: 114COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F0939 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 009A003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041BD30 Relevance: 4.6, APIs: 3, Instructions: 60librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009A0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041BE70 Relevance: 1.5, APIs: 1, Instructions: 27libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A23 Relevance: 1.3, APIs: 1, Instructions: 60sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A2F Relevance: 1.3, APIs: 1, Instructions: 53sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F05F8 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401A54 Relevance: 1.3, APIs: 1, Instructions: 47sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C110 Relevance: 37.8, APIs: 25, Instructions: 297timememorythreadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009A092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004025B8 Relevance: 1.7, Strings: 1, Instructions: 448COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040227B Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401545 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009F0216 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401551 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401563 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401582 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040158C Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009A0D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401590 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401617 Relevance: .0, Instructions: 25nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 6.7% |
Dynamic/Decrypted Code Coverage: | 17.5% |
Signature Coverage: | 0% |
Total number of Nodes: | 177 |
Total number of Limit Nodes: | 8 |
Graph
Function 00401546 Relevance: 10.8, APIs: 7, Instructions: 295COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040327E Relevance: 3.1, APIs: 2, Instructions: 114COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009A003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041BD30 Relevance: 4.6, APIs: 3, Instructions: 60librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A7F629 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 009A0E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041BE70 Relevance: 1.5, APIs: 1, Instructions: 27libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A23 Relevance: 1.3, APIs: 1, Instructions: 60sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A2F Relevance: 1.3, APIs: 1, Instructions: 53sleepCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A7F2E8 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401A54 Relevance: 1.3, APIs: 1, Instructions: 47sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C110 Relevance: 37.8, APIs: 25, Instructions: 297timememorythreadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 9.4% |
Dynamic/Decrypted Code Coverage: | 19.6% |
Signature Coverage: | 0% |
Total number of Nodes: | 143 |
Total number of Limit Nodes: | 6 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F78 Relevance: 3.2, APIs: 2, Instructions: 208COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401707 Relevance: 1.6, APIs: 1, Instructions: 81nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0088003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041CDE0 Relevance: 4.6, APIs: 3, Instructions: 60librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3F98B Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00880E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041CF20 Relevance: 1.5, APIs: 1, Instructions: 27libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401903 Relevance: 1.3, APIs: 1, Instructions: 62sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018EC Relevance: 1.3, APIs: 1, Instructions: 62sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018F8 Relevance: 1.3, APIs: 1, Instructions: 56sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401916 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040191A Relevance: 1.3, APIs: 1, Instructions: 48sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040191D Relevance: 1.3, APIs: 1, Instructions: 48sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00A3F64A Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401929 Relevance: 1.3, APIs: 1, Instructions: 47sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D240 Relevance: 42.3, APIs: 23, Strings: 1, Instructions: 294timethreadfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D080 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 77registryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 0.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 6% |
Total number of Nodes: | 1389 |
Total number of Limit Nodes: | 0 |
Graph
Function 00401AA1 Relevance: 1.5, APIs: 1, Instructions: 20memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D240 Relevance: 65.0, APIs: 35, Strings: 2, Instructions: 294timethreadfileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404569 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D080 Relevance: 17.6, APIs: 6, Strings: 4, Instructions: 77registryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D4E6 Relevance: 9.1, APIs: 6, Instructions: 83timeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040100F Relevance: 7.5, APIs: 5, Instructions: 44memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|