Windows
Analysis Report
file.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- file.exe (PID: 7628 cmdline:
"C:\Users\ user\Deskt op\file.ex e" MD5: C9059DFB76AD9E011D4E11608CCC98CC) - wscript.exe (PID: 7672 cmdline:
"C:\Window s\System32 \WScript.e xe" "C:\Ms Container\ P69CZ8d7qX WcyOsB66pH SLt72y6ypl qEAs.vbe" MD5: FF00E0480075B095948000BDC66E81F0) - cmd.exe (PID: 7832 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\MsCo ntainer\GH GhSTUsO1Bq 4f5yX2eWVB .bat" " MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7840 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chainportruntimeCrtMonitor.exe (PID: 7876 cmdline:
"C:\MsCont ainer/chai nportrunti meCrtMonit or.exe" MD5: 38514F88AFF517EA6BE4724D24B28FE2) - powershell.exe (PID: 7972 cmdline:
"powershel l" -Comman d Add-MpPr eference - ExclusionP ath 'C:\Us ers\user\A ppData\Loc al\Temp\ka hKUDRlEYHf KIalWlM.ex e' MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 7992 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - WmiPrvSE.exe (PID: 7428 cmdline:
C:\Windows \system32\ wbem\wmipr vse.exe -s ecured -Em bedding MD5: 60FF40CFD7FB8FE41EE4FE9AE5FE1C51) - cmd.exe (PID: 8072 cmdline:
"C:\Window s\System32 \cmd.exe" /C "C:\Use rs\user\Ap pData\Loca l\Temp\hlV W2PE0oG.ba t" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 8084 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chcp.com (PID: 8128 cmdline:
chcp 65001 MD5: 33395C4732A49065EA72590B14B64F32) - PING.EXE (PID: 8144 cmdline:
ping -n 10 localhost MD5: 2F46799D79D22AC72C241EC0322B011D) - kahKUDRlEYHfKIalWlM.exe (PID: 7644 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\kahKUD RlEYHfKIal WlM.exe" MD5: 38514F88AFF517EA6BE4724D24B28FE2)
- kahKUDRlEYHfKIalWlM.exe (PID: 7244 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\kahKUDR lEYHfKIalW lM.exe MD5: 38514F88AFF517EA6BE4724D24B28FE2)
- kahKUDRlEYHfKIalWlM.exe (PID: 7264 cmdline:
C:\Users\u ser\AppDat a\Local\Te mp\kahKUDR lEYHfKIalW lM.exe MD5: 38514F88AFF517EA6BE4724D24B28FE2)
- svchost.exe (PID: 3220 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DCRat | DCRat is a typical RAT that has been around since at least June 2019. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
{"C2 url": "http://193.3.168.50/privatetemp3line/Track14/Mariadb/flower/dleGeneratorBettersecure/SqlExternalDatalifedatalife/0pipe/7Js/AsyncServer/473datalife/linebigloadprivate", "Params": {"0": "{SYSTEMDRIVE}/Users/", "1": "false", "2": "false", "3": "true", "4": "true", "5": "true", "6": "true", "7": "false", "8": "true", "9": "true", "10": "true", "11": "true", "12": "true", "13": "true", "14": "true"}}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_DCRat_1 | Yara detected DCRat | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_DCRat_1 | Yara detected DCRat | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
Click to see the 5 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
Click to see the 5 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: vburov: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-05T10:53:17.949836+0100 | 2048095 | 1 | A Network Trojan was detected | 192.168.2.4 | 49734 | 193.3.168.50 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 14_2_00007FFD9BD009FA | |
Source: | Code function: | 14_2_00007FFD9BD011CE |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00E3A69B | |
Source: | Code function: | 0_2_00E4C220 |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Software Vulnerabilities |
---|
Source: | Child: |
Source: | Code function: | 4_2_00007FFD9B93CD6D | |
Source: | Code function: | 14_2_00007FFD9B791A8E | |
Source: | Code function: | 14_2_00007FFD9B93CD6D | |
Source: | Code function: | 14_2_00007FFD9BD003E8 | |
Source: | Code function: | 14_2_00007FFD9BD00578 | |
Source: | Code function: | 14_2_00007FFD9BD00588 |
Networking |
---|
Source: | Suricata IDS: |
Source: | Process created: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Code function: | 0_2_00E36FAA |
Source: | File created: |
Source: | Code function: | 0_2_00E3848E | |
Source: | Code function: | 0_2_00E340FE | |
Source: | Code function: | 0_2_00E400B7 | |
Source: | Code function: | 0_2_00E44088 | |
Source: | Code function: | 0_2_00E551C9 | |
Source: | Code function: | 0_2_00E47153 | |
Source: | Code function: | 0_2_00E332F7 | |
Source: | Code function: | 0_2_00E462CA | |
Source: | Code function: | 0_2_00E443BF | |
Source: | Code function: | 0_2_00E3F461 | |
Source: | Code function: | 0_2_00E5D440 | |
Source: | Code function: | 0_2_00E3C426 | |
Source: | Code function: | 0_2_00E477EF | |
Source: | Code function: | 0_2_00E5D8EE | |
Source: | Code function: | 0_2_00E3286B | |
Source: | Code function: | 0_2_00E619F4 | |
Source: | Code function: | 0_2_00E3E9B7 | |
Source: | Code function: | 0_2_00E46CDC | |
Source: | Code function: | 0_2_00E43E0B | |
Source: | Code function: | 0_2_00E3EFE2 | |
Source: | Code function: | 0_2_00E54F9A | |
Source: | Code function: | 4_2_00007FFD9B780DA7 | |
Source: | Code function: | 4_2_00007FFD9B93028A | |
Source: | Code function: | 4_2_00007FFD9B9449FA | |
Source: | Code function: | 14_2_00007FFD9B79B60D | |
Source: | Code function: | 14_2_00007FFD9B79CB59 | |
Source: | Code function: | 14_2_00007FFD9B79CFDD | |
Source: | Code function: | 14_2_00007FFD9B79CD82 | |
Source: | Code function: | 14_2_00007FFD9B79CD35 | |
Source: | Code function: | 14_2_00007FFD9B7CA000 | |
Source: | Code function: | 14_2_00007FFD9B7DED0D | |
Source: | Code function: | 14_2_00007FFD9B7DECD1 | |
Source: | Code function: | 14_2_00007FFD9B78F243 | |
Source: | Code function: | 14_2_00007FFD9B780DA7 | |
Source: | Code function: | 14_2_00007FFD9B93028A | |
Source: | Code function: | 14_2_00007FFD9BCF6377 | |
Source: | Code function: | 15_2_00007FFD9B770DA7 | |
Source: | Code function: | 19_2_00007FFD9B790DA7 |
Source: | Dropped File: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | Code function: | 0_2_00E36C74 |
Source: | Code function: | 0_2_00E4A6C2 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Command line argument: | 0_2_00E4DF1E | |
Source: | Command line argument: | 0_2_00E4DF1E | |
Source: | Command line argument: | 0_2_00E4DF1E | |
Source: | Command line argument: | 0_2_00E4DF1E |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 0_2_00E4F653 | |
Source: | Code function: | 0_2_00E4EB96 | |
Source: | Code function: | 4_2_00007FFD9B7800C1 | |
Source: | Code function: | 8_2_00007FFD9B66D2A6 | |
Source: | Code function: | 8_2_00007FFD9B7800C1 | |
Source: | Code function: | 8_2_00007FFD9B85231B | |
Source: | Code function: | 14_2_00007FFD9B7DD8FD | |
Source: | Code function: | 14_2_00007FFD9B7DD937 | |
Source: | Code function: | 14_2_00007FFD9B7800C1 | |
Source: | Code function: | 14_2_00007FFD9BCF8D77 | |
Source: | Code function: | 14_2_00007FFD9BCF0527 | |
Source: | Code function: | 14_2_00007FFD9BCF0527 | |
Source: | Code function: | 15_2_00007FFD9B7700C1 | |
Source: | Code function: | 19_2_00007FFD9B7900C1 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Persistence and Installation Behavior |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Code function: | 4_2_00007FFD9B94340A |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | File opened: |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | |||
Source: | File Volume queried: |
Source: | Code function: | 0_2_00E3A69B | |
Source: | Code function: | 0_2_00E4C220 |
Source: | Code function: | 0_2_00E4E6A3 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-25012 |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 4_2_00007FFD9B94340A |
Source: | Code function: | 0_2_00E4F838 |
Source: | Code function: | 0_2_00E57DEE |
Source: | Code function: | 0_2_00E5C030 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: |
Source: | Code function: | 0_2_00E4F838 | |
Source: | Code function: | 0_2_00E4F9D5 | |
Source: | Code function: | 0_2_00E4FBCA | |
Source: | Code function: | 0_2_00E58EBD |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00E4F654 |
Source: | Code function: | 0_2_00E4AF0F |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Code function: | 0_2_00E4DF1E |
Source: | Code function: | 0_2_00E3B146 |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 11 Scripting | Valid Accounts | 11 Windows Management Instrumentation | 11 Scripting | 1 DLL Side-Loading | 11 Disable or Modify Tools | 1 OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Archive Collected Data | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 12 Process Injection | 11 Deobfuscate/Decode Files or Information | LSASS Memory | 3 File and Directory Discovery | Remote Desktop Protocol | 2 Data from Local System | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 Command and Scripting Interpreter | Logon Script (Windows) | Logon Script (Windows) | 4 Obfuscated Files or Information | Security Account Manager | 147 System Information Discovery | SMB/Windows Admin Shares | 1 Clipboard Data | 11 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 3 Software Packing | NTDS | 241 Security Software Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 2 Process Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 21 Masquerading | Cached Domain Credentials | 141 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 141 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 12 Process Injection | Proc Filesystem | 1 Remote System Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 1 System Network Configuration Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
55% | ReversingLabs | ByteCode-MSIL.Trojan.Uztuby | ||
100% | Avira | VBS/Runner.VPG | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1323342 | ||
100% | Avira | TR/AVI.Agent.updqb | ||
100% | Avira | VBS/Runner.VPG | ||
100% | Avira | HEUR/AGEN.1323342 | ||
100% | Avira | TR/AVI.Agent.updqb | ||
100% | Avira | BAT/Delbat.C | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
58% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
58% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
50% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
17% | ReversingLabs | |||
4% | ReversingLabs | |||
25% | ReversingLabs | |||
4% | ReversingLabs | |||
29% | ReversingLabs | Win32.Trojan.Generic | ||
25% | ReversingLabs | |||
50% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
16% | ReversingLabs | |||
29% | ReversingLabs | Win32.Trojan.Generic | ||
16% | ReversingLabs | |||
17% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
true |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.3.168.50 | unknown | Denmark | 2107 | ARNES-NETAcademicandResearchNetworkofSloveniaSI | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1569008 |
Start date and time: | 2024-12-05 10:52:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 23 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | file.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.expl.evad.winEXE@25/44@0/2 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, schtasks.exe
- Excluded IPs from analysis (whitelisted): 23.218.208.109
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, e16604.g.akamaiedge.net, ctldl.windowsupdate.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target kahKUDRlEYHfKIalWlM.exe, PID 7264 because it is empty
- Execution Graph export aborted for target kahKUDRlEYHfKIalWlM.exe, PID 7644 because it is empty
- Execution Graph export aborted for target powershell.exe, PID 7972 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: file.exe
Time | Type | Description |
---|---|---|
04:53:09 | API Interceptor | |
04:53:16 | API Interceptor | |
04:53:17 | API Interceptor | |
09:53:09 | Task Scheduler | |
09:53:10 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.3.168.50 | Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ARNES-NETAcademicandResearchNetworkofSloveniaSI | Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| |
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\Desktop\GYwcCMoE.log | Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat | Browse | |||
Get hash | malicious | DCRat | Browse | |||
Get hash | malicious | DCRat | Browse | |||
Get hash | malicious | DCRat | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, Xmrig, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 76 |
Entropy (8bit): | 4.66715165176704 |
Encrypted: | false |
SSDEEP: | 3:AI18oYydpeKHAXPlmXQlOKfb49kq:trf6KglmXQ4b9kq |
MD5: | F64211E9D1EC38EDE33666033382D99C |
SHA1: | B602450C1B9D00043F20DCB60537E8706FCAD872 |
SHA-256: | 6E4D045D43E97C5FCA3DDC26016DB1F1C73B334C6FE4CEE92B65974C745A9CCA |
SHA-512: | 1E80F74C7A6582AC8187BB22DD70FA38E8D18840D4A45D27098C6EB517228B836218211418B147FC0060CC7029AE12D6ABD0D6348B731169B93C9062876C677D |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 212 |
Entropy (8bit): | 5.775012186923779 |
Encrypted: | false |
SSDEEP: | 6:GUwqK+NkLzWbH1xdyrFnBaORbM5nCkDaj/4JqWLz9:GlMCzWL1xdyhBaORbQCwSQJpLp |
MD5: | CCC3DE297113F78D2B92B26BF192FCE3 |
SHA1: | 417DCFBA717CE68EBD96B71A2EDAC15F93E91AAE |
SHA-256: | 2E776534DAB440E19BDA0F46B1BD2A21F2F9C2DEE1C225632F87907939516D37 |
SHA-512: | F4C1AEFDDFCC7A9EB3FE5F333AD287FC0F4353C475EAD34890FFC1609605CE1544BBE0EE4A7192B856AF7540A5D1FCDFE9649856C3A04150C6EDC709B1BB6459 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\file.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2009600 |
Entropy (8bit): | 7.5678452559926175 |
Encrypted: | false |
SSDEEP: | 49152:Z1ijXQywiXW604Jjh42gv9Gk2AWDpL5ml:Z1IZXWCJjhZgHW1N4 |
MD5: | 38514F88AFF517EA6BE4724D24B28FE2 |
SHA1: | 0D9CE3815F04C401561339B056C7AB2BA907E16C |
SHA-256: | 92C34270DF9842C931AB9E4AF87A0CBDD1F3B12E70482D474C3A9D0029F09ADD |
SHA-512: | C7516E29A99FC053D07DA626BDCE8AB37917267DE2911685DEBD3E0764819B3A387626D98413EC62808789E28E15739E0B533A9C8AB765215506BDF6AD5EF707 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073444247601114 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrS:KooCEYhgYEL0In |
MD5: | A6BBC3ECCF86B784614349F032E455A8 |
SHA1: | EF03AB930DB0882B44E8751D31DFD112F2C26810 |
SHA-256: | A81ECD6D7FB124FA08D91ABEF5E71FF3C71E682047FA2EE6FD7B4D1DB7E60666 |
SHA-512: | 0793CEACB6274027F488DBA8187C2A0C9DD9DFF6EC9CA32AC9D200481A7300A83C781A0EE4514FF6C4E68CA5AF41272139A95C2A1A6307635A9E0AFDA8313898 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42210140213061104 |
Encrypted: | false |
SSDEEP: | 1536:BSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Baza/vMUM2Uvz7DO |
MD5: | 9D5FED7ECDBAC6662766D68B46024E36 |
SHA1: | 5ABFA6076B45E8991C7EEDF350398CD53708030D |
SHA-256: | 6366BE89F0E1CFA8C1398934C8A898700A7C67FE4A7FD045158645ED3230DD5D |
SHA-512: | 547D171CE40AFCB6DFBB186C3394D09247348A975C0ABD597C25595262C3D4EE50CABA237FF8254F6C162DC91E09F7C831FAF6D510B6AA59A7ABC95F0809896B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07576490241172268 |
Encrypted: | false |
SSDEEP: | 3:SmltEYeA54KPhvCjn13a/25+p0XlAllcVO/lnlZMxZNQl:SmUzm4KPha53q25V1AOewk |
MD5: | 5D81E952F3ED47057783EF34A59FE71E |
SHA1: | DA89514A6A365BB64725D8A9884BC954F64C606B |
SHA-256: | 1C962C52AFC907BBD8FF7952580AEF17A4008CC43380EC2B97153AA9C2B9AF78 |
SHA-512: | 1BE8CBDF6A3E1D7C5EB373889577CA12F89216DA3C5AAE487053A6F3F1547DCA6008E278A6F235AB74FEDCCC8B0647A7519B1E3C53D863B284CA193020420598 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\chainportruntimeCrtMonitor.exe.log
Download File
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1396 |
Entropy (8bit): | 5.350961817021757 |
Encrypted: | false |
SSDEEP: | 24:ML9E4KQwKDE4KGKZI6KhPKIE4TKBGKoZAE4KKUNrJE4qtE4KlOU4mZsXE4Npv:MxHKQwYHKGSI6oPtHTHhAHKKkrJHmHKu |
MD5: | EBB3E33FCCEC5303477CB59FA0916A28 |
SHA1: | BBF597668E3DB4721CA7B1E1FE3BA66E4D89CD89 |
SHA-256: | DF0C7154CD75ADDA09758C06F758D47F20921F0EB302310849175D3A7346561F |
SHA-512: | 663994B1F78D05972276CD30A28FE61B33902D71BF1DFE4A58EA8EEE753FBDE393213B5BA0C608B9064932F0360621AF4B4190976BE8C00824A6EA0D76334571 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 847 |
Entropy (8bit): | 5.354334472896228 |
Encrypted: | false |
SSDEEP: | 24:ML9E4KQwKDE4KGKZI6KhPKIE4TKBGKoZAE4KKUNb:MxHKQwYHKGSI6oPtHTHhAHKKkb |
MD5: | 9F9FA9EFE67E9BBD165432FA39813EEA |
SHA1: | 6FE9587FB8B6D9FE9FA9ADE987CB8112C294247A |
SHA-256: | 4488EA75E0AC1E2DEB4B7FC35D304CAED2F877A7FB4CC6B8755AE13D709CF37B |
SHA-512: | F4666179D760D32871DDF54700D6B283AD8DA82FA6B867A214557CBAB757F74ACDFCAD824FB188005C0CEF3B05BF2352B9CA51B2C55AECF762468BB8F5560DB3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1510207563435464 |
Encrypted: | false |
SSDEEP: | 3:Nlllullkv/tz:NllU+v/ |
MD5: | 6442F277E58B3984BA5EEE0C15C0C6AD |
SHA1: | 5343ADC2E7F102EC8FB6A101508730898CB14F57 |
SHA-256: | 36B765624FCA82C57E4C5D3706FBD81B5419F18FC3DD7B77CD185E6E3483382D |
SHA-512: | F9E62F510D5FB788F40EBA13287C282444607D2E0033D2233BC6C39CA3E1F5903B65A07F85FA0942BEDDCE2458861073772ACA06F291FA68F23C765B0CA5CA17 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5712781801655107 |
Encrypted: | false |
SSDEEP: | 12:TLVNFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TL1F1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 05A60B4620923FD5D53B9204391452AF |
SHA1: | DC12F90925033F25C70A720E01D5F8666D0B46E4 |
SHA-256: | 6F1CA729609806AF88218D0A35C3B9E34252900341A0E15D71F7F9199E422E13 |
SHA-512: | 068A954C0C7A68E603D72032A447E7652B1E9CED5522562FBCBD9EC0A5D2D943701100049FA0A750E71C4D3D84210B48D10855E7CC60919E04ED884983D3C3D6 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 106496 |
Entropy (8bit): | 1.1358696453229276 |
Encrypted: | false |
SSDEEP: | 192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544 |
MD5: | 28591AA4E12D1C4FC761BE7C0A468622 |
SHA1: | BC4968A84C19377D05A8BB3F208FBFAC49F4820B |
SHA-256: | 51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9 |
SHA-512: | 5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB |
Malicious: | false |
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 701 |
Entropy (8bit): | 5.89743604568768 |
Encrypted: | false |
SSDEEP: | 12:Ma1lhokNFvEE+AA+RQjfzA7qcE0j8RQYXHCoXAHYsuWgsHM0FGB3CY2w7M9ulLm:rEEjdQjf4qSMNZ+5uWg6rWuw7dlLm |
MD5: | 71B8474E859D543BB8489DA42E270634 |
SHA1: | 2230E8E932C74851E4EE104676B112BDAA4E1E34 |
SHA-256: | 633D5393926EA8661DA3C6910864198C340B1218036386458AB855DEF6944810 |
SHA-512: | 576C885A967ADB0A9DEB72F89B6CF5E2070D90676704C3EB7E57B1FFA376A7CFF3CA114B7C0B4E9BD960866B4803303CD3DDD35C24A1573616EBFC259E03A37C |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98304 |
Entropy (8bit): | 0.08235737944063153 |
Encrypted: | false |
SSDEEP: | 12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO |
MD5: | 369B6DD66F1CAD49D0952C40FEB9AD41 |
SHA1: | D05B2DE29433FB113EC4C558FF33087ED7481DD4 |
SHA-256: | 14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D |
SHA-512: | 771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 114688 |
Entropy (8bit): | 0.9746603542602881 |
Encrypted: | false |
SSDEEP: | 192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn |
MD5: | 780853CDDEAEE8DE70F28A4B255A600B |
SHA1: | AD7A5DA33F7AD12946153C497E990720B09005ED |
SHA-256: | 1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3 |
SHA-512: | E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28672 |
Entropy (8bit): | 2.5793180405395284 |
Encrypted: | false |
SSDEEP: | 96:/xealJiylsMjLslk5nYPphZEhcR2hO2mOeVgN8tmKqWkh3qzRk4PeOhZ3hcR1hOI:/xGZR8wbtxq5uWRHKloIN7YItnb6Ggz |
MD5: | 41EA9A4112F057AE6BA17E2838AEAC26 |
SHA1: | F2B389103BFD1A1A050C4857A995B09FEAFE8903 |
SHA-256: | CE84656EAEFC842355D668E7141F84383D3A0C819AE01B26A04F9021EF0AC9DB |
SHA-512: | 29E848AD16D458F81D8C4F4E288094B4CFC103AD99B4511ED1A4846542F9128736A87AAC5F4BFFBEFE7DF99A05EB230911EDCE99FEE3877DEC130C2781962103 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40960 |
Entropy (8bit): | 0.8553638852307782 |
Encrypted: | false |
SSDEEP: | 48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil |
MD5: | 28222628A3465C5F0D4B28F70F97F482 |
SHA1: | 1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14 |
SHA-256: | 93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4 |
SHA-512: | C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49152 |
Entropy (8bit): | 0.8180424350137764 |
Encrypted: | false |
SSDEEP: | 96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG |
MD5: | 349E6EB110E34A08924D92F6B334801D |
SHA1: | BDFB289DAFF51890CC71697B6322AA4B35EC9169 |
SHA-256: | C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A |
SHA-512: | 2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574 |
Malicious: | false |
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.163856189774724 |
Encrypted: | false |
SSDEEP: | 3:sodqrBjQVKBn:sAqrVtBn |
MD5: | DD6EE51E1E770D91820C6DBBEBAFCD0A |
SHA1: | BE7AC8CEB2710CF816DA10262A66DAF7AC59CEDD |
SHA-256: | A167A41FDECD16E44CCA605D9DB9E5C5043AE0ACA0FBF274905DD86CC38BE209 |
SHA-512: | 3C367E9CD482F88FFEDDF4CD8E7AAD503B5E63D4A590B09A1817EA79944FC2538C9CDE6170DE6CDCA1DEC0ED75F125D4ED6A3F8974625A1C86A58E1D5D149C68 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40960 |
Entropy (8bit): | 0.8553638852307782 |
Encrypted: | false |
SSDEEP: | 48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil |
MD5: | 28222628A3465C5F0D4B28F70F97F482 |
SHA1: | 1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14 |
SHA-256: | 93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4 |
SHA-512: | C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 106496 |
Entropy (8bit): | 1.1358696453229276 |
Encrypted: | false |
SSDEEP: | 192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544 |
MD5: | 28591AA4E12D1C4FC761BE7C0A468622 |
SHA1: | BC4968A84C19377D05A8BB3F208FBFAC49F4820B |
SHA-256: | 51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9 |
SHA-512: | 5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5707520969659783 |
Encrypted: | false |
SSDEEP: | 12:TLVlFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TLxF1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 9F6D153D934BCC50E8BC57E7014B201A |
SHA1: | 50B3F813A1A8186DE3F6E9791EC41D95A8DC205D |
SHA-256: | 2A7FC7F64938AD07F7249EC0BED6F48BC5302EA84FE9E61E276436EA942BA230 |
SHA-512: | B8CA2DCB8D62A0B2ED8795C3F67E4698F3BCB208C26FBD8BA9FD4DA82269E6DE9C5759F27F28DC108677DDEBBAC96D60C4ED2E64C90D51DB5B0F70331185B33F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 185 |
Entropy (8bit): | 5.2234515926159935 |
Encrypted: | false |
SSDEEP: | 3:mKDDVNGvTVLuVFcROr+jn9m1t+kiE2J5xAIcuJzPJHBvBktKcKZG1t+kiE2J5xAV:hCRLuVFOOr+DE1wkn23fJzxHBvKOZG1n |
MD5: | 9DA785D6C0E5B8A2E11B209A4D0EAD2C |
SHA1: | 476C92CAAA5D56AC29586E8737B8931777E4A352 |
SHA-256: | 7B6565DEAF7C967118E52022321AAD502F184FEAD9FB8E577ACD8D7AFF226987 |
SHA-512: | 66E56B8B20E2BCBB8F9569853D694A938414736707ED993C29DFE1E907EA182B80BEE40D791731FDD820D50FBEBADE1D9708A16C8555E517443E74A79B732E67 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2009600 |
Entropy (8bit): | 7.5678452559926175 |
Encrypted: | false |
SSDEEP: | 49152:Z1ijXQywiXW604Jjh42gv9Gk2AWDpL5ml:Z1IZXWCJjhZgHW1N4 |
MD5: | 38514F88AFF517EA6BE4724D24B28FE2 |
SHA1: | 0D9CE3815F04C401561339B056C7AB2BA907E16C |
SHA-256: | 92C34270DF9842C931AB9E4AF87A0CBDD1F3B12E70482D474C3A9D0029F09ADD |
SHA-512: | C7516E29A99FC053D07DA626BDCE8AB37917267DE2911685DEBD3E0764819B3A387626D98413EC62808789E28E15739E0B533A9C8AB765215506BDF6AD5EF707 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5707520969659783 |
Encrypted: | false |
SSDEEP: | 12:TLVlFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TLxF1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 9F6D153D934BCC50E8BC57E7014B201A |
SHA1: | 50B3F813A1A8186DE3F6E9791EC41D95A8DC205D |
SHA-256: | 2A7FC7F64938AD07F7249EC0BED6F48BC5302EA84FE9E61E276436EA942BA230 |
SHA-512: | B8CA2DCB8D62A0B2ED8795C3F67E4698F3BCB208C26FBD8BA9FD4DA82269E6DE9C5759F27F28DC108677DDEBBAC96D60C4ED2E64C90D51DB5B0F70331185B33F |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 114688 |
Entropy (8bit): | 0.9746603542602881 |
Encrypted: | false |
SSDEEP: | 192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn |
MD5: | 780853CDDEAEE8DE70F28A4B255A600B |
SHA1: | AD7A5DA33F7AD12946153C497E990720B09005ED |
SHA-256: | 1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3 |
SHA-512: | E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.243856189774723 |
Encrypted: | false |
SSDEEP: | 3:qVuT5Sn:qASn |
MD5: | FE384112227DFA2593CAB2C6C84D24C6 |
SHA1: | 35862614DDC1033EAF1B5646FD3560EE2308B829 |
SHA-256: | FCDD97F3B537F0E1CC5CDACAF37521CECF808BBDE312150FB8883F1F7AF026F2 |
SHA-512: | 3C4EC3EC59D32B3528A46ACAEDD91BEEE36682BC9EAA66D750ED80DCC852A7FB498F8C96B448E063AEB662EA265C09FC2573A744A3297903BD10A0DDDEE971DF |
Malicious: | false |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69632 |
Entropy (8bit): | 5.932541123129161 |
Encrypted: | false |
SSDEEP: | 1536:yo63BdpcSWxaQ/RKd8Skwea/e+hTEqS/ABGegJBb07j:j+9W+p/LEqu6GegG |
MD5: | F4B38D0F95B7E844DD288B441EBC9AAF |
SHA1: | 9CBF5C6E865AE50CEC25D95EF70F3C8C0F2A6CBF |
SHA-256: | AAB95596475CA74CEDE5BA50F642D92FA029F6F74F6FAEAE82A9A07285A5FB97 |
SHA-512: | 2300D8FC857986DC9560225DE36C221C6ECB4F98ADB954D896ED6AFF305C3A3C05F5A9F1D5EF0FC9094355D60327DDDFAFC81A455596DCD28020A9A89EF50E1A |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24576 |
Entropy (8bit): | 5.535426842040921 |
Encrypted: | false |
SSDEEP: | 384:aShD1nf4AeGAJVdBb9h2d7WNrFBo29TZHD1qPPPPPDPC2C6/Xa3c4J9UbWr4e169:aSPUrJVH94sDBLVZHxqPPPPPDPC2C6/X |
MD5: | 5420053AF2D273C456FB46C2CDD68F64 |
SHA1: | EA1808D7A8C401A68097353BB51A85F1225B429C |
SHA-256: | A4DFD8B1735598699A410538B8B2ACE6C9A68631D2A26FBF8089D6537DBB30F2 |
SHA-512: | DD4C7625A1E8222286CE8DD3FC94B7C0A053B1AD3BF28D848C65E846D04A721EA4BFFAFA234A4A96AB218CEE3FC1F5788E996C6A6DD56E5A9AB41158131DFD4B |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 22016 |
Entropy (8bit): | 5.41854385721431 |
Encrypted: | false |
SSDEEP: | 384:8Np+VQupukpNURNzOLn7TcZ64vTUbqryealcpA2:bPpu0NyzOL0ZJ4bavae |
MD5: | BBDE7073BAAC996447F749992D65FFBA |
SHA1: | 2DA17B715689186ABEE25419A59C280800F7EDDE |
SHA-256: | 1FAE639DF1C497A54C9F42A8366EDAE3C0A6FEB4EB917ECAD9323EF8D87393E8 |
SHA-512: | 0EBDDE3A13E3D27E4FFDAF162382D463D8F7E7492B7F5C52D3050ECA3E6BD7A58353E8EC49524A9601CDF8AAC18531F77C2CC6F50097D47BE55DB17A387621DF |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32256 |
Entropy (8bit): | 5.631194486392901 |
Encrypted: | false |
SSDEEP: | 384:lP/qZmINM9WPs9Q617EsO2m2g7udB2HEsrW+a4yiym4I16Gl:lP/imaPyQ4T5dsHSt9nQ |
MD5: | D8BF2A0481C0A17A634D066A711C12E9 |
SHA1: | 7CC01A58831ED109F85B64FE4920278CEDF3E38D |
SHA-256: | 2B93377EA087225820A9F8E4F331005A0C600D557242366F06E0C1EAE003D669 |
SHA-512: | 7FB4EB786528AD15DF044F16973ECA05F05F035491E9B1C350D6AA30926AAE438E98F37BE1BB80510310A91BC820BA3EDDAF7759D7D599BCDEBA0C9DF6302F60 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 22016 |
Entropy (8bit): | 5.41854385721431 |
Encrypted: | false |
SSDEEP: | 384:8Np+VQupukpNURNzOLn7TcZ64vTUbqryealcpA2:bPpu0NyzOL0ZJ4bavae |
MD5: | BBDE7073BAAC996447F749992D65FFBA |
SHA1: | 2DA17B715689186ABEE25419A59C280800F7EDDE |
SHA-256: | 1FAE639DF1C497A54C9F42A8366EDAE3C0A6FEB4EB917ECAD9323EF8D87393E8 |
SHA-512: | 0EBDDE3A13E3D27E4FFDAF162382D463D8F7E7492B7F5C52D3050ECA3E6BD7A58353E8EC49524A9601CDF8AAC18531F77C2CC6F50097D47BE55DB17A387621DF |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 5.645950918301459 |
Encrypted: | false |
SSDEEP: | 384:fRDtCEPOaiRBCSzHADW8S3YVDOy6Vgh/UaFTKqrPd62GTB7ZyTG4sTaG:fR/IMEACDoJ86/UoTKqZwJ8TG4 |
MD5: | E84DCD8370FAC91DE71DEF8DCF09BFEC |
SHA1: | 2E73453750A36FD3611D5007BBB26A39DDF5F190 |
SHA-256: | DD7AC164E789CAD96D30930EFE9BBA99698473EDEA38252C2C0EA44043FB1DB5 |
SHA-512: | 77461BA74518E6AE9572EC916499058F45D0576535C20FAE74D0CB904DC79ED668B94885BFC38E24D5DEEAE7FBEF79B768216F1422B2178277DBD3209FC2AFD9 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32256 |
Entropy (8bit): | 5.631194486392901 |
Encrypted: | false |
SSDEEP: | 384:lP/qZmINM9WPs9Q617EsO2m2g7udB2HEsrW+a4yiym4I16Gl:lP/imaPyQ4T5dsHSt9nQ |
MD5: | D8BF2A0481C0A17A634D066A711C12E9 |
SHA1: | 7CC01A58831ED109F85B64FE4920278CEDF3E38D |
SHA-256: | 2B93377EA087225820A9F8E4F331005A0C600D557242366F06E0C1EAE003D669 |
SHA-512: | 7FB4EB786528AD15DF044F16973ECA05F05F035491E9B1C350D6AA30926AAE438E98F37BE1BB80510310A91BC820BA3EDDAF7759D7D599BCDEBA0C9DF6302F60 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69632 |
Entropy (8bit): | 5.932541123129161 |
Encrypted: | false |
SSDEEP: | 1536:yo63BdpcSWxaQ/RKd8Skwea/e+hTEqS/ABGegJBb07j:j+9W+p/LEqu6GegG |
MD5: | F4B38D0F95B7E844DD288B441EBC9AAF |
SHA1: | 9CBF5C6E865AE50CEC25D95EF70F3C8C0F2A6CBF |
SHA-256: | AAB95596475CA74CEDE5BA50F642D92FA029F6F74F6FAEAE82A9A07285A5FB97 |
SHA-512: | 2300D8FC857986DC9560225DE36C221C6ECB4F98ADB954D896ED6AFF305C3A3C05F5A9F1D5EF0FC9094355D60327DDDFAFC81A455596DCD28020A9A89EF50E1A |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89600 |
Entropy (8bit): | 5.905167202474779 |
Encrypted: | false |
SSDEEP: | 1536:mspaoWV6yRfXRFHJh/fLiSI82VawF1YBJcqe:1paoWMy5XXnfXf2YSYBJcqe |
MD5: | 06442F43E1001D860C8A19A752F19085 |
SHA1: | 9FBDC199E56BC7371292AA1A25CF4F8A6F49BB6D |
SHA-256: | 6FB2FAAC08F55BDF18F3FCEE44C383B877F416B97085DBEE4746300723F3304F |
SHA-512: | 3592162D6D7F0B298C2D277942F9C7E86A29078A4D7B73903183C97DACABC87E0523F0EF992F2BD7350AA8AE9D49910B3CE199BC4103F7DC268BF319293CD577 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 5.645950918301459 |
Encrypted: | false |
SSDEEP: | 384:fRDtCEPOaiRBCSzHADW8S3YVDOy6Vgh/UaFTKqrPd62GTB7ZyTG4sTaG:fR/IMEACDoJ86/UoTKqZwJ8TG4 |
MD5: | E84DCD8370FAC91DE71DEF8DCF09BFEC |
SHA1: | 2E73453750A36FD3611D5007BBB26A39DDF5F190 |
SHA-256: | DD7AC164E789CAD96D30930EFE9BBA99698473EDEA38252C2C0EA44043FB1DB5 |
SHA-512: | 77461BA74518E6AE9572EC916499058F45D0576535C20FAE74D0CB904DC79ED668B94885BFC38E24D5DEEAE7FBEF79B768216F1422B2178277DBD3209FC2AFD9 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89600 |
Entropy (8bit): | 5.905167202474779 |
Encrypted: | false |
SSDEEP: | 1536:mspaoWV6yRfXRFHJh/fLiSI82VawF1YBJcqe:1paoWMy5XXnfXf2YSYBJcqe |
MD5: | 06442F43E1001D860C8A19A752F19085 |
SHA1: | 9FBDC199E56BC7371292AA1A25CF4F8A6F49BB6D |
SHA-256: | 6FB2FAAC08F55BDF18F3FCEE44C383B877F416B97085DBEE4746300723F3304F |
SHA-512: | 3592162D6D7F0B298C2D277942F9C7E86A29078A4D7B73903183C97DACABC87E0523F0EF992F2BD7350AA8AE9D49910B3CE199BC4103F7DC268BF319293CD577 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 24576 |
Entropy (8bit): | 5.535426842040921 |
Encrypted: | false |
SSDEEP: | 384:aShD1nf4AeGAJVdBb9h2d7WNrFBo29TZHD1qPPPPPDPC2C6/Xa3c4J9UbWr4e169:aSPUrJVH94sDBLVZHxqPPPPPDPC2C6/X |
MD5: | 5420053AF2D273C456FB46C2CDD68F64 |
SHA1: | EA1808D7A8C401A68097353BB51A85F1225B429C |
SHA-256: | A4DFD8B1735598699A410538B8B2ACE6C9A68631D2A26FBF8089D6537DBB30F2 |
SHA-512: | DD4C7625A1E8222286CE8DD3FC94B7C0A053B1AD3BF28D848C65E846D04A721EA4BFFAFA234A4A96AB218CEE3FC1F5788E996C6A6DD56E5A9AB41158131DFD4B |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\PING.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 502 |
Entropy (8bit): | 4.6048426069826895 |
Encrypted: | false |
SSDEEP: | 12:PZ5pTcgTcgTcgTcgTcgTcgTcgTcgTcgTLs4oS/AFSkIrxMVlmJHaVzvv:LdUOAokItULVDv |
MD5: | 3772C8A6BE7A12366E9B4E96F4489643 |
SHA1: | 4E93A70C1604E3A378B0A6330BD7C7C4CE7AB6DE |
SHA-256: | 815727123D8C135F839CC45D3AB906B47EEAC9FE23AF26CBBB5B931E56F975AA |
SHA-512: | C19DF3B7E1A809E7B7093A8F8C60D7E60DEA489D8F7D614D454E815A16D7F92363B439E380FADBA1CCA0BEEED2915855BF168E79A3D6DE49DF4BE46A29759767 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.505513225724165 |
TrID: |
|
File name: | file.exe |
File size: | 2'331'371 bytes |
MD5: | c9059dfb76ad9e011d4e11608ccc98cc |
SHA1: | c7ec739a977cc99a19e39103e2a20d59a6094508 |
SHA256: | 906e30690506eb761b3f84f7ae1146db9dc796e60d87303173fc99370485c58f |
SHA512: | da494d85e5689c65f2369bcff41479ec9a797322c761e18138c1e2397e0879986dc9bca64d9cdc20999902db90fdec8f94ad36184997d396433ab1a7c2e1b9ce |
SSDEEP: | 49152:IBJR1ijXQywiXW604Jjh42gv9Gk2AWDpL5mlP:yr1IZXWCJjhZgHW1N4P |
TLSH: | B2B5C046BAD34E73C1943F7188D7102D82B1DE363536EF8B3A0F6995AC161728A162F3 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......x_c.<>..<>..<>......1>.......>......$>...I..>>...I../>...I..+>...I...>..5F..7>..5F..;>..<>..)?...I...>...I..=>...I..=>...I..=>. |
Icon Hash: | 1515d4d4442f2d2d |
Entrypoint: | 0x41f530 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6220BF8D [Thu Mar 3 13:15:57 2022 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | 12e12319f1029ec4f8fcbed7e82df162 |
Instruction |
---|
call 00007F825CC147ABh |
jmp 00007F825CC140BDh |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push ebp |
mov ebp, esp |
push esi |
push dword ptr [ebp+08h] |
mov esi, ecx |
call 00007F825CC06F07h |
mov dword ptr [esi], 004356D0h |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
and dword ptr [ecx+04h], 00000000h |
mov eax, ecx |
and dword ptr [ecx+08h], 00000000h |
mov dword ptr [ecx+04h], 004356D8h |
mov dword ptr [ecx], 004356D0h |
ret |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
int3 |
push ebp |
mov ebp, esp |
push esi |
mov esi, ecx |
lea eax, dword ptr [esi+04h] |
mov dword ptr [esi], 004356B8h |
push eax |
call 00007F825CC1754Fh |
test byte ptr [ebp+08h], 00000001h |
pop ecx |
je 00007F825CC1424Ch |
push 0000000Ch |
push esi |
call 00007F825CC13809h |
pop ecx |
pop ecx |
mov eax, esi |
pop esi |
pop ebp |
retn 0004h |
push ebp |
mov ebp, esp |
sub esp, 0Ch |
lea ecx, dword ptr [ebp-0Ch] |
call 00007F825CC06E82h |
push 0043BEF0h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
call 00007F825CC17009h |
int3 |
push ebp |
mov ebp, esp |
sub esp, 0Ch |
lea ecx, dword ptr [ebp-0Ch] |
call 00007F825CC141C8h |
push 0043C0F4h |
lea eax, dword ptr [ebp-0Ch] |
push eax |
call 00007F825CC16FECh |
int3 |
jmp 00007F825CC18A87h |
int3 |
int3 |
int3 |
int3 |
push 00422900h |
push dword ptr fs:[00000000h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x3d070 | 0x34 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3d0a4 | 0x50 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x64000 | 0xdff8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x72000 | 0x233c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x3b11c | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x355f8 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x33000 | 0x278 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x3c5ec | 0x120 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x31bdc | 0x31c00 | 2831bb8b11e3209658a53131886cdf98 | False | 0.5909380888819096 | data | 6.712962136932442 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x33000 | 0xaec0 | 0xb000 | 042f11346230ca5aa360727d9908e809 | False | 0.4579190340909091 | data | 5.261605615899847 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3e000 | 0x24720 | 0x1000 | 9670b581969e508258d8bc903025de5e | False | 0.451416015625 | data | 4.387459135575936 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.didat | 0x63000 | 0x190 | 0x200 | c83554035c63bb446c6208d0c8fa0256 | False | 0.4453125 | data | 3.3327310103022305 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x64000 | 0xdff8 | 0xe000 | ba08fbcd0ed7d9e6a268d75148d9914b | False | 0.6373639787946429 | data | 6.638661032196024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x72000 | 0x233c | 0x2400 | 40b5e17755fd6fdd34de06e5cdb7f711 | False | 0.7749565972222222 | data | 6.623012966548067 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
PNG | 0x64650 | 0xb45 | PNG image data, 93 x 302, 8-bit/color RGB, non-interlaced | English | United States | 1.0027729636048528 |
PNG | 0x65198 | 0x15a9 | PNG image data, 186 x 604, 8-bit/color RGB, non-interlaced | English | United States | 0.9363390441839495 |
RT_ICON | 0x66748 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, resolution 2834 x 2834 px/m, 256 important colors | English | United States | 0.47832369942196534 |
RT_ICON | 0x66cb0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, resolution 2834 x 2834 px/m, 256 important colors | English | United States | 0.5410649819494585 |
RT_ICON | 0x67558 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, resolution 2834 x 2834 px/m, 256 important colors | English | United States | 0.4933368869936034 |
RT_ICON | 0x68400 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024, resolution 2834 x 2834 px/m | English | United States | 0.5390070921985816 |
RT_ICON | 0x68868 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096, resolution 2834 x 2834 px/m | English | United States | 0.41393058161350843 |
RT_ICON | 0x69910 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216, resolution 2834 x 2834 px/m | English | United States | 0.3479253112033195 |
RT_ICON | 0x6beb8 | 0x3d71 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 0.9809269502193401 |
RT_DIALOG | 0x70588 | 0x286 | data | English | United States | 0.5092879256965944 |
RT_DIALOG | 0x70358 | 0x13a | data | English | United States | 0.60828025477707 |
RT_DIALOG | 0x70498 | 0xec | data | English | United States | 0.6991525423728814 |
RT_DIALOG | 0x70228 | 0x12e | data | English | United States | 0.5927152317880795 |
RT_DIALOG | 0x6fef0 | 0x338 | data | English | United States | 0.45145631067961167 |
RT_DIALOG | 0x6fc98 | 0x252 | data | English | United States | 0.5757575757575758 |
RT_STRING | 0x70f68 | 0x1e2 | data | English | United States | 0.3900414937759336 |
RT_STRING | 0x71150 | 0x1cc | data | English | United States | 0.4282608695652174 |
RT_STRING | 0x71320 | 0x1b8 | data | English | United States | 0.45681818181818185 |
RT_STRING | 0x714d8 | 0x146 | data | English | United States | 0.5153374233128835 |
RT_STRING | 0x71620 | 0x46c | data | English | United States | 0.3454063604240283 |
RT_STRING | 0x71a90 | 0x166 | data | English | United States | 0.49162011173184356 |
RT_STRING | 0x71bf8 | 0x152 | data | English | United States | 0.5059171597633136 |
RT_STRING | 0x71d50 | 0x10a | data | English | United States | 0.49624060150375937 |
RT_STRING | 0x71e60 | 0xbc | data | English | United States | 0.6329787234042553 |
RT_STRING | 0x71f20 | 0xd6 | data | English | United States | 0.5747663551401869 |
RT_GROUP_ICON | 0x6fc30 | 0x68 | data | English | United States | 0.7019230769230769 |
RT_MANIFEST | 0x70810 | 0x753 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.3957333333333333 |
DLL | Import |
---|---|
KERNEL32.dll | GetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, CreateDirectoryW, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, InterlockedDecrement, GetVersionExW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleFileNameW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, GetCurrentProcessId, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, LoadResource, SizeofResource, SetCurrentDirectoryW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, ExpandEnvironmentStringsW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetTimeFormatW, GetDateFormatW, GetNumberFormatW, DecodePointer, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetOEMCP, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, IsProcessorFeaturePresent, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, TerminateProcess, LocalFree, RtlUnwind, EncodePointer, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, HeapReAlloc, GetStringTypeW, LCMapStringW, FindFirstFileExA, FindNextFileA, IsValidCodePage |
OLEAUT32.dll | SysAllocString, SysFreeString, VariantClear |
gdiplus.dll | GdipAlloc, GdipDisposeImage, GdipCloneImage, GdipCreateBitmapFromStream, GdipCreateBitmapFromStreamICM, GdipCreateHBITMAPFromBitmap, GdiplusStartup, GdiplusShutdown, GdipFree |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-05T10:53:17.949836+0100 | 2048095 | ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in (POST) | 1 | 192.168.2.4 | 49734 | 193.3.168.50 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 5, 2024 10:53:16.576716900 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:16.696769953 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:16.696861029 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:16.710395098 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:16.830342054 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:17.066200972 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:17.186105013 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:17.935105085 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:17.949781895 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:17.949829102 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:17.949836016 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:17.981781960 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:18.101766109 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:18.336882114 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:18.384511948 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:18.456690073 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:18.580662966 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:18.734464884 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:18.783822060 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:19.978777885 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:19.979149103 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.099649906 CET | 80 | 49734 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.099663973 CET | 80 | 49740 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.099730015 CET | 49734 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.099776030 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.104814053 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.224565029 CET | 80 | 49740 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.460542917 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.471054077 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.580271006 CET | 80 | 49740 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.590759993 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.590835094 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.595257044 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:20.714961052 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:20.940305948 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:21.060106993 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.060250998 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.336755037 CET | 80 | 49740 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.486901045 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:21.569391966 CET | 80 | 49740 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.678308964 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:21.829662085 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.875628948 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:21.971406937 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:21.995469093 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:21.996874094 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:22.006339073 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:22.061327934 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:22.126058102 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:22.283778906 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:22.378456116 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:22.498230934 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:22.565541983 CET | 49740 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.233376026 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:23.283808947 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.465343952 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:23.613596916 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.613677979 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.613929987 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.733680010 CET | 80 | 49745 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:23.733748913 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.733752966 CET | 80 | 49741 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:23.733824015 CET | 49741 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.734152079 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.734194040 CET | 80 | 49744 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:23.734275103 CET | 49744 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:23.853815079 CET | 80 | 49745 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.080730915 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.144835949 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.146629095 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.200459003 CET | 80 | 49745 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.264688015 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.265476942 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.289794922 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.309526920 CET | 80 | 49745 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.409529924 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.649388075 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.704881907 CET | 80 | 49745 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.708786011 CET | 49745 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.769476891 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769490004 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769499063 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769570112 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.769586086 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769634962 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.769812107 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769821882 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769876957 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.769911051 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769922018 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.769970894 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.770066977 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.770076990 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.770133018 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.889657974 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.889708042 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.889755011 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.889765024 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.889765024 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.889789104 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.889794111 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.889816999 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.889844894 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:24.933533907 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:24.936855078 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.053536892 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.053638935 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.101795912 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.104041100 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.141158104 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.217597961 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.238255024 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.238373041 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.260951042 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.261014938 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.261147976 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.358222961 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358253956 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358263969 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358273983 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358330965 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358383894 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358392954 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358469963 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358479023 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358558893 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358737946 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358747005 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.358902931 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.359018087 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.359216928 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.380847931 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.508181095 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:25.580646992 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.611988068 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:25.731671095 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.074276924 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.246663094 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.499133110 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.580671072 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.733485937 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.860915899 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.861126900 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.861212969 CET | 49750 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.980896950 CET | 80 | 49750 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.981057882 CET | 49750 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.981178999 CET | 49750 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.981286049 CET | 80 | 49746 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.981350899 CET | 49746 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:26.981880903 CET | 80 | 49748 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:26.982141972 CET | 49748 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.081751108 CET | 49750 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.082123995 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.101108074 CET | 80 | 49750 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.201828003 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.201899052 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.201997995 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.202207088 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.245477915 CET | 80 | 49750 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.321652889 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.321867943 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.322191954 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.322307110 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.441941977 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.549489975 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.669254065 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.669337988 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.674469948 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:27.794457912 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.949670076 CET | 80 | 49750 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:27.949736118 CET | 49750 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.439523935 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:28.562184095 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:28.580650091 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.611906052 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.677506924 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:28.733004093 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.797455072 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:28.846277952 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.922827959 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.922965050 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:28.923289061 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.043112993 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:29.043186903 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.043292046 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.043445110 CET | 80 | 49751 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:29.043977022 CET | 49751 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.044405937 CET | 80 | 49752 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:29.044461966 CET | 49752 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.163403988 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:29.393503904 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:29.513381004 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:30.282882929 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:30.330672979 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.517685890 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:30.565030098 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.642108917 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.642378092 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.762159109 CET | 80 | 49754 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:30.762173891 CET | 80 | 49753 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:30.762255907 CET | 49753 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.762357950 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.762357950 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:30.882159948 CET | 80 | 49754 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:31.112122059 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:31.232314110 CET | 80 | 49754 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:32.009406090 CET | 80 | 49754 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:32.049436092 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.245738029 CET | 80 | 49754 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:32.299577951 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.360023022 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.479895115 CET | 80 | 49755 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:32.479965925 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.480103970 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.599890947 CET | 80 | 49755 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:32.830878973 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:32.950721979 CET | 80 | 49755 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.690920115 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.691200972 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.718775988 CET | 80 | 49755 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.718904018 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.811896086 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.812057972 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.812182903 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.812398911 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.813009977 CET | 80 | 49755 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.813188076 CET | 49755 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.931857109 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.932049036 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:33.932118893 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:33.932337999 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:34.052050114 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:34.159106016 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:34.278862000 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:34.278956890 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:34.283932924 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:34.403753042 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.050003052 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.096358061 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.170809984 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.221303940 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.285732031 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.330703974 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.405895948 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.455679893 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.531600952 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.531794071 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.532007933 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.651608944 CET | 80 | 49756 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.651684046 CET | 80 | 49758 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.651715040 CET | 49756 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.651793957 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.652005911 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.652065039 CET | 80 | 49757 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:35.652261019 CET | 49757 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:35.771682978 CET | 80 | 49758 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:36.002718925 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:36.122550964 CET | 80 | 49758 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:36.889818907 CET | 80 | 49758 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:36.940042973 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.125454903 CET | 80 | 49758 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:37.174421072 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.250484943 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.370436907 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:37.370515108 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.370738983 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.490540981 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:37.750035048 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:37.870045900 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:38.607925892 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:38.658787012 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:38.841646910 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:38.893168926 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:38.968492985 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:38.968787909 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:39.088535070 CET | 80 | 49760 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:39.088612080 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:39.088669062 CET | 80 | 49759 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:39.088768005 CET | 49759 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:39.088969946 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:39.208636045 CET | 80 | 49760 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:39.440166950 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:39.560082912 CET | 80 | 49760 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:40.327800989 CET | 80 | 49760 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:40.377552986 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.385412931 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.385687113 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.505372047 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:40.505814075 CET | 80 | 49760 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:40.505913973 CET | 49760 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.508764982 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.566241026 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:40.686192989 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:40.952542067 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.027368069 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.072427034 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.072442055 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.147245884 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.147329092 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.147509098 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.267174959 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.502707005 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.622538090 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.755453110 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:41.799499035 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:41.993649960 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.033991098 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.385531902 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.440123081 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.617727041 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.658811092 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.733875990 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.733952999 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.734286070 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.854130030 CET | 80 | 49761 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.854162931 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.854263067 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.854263067 CET | 49761 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.854571104 CET | 80 | 49762 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:42.854708910 CET | 49762 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.855597973 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:42.975632906 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:43.205878973 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:43.325769901 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.100519896 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.143249989 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.337546110 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.338491917 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.455291986 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.458651066 CET | 80 | 49763 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.458704948 CET | 49763 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.575097084 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.575208902 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.580044985 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:44.699871063 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:44.924592018 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:45.044471025 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:45.814090014 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:45.861958027 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.049483061 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:46.096324921 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.173021078 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.173305035 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.293098927 CET | 80 | 49765 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:46.293222904 CET | 80 | 49764 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:46.293319941 CET | 49764 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.293327093 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.295015097 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.415358067 CET | 80 | 49765 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:46.643309116 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:46.763129950 CET | 80 | 49765 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.003613949 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.003978014 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.123450041 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.124835014 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.124984980 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.125874043 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.165473938 CET | 80 | 49765 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.244823933 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.245672941 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.246049881 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.246284008 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.261548996 CET | 80 | 49765 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.262120962 CET | 49765 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.366039991 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.471735954 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.591592073 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.591658115 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:47.596373081 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:47.716090918 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.371664047 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.424451113 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.483824968 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.533813000 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.605647087 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.658829927 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.717506886 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.768207073 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.844310999 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.844531059 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.844700098 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.965254068 CET | 80 | 49768 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.965270996 CET | 80 | 49766 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.965281963 CET | 80 | 49767 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:48.965405941 CET | 49766 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.965425968 CET | 49767 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.965445042 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:48.965683937 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:49.085429907 CET | 80 | 49768 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:49.315287113 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:49.435745955 CET | 80 | 49768 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:50.204859972 CET | 80 | 49768 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:50.252688885 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:50.437592983 CET | 80 | 49768 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:50.486951113 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:50.566731930 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:50.686582088 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:50.686661005 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:50.686804056 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:50.807554960 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:51.033956051 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:51.153772116 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:51.924709082 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:51.971577883 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.157598019 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:52.205800056 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.282377958 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.282670021 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.403158903 CET | 80 | 49770 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:52.403230906 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.403414965 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.403609037 CET | 80 | 49769 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:52.403660059 CET | 49769 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.523225069 CET | 80 | 49770 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:52.752778053 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:52.872590065 CET | 80 | 49770 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.612966061 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.613061905 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.640650034 CET | 80 | 49770 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.640718937 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.732893944 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.733185053 CET | 80 | 49770 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.733292103 CET | 49770 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.733421087 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.733421087 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.734422922 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.853152990 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.854173899 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:53.854255915 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.854407072 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:53.974209070 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:54.080806971 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:54.200830936 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:54.200848103 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:54.227942944 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:54.348361969 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:54.971354961 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.018215895 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.099199057 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.143196106 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.205805063 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.245676041 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.337575912 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.393218994 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.456701040 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.456728935 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.457048893 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.576836109 CET | 80 | 49774 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.576908112 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.576955080 CET | 80 | 49771 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.577002048 CET | 49771 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.577035904 CET | 80 | 49772 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.577076912 CET | 49772 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.577171087 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:55.697232008 CET | 80 | 49774 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:55.924618959 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:56.044579983 CET | 80 | 49774 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:56.814743996 CET | 80 | 49774 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:56.861974955 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.049464941 CET | 80 | 49774 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:57.052966118 CET | 49768 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.096391916 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.172096014 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.292267084 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:57.295190096 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.295377970 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.480499029 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:57.643596888 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:57.763376951 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:58.534506083 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:58.580712080 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:58.769474983 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:58.818947077 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:58.891860008 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:58.892206907 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:59.011938095 CET | 80 | 49782 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:59.011972904 CET | 80 | 49776 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:59.012012005 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:59.012048960 CET | 49776 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:59.012243986 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:59.131910086 CET | 80 | 49782 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:53:59.362354994 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:53:59.482264042 CET | 80 | 49782 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.222517967 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.222803116 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.249665022 CET | 80 | 49782 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.250966072 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.342298985 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.342525005 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.342576027 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.342746973 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.343225956 CET | 80 | 49782 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.343281031 CET | 49782 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.462991953 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.463067055 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.463274002 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.463320017 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.583136082 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.690269947 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.810075998 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.810098886 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:00.815298080 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:00.935331106 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:01.580931902 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:01.627897024 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:01.700419903 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:01.752685070 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:01.813365936 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:01.862085104 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:01.933358908 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:01.986967087 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.058713913 CET | 49774 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.062325001 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.062391996 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.062736988 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.182332993 CET | 80 | 49783 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:02.182400942 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:02.182404995 CET | 49783 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.182488918 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.182672024 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.182737112 CET | 80 | 49784 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:02.182795048 CET | 49784 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.304013968 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:02.533929110 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:02.653800964 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:03.423392057 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:03.471482038 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:03.657381058 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:03.721338034 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:03.976929903 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:03.977839947 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:04.097584963 CET | 80 | 49790 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:04.097657919 CET | 49790 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:04.097703934 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:04.097769976 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:04.097999096 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:04.217690945 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:04.456852913 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:04.576601028 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:05.335057974 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:05.377723932 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.573086977 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:05.627616882 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.685853958 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.686168909 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.805866957 CET | 80 | 49802 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:05.805953026 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.806121111 CET | 80 | 49796 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:05.806138039 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.806204081 CET | 49796 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:05.929223061 CET | 80 | 49802 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:06.159145117 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.278987885 CET | 80 | 49802 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:06.816591978 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.816673994 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.936503887 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:06.936578035 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.937311888 CET | 80 | 49802 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:06.937504053 CET | 49802 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.938783884 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:06.939593077 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:07.058481932 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:07.059396982 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:07.059544086 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:07.059884071 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:07.179558039 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:07.284147024 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:07.403945923 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:07.406651020 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:07.408967972 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:07.529856920 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:08.175604105 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:08.221381903 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.298099995 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:08.346390009 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.409806013 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:08.458518982 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.533394098 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:08.580729961 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.928621054 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.929025888 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:08.929150105 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.048721075 CET | 80 | 49803 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:09.048782110 CET | 49803 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.048832893 CET | 80 | 49810 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:09.048906088 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.049104929 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.049263954 CET | 80 | 49804 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:09.049316883 CET | 49804 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.169317007 CET | 80 | 49810 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:09.393372059 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:09.513077974 CET | 80 | 49810 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:10.287276983 CET | 80 | 49810 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:10.330741882 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:10.521159887 CET | 80 | 49810 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:10.565376997 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:10.644793034 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:10.764688969 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:10.765209913 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:10.765209913 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:10.885003090 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:11.112150908 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:11.231983900 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.002557993 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.049494028 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.237816095 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.283864975 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.360265017 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.360296965 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.480114937 CET | 80 | 49822 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.480635881 CET | 80 | 49816 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.480722904 CET | 49816 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.480734110 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.480917931 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.600589991 CET | 80 | 49822 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:12.830893040 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:12.951128006 CET | 80 | 49822 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.425530910 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.425852060 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.543184996 CET | 49810 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.546737909 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.546849966 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.546973944 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.547054052 CET | 80 | 49822 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.547111988 CET | 49822 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.549285889 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.666688919 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.668977022 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.669105053 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.669290066 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:13.788898945 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:13.937997103 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:14.048043966 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:14.057769060 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:14.057837963 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:14.168317080 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:14.785610914 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:14.830746889 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:14.907636881 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:14.955756903 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.021601915 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.065104961 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.141366959 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.190126896 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.266954899 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.267471075 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.267956018 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.387212992 CET | 80 | 49823 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.387331963 CET | 49823 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.387686014 CET | 80 | 49824 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.387722015 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.387739897 CET | 49824 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.387804031 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.388012886 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.507657051 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:15.737174988 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:15.856930971 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:16.625627995 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:16.674504995 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:16.861372948 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:16.908973932 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.033740997 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.034343004 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.153973103 CET | 80 | 49830 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:17.154081106 CET | 49830 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.154088974 CET | 80 | 49835 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:17.154169083 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.154334068 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.273978949 CET | 80 | 49835 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:17.502710104 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:17.622493982 CET | 80 | 49835 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:18.393225908 CET | 80 | 49835 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:18.440114021 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:18.629383087 CET | 80 | 49835 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:18.674495935 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:18.754827023 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:18.874644995 CET | 80 | 49841 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:18.875077009 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:18.875300884 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:18.996150970 CET | 80 | 49841 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:19.221476078 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:19.341434956 CET | 80 | 49841 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.035079956 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.035214901 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.113811970 CET | 80 | 49841 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.113867998 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.154841900 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.154917002 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.155073881 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.155261993 CET | 80 | 49841 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.155308962 CET | 49841 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.156754971 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.274751902 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.276416063 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.276479006 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.276611090 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.396317959 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.502754927 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.622591019 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.622613907 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:20.627729893 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:20.748953104 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:21.393438101 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:21.440124035 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.515396118 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:21.565130949 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.629386902 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:21.674506903 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.749331951 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:21.799509048 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.879806042 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.879884958 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.880692959 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:21.999988079 CET | 80 | 49842 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:22.000046015 CET | 49842 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:22.000463009 CET | 80 | 49844 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:22.000505924 CET | 49844 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:22.000560045 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:22.000633955 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:22.000765085 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:22.121051073 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:22.346514940 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:22.466310024 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:23.239417076 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:23.283884048 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.473486900 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:23.518254042 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.625763893 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.626118898 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.643695116 CET | 49835 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.746633053 CET | 80 | 49855 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:23.746700048 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.746805906 CET | 80 | 49849 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:23.746857882 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.746859074 CET | 49849 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:23.866554022 CET | 80 | 49855 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:24.096457005 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:24.216681957 CET | 80 | 49855 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:24.985985994 CET | 80 | 49855 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:25.033895969 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.221291065 CET | 80 | 49855 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:25.268265963 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.342168093 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.462220907 CET | 80 | 49861 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:25.462359905 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.462532997 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.582459927 CET | 80 | 49861 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:25.815372944 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:25.937113047 CET | 80 | 49861 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.644435883 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.644650936 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.700790882 CET | 80 | 49861 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.700845003 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.764204979 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.764256001 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.764516115 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.764786959 CET | 80 | 49861 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.764831066 CET | 49861 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.783737898 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.884690046 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.903412104 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:26.903472900 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:26.903601885 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:27.023570061 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:27.112154961 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:27.231942892 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:27.231983900 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:27.252861023 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:27.372713089 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.002809048 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.049544096 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.141382933 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.190136909 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.237238884 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.283912897 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.373301029 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.424551964 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.542870998 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.542944908 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.543247938 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.662976027 CET | 80 | 49863 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.662992001 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.663038015 CET | 49863 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.663081884 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.663238049 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.663353920 CET | 80 | 49867 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:28.663414955 CET | 49867 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:28.782953978 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:29.018651962 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:29.138639927 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:29.900537014 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:29.955787897 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.133487940 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:30.174526930 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.247690916 CET | 49855 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.247782946 CET | 49754 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.247864008 CET | 49758 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.252315044 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.252707958 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.373420954 CET | 80 | 49869 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:30.373492002 CET | 49869 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.373557091 CET | 80 | 49875 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:30.373629093 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.373761892 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.493458986 CET | 80 | 49875 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:30.721587896 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:30.841356993 CET | 80 | 49875 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:31.612174034 CET | 80 | 49875 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:31.658937931 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:31.845249891 CET | 80 | 49875 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:31.893291950 CET | 49875 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:31.968871117 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:32.088670969 CET | 80 | 49881 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:32.089644909 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:32.089801073 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:32.209647894 CET | 80 | 49881 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:32.440354109 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:32.560295105 CET | 80 | 49881 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.264539957 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.327086926 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.327554941 CET | 80 | 49881 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.327606916 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.384382010 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.386863947 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.389946938 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.447200060 CET | 80 | 49881 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.447248936 CET | 49881 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.509627104 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.564383984 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.684158087 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.684235096 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.684422970 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.737289906 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:33.804322004 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.857237101 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:33.857256889 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:34.034198046 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:34.154093981 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:34.626430988 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:34.674542904 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:34.861550093 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:34.908914089 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:34.934099913 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:34.987287998 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.169424057 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:35.221416950 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.296947002 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.296947002 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.297266006 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.416986942 CET | 80 | 49890 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:35.417385101 CET | 80 | 49885 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:35.417637110 CET | 49885 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.417653084 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.417795897 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.418483973 CET | 80 | 49887 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:35.418556929 CET | 49887 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.537471056 CET | 80 | 49890 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:35.810736895 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:35.930720091 CET | 80 | 49890 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:36.661237955 CET | 80 | 49890 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:36.705791950 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:36.893187046 CET | 80 | 49890 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:36.940172911 CET | 49890 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:37.016288042 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:37.136054039 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:37.136122942 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:37.136306047 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:37.256185055 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:37.487129927 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:37.606946945 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:38.377856970 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:38.424552917 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.613437891 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:38.658910036 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.734179020 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.734474897 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.854379892 CET | 80 | 49895 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:38.854393005 CET | 80 | 49901 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:38.854439020 CET | 49895 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.854494095 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.854660034 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:38.974884033 CET | 80 | 49901 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:39.206872940 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.326673985 CET | 80 | 49901 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:39.878719091 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.878743887 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.998595953 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.998631954 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:39.998816013 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.998816967 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:39.998827934 CET | 80 | 49901 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:39.998924971 CET | 49901 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:40.118397951 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:40.118561029 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:40.118938923 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:40.122859955 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:40.242625952 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:40.346879959 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:40.466850996 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:40.466936111 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:40.476926088 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:40.596898079 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.236069918 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.283915997 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.356594086 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.408940077 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.469062090 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.518285990 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.588990927 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.643316031 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.708440065 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.708466053 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.708894968 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.828720093 CET | 80 | 49909 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.828790903 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.829008102 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.831865072 CET | 80 | 49906 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.831904888 CET | 80 | 49907 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:41.831921101 CET | 49906 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.831945896 CET | 49907 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:41.948712111 CET | 80 | 49909 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:42.174653053 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:42.294801950 CET | 80 | 49909 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:43.067507982 CET | 80 | 49909 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:43.109121084 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:43.301377058 CET | 80 | 49909 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:43.346432924 CET | 49909 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:43.425920010 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:43.545669079 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:43.545769930 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:43.545988083 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:43.665745020 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:43.929065943 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:44.048831940 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:44.791619062 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:44.846426010 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.051865101 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:45.096436977 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.173661947 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.173868895 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.293642044 CET | 80 | 49921 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:45.293709993 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.293869019 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.293927908 CET | 80 | 49915 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:45.293970108 CET | 49915 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.413681030 CET | 80 | 49921 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:45.643388033 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:45.834358931 CET | 80 | 49921 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:46.475893974 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.476365089 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.531136036 CET | 80 | 49921 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:46.534207106 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.595797062 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:46.595881939 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.596348047 CET | 80 | 49921 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:46.596430063 CET | 49921 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.743530989 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:46.863260984 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.098803997 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.219338894 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.219352007 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.308856964 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.428689957 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.428767920 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.428898096 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.548547029 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.784110069 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.836030960 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:47.877685070 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:47.904010057 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:48.068979979 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:48.115262032 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:48.669554949 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:48.724849939 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:48.905261040 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:48.955797911 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.034586906 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.034656048 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.034909010 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.154620886 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:49.154690027 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.154870987 CET | 80 | 49926 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:49.154923916 CET | 49926 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.155143023 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.155296087 CET | 80 | 49928 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:49.155343056 CET | 49928 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.274992943 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:49.523631096 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:49.643599987 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:50.396166086 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:50.440176010 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.629112005 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:50.629447937 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.749583960 CET | 80 | 49934 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:50.749650955 CET | 49934 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.751874924 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.871639013 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:50.871763945 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.871925116 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:50.991636038 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:51.221606016 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:51.341970921 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:52.109564066 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:52.174552917 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.345233917 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:52.396374941 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.590723038 CET | 49942 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.590724945 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.710592031 CET | 80 | 49942 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:52.710942984 CET | 80 | 49939 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:52.712915897 CET | 49939 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.716839075 CET | 49942 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.741838932 CET | 49942 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:52.861553907 CET | 80 | 49942 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.081927061 CET | 49942 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.082511902 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.202554941 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.202641964 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.219307899 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.245168924 CET | 80 | 49942 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.247526884 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.339032888 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.367212057 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.367279053 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.367682934 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.487507105 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.565650940 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.684061050 CET | 80 | 49942 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.684118986 CET | 49942 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.685431957 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.685529947 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:53.721549988 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:53.841303110 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:54.440152884 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:54.565224886 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:54.605053902 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:54.673150063 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:54.752716064 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:54.837070942 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:54.841217041 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:54.969918966 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:54.970304012 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:54.970767975 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.090090990 CET | 80 | 49946 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:55.090167046 CET | 49946 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.090461016 CET | 80 | 49947 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:55.090487957 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:55.090513945 CET | 49947 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.090569019 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.090745926 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.210592031 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:55.576205969 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:55.696055889 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:56.332887888 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:56.564897060 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:56.565013885 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.688020945 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.688024044 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.808011055 CET | 80 | 49955 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:56.808253050 CET | 80 | 49951 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:56.808288097 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.808407068 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.808459997 CET | 49951 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:56.928522110 CET | 80 | 49955 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:57.159410954 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:57.279233932 CET | 80 | 49955 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:58.047489882 CET | 80 | 49955 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:58.159185886 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:58.281289101 CET | 80 | 49955 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:58.362087965 CET | 49955 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.054778099 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.175225019 CET | 80 | 49961 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.175306082 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.176068068 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.295774937 CET | 80 | 49961 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.534157038 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.655206919 CET | 80 | 49961 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.691337109 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.691386938 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.811213970 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.811290979 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.811508894 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.819211006 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.857191086 CET | 80 | 49961 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.931225061 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.939230919 CET | 80 | 49967 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:54:59.939307928 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:54:59.939574003 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:00.059801102 CET | 80 | 49967 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:00.152484894 CET | 80 | 49961 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:00.152616978 CET | 49961 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:00.160885096 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:00.280970097 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:00.280982971 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:00.284395933 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:00.404241085 CET | 80 | 49967 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:01.052923918 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:01.177547932 CET | 80 | 49967 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:01.179377079 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:01.285175085 CET | 80 | 49966 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:01.330825090 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:01.413055897 CET | 80 | 49967 | 193.3.168.50 | 192.168.2.4 |
Dec 5, 2024 10:55:01.443478107 CET | 49966 | 80 | 192.168.2.4 | 193.3.168.50 |
Dec 5, 2024 10:55:01.643321991 CET | 49967 | 80 | 192.168.2.4 | 193.3.168.50 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49734 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:16.710395098 CET | 440 | OUT | |
Dec 5, 2024 10:53:17.066200972 CET | 344 | OUT | |
Dec 5, 2024 10:53:17.935105085 CET | 25 | IN | |
Dec 5, 2024 10:53:17.949781895 CET | 1236 | IN | |
Dec 5, 2024 10:53:17.949829102 CET | 350 | IN | |
Dec 5, 2024 10:53:17.981781960 CET | 416 | OUT | |
Dec 5, 2024 10:53:18.336882114 CET | 384 | OUT | |
Dec 5, 2024 10:53:18.384511948 CET | 25 | IN | |
Dec 5, 2024 10:53:18.734464884 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49740 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:20.104814053 CET | 417 | OUT | |
Dec 5, 2024 10:53:20.460542917 CET | 1060 | OUT | |
Dec 5, 2024 10:53:21.336755037 CET | 25 | IN | |
Dec 5, 2024 10:53:21.569391966 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49741 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:20.595257044 CET | 441 | OUT | |
Dec 5, 2024 10:53:20.940305948 CET | 1936 | OUT | |
Dec 5, 2024 10:53:21.829662085 CET | 25 | IN | |
Dec 5, 2024 10:53:22.061327934 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49744 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:22.006339073 CET | 417 | OUT | |
Dec 5, 2024 10:53:22.378456116 CET | 1060 | OUT | |
Dec 5, 2024 10:53:23.233376026 CET | 25 | IN | |
Dec 5, 2024 10:53:23.465343952 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49745 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:23.734152079 CET | 441 | OUT | |
Dec 5, 2024 10:53:24.080730915 CET | 1060 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49746 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:24.289794922 CET | 487 | OUT | |
Dec 5, 2024 10:53:24.649388075 CET | 12360 | OUT | |
Dec 5, 2024 10:53:24.769570112 CET | 7416 | OUT | |
Dec 5, 2024 10:53:24.769634962 CET | 2472 | OUT | |
Dec 5, 2024 10:53:24.769876957 CET | 4944 | OUT | |
Dec 5, 2024 10:53:24.769970894 CET | 4944 | OUT | |
Dec 5, 2024 10:53:24.770133018 CET | 4944 | OUT | |
Dec 5, 2024 10:53:24.889765024 CET | 2472 | OUT | |
Dec 5, 2024 10:53:24.889789104 CET | 2472 | OUT | |
Dec 5, 2024 10:53:24.889816999 CET | 4944 | OUT | |
Dec 5, 2024 10:53:24.889844894 CET | 2472 | OUT | |
Dec 5, 2024 10:53:25.508181095 CET | 25 | IN | |
Dec 5, 2024 10:53:26.074276924 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49748 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:25.261147976 CET | 441 | OUT | |
Dec 5, 2024 10:53:25.611988068 CET | 1060 | OUT | |
Dec 5, 2024 10:53:26.499133110 CET | 25 | IN | |
Dec 5, 2024 10:53:26.733485937 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49750 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:26.981178999 CET | 417 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49751 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:27.201997995 CET | 441 | OUT | |
Dec 5, 2024 10:53:27.549489975 CET | 1936 | OUT | |
Dec 5, 2024 10:53:28.439523935 CET | 25 | IN | |
Dec 5, 2024 10:53:28.677506924 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49752 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:27.322307110 CET | 441 | OUT | |
Dec 5, 2024 10:53:27.674469948 CET | 1060 | OUT | |
Dec 5, 2024 10:53:28.562184095 CET | 25 | IN | |
Dec 5, 2024 10:53:28.797455072 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49753 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:29.043292046 CET | 417 | OUT | |
Dec 5, 2024 10:53:29.393503904 CET | 1060 | OUT | |
Dec 5, 2024 10:53:30.282882929 CET | 25 | IN | |
Dec 5, 2024 10:53:30.517685890 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49754 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:30.762357950 CET | 417 | OUT | |
Dec 5, 2024 10:53:31.112122059 CET | 1060 | OUT | |
Dec 5, 2024 10:53:32.009406090 CET | 25 | IN | |
Dec 5, 2024 10:53:32.245738029 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49755 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:32.480103970 CET | 441 | OUT | |
Dec 5, 2024 10:53:32.830878973 CET | 1060 | OUT | |
Dec 5, 2024 10:53:33.718775988 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49756 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:33.812182903 CET | 441 | OUT | |
Dec 5, 2024 10:53:34.159106016 CET | 1936 | OUT | |
Dec 5, 2024 10:53:35.050003052 CET | 25 | IN | |
Dec 5, 2024 10:53:35.285732031 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49757 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:33.932337999 CET | 441 | OUT | |
Dec 5, 2024 10:53:34.283932924 CET | 1060 | OUT | |
Dec 5, 2024 10:53:35.170809984 CET | 25 | IN | |
Dec 5, 2024 10:53:35.405895948 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49758 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:35.652005911 CET | 417 | OUT | |
Dec 5, 2024 10:53:36.002718925 CET | 1060 | OUT | |
Dec 5, 2024 10:53:36.889818907 CET | 25 | IN | |
Dec 5, 2024 10:53:37.125454903 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49759 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:37.370738983 CET | 441 | OUT | |
Dec 5, 2024 10:53:37.750035048 CET | 1056 | OUT | |
Dec 5, 2024 10:53:38.607925892 CET | 25 | IN | |
Dec 5, 2024 10:53:38.841646910 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49760 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:39.088969946 CET | 441 | OUT | |
Dec 5, 2024 10:53:39.440166950 CET | 1056 | OUT | |
Dec 5, 2024 10:53:40.327800989 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49761 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:40.566241026 CET | 441 | OUT | |
Dec 5, 2024 10:53:40.952542067 CET | 1936 | OUT | |
Dec 5, 2024 10:53:41.755453110 CET | 25 | IN | |
Dec 5, 2024 10:53:41.993649960 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49762 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:41.147509098 CET | 441 | OUT | |
Dec 5, 2024 10:53:41.502707005 CET | 1060 | OUT | |
Dec 5, 2024 10:53:42.385531902 CET | 25 | IN | |
Dec 5, 2024 10:53:42.617727041 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49763 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:42.855597973 CET | 417 | OUT | |
Dec 5, 2024 10:53:43.205878973 CET | 1056 | OUT | |
Dec 5, 2024 10:53:44.100519896 CET | 25 | IN | |
Dec 5, 2024 10:53:44.337546110 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49764 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:44.580044985 CET | 441 | OUT | |
Dec 5, 2024 10:53:44.924592018 CET | 1060 | OUT | |
Dec 5, 2024 10:53:45.814090014 CET | 25 | IN | |
Dec 5, 2024 10:53:46.049483061 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49765 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:46.295015097 CET | 441 | OUT | |
Dec 5, 2024 10:53:46.643309116 CET | 1060 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49766 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:47.124984980 CET | 441 | OUT | |
Dec 5, 2024 10:53:47.471735954 CET | 1936 | OUT | |
Dec 5, 2024 10:53:48.371664047 CET | 25 | IN | |
Dec 5, 2024 10:53:48.605647087 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49767 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:47.246284008 CET | 441 | OUT | |
Dec 5, 2024 10:53:47.596373081 CET | 1056 | OUT | |
Dec 5, 2024 10:53:48.483824968 CET | 25 | IN | |
Dec 5, 2024 10:53:48.717506886 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49768 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:48.965683937 CET | 417 | OUT | |
Dec 5, 2024 10:53:49.315287113 CET | 1060 | OUT | |
Dec 5, 2024 10:53:50.204859972 CET | 25 | IN | |
Dec 5, 2024 10:53:50.437592983 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49769 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:50.686804056 CET | 441 | OUT | |
Dec 5, 2024 10:53:51.033956051 CET | 1060 | OUT | |
Dec 5, 2024 10:53:51.924709082 CET | 25 | IN | |
Dec 5, 2024 10:53:52.157598019 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49770 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:52.403414965 CET | 441 | OUT | |
Dec 5, 2024 10:53:52.752778053 CET | 1060 | OUT | |
Dec 5, 2024 10:53:53.640650034 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49771 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:53.733421087 CET | 441 | OUT | |
Dec 5, 2024 10:53:54.080806971 CET | 1924 | OUT | |
Dec 5, 2024 10:53:54.971354961 CET | 25 | IN | |
Dec 5, 2024 10:53:55.205805063 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49772 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:53.854407072 CET | 441 | OUT | |
Dec 5, 2024 10:53:54.227942944 CET | 1060 | OUT | |
Dec 5, 2024 10:53:55.099199057 CET | 25 | IN | |
Dec 5, 2024 10:53:55.337575912 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49774 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:55.577171087 CET | 417 | OUT | |
Dec 5, 2024 10:53:55.924618959 CET | 1060 | OUT | |
Dec 5, 2024 10:53:56.814743996 CET | 25 | IN | |
Dec 5, 2024 10:53:57.049464941 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49776 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:57.295377970 CET | 441 | OUT | |
Dec 5, 2024 10:53:57.643596888 CET | 1060 | OUT | |
Dec 5, 2024 10:53:58.534506083 CET | 25 | IN | |
Dec 5, 2024 10:53:58.769474983 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49782 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:53:59.012243986 CET | 441 | OUT | |
Dec 5, 2024 10:53:59.362354994 CET | 1060 | OUT | |
Dec 5, 2024 10:54:00.249665022 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49783 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:00.342746973 CET | 441 | OUT | |
Dec 5, 2024 10:54:00.690269947 CET | 1936 | OUT | |
Dec 5, 2024 10:54:01.580931902 CET | 25 | IN | |
Dec 5, 2024 10:54:01.813365936 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49784 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:00.463274002 CET | 441 | OUT | |
Dec 5, 2024 10:54:00.815298080 CET | 1060 | OUT | |
Dec 5, 2024 10:54:01.700419903 CET | 25 | IN | |
Dec 5, 2024 10:54:01.933358908 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49790 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:02.182672024 CET | 417 | OUT | |
Dec 5, 2024 10:54:02.533929110 CET | 1060 | OUT | |
Dec 5, 2024 10:54:03.423392057 CET | 25 | IN | |
Dec 5, 2024 10:54:03.657381058 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49796 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:04.097999096 CET | 417 | OUT | |
Dec 5, 2024 10:54:04.456852913 CET | 1060 | OUT | |
Dec 5, 2024 10:54:05.335057974 CET | 25 | IN | |
Dec 5, 2024 10:54:05.573086977 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49802 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:05.806138039 CET | 417 | OUT | |
Dec 5, 2024 10:54:06.159145117 CET | 1060 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49803 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:06.938783884 CET | 441 | OUT | |
Dec 5, 2024 10:54:07.284147024 CET | 1936 | OUT | |
Dec 5, 2024 10:54:08.175604105 CET | 25 | IN | |
Dec 5, 2024 10:54:08.409806013 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49804 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:07.059884071 CET | 441 | OUT | |
Dec 5, 2024 10:54:07.408967972 CET | 1060 | OUT | |
Dec 5, 2024 10:54:08.298099995 CET | 25 | IN | |
Dec 5, 2024 10:54:08.533394098 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49810 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:09.049104929 CET | 417 | OUT | |
Dec 5, 2024 10:54:09.393372059 CET | 1060 | OUT | |
Dec 5, 2024 10:54:10.287276983 CET | 25 | IN | |
Dec 5, 2024 10:54:10.521159887 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49816 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:10.765209913 CET | 441 | OUT | |
Dec 5, 2024 10:54:11.112150908 CET | 1060 | OUT | |
Dec 5, 2024 10:54:12.002557993 CET | 25 | IN | |
Dec 5, 2024 10:54:12.237816095 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49822 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:12.480917931 CET | 441 | OUT | |
Dec 5, 2024 10:54:12.830893040 CET | 1060 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49823 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:13.546973944 CET | 441 | OUT | |
Dec 5, 2024 10:54:13.937997103 CET | 1908 | OUT | |
Dec 5, 2024 10:54:14.785610914 CET | 25 | IN | |
Dec 5, 2024 10:54:15.021601915 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49824 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:13.669290066 CET | 441 | OUT | |
Dec 5, 2024 10:54:14.048043966 CET | 1060 | OUT | |
Dec 5, 2024 10:54:14.907636881 CET | 25 | IN | |
Dec 5, 2024 10:54:15.141366959 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49830 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:15.388012886 CET | 417 | OUT | |
Dec 5, 2024 10:54:15.737174988 CET | 1060 | OUT | |
Dec 5, 2024 10:54:16.625627995 CET | 25 | IN | |
Dec 5, 2024 10:54:16.861372948 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49835 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:17.154334068 CET | 417 | OUT | |
Dec 5, 2024 10:54:17.502710104 CET | 1060 | OUT | |
Dec 5, 2024 10:54:18.393225908 CET | 25 | IN | |
Dec 5, 2024 10:54:18.629383087 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 49841 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:18.875300884 CET | 441 | OUT | |
Dec 5, 2024 10:54:19.221476078 CET | 1060 | OUT | |
Dec 5, 2024 10:54:20.113811970 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 49842 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:20.155073881 CET | 441 | OUT | |
Dec 5, 2024 10:54:20.502754927 CET | 1936 | OUT | |
Dec 5, 2024 10:54:21.393438101 CET | 25 | IN | |
Dec 5, 2024 10:54:21.629386902 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 49844 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:20.276611090 CET | 441 | OUT | |
Dec 5, 2024 10:54:20.627729893 CET | 1060 | OUT | |
Dec 5, 2024 10:54:21.515396118 CET | 25 | IN | |
Dec 5, 2024 10:54:21.749331951 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 49849 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:22.000765085 CET | 417 | OUT | |
Dec 5, 2024 10:54:22.346514940 CET | 1060 | OUT | |
Dec 5, 2024 10:54:23.239417076 CET | 25 | IN | |
Dec 5, 2024 10:54:23.473486900 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 49855 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:23.746857882 CET | 417 | OUT | |
Dec 5, 2024 10:54:24.096457005 CET | 1056 | OUT | |
Dec 5, 2024 10:54:24.985985994 CET | 25 | IN | |
Dec 5, 2024 10:54:25.221291065 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 49861 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:25.462532997 CET | 441 | OUT | |
Dec 5, 2024 10:54:25.815372944 CET | 1060 | OUT | |
Dec 5, 2024 10:54:26.700790882 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 49863 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:26.764516115 CET | 441 | OUT | |
Dec 5, 2024 10:54:27.112154961 CET | 1936 | OUT | |
Dec 5, 2024 10:54:28.002809048 CET | 25 | IN | |
Dec 5, 2024 10:54:28.237238884 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 49867 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:26.903601885 CET | 441 | OUT | |
Dec 5, 2024 10:54:27.252861023 CET | 1056 | OUT | |
Dec 5, 2024 10:54:28.141382933 CET | 25 | IN | |
Dec 5, 2024 10:54:28.373301029 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 49869 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:28.663238049 CET | 417 | OUT | |
Dec 5, 2024 10:54:29.018651962 CET | 1060 | OUT | |
Dec 5, 2024 10:54:29.900537014 CET | 25 | IN | |
Dec 5, 2024 10:54:30.133487940 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 49875 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:30.373761892 CET | 417 | OUT | |
Dec 5, 2024 10:54:30.721587896 CET | 1060 | OUT | |
Dec 5, 2024 10:54:31.612174034 CET | 25 | IN | |
Dec 5, 2024 10:54:31.845249891 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.4 | 49881 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:32.089801073 CET | 441 | OUT | |
Dec 5, 2024 10:54:32.440354109 CET | 1060 | OUT | |
Dec 5, 2024 10:54:33.327554941 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.4 | 49885 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:33.389946938 CET | 441 | OUT | |
Dec 5, 2024 10:54:33.737289906 CET | 1936 | OUT | |
Dec 5, 2024 10:54:34.626430988 CET | 25 | IN | |
Dec 5, 2024 10:54:34.861550093 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.4 | 49887 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:33.684422970 CET | 441 | OUT | |
Dec 5, 2024 10:54:34.034198046 CET | 1060 | OUT | |
Dec 5, 2024 10:54:34.934099913 CET | 25 | IN | |
Dec 5, 2024 10:54:35.169424057 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.4 | 49890 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:35.417795897 CET | 417 | OUT | |
Dec 5, 2024 10:54:35.810736895 CET | 1060 | OUT | |
Dec 5, 2024 10:54:36.661237955 CET | 25 | IN | |
Dec 5, 2024 10:54:36.893187046 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.4 | 49895 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:37.136306047 CET | 441 | OUT | |
Dec 5, 2024 10:54:37.487129927 CET | 1056 | OUT | |
Dec 5, 2024 10:54:38.377856970 CET | 25 | IN | |
Dec 5, 2024 10:54:38.613437891 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.4 | 49901 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:38.854660034 CET | 441 | OUT | |
Dec 5, 2024 10:54:39.206872940 CET | 1056 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.4 | 49906 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:39.998816967 CET | 441 | OUT | |
Dec 5, 2024 10:54:40.346879959 CET | 1936 | OUT | |
Dec 5, 2024 10:54:41.236069918 CET | 25 | IN | |
Dec 5, 2024 10:54:41.469062090 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.4 | 49907 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:40.122859955 CET | 441 | OUT | |
Dec 5, 2024 10:54:40.476926088 CET | 1060 | OUT | |
Dec 5, 2024 10:54:41.356594086 CET | 25 | IN | |
Dec 5, 2024 10:54:41.588990927 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.4 | 49909 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:41.829008102 CET | 417 | OUT | |
Dec 5, 2024 10:54:42.174653053 CET | 1060 | OUT | |
Dec 5, 2024 10:54:43.067507982 CET | 25 | IN | |
Dec 5, 2024 10:54:43.301377058 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.4 | 49915 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:43.545988083 CET | 441 | OUT | |
Dec 5, 2024 10:54:43.929065943 CET | 1060 | OUT | |
Dec 5, 2024 10:54:44.791619062 CET | 25 | IN | |
Dec 5, 2024 10:54:45.051865101 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.4 | 49921 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:45.293869019 CET | 441 | OUT | |
Dec 5, 2024 10:54:45.643388033 CET | 1060 | OUT | |
Dec 5, 2024 10:54:46.531136036 CET | 25 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.4 | 49926 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:46.743530989 CET | 441 | OUT | |
Dec 5, 2024 10:54:47.098803997 CET | 1936 | OUT | |
Dec 5, 2024 10:54:47.836030960 CET | 25 | IN | |
Dec 5, 2024 10:54:48.068979979 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.4 | 49928 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:47.428898096 CET | 441 | OUT | |
Dec 5, 2024 10:54:47.784110069 CET | 1060 | OUT | |
Dec 5, 2024 10:54:48.669554949 CET | 25 | IN | |
Dec 5, 2024 10:54:48.905261040 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
70 | 192.168.2.4 | 49934 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:49.155143023 CET | 417 | OUT | |
Dec 5, 2024 10:54:49.523631096 CET | 1060 | OUT | |
Dec 5, 2024 10:54:50.396166086 CET | 25 | IN | |
Dec 5, 2024 10:54:50.629112005 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
71 | 192.168.2.4 | 49939 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:50.871925116 CET | 441 | OUT | |
Dec 5, 2024 10:54:51.221606016 CET | 1060 | OUT | |
Dec 5, 2024 10:54:52.109564066 CET | 25 | IN | |
Dec 5, 2024 10:54:52.345233917 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
72 | 192.168.2.4 | 49942 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:52.741838932 CET | 441 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
73 | 192.168.2.4 | 49946 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:53.219307899 CET | 441 | OUT | |
Dec 5, 2024 10:54:53.565650940 CET | 1936 | OUT | |
Dec 5, 2024 10:54:54.440152884 CET | 25 | IN | |
Dec 5, 2024 10:54:54.673150063 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
74 | 192.168.2.4 | 49947 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:53.367682934 CET | 441 | OUT | |
Dec 5, 2024 10:54:53.721549988 CET | 1056 | OUT | |
Dec 5, 2024 10:54:54.605053902 CET | 25 | IN | |
Dec 5, 2024 10:54:54.837070942 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
75 | 192.168.2.4 | 49951 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:55.090745926 CET | 417 | OUT | |
Dec 5, 2024 10:54:55.576205969 CET | 1060 | OUT | |
Dec 5, 2024 10:54:56.332887888 CET | 25 | IN | |
Dec 5, 2024 10:54:56.564897060 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
76 | 192.168.2.4 | 49955 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:56.808407068 CET | 417 | OUT | |
Dec 5, 2024 10:54:57.159410954 CET | 1060 | OUT | |
Dec 5, 2024 10:54:58.047489882 CET | 25 | IN | |
Dec 5, 2024 10:54:58.281289101 CET | 200 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
77 | 192.168.2.4 | 49961 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:59.176068068 CET | 441 | OUT | |
Dec 5, 2024 10:54:59.534157038 CET | 1060 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
78 | 192.168.2.4 | 49966 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:59.811508894 CET | 441 | OUT | |
Dec 5, 2024 10:55:00.160885096 CET | 1936 | OUT | |
Dec 5, 2024 10:55:01.052923918 CET | 25 | IN | |
Dec 5, 2024 10:55:01.285175085 CET | 349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
79 | 192.168.2.4 | 49967 | 193.3.168.50 | 80 | 7244 | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 5, 2024 10:54:59.939574003 CET | 441 | OUT | |
Dec 5, 2024 10:55:00.284395933 CET | 1056 | OUT | |
Dec 5, 2024 10:55:01.177547932 CET | 25 | IN | |
Dec 5, 2024 10:55:01.413055897 CET | 200 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:52:53 |
Start date: | 05/12/2024 |
Path: | C:\Users\user\Desktop\file.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe30000 |
File size: | 2'331'371 bytes |
MD5 hash: | C9059DFB76AD9E011D4E11608CCC98CC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 04:52:54 |
Start date: | 05/12/2024 |
Path: | C:\Windows\SysWOW64\wscript.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xdf0000 |
File size: | 147'456 bytes |
MD5 hash: | FF00E0480075B095948000BDC66E81F0 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 04:53:05 |
Start date: | 05/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 04:53:05 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 04:53:05 |
Start date: | 05/12/2024 |
Path: | C:\MsContainer\chainportruntimeCrtMonitor.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x570000 |
File size: | 2'009'600 bytes |
MD5 hash: | 38514F88AFF517EA6BE4724D24B28FE2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 04:53:08 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x800000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 04:53:08 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 04:53:08 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff633620000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 04:53:08 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 04:53:08 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\chcp.com |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6911d0000 |
File size: | 14'848 bytes |
MD5 hash: | 33395C4732A49065EA72590B14B64F32 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 04:53:09 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\PING.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70a9a0000 |
File size: | 22'528 bytes |
MD5 hash: | 2F46799D79D22AC72C241EC0322B011D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 04:53:09 |
Start date: | 05/12/2024 |
Path: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf80000 |
File size: | 2'009'600 bytes |
MD5 hash: | 38514F88AFF517EA6BE4724D24B28FE2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Has exited: | false |
Target ID: | 15 |
Start time: | 04:53:10 |
Start date: | 05/12/2024 |
Path: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x960000 |
File size: | 2'009'600 bytes |
MD5 hash: | 38514F88AFF517EA6BE4724D24B28FE2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 04:53:11 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\wbem\WmiPrvSE.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff693ab0000 |
File size: | 496'640 bytes |
MD5 hash: | 60FF40CFD7FB8FE41EE4FE9AE5FE1C51 |
Has elevated privileges: | true |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 04:53:17 |
Start date: | 05/12/2024 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 19 |
Start time: | 04:53:18 |
Start date: | 05/12/2024 |
Path: | C:\Users\user\AppData\Local\Temp\kahKUDRlEYHfKIalWlM.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x3e0000 |
File size: | 2'009'600 bytes |
MD5 hash: | 38514F88AFF517EA6BE4724D24B28FE2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 9.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 9.2% |
Total number of Nodes: | 1510 |
Total number of Limit Nodes: | 44 |
Graph
Function 00E4DF1E Relevance: 42.2, APIs: 17, Strings: 7, Instructions: 195filesleeptimeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4A6C2 Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 100memorywindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A69B Relevance: 7.6, APIs: 5, Instructions: 105fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3848E Relevance: 2.5, APIs: 1, Instructions: 960COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4B7E0 Relevance: 109.2, APIs: 48, Strings: 14, Instructions: 731windowfilesleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E40863 Relevance: 98.3, APIs: 23, Strings: 33, Instructions: 316libraryfileloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4C73F Relevance: 51.2, APIs: 23, Strings: 6, Instructions: 428windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4D4D4 Relevance: 21.1, APIs: 11, Strings: 1, Instructions: 97windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E53B72 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 63COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4B568 Relevance: 7.5, APIs: 5, Instructions: 38windowCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39785 Relevance: 6.1, APIs: 4, Instructions: 56fileCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5AD34 Relevance: 6.1, APIs: 4, Instructions: 52libraryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39F7A Relevance: 4.6, APIs: 3, Instructions: 111fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A2B2 Relevance: 4.6, APIs: 3, Instructions: 55COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5AF6C Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 47COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5ADAF Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 30memoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5BBF0 Relevance: 3.2, APIs: 2, Instructions: 168COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39A74 Relevance: 3.1, APIs: 2, Instructions: 116COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E31E50 Relevance: 3.1, APIs: 2, Instructions: 86COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39DA2 Relevance: 3.1, APIs: 2, Instructions: 83timeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3966E Relevance: 3.1, APIs: 2, Instructions: 82fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39E80 Relevance: 3.1, APIs: 2, Instructions: 56COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E58E54 Relevance: 3.0, APIs: 2, Instructions: 44memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4109E Relevance: 3.0, APIs: 2, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A4ED Relevance: 3.0, APIs: 2, Instructions: 29COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A1E0 Relevance: 3.0, APIs: 2, Instructions: 27fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4AC7C Relevance: 3.0, APIs: 2, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A243 Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4DEC2 Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4081B Relevance: 3.0, APIs: 2, Instructions: 24libraryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4A3B9 Relevance: 3.0, APIs: 2, Instructions: 23windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E52B8C Relevance: 3.0, APIs: 2, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E312F1 Relevance: 3.0, APIs: 2, Instructions: 11COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E31A04 Relevance: 1.8, APIs: 1, Instructions: 312COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E33BBA Relevance: 1.7, APIs: 1, Instructions: 177COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E38284 Relevance: 1.6, APIs: 1, Instructions: 114COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E313E1 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E313DC Relevance: 1.6, APIs: 1, Instructions: 95COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4B093 Relevance: 1.6, APIs: 1, Instructions: 83COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5AC98 Relevance: 1.6, APIs: 1, Instructions: 65libraryloaderCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39215 Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5C479 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5B136 Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E53C0D Relevance: 1.5, APIs: 1, Instructions: 34libraryloaderCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E58E06 Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E35ABD Relevance: 1.5, APIs: 1, Instructions: 31COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3A56D Relevance: 1.5, APIs: 1, Instructions: 27COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E40E08 Relevance: 1.5, APIs: 1, Instructions: 21threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4A626 Relevance: 1.5, APIs: 1, Instructions: 16memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4DD6D Relevance: 1.5, APIs: 1, Instructions: 13windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E398BC Relevance: 1.5, APIs: 1, Instructions: 12COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E44B Relevance: 1.5, APIs: 1, Instructions: 10COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E423 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E419 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E3EF Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E446 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E432 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E43C Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E40A Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E414 Relevance: 1.5, APIs: 1, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39F09 Relevance: 1.5, APIs: 1, Instructions: 7fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4AC04 Relevance: 1.5, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39620 Relevance: 1.3, APIs: 1, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4C220 Relevance: 51.0, APIs: 25, Strings: 4, Instructions: 286timewindowfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E36FAA Relevance: 28.3, APIs: 12, Strings: 4, Instructions: 328fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5D8EE Relevance: 10.1, APIs: 1, Strings: 4, Instructions: 1381COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E6A3 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 49COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4F838 Relevance: 6.1, APIs: 4, Instructions: 73COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4AF0F Relevance: 3.0, APIs: 2, Instructions: 45COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E36C74 Relevance: 3.0, APIs: 2, Instructions: 16windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4F654 Relevance: 1.6, APIs: 1, Instructions: 147COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3B146 Relevance: 1.5, APIs: 1, Instructions: 28COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E340FE Relevance: 1.5, Strings: 1, Instructions: 276COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4F9D5 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5C030 Relevance: 1.3, APIs: 1, Instructions: 5memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E462CA Relevance: .8, Instructions: 829COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E477EF Relevance: .8, Instructions: 817COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3F461 Relevance: .7, Instructions: 694COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E47153 Relevance: .5, Instructions: 536COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3C426 Relevance: .5, Instructions: 454COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E46CDC Relevance: .3, Instructions: 343COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3E9B7 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E44088 Relevance: .3, Instructions: 270COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E443BF Relevance: .2, Instructions: 243COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E551C9 Relevance: .2, Instructions: 237COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E54F9A Relevance: .2, Instructions: 214COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3EFE2 Relevance: .2, Instructions: 161COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E400B7 Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E43E0B Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5CB22 Relevance: 24.6, APIs: 13, Strings: 1, Instructions: 114COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E49711 Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 126memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4D69E Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 79windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E52E31 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 303COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4B5C0 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 98windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E39382 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 135fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E41218 Relevance: 12.1, APIs: 8, Instructions: 125timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5F68D Relevance: 10.7, APIs: 7, Instructions: 152fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4E5EE Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 45libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4146A Relevance: 9.1, APIs: 6, Instructions: 98timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4DC3B Relevance: 9.0, APIs: 6, Instructions: 42windowsynchronizationCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4B6DD Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 58windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E57E73 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E3F2C5 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 20libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5BF30 Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E40EED Relevance: 7.5, APIs: 5, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E41FDD Relevance: 7.5, APIs: 5, Instructions: 39COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E531D6 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 112COMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4A663 Relevance: 6.0, APIs: 4, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E375DE Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 137timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E4101F Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 49threadCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E5BB4E Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 45COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00E40FE4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 19synchronizationCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 2.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 12 |
Total number of Limit Nodes: | 0 |
Graph
Function 00007FFD9B780DA7 Relevance: .3, Instructions: 293COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B93CD6D Relevance: .1, Instructions: 99COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B93E7FD Relevance: 1.6, APIs: 1, Instructions: 139threadinjectionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7808D0 Relevance: .2, Instructions: 181COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780960 Relevance: .1, Instructions: 138COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780908 Relevance: .1, Instructions: 133COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780998 Relevance: .1, Instructions: 113COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78705A Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B784FB8 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C25 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C38 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780B7F Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C40 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C50 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7806AD Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7813E0 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7806D0 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7866D2 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B94340A Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B856605 Relevance: .4, Instructions: 437COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78604D Relevance: .4, Instructions: 395COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B789738 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B66E620 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78A64C Relevance: .1, Instructions: 99COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7833B5 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B85414D Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B854400 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8541D1 Relevance: .0, Instructions: 29COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 5.5% |
Dynamic/Decrypted Code Coverage: | 45.5% |
Signature Coverage: | 18.2% |
Total number of Nodes: | 22 |
Total number of Limit Nodes: | 0 |
Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BD011CE Relevance: 1.8, APIs: 1, Instructions: 308encryptionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BD009FA Relevance: 1.7, APIs: 1, Instructions: 203encryptionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B79CB59 Relevance: .7, Instructions: 667COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780DA7 Relevance: .3, Instructions: 294COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B93E7FD Relevance: 1.6, APIs: 1, Instructions: 139threadinjectionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B79D947 Relevance: .4, Instructions: 404COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCDF0 Relevance: .3, Instructions: 308COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCE38 Relevance: .3, Instructions: 285COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D9AC8 Relevance: .2, Instructions: 197COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCCB8 Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DBAD5 Relevance: .2, Instructions: 174COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DD133 Relevance: .1, Instructions: 149COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCDFD Relevance: .1, Instructions: 149COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DD9E9 Relevance: .1, Instructions: 139COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7988E9 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DD681 Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCF20 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDB09 Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DD5D1 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78705A Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDCD8 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DD93A Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B784FB8 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B798579 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D9359 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DE085 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C25 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DE0C1 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CE210 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDDF9 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7811A2 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DCDB0 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CB101 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D441A Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DA241 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CC8C5 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B797F6D Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C38 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CADF1 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6C8E Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B780C40 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CCE49 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CAD79 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B9739 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7C54B9 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B798711 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CC929 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CC859 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CDE09 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6429 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DB949 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B798C05 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A2A4F Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D59D0 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D58F0 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CCE60 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CD479 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D2E99 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CB388 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D29C9 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CC940 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CDE20 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DB960 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D4489 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7CD490 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D20E2 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D7540 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D2EB0 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B79841D Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B797BFD Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D1C68 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A077C Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DB44F Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B797A55 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DBD70 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D1F1C Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A118A Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D248C Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7866D2 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6C67 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770DA7 Relevance: .3, Instructions: 295COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7708D0 Relevance: .2, Instructions: 181COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770960 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770908 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770998 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B77705A Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B774FB8 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770C25 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7711A2 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770C38 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770B7F Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770C40 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770C50 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7706AD Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7713E0 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7706D0 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7766D2 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790DA7 Relevance: .3, Instructions: 295COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7908D0 Relevance: .2, Instructions: 177COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790960 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790908 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790998 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B79705A Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B794FB8 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790C25 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7911A2 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790C38 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790C40 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790C50 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7906AD Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7913E0 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7906D0 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7966D2 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|