Edit tour
Windows
Analysis Report
fIPSLgT0lO.exe
Overview
General Information
Sample name: | fIPSLgT0lO.exerenamed because original name is a hash value |
Original sample name: | 3c4c48003d8ddf5dc37e44fb340e81951ccb473dbb548e9752b83c69291a54f1.exe |
Analysis ID: | 1573902 |
MD5: | 016d22f02af7424e8d99c6c243adcdb7 |
SHA1: | 1a4148700ab479b4c455a1eb9d5f48ac56799054 |
SHA256: | 3c4c48003d8ddf5dc37e44fb340e81951ccb473dbb548e9752b83c69291a54f1 |
Tags: | 181-131-217-244exeuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Antivirus / Scanner detection for submitted sample
Multi AV Scanner detection for submitted file
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
AI detected suspicious sample
Machine Learning detection for sample
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
- fIPSLgT0lO.exe (PID: 3020 cmdline:
"C:\Users\ user\Deskt op\fIPSLgT 0lO.exe" MD5: 016D22F02AF7424E8D99C6C243ADCDB7)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
⊘No Sigma rule has matched
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Large array initialization: |
Source: | Code function: | 0_2_0197F960 | |
Source: | Code function: | 0_2_0197408C | |
Source: | Code function: | 0_2_019717CF | |
Source: | Code function: | 0_2_019717E0 | |
Source: | Code function: | 0_2_019746B0 | |
Source: | Code function: | 0_2_01971DA8 | |
Source: | Code function: | 0_2_01971DE2 | |
Source: | Code function: | 0_2_01976F91 | |
Source: | Code function: | 0_2_01976FA0 | |
Source: | Code function: | 0_2_01971EBD | |
Source: | Code function: | 0_2_01971E0C | |
Source: | Code function: | 0_2_01971E2C | |
Source: | Code function: | 0_2_01971E40 | |
Source: | Code function: | 0_2_01971E68 | |
Source: | Code function: | 0_2_05BA3808 | |
Source: | Code function: | 0_2_05BA03C7 | |
Source: | Code function: | 0_2_05BA1470 | |
Source: | Code function: | 0_2_05BA06FF | |
Source: | Code function: | 0_2_05BC24D8 | |
Source: | Code function: | 0_2_05BC7428 | |
Source: | Code function: | 0_2_05BC8762 | |
Source: | Code function: | 0_2_05BC56B0 | |
Source: | Code function: | 0_2_05BCD191 | |
Source: | Code function: | 0_2_05BCA8E0 | |
Source: | Code function: | 0_2_05BC6B98 | |
Source: | Code function: | 0_2_05BC0B58 | |
Source: | Code function: | 0_2_05BC4A98 | |
Source: | Code function: | 0_2_05BC24C8 | |
Source: | Code function: | 0_2_05BCA430 | |
Source: | Code function: | 0_2_05BC7419 | |
Source: | Code function: | 0_2_05BC6068 | |
Source: | Code function: | 0_2_05BC6068 | |
Source: | Code function: | 0_2_05BC4DE0 | |
Source: | Code function: | 0_2_05BC6E15 | |
Source: | Code function: | 0_2_05BCA98C | |
Source: | Code function: | 0_2_05BCA8E0 | |
Source: | Code function: | 0_2_05BCA8D1 | |
Source: | Code function: | 0_2_05BC6B8B | |
Source: | Code function: | 0_2_05BCCB1A | |
Source: | Code function: | 0_2_05BCA8E0 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Static PE information: |
Source: | Code function: | 0_2_059C3B62 | |
Source: | Code function: | 0_2_05BAE691 |
Source: | Static PE information: |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Code function: | 0_2_05BC2728 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 131 Windows Management Instrumentation | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Disable or Modify Tools | OS Credential Dumping | 1 Query Registry | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 141 Virtualization/Sandbox Evasion | LSASS Memory | 121 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Deobfuscate/Decode Files or Information | Security Account Manager | 141 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 2 Obfuscated Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 22 Software Packing | LSA Secrets | 123 System Information Discovery | SSH | Keylogging | 3 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Timestomp | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
63% | ReversingLabs | ByteCode-MSIL.Trojan.Heracles | ||
100% | Avira | HEUR/AGEN.1323341 | ||
100% | Joe Sandbox ML |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
formationslistcomplet2.sexidude.com | 181.131.217.244 | true | false | high | |
bitbucket.org | 185.166.143.49 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
181.131.217.244 | formationslistcomplet2.sexidude.com | Colombia | 13489 | EPMTelecomunicacionesSAESPCO | false | |
185.166.143.49 | bitbucket.org | Germany | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573902 |
Start date and time: | 2024-12-12 17:48:59 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 20s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | fIPSLgT0lO.exerenamed because original name is a hash value |
Original Sample Name: | 3c4c48003d8ddf5dc37e44fb340e81951ccb473dbb548e9752b83c69291a54f1.exe |
Detection: | MAL |
Classification: | mal84.evad.winEXE@1/0@11/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 4.175.87.197, 13.107.246.63
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: fIPSLgT0lO.exe
Time | Type | Description |
---|---|---|
11:49:55 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
181.131.217.244 | Get hash | malicious | Remcos | Browse | ||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
185.166.143.49 | Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bitbucket.org | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
formationslistcomplet2.sexidude.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | AsyncRAT, DcRat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EPMTelecomunicacionesSAESPCO | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
⊘No created / dropped files found
File type: | |
Entropy (8bit): | 7.934254491114372 |
TrID: |
|
File name: | fIPSLgT0lO.exe |
File size: | 606'720 bytes |
MD5: | 016d22f02af7424e8d99c6c243adcdb7 |
SHA1: | 1a4148700ab479b4c455a1eb9d5f48ac56799054 |
SHA256: | 3c4c48003d8ddf5dc37e44fb340e81951ccb473dbb548e9752b83c69291a54f1 |
SHA512: | 4475237cafdc0f1b678fba94c63b755b8451062da7fd69b4bd4276dc0926bf7b45e63ab4a85dbb3f2e781f8aef00a1938d9dc86b05f5935e957ce3c6d3ad08f6 |
SSDEEP: | 12288:Xzt4ktnPfSk1fXq1nThCpEOFYTJu+qHUM0LvnOuvtICV:CGf184pEO+TJaUMOnhIC |
TLSH: | EED41292768B17A0C645403868FB9D1923F563822A33EBE3799D429E9DD3781CF50FC9 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....V................0..8...........W... ...`....@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x4957ce |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0xA90F56EF [Tue Nov 18 04:19:59 2059 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x95780 | 0x4b | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x96000 | 0x570 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x98000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x937d4 | 0x93800 | 23132605f91acbc32dc54b65f802303e | False | 0.9512529793432203 | data | 7.941976982068131 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x96000 | 0x570 | 0x600 | 177803e1d307ad9f6e72bb66ec34b7c2 | False | 0.4055989583333333 | data | 3.9668451251431556 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x98000 | 0xc | 0x200 | d196c65357c937e5cd009d7fb9d8cd13 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x960a0 | 0x2e4 | data | 0.4297297297297297 | ||
RT_MANIFEST | 0x96384 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:49:55.795459986 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:49:55.915394068 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:49:55.915611029 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:49:55.924227953 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:49:56.044753075 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:49:56.044819117 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:49:56.171276093 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:06.299830914 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:06.354743004 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:06.533725977 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:06.537235975 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:06.665148020 CET | 30203 | 49730 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:06.665298939 CET | 49730 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:06.881850004 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:06.881896973 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:06.881983995 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:06.945902109 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:06.945931911 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:08.710685015 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:08.710863113 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:08.715107918 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:08.715128899 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:08.715658903 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:08.760987997 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:08.769364119 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:08.811340094 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:09.396163940 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:09.396220922 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:09.396238089 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:09.396250010 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:09.396270990 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:09.396373987 CET | 443 | 49731 | 185.166.143.49 | 192.168.2.4 |
Dec 12, 2024 17:50:09.396416903 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:09.404021025 CET | 49731 | 443 | 192.168.2.4 | 185.166.143.49 |
Dec 12, 2024 17:50:09.527475119 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:09.647420883 CET | 30203 | 49732 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:09.647517920 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:09.648344994 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:09.768630981 CET | 30203 | 49732 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:09.768738985 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:09.888577938 CET | 30203 | 49732 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:11.022254944 CET | 30203 | 49732 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:11.022325993 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.022500038 CET | 49732 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.136825085 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.142304897 CET | 30203 | 49732 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:11.257060051 CET | 30203 | 49734 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:11.257179976 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.257967949 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.377861023 CET | 30203 | 49734 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:11.377935886 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:11.503501892 CET | 30203 | 49734 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:12.618432999 CET | 30203 | 49734 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:12.618623018 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:12.618824005 CET | 49734 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:12.730964899 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:12.739614964 CET | 30203 | 49734 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:12.850972891 CET | 30203 | 49736 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:12.851063013 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:12.851831913 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:12.971878052 CET | 30203 | 49736 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:12.971950054 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:13.092207909 CET | 30203 | 49736 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:17.294926882 CET | 30203 | 49736 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:17.297765970 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.297964096 CET | 49736 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.402992010 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.418282986 CET | 30203 | 49736 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:17.522810936 CET | 30203 | 49740 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:17.522912025 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.523900986 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.643877029 CET | 30203 | 49740 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:17.643965960 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:17.766839027 CET | 30203 | 49740 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:18.889946938 CET | 30203 | 49740 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:18.890043974 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:18.890269041 CET | 49740 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:18.996721983 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:19.010046005 CET | 30203 | 49740 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:19.120836020 CET | 30203 | 49741 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:19.121058941 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:19.121969938 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:19.247911930 CET | 30203 | 49741 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:19.247965097 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:19.367595911 CET | 30203 | 49741 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:41.030113935 CET | 30203 | 49741 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:41.030169964 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:41.030314922 CET | 49741 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:41.150068998 CET | 30203 | 49741 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:41.996521950 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:42.116600037 CET | 30203 | 49743 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:42.116769075 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:42.117712975 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:42.237829924 CET | 30203 | 49743 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:42.237993002 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:42.358318090 CET | 30203 | 49743 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:43.472083092 CET | 30203 | 49743 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:43.472134113 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:43.472306013 CET | 49743 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:43.574503899 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:43.593188047 CET | 30203 | 49743 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:43.882448912 CET | 30203 | 49744 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:43.882669926 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:43.883466005 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:44.003361940 CET | 30203 | 49744 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:44.003416061 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:44.127969980 CET | 30203 | 49744 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:54.250351906 CET | 30203 | 49744 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:54.250725031 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.250725985 CET | 49744 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.355473995 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.370554924 CET | 30203 | 49744 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:54.475336075 CET | 30203 | 49752 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:54.476144075 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.476797104 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.599030018 CET | 30203 | 49752 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:50:54.599090099 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:50:54.719794035 CET | 30203 | 49752 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:16.374509096 CET | 30203 | 49752 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:16.374588966 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:16.374783039 CET | 49752 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:16.497550964 CET | 30203 | 49752 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:19.331962109 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:19.452645063 CET | 30203 | 49809 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:19.452883005 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:19.453907013 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:19.573760986 CET | 30203 | 49809 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:19.573828936 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:19.694021940 CET | 30203 | 49809 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:20.833015919 CET | 30203 | 49809 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:20.833082914 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:20.833236933 CET | 49809 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:20.949670076 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:20.952950001 CET | 30203 | 49809 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:21.069556952 CET | 30203 | 49814 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:21.069689035 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:21.070429087 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:21.190404892 CET | 30203 | 49814 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:21.190511942 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:21.310720921 CET | 30203 | 49814 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:22.448904991 CET | 30203 | 49814 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:22.449156046 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.449321032 CET | 49814 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.558777094 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.569006920 CET | 30203 | 49814 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:22.679279089 CET | 30203 | 49819 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:22.679538965 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.680982113 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.801625013 CET | 30203 | 49819 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:22.801728964 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:22.921509981 CET | 30203 | 49819 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:24.046185970 CET | 30203 | 49819 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:24.046508074 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.046508074 CET | 49819 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.152781010 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.167187929 CET | 30203 | 49819 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:24.272486925 CET | 30203 | 49824 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:24.272643089 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.273403883 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.393198967 CET | 30203 | 49824 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:24.393316984 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:24.513330936 CET | 30203 | 49824 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:25.673912048 CET | 30203 | 49824 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:25.673996925 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:25.674139023 CET | 49824 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:25.778022051 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:25.794531107 CET | 30203 | 49824 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:25.897901058 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:25.897981882 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:25.898863077 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:26.020956039 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:26.021095037 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:26.146353960 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:27.137425900 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:27.257369995 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:27.257487059 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:27.378989935 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:30.386058092 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:30.386142969 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.386285067 CET | 49827 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.496434927 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.506021976 CET | 30203 | 49827 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:30.616475105 CET | 30203 | 49840 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:30.616575003 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.617315054 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.739357948 CET | 30203 | 49840 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:30.741883039 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:30.861802101 CET | 30203 | 49840 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:35.007029057 CET | 30203 | 49840 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:35.007102966 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.007330894 CET | 49840 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.121424913 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.127135992 CET | 30203 | 49840 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:35.241590023 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:35.241679907 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.242362976 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.362960100 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:35.363018990 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:35.483021975 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:36.606431007 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:36.608167887 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:36.608169079 CET | 49851 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:36.729890108 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:36.730906963 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:36.850693941 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:36.850786924 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:36.851454020 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:36.971221924 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:36.971287966 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:37.091109037 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:39.559037924 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:39.680008888 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:39.680079937 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:39.800280094 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:42.368285894 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:42.370104074 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.370259047 CET | 49855 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.480906010 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.490174055 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:42.601361990 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:42.601644993 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.602359056 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.722265959 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:42.725281000 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:42.845309973 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:43.918452024 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:43.945029974 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:43.945084095 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:43.945216894 CET | 49871 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.038764954 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.059215069 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.066812992 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.066833019 CET | 30203 | 49871 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.313962936 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.317975044 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.320785046 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.443219900 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.445904970 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.568818092 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.731817007 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:44.889703989 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:44.890221119 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:45.010555029 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:48.852334023 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:48.852404118 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:48.852560997 CET | 49875 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:48.974116087 CET | 30203 | 49875 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:53.895162106 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:54.015352964 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:54.015459061 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:54.016386032 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:54.152518988 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:54.152616978 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:54.277184963 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:58.026845932 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:58.146779060 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:58.146892071 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:58.266777992 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:58.385570049 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Dec 12, 2024 17:51:58.385819912 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:58.385821104 CET | 49896 | 30203 | 192.168.2.4 | 181.131.217.244 |
Dec 12, 2024 17:51:58.505896091 CET | 30203 | 49896 | 181.131.217.244 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:49:54.027766943 CET | 51972 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:49:55.042582035 CET | 51972 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:49:55.792690992 CET | 53 | 51972 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:49:55.792704105 CET | 53 | 51972 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:50:06.737159967 CET | 54803 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:50:06.877274036 CET | 53 | 54803 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:50:41.137655973 CET | 52440 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:50:41.995749950 CET | 53 | 52440 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:16.480863094 CET | 52238 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:17.495599031 CET | 52238 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:18.511224985 CET | 52238 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:19.330806971 CET | 53 | 52238 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:19.330840111 CET | 53 | 52238 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:19.330849886 CET | 53 | 52238 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:48.965157986 CET | 56460 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:49.964440107 CET | 56460 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:50.980417013 CET | 56460 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:52.980045080 CET | 56460 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 12, 2024 17:51:53.892133951 CET | 53 | 56460 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:53.892209053 CET | 53 | 56460 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:53.892219067 CET | 53 | 56460 | 1.1.1.1 | 192.168.2.4 |
Dec 12, 2024 17:51:53.892723083 CET | 53 | 56460 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:49:54.027766943 CET | 192.168.2.4 | 1.1.1.1 | 0xb010 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:49:55.042582035 CET | 192.168.2.4 | 1.1.1.1 | 0xb010 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:50:06.737159967 CET | 192.168.2.4 | 1.1.1.1 | 0x7e9e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:50:41.137655973 CET | 192.168.2.4 | 1.1.1.1 | 0xcb5e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:16.480863094 CET | 192.168.2.4 | 1.1.1.1 | 0xe39d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:17.495599031 CET | 192.168.2.4 | 1.1.1.1 | 0xe39d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:18.511224985 CET | 192.168.2.4 | 1.1.1.1 | 0xe39d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:48.965157986 CET | 192.168.2.4 | 1.1.1.1 | 0xcea3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:49.964440107 CET | 192.168.2.4 | 1.1.1.1 | 0xcea3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:50.980417013 CET | 192.168.2.4 | 1.1.1.1 | 0xcea3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:51:52.980045080 CET | 192.168.2.4 | 1.1.1.1 | 0xcea3 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:49:55.792690992 CET | 1.1.1.1 | 192.168.2.4 | 0xb010 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:49:55.792704105 CET | 1.1.1.1 | 192.168.2.4 | 0xb010 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:50:06.877274036 CET | 1.1.1.1 | 192.168.2.4 | 0x7e9e | No error (0) | 185.166.143.49 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:50:06.877274036 CET | 1.1.1.1 | 192.168.2.4 | 0x7e9e | No error (0) | 185.166.143.50 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:50:06.877274036 CET | 1.1.1.1 | 192.168.2.4 | 0x7e9e | No error (0) | 185.166.143.48 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:50:41.995749950 CET | 1.1.1.1 | 192.168.2.4 | 0xcb5e | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:19.330806971 CET | 1.1.1.1 | 192.168.2.4 | 0xe39d | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:19.330840111 CET | 1.1.1.1 | 192.168.2.4 | 0xe39d | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:19.330849886 CET | 1.1.1.1 | 192.168.2.4 | 0xe39d | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:53.892133951 CET | 1.1.1.1 | 192.168.2.4 | 0xcea3 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:53.892209053 CET | 1.1.1.1 | 192.168.2.4 | 0xcea3 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:53.892219067 CET | 1.1.1.1 | 192.168.2.4 | 0xcea3 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:51:53.892723083 CET | 1.1.1.1 | 192.168.2.4 | 0xcea3 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49731 | 185.166.143.49 | 443 | 3020 | C:\Users\user\Desktop\fIPSLgT0lO.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 16:50:08 UTC | 101 | OUT | |
2024-12-12 16:50:09 UTC | 5939 | IN |