Edit tour
Windows
Analysis Report
4JwhvqLe8n.exe
Overview
General Information
Sample name: | 4JwhvqLe8n.exerenamed because original name is a hash value |
Original sample name: | 66e6c38dc2c5e1dc03209e8f876d546c94a1b806c6e02c3b33f5e523eb3fdff9.exe |
Analysis ID: | 1573906 |
MD5: | b58e300ca8077adc4094e9044bcdbbc8 |
SHA1: | abc3b46626e17e22b744b9fe44833919255121ce |
SHA256: | 66e6c38dc2c5e1dc03209e8f876d546c94a1b806c6e02c3b33f5e523eb3fdff9 |
Tags: | 181-131-217-244exeuser-JAMESWT_MHT |
Infos: | |
Detection
Score: | 96 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Detected unpacking (creates a PE file in dynamic memory)
Multi AV Scanner detection for submitted file
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
.NET source code contains very large array initializations
AI detected suspicious sample
Allocates memory in foreign processes
Drops large PE files
Injects a PE file into a foreign processes
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Compiles C# or VB.Net code
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Contains long sleeps (>= 3 min)
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain (may stop execution after checking a module file name)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
Queries sensitive BIOS Information (via WMI, Win32_Bios & Win32_BaseBoard, often done to detect virtual machines)
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Classification
- System is w10x64
- 4JwhvqLe8n.exe (PID: 8068 cmdline:
"C:\Users\ user\Deskt op\4JwhvqL e8n.exe" MD5: B58E300CA8077ADC4094E9044BCDBBC8) - csc.exe (PID: 7552 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\csc .exe" MD5: EB80BB1CA9B9C7F516FF69AFCFD75B7D)
- cleanup
⊘No configs have been found
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security | ||
JoeSecurity_CosturaAssemblyLoader | Yara detected Costura Assembly Loader | Joe Security |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
⊘No Suricata rule has matched
Click to jump to signature section
Show All Signature Results
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Compliance |
---|
Source: | Unpacked PE file: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Large array initialization: |
Source: | File dump: | Jump to dropped file |
Source: | Code function: | 1_2_0040A8CC | |
Source: | Code function: | 1_2_0040B077 | |
Source: | Code function: | 1_2_0041E814 | |
Source: | Code function: | 1_2_0040B035 | |
Source: | Code function: | 1_2_0040B0D9 | |
Source: | Code function: | 1_2_0040B08B | |
Source: | Code function: | 1_2_0040B095 | |
Source: | Code function: | 1_2_00421943 | |
Source: | Code function: | 1_2_0040A954 | |
Source: | Code function: | 1_2_0040A96E | |
Source: | Code function: | 1_2_0040A9D8 | |
Source: | Code function: | 1_2_0040A984 | |
Source: | Code function: | 1_2_0040B9A7 | |
Source: | Code function: | 1_2_0040A9AE | |
Source: | Code function: | 1_2_00415210 | |
Source: | Code function: | 1_2_0040AAC9 | |
Source: | Code function: | 1_2_0040AAFE | |
Source: | Code function: | 1_2_0040AAAD | |
Source: | Code function: | 1_2_0040AAB2 | |
Source: | Code function: | 1_2_0040B342 | |
Source: | Code function: | 1_2_0040BB4A | |
Source: | Code function: | 1_2_0040B335 | |
Source: | Code function: | 1_2_0040BBF1 | |
Source: | Code function: | 1_2_0040B3A9 | |
Source: | Code function: | 1_2_0040B459 | |
Source: | Code function: | 1_2_0040B401 | |
Source: | Code function: | 1_2_0040B410 | |
Source: | Code function: | 1_2_0040B41F | |
Source: | Code function: | 1_2_0040B489 | |
Source: | Code function: | 1_2_0040B494 | |
Source: | Code function: | 1_2_0040BD59 | |
Source: | Code function: | 1_2_0040BD60 | |
Source: | Code function: | 1_2_0041ED65 | |
Source: | Code function: | 1_2_0040BD66 | |
Source: | Code function: | 1_2_0040B504 | |
Source: | Code function: | 1_2_0040B524 | |
Source: | Code function: | 1_2_0040B5D4 | |
Source: | Code function: | 1_2_00407E57 | |
Source: | Code function: | 1_2_0041FDAB | |
Source: | Code function: | 1_2_0040B5B8 | |
Source: | Code function: | 1_2_0040ADBC | |
Source: | Code function: | 1_2_00421E53 | |
Source: | Code function: | 1_2_0040B609 | |
Source: | Code function: | 1_2_0040AE15 | |
Source: | Code function: | 1_2_0040B616 | |
Source: | Code function: | 1_2_0040AE1C | |
Source: | Code function: | 1_2_0040C635 | |
Source: | Code function: | 1_2_0040AE38 | |
Source: | Code function: | 1_2_0040AF5C | |
Source: | Code function: | 1_2_0040AF64 | |
Source: | Code function: | 1_2_0040BF78 | |
Source: | Code function: | 1_2_0040B709 | |
Source: | Code function: | 1_2_0040BFD1 | |
Source: | Code function: | 1_2_0040BFB0 | |
Source: | Code function: | 3_2_069847D2 | |
Source: | Code function: | 3_2_06987158 | |
Source: | Code function: | 3_2_06987148 | |
Source: | Code function: | 3_2_06981BB0 | |
Source: | Code function: | 3_2_06981BC0 | |
Source: | Code function: | 3_2_06984868 | |
Source: | Code function: | 3_2_094B073F | |
Source: | Code function: | 3_2_094B0A77 | |
Source: | Code function: | 3_2_094B17E8 | |
Source: | Code function: | 3_2_094C258B | |
Source: | Code function: | 3_2_094C307F | |
Source: | Code function: | 3_2_094C30AF | |
Source: | Code function: | 3_2_095F5938 | |
Source: | Code function: | 3_2_095F4D20 | |
Source: | Code function: | 3_2_095F0DD8 | |
Source: | Code function: | 3_2_095F2758 | |
Source: | Code function: | 3_2_095F7620 | |
Source: | Code function: | 3_2_095FC9E2 | |
Source: | Code function: | 3_2_095FCBF2 | |
Source: | Code function: | 3_2_095FCBBB | |
Source: | Code function: | 3_2_095FCAEE | |
Source: | Code function: | 3_2_095F5068 | |
Source: | Code function: | 3_2_095FA4B0 | |
Source: | Code function: | 3_2_095F7613 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: | ||
Source: | Task registration methods: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Code function: | 1_2_00401020 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | Unpacked PE file: |
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Static PE information: |
Source: | Code function: | 1_2_00408244 | |
Source: | Code function: | 1_2_004173B8 | |
Source: | Code function: | 3_2_069874D8 | |
Source: | Code function: | 3_2_069842C0 | |
Source: | Code function: | 3_2_069843C8 | |
Source: | Code function: | 3_2_069843D8 | |
Source: | Code function: | 3_2_094C180D | |
Source: | Code function: | 3_2_094CBAD7 | |
Source: | Code function: | 3_2_094C0690 | |
Source: | Code function: | 3_2_095F0159 | |
Source: | Code function: | 3_2_095FB3DF | |
Source: | Code function: | 3_2_095FB415 | |
Source: | Code function: | 3_2_095FD639 | |
Source: | Code function: | 3_2_09813998 | |
Source: | Code function: | 3_2_098131AB | |
Source: | Code function: | 3_2_098121CD | |
Source: | Code function: | 3_2_09813323 | |
Source: | Code function: | 3_2_09812133 | |
Source: | Code function: | 3_2_09812B4E | |
Source: | Code function: | 3_2_09813176 | |
Source: | Code function: | 3_2_098142CA |
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: | ||
Source: | High entropy of concatenated method names: |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Queries sensitive disk information (via WMI, Win32_DiskDrive, often done to detect virtual machines)
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Evasive API call chain: | graph_1-14719 |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | API call chain: | graph_1-14721 |
Source: | Code function: | 1_2_0041343A |
Source: | Process token adjusted: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Code function: | 1_2_0041343A | |
Source: | Code function: | 1_2_00415AE9 |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory allocated: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Code function: | 1_2_0040EC80 |
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 1_2_0041C45E |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 131 Windows Management Instrumentation | 1 Scheduled Task/Job | 31 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Scheduled Task/Job | 11 Disable or Modify Tools | LSASS Memory | 141 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Native API | 1 DLL Side-Loading | 1 Registry Run Keys / Startup Folder | 141 Virtualization/Sandbox Evasion | Security Account Manager | 141 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 31 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Deobfuscate/Decode Files or Information | LSA Secrets | 134 System Information Discovery | SSH | Keylogging | 3 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 3 Software Packing | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
42% | ReversingLabs | Win32.Backdoor.Remcos |
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
⊘No Antivirus matches
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bitbucket.org | 185.166.143.49 | true | false | high | |
navegacionseguracol24vip.org | 181.131.217.244 | true | false | high | |
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | 217.20.58.100 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
181.131.217.244 | navegacionseguracol24vip.org | Colombia | 13489 | EPMTelecomunicacionesSAESPCO | false | |
185.166.143.49 | bitbucket.org | Germany | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1573906 |
Start date and time: | 2024-12-12 17:51:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 4JwhvqLe8n.exerenamed because original name is a hash value |
Original Sample Name: | 66e6c38dc2c5e1dc03209e8f876d546c94a1b806c6e02c3b33f5e523eb3fdff9.exe |
Detection: | MAL |
Classification: | mal96.evad.winEXE@3/1@2/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.63, 4.175.87.197, 20.12.23.50
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 4JwhvqLe8n.exe
Time | Type | Description |
---|---|---|
11:52:48 | API Interceptor | |
17:52:53 | Autostart | |
17:53:01 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
181.131.217.244 | Get hash | malicious | Remcos | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | Unknown | Browse | |||
185.166.143.49 | Get hash | malicious | HTMLPhisher | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
navegacionseguracol24vip.org | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
bitbucket.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | AveMaria, DcRat, StormKitty, VenomRAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Captcha Phish | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
EPMTelecomunicacionesSAESPCO | Get hash | malicious | Remcos | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
⊘No context
Process: | C:\Users\user\Desktop\4JwhvqLe8n.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 979567344 |
Entropy (8bit): | 0.03687271612861637 |
Encrypted: | false |
SSDEEP: | |
MD5: | 562A60041F05642EC1385D4485B2367A |
SHA1: | 73084B32C52D7B55DEAC6F80C550F2F6B1E43998 |
SHA-256: | 7B4BE96B41FCEAC779AFE4F8A90E29727DC069E2ABAB8978652A9B5A5176D884 |
SHA-512: | 8E918EA5F916947F3FDD4F81900CAA6B969CD5D3F062B5928B72A4BA1EEE1B5DFABDFE7DA2F8EA5A3DB4FED261907365F7456CB2D428852B04DC2EA4EDB9BF7F |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.05725668491521 |
TrID: |
|
File name: | 4JwhvqLe8n.exe |
File size: | 2'652'160 bytes |
MD5: | b58e300ca8077adc4094e9044bcdbbc8 |
SHA1: | abc3b46626e17e22b744b9fe44833919255121ce |
SHA256: | 66e6c38dc2c5e1dc03209e8f876d546c94a1b806c6e02c3b33f5e523eb3fdff9 |
SHA512: | abfae0cd1d5b9a1475449f1f4ece4c72d7731bf1e01e721ebf31e656c65406b430f87b65334a9e9150530357f58b6ea7d31b5d55b4ae9800ad64d9bdc5998ea3 |
SSDEEP: | 24576:Mo48sSW8kD+xpdPChyjn4CqnlwRsdkoAgEsJUtDkMvF9Am:p4bIk6qhyL4osdkovEsJUFxPJ |
TLSH: | 45C56CC6D940C847F97A19FDE91A78F0422F3FB9D93EA06B9B907F2DB231AC10415952 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......8)4.|HZ.|HZ.|HZ.g...jHZ.g....HZ.g...GHZ.u0..qHZ.|H[..HZ.g...kHZ.g...}HZ.g...}HZ.Rich|HZ.........................PE..L......d... |
Icon Hash: | 070b71b030211f88 |
Entrypoint: | 0x415891 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x64ECE0A8 [Mon Aug 28 18:00:08 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 1 |
File Version Major: | 5 |
File Version Minor: | 1 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 1 |
Import Hash: | fba9a06cd911d183f0aec1159c439b07 |
Signature Valid: | |
Signature Issuer: | |
Signature Validation Error: | |
Error Number: | |
Not Before, Not After | |
Subject Chain | |
Version: | |
Thumbprint MD5: | |
Thumbprint SHA-1: | |
Thumbprint SHA-256: | |
Serial: |
Instruction |
---|
call 00007FAF890FFEDDh |
jmp 00007FAF890F919Eh |
int3 |
int3 |
int3 |
int3 |
int3 |
mov edx, dword ptr [esp+0Ch] |
mov ecx, dword ptr [esp+04h] |
test edx, edx |
je 00007FAF890F937Bh |
xor eax, eax |
mov al, byte ptr [esp+08h] |
test al, al |
jne 00007FAF890F9328h |
cmp edx, 00000080h |
jc 00007FAF890F9320h |
cmp dword ptr [00432CC0h], 00000000h |
je 00007FAF890F9317h |
jmp 00007FAF890FFF42h |
push edi |
mov edi, ecx |
cmp edx, 04h |
jc 00007FAF890F9343h |
neg ecx |
and ecx, 03h |
je 00007FAF890F931Eh |
sub edx, ecx |
mov byte ptr [edi], al |
add edi, 01h |
sub ecx, 01h |
jne 00007FAF890F9308h |
mov ecx, eax |
shl eax, 08h |
add eax, ecx |
mov ecx, eax |
shl eax, 10h |
add eax, ecx |
mov ecx, edx |
and edx, 03h |
shr ecx, 02h |
je 00007FAF890F9318h |
rep stosd |
test edx, edx |
je 00007FAF890F931Ch |
mov byte ptr [edi], al |
add edi, 01h |
sub edx, 01h |
jne 00007FAF890F9308h |
mov eax, dword ptr [esp+08h] |
pop edi |
ret |
mov eax, dword ptr [esp+04h] |
ret |
mov edi, edi |
push ebp |
mov ebp, esp |
mov ecx, dword ptr [ebp+0Ch] |
push ebx |
xor ebx, ebx |
cmp ecx, ebx |
jbe 00007FAF890F932Dh |
push FFFFFFE0h |
xor edx, edx |
pop eax |
div ecx |
cmp eax, dword ptr [ebp+10h] |
jnc 00007FAF890F9321h |
call 00007FAF890F7DDEh |
mov dword ptr [eax], 0000000Ch |
xor eax, eax |
jmp 00007FAF890F9353h |
imul ecx, dword ptr [ebp+10h] |
push esi |
push edi |
mov esi, ecx |
cmp dword ptr [ebp+08h], ebx |
je 00007FAF890F931Dh |
push dword ptr [ebp+08h] |
call 00007FAF890FA9FEh |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x2f4c4 | 0x78 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x34000 | 0x2573d0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0xc7e00 | 0x2860 | .rsrc |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xc8000 | 0x22fc | .rsrc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x272b0 | 0x1c | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x2c150 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x27000 | 0x1bc | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x26000 | 0x25400 | 322bee9ae1b5d94b5b2fb7fb5a6af11d | False | 0.5403143351510067 | data | 6.613060638092758 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x27000 | 0x9000 | 0x9000 | 81a1c90b898ffbd833b6d78098a5839e | False | 0.3275282118055556 | data | 4.397029732712187 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x30000 | 0x4000 | 0x1c00 | 84f180ff30a786befa816e36aabd66fc | False | 0.2925502232142857 | data | 4.000425788178025 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x34000 | 0x2573d0 | 0x257400 | 922980e07f33f2cbed318f9698257843 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_BITMAP | 0x34924 | 0x1d4e8 | Device independent bitmap graphic, 200 x 200 x 24, image size 120000, resolution 3780 x 3780 px/m | 0.651107964011996 | ||
RT_BITMAP | 0x51e0c | 0x9ea4 | Device independent bitmap graphic, 483 x 21 x 32, image size 40572, resolution 3582 x 3582 px/m | 0.36169112577563284 | ||
RT_BITMAP | 0x5bcb0 | 0x50138 | PC bitmap, Windows 3.x format, 41447 x 2 x 40, image size 328097, cbSize 327992, bits offset 54 | 0.9418796799921949 | ||
RT_ICON | 0xabde8 | 0x3a48 | Device independent bitmap graphic, 60 x 120 x 32, image size 14880 | 0.1794906166219839 | ||
RT_ICON | 0xaf830 | 0xcd63 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | 0.8217158941782841 | ||
RT_ICON | 0xbc594 | 0x43db6 | PC bitmap, Windows 3.x format, 34872 x 2 x 46, image size 278651, cbSize 277942, bits offset 54 | 0.9944844607867829 | ||
RT_ICON | 0x10034c | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 0 | English | United States | 0.21341463414634146 |
RT_ICON | 0x1009b4 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | United States | 0.271505376344086 |
RT_ICON | 0x100c9c | 0x1e8 | Device independent bitmap graphic, 24 x 48 x 4, image size 0 | English | United States | 0.36475409836065575 |
RT_ICON | 0x100e84 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | United States | 0.4864864864864865 |
RT_ICON | 0x100fac | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | United States | 0.12366737739872068 |
RT_ICON | 0x101e54 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | United States | 0.14620938628158844 |
RT_ICON | 0x1026fc | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | English | United States | 0.16589861751152074 |
RT_ICON | 0x102dc4 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | United States | 0.16257225433526012 |
RT_ICON | 0x10332c | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 0 | English | United States | 0.018600023670740005 |
RT_ICON | 0x145354 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | United States | 0.08858921161825727 |
RT_ICON | 0x1478fc | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | United States | 0.12617260787992496 |
RT_ICON | 0x1489a4 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | English | United States | 0.1819672131147541 |
RT_ICON | 0x14932c | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | United States | 0.26684397163120566 |
RT_ICON | 0x149794 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 0 | English | United States | 0.21341463414634146 |
RT_ICON | 0x149dfc | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 0 | English | United States | 0.271505376344086 |
RT_ICON | 0x14a0e4 | 0x1e8 | Device independent bitmap graphic, 24 x 48 x 4, image size 0 | English | United States | 0.36475409836065575 |
RT_ICON | 0x14a2cc | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 0 | English | United States | 0.4864864864864865 |
RT_ICON | 0x14a3f4 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | English | United States | 0.12366737739872068 |
RT_ICON | 0x14b29c | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | English | United States | 0.14620938628158844 |
RT_ICON | 0x14bb44 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | English | United States | 0.16589861751152074 |
RT_ICON | 0x14c20c | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | English | United States | 0.16257225433526012 |
RT_ICON | 0x14c774 | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 0 | English | United States | 0.018600023670740005 |
RT_ICON | 0x18e79c | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | English | United States | 0.08858921161825727 |
RT_ICON | 0x190d44 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | English | United States | 0.12617260787992496 |
RT_ICON | 0x191dec | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | English | United States | 0.1819672131147541 |
RT_ICON | 0x192774 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | English | United States | 0.26684397163120566 |
RT_MENU | 0x192bdc | 0x4a | data | English | United States | 0.8648648648648649 |
RT_DIALOG | 0x192c28 | 0x10a | data | English | United States | 0.6804511278195489 |
RT_STRING | 0x192d34 | 0x70 | data | English | United States | 0.6785714285714286 |
RT_ACCELERATOR | 0x192da4 | 0x10 | data | English | United States | 1.25 |
RT_RCDATA | 0x192db4 | 0xf7ece | Delphi compiled form 'TfPNGMessage' | 0.20263081707372316 | ||
RT_GROUP_ICON | 0x28ac84 | 0xbc | data | English | United States | 0.5904255319148937 |
RT_GROUP_ICON | 0x28ad40 | 0xbc | data | English | United States | 0.6117021276595744 |
RT_VERSION | 0x28adfc | 0x37c | data | English | United States | 0.4226457399103139 |
RT_MANIFEST | 0x28b178 | 0x255 | ASCII text, with very long lines (353), with CRLF line terminators | English | United States | 0.4991624790619765 |
DLL | Import |
---|---|
KERNEL32.dll | FreeEnvironmentStringsW, CloseHandle, LocalFree, ResumeThread, lstrcpyW, FreeLibrary, LoadLibraryW, MultiByteToWideChar, GetProcAddress, Sleep, lstrcpynW, SetFilePointerEx, WriteFile, ReadFile, CreateFileW, FlushFileBuffers, GetFileSizeEx, RaiseException, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, GetLocaleInfoA, GetLocaleInfoW, SetFilePointer, AllocConsole, FreeConsole, GetStdHandle, lstrcmpiW, FormatMessageW, QueryPerformanceCounter, ReleaseSemaphore, CreateSemaphoreW, OpenSemaphoreW, GetConsoleMode, GetConsoleCP, RtlUnwind, GetSystemTimeAsFileTime, SetCurrentDirectoryW, FindResourceExW, GetLastError, GetStartupInfoW, lstrlenW, GetModuleFileNameW, GetEnvironmentStringsW, CreateProcessW, GetEnvironmentVariableW, GetCommandLineW, LockResource, SizeofResource, WideCharToMultiByte, LoadResource, FindResourceW, GetCurrentProcessId, GetTickCount, SetHandleCount, LCMapStringW, HeapCreate, IsProcessorFeaturePresent, GetStringTypeW, ExitProcess, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, EncodePointer, DecodePointer, SetStdHandle, GetFileType, WriteConsoleW, HeapSetInformation, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetModuleHandleW, SetLastError, GetCurrentThreadId |
USER32.dll | GetDesktopWindow, MessageBoxW |
ADVAPI32.dll | RegQueryValueExW, RegOpenKeyW, IsTextUnicode, RegCreateKeyW, RegSetValueExW, RegCloseKey, RegOpenKeyExW, RegCreateKeyExW |
SHELL32.dll | CommandLineToArgvW |
SHLWAPI.dll | StrNCatW, PathFileExistsW, UrlEscapeW, UrlUnescapeW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:52:49.038386106 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:49.183659077 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:49.183774948 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:49.278188944 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:49.398365974 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:49.398659945 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:49.573280096 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:50.552381039 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:50.597382069 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:50.785814047 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:50.818085909 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:50.944050074 CET | 30203 | 49766 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:50.944236994 CET | 49766 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:51.542293072 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:51.542336941 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:51.542412043 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:51.557173967 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:51.557200909 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:52.983409882 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:52.983498096 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.144628048 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.144655943 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.145642042 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.191122055 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.356070995 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.403321981 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.958321095 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.958350897 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.958404064 CET | 443 | 49772 | 185.166.143.49 | 192.168.2.10 |
Dec 12, 2024 17:52:53.958416939 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.958439112 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.958487034 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:53.963701010 CET | 49772 | 443 | 192.168.2.10 | 185.166.143.49 |
Dec 12, 2024 17:52:54.083100080 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:54.203099966 CET | 30203 | 49778 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:54.203202963 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:54.203950882 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:54.323925018 CET | 30203 | 49778 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:54.324045897 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:54.463037968 CET | 30203 | 49778 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:55.564188004 CET | 30203 | 49778 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:55.564289093 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:55.565287113 CET | 49778 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:55.676664114 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:55.689600945 CET | 30203 | 49778 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:55.804349899 CET | 30203 | 49780 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:55.805937052 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:55.823251963 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:55.943239927 CET | 30203 | 49780 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:55.943300962 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:56.063018084 CET | 30203 | 49780 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:57.164239883 CET | 30203 | 49780 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:57.164326906 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.164526939 CET | 49780 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.270262957 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.284740925 CET | 30203 | 49780 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:57.390197992 CET | 30203 | 49786 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:57.393997908 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.394974947 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.514681101 CET | 30203 | 49786 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:52:57.517946959 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:52:57.638257980 CET | 30203 | 49786 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:01.906131983 CET | 30203 | 49786 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:01.906246901 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:01.906450033 CET | 49786 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:02.021007061 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:02.026441097 CET | 30203 | 49786 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:02.141035080 CET | 30203 | 49797 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:02.141130924 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:02.141910076 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:02.261806965 CET | 30203 | 49797 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:02.261991024 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:02.381803036 CET | 30203 | 49797 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:12.523837090 CET | 30203 | 49797 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:12.525146008 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.525300980 CET | 49797 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.630116940 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.644995928 CET | 30203 | 49797 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:12.749877930 CET | 30203 | 49823 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:12.750195980 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.751038074 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.870910883 CET | 30203 | 49823 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:12.870995045 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:12.994607925 CET | 30203 | 49823 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:17.131793976 CET | 30203 | 49823 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:17.131906986 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.132008076 CET | 49823 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.239223957 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.256107092 CET | 30203 | 49823 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:17.358966112 CET | 30203 | 49834 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:17.359045982 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.359864950 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.483408928 CET | 30203 | 49834 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:17.483464003 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:17.603230000 CET | 30203 | 49834 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:21.732676983 CET | 30203 | 49834 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:21.732789040 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:21.732958078 CET | 49834 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:21.848676920 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:21.854048967 CET | 30203 | 49834 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:21.968672991 CET | 30203 | 49844 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:21.968911886 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:21.969926119 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:22.089628935 CET | 30203 | 49844 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:22.089760065 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:22.209805965 CET | 30203 | 49844 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:23.459825993 CET | 30203 | 49844 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:23.461875916 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.461875916 CET | 49844 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.567245960 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.581614017 CET | 30203 | 49844 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:23.687236071 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:23.687377930 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.688163996 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.808346033 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:23.808440924 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:23.928364992 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:25.202486992 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:25.202541113 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.202797890 CET | 49851 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.316998959 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.323143005 CET | 30203 | 49851 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:25.437930107 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:25.438039064 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.438796043 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.561582088 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:25.561665058 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:25.681504965 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:26.792310953 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:26.792378902 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:26.792570114 CET | 49855 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:26.898076057 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:26.912681103 CET | 30203 | 49855 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:27.018052101 CET | 30203 | 49859 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:27.018254042 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:27.054733038 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:27.174801111 CET | 30203 | 49859 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:27.174884081 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:27.294811010 CET | 30203 | 49859 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:28.504092932 CET | 30203 | 49859 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:28.504179955 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.504324913 CET | 49859 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.614132881 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.624258995 CET | 30203 | 49859 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:28.734090090 CET | 30203 | 49865 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:28.736249924 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.736921072 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.857044935 CET | 30203 | 49865 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:28.860019922 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:28.979902029 CET | 30203 | 49865 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:30.094089985 CET | 30203 | 49865 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:30.094153881 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.094810009 CET | 49865 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.208444118 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.218039989 CET | 30203 | 49865 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:30.328485012 CET | 30203 | 49870 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:30.328639030 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.329389095 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.449076891 CET | 30203 | 49870 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:30.449134111 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:30.568999052 CET | 30203 | 49870 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:31.733891964 CET | 30203 | 49870 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:31.733998060 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:31.734224081 CET | 49870 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:31.848396063 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:31.856472015 CET | 30203 | 49870 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:31.968240023 CET | 30203 | 49874 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:31.969983101 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:31.970729113 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:32.090614080 CET | 30203 | 49874 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:32.093993902 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:32.213706970 CET | 30203 | 49874 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:36.316097975 CET | 30203 | 49874 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:36.316171885 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.316523075 CET | 49874 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.426747084 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.438411951 CET | 30203 | 49874 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:36.549422979 CET | 30203 | 49885 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:36.549514055 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.550360918 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.670087099 CET | 30203 | 49885 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:36.670141935 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:36.791585922 CET | 30203 | 49885 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:37.920850992 CET | 30203 | 49885 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:37.921077967 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:37.921159029 CET | 49885 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:38.035967112 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:38.041160107 CET | 30203 | 49885 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:38.191005945 CET | 30203 | 49888 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:38.191329002 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:38.192028999 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:38.322134972 CET | 30203 | 49888 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:38.322199106 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:38.441898108 CET | 30203 | 49888 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:39.562650919 CET | 30203 | 49888 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:39.562973022 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:39.562973022 CET | 49888 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:39.676505089 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:39.689939022 CET | 30203 | 49888 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:39.796685934 CET | 30203 | 49892 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:39.796756983 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:39.797740936 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:39.919392109 CET | 30203 | 49892 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:39.919779062 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:40.045952082 CET | 30203 | 49892 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:41.155446053 CET | 30203 | 49892 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:41.155512094 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.155925035 CET | 49892 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.270420074 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.282465935 CET | 30203 | 49892 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:41.395685911 CET | 30203 | 49897 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:41.395999908 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.396701097 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.516565084 CET | 30203 | 49897 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:41.516670942 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:41.637362957 CET | 30203 | 49897 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:42.760343075 CET | 30203 | 49897 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:42.760431051 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:42.760632038 CET | 49897 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:42.864186049 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:42.884094954 CET | 30203 | 49897 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:42.987416983 CET | 30203 | 49903 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:42.987518072 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:42.988444090 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:43.113948107 CET | 30203 | 49903 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:53:43.114053965 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:53:43.234978914 CET | 30203 | 49903 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:04.877846956 CET | 30203 | 49903 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:04.877932072 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:04.878294945 CET | 49903 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:04.998512983 CET | 30203 | 49903 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:05.006242037 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:05.126785994 CET | 30203 | 49954 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:05.126933098 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:05.128463030 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:05.249134064 CET | 30203 | 49954 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:05.249398947 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:05.369626045 CET | 30203 | 49954 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:06.506442070 CET | 30203 | 49954 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:06.506530046 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.506645918 CET | 49954 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.614114046 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.626409054 CET | 30203 | 49954 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:06.734064102 CET | 30203 | 49957 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:06.734611988 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.735291958 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.857206106 CET | 30203 | 49957 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:06.858017921 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:06.978775024 CET | 30203 | 49957 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:11.232099056 CET | 30203 | 49957 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:11.232182980 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.232419014 CET | 49957 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.349663019 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.352925062 CET | 30203 | 49957 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:11.469556093 CET | 30203 | 49970 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:11.469660997 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.470628977 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.590617895 CET | 30203 | 49970 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:11.590681076 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:11.713006020 CET | 30203 | 49970 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:12.862992048 CET | 30203 | 49970 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:12.863451958 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:12.863619089 CET | 49970 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:12.973509073 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:12.990272045 CET | 30203 | 49970 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:13.095659018 CET | 30203 | 49974 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:13.096645117 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:13.097316027 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:13.217242002 CET | 30203 | 49974 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:13.221208096 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:13.341409922 CET | 30203 | 49974 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:14.634933949 CET | 30203 | 49974 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:14.635054111 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:14.635318995 CET | 49974 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:14.739237070 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:14.755101919 CET | 30203 | 49974 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:14.859299898 CET | 30203 | 49979 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:14.860558033 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:14.861371040 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:14.981117010 CET | 30203 | 49979 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:14.981476068 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:15.102334976 CET | 30203 | 49979 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:16.224427938 CET | 30203 | 49979 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:16.224523067 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.224644899 CET | 49979 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.332654953 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.344307899 CET | 30203 | 49979 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:16.453800917 CET | 30203 | 49983 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:16.454063892 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.455020905 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.575097084 CET | 30203 | 49983 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:16.575328112 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:16.695450068 CET | 30203 | 49983 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:17.828965902 CET | 30203 | 49983 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:17.829108000 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:17.829406977 CET | 49983 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:17.944762945 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:17.949136972 CET | 30203 | 49983 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:18.065177917 CET | 30203 | 49989 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:18.065275908 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:18.066123962 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:18.186060905 CET | 30203 | 49989 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:18.188054085 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:18.309118032 CET | 30203 | 49989 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:19.589436054 CET | 30203 | 49989 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:19.589539051 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:19.589665890 CET | 49989 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:19.692394972 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:19.709598064 CET | 30203 | 49989 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:19.814450026 CET | 30203 | 49993 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:19.814672947 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:19.815383911 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:19.935441017 CET | 30203 | 49993 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:19.936959028 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:20.059176922 CET | 30203 | 49993 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:21.288325071 CET | 30203 | 49993 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:21.288407087 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.294663906 CET | 49993 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.412540913 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.414438009 CET | 30203 | 49993 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:21.532332897 CET | 30203 | 49998 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:21.534089088 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.534823895 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.656207085 CET | 30203 | 49998 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:21.656763077 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:21.777692080 CET | 30203 | 49998 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:22.967035055 CET | 30203 | 49998 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:22.967209101 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:22.967310905 CET | 49998 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:23.083198071 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:23.087074041 CET | 30203 | 49998 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:23.203110933 CET | 30203 | 50000 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:23.203203917 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:23.203918934 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:23.325700045 CET | 30203 | 50000 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:23.325773001 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:23.447297096 CET | 30203 | 50000 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:24.725979090 CET | 30203 | 50000 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:24.726114988 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:24.726279020 CET | 50000 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:24.832828045 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:24.846043110 CET | 30203 | 50000 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:24.952841043 CET | 30203 | 50001 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:24.952931881 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:24.953735113 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:25.073771000 CET | 30203 | 50001 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:25.073829889 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:25.193794012 CET | 30203 | 50001 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:26.309708118 CET | 30203 | 50001 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:26.309804916 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.309967995 CET | 50001 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.426516056 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.429636955 CET | 30203 | 50001 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:26.546519995 CET | 30203 | 50002 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:26.546603918 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.547584057 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.667273998 CET | 30203 | 50002 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:26.667541027 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:26.787408113 CET | 30203 | 50002 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:28.045767069 CET | 30203 | 50002 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:28.045850992 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.046156883 CET | 50002 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.161004066 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.166019917 CET | 30203 | 50002 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:28.281965971 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:28.282093048 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.282907963 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.402731895 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:28.404150963 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:28.526982069 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:30.958331108 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:31.078224897 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:31.078294992 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:31.198278904 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:31.395211935 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:31.515388966 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:31.515455008 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:31.635400057 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:32.419152021 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:32.539139032 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:32.539210081 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:32.650357008 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:32.650470972 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:32.650599003 CET | 50003 | 30203 | 192.168.2.10 | 181.131.217.244 |
Dec 12, 2024 17:54:32.659137011 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:32.770808935 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Dec 12, 2024 17:54:32.770827055 CET | 30203 | 50003 | 181.131.217.244 | 192.168.2.10 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 12, 2024 17:52:48.897732019 CET | 61607 | 53 | 192.168.2.10 | 1.1.1.1 |
Dec 12, 2024 17:52:49.035656929 CET | 53 | 61607 | 1.1.1.1 | 192.168.2.10 |
Dec 12, 2024 17:52:51.005080938 CET | 63082 | 53 | 192.168.2.10 | 1.1.1.1 |
Dec 12, 2024 17:52:51.537967920 CET | 53 | 63082 | 1.1.1.1 | 192.168.2.10 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:52:48.897732019 CET | 192.168.2.10 | 1.1.1.1 | 0xe613 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 12, 2024 17:52:51.005080938 CET | 192.168.2.10 | 1.1.1.1 | 0xaa8c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | 217.20.58.100 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | 217.20.58.101 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | 217.20.58.99 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | 217.20.58.98 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:43.138993025 CET | 1.1.1.1 | 192.168.2.10 | 0xb1d4 | No error (0) | 84.201.211.21 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:49.035656929 CET | 1.1.1.1 | 192.168.2.10 | 0xe613 | No error (0) | 181.131.217.244 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:51.537967920 CET | 1.1.1.1 | 192.168.2.10 | 0xaa8c | No error (0) | 185.166.143.49 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:51.537967920 CET | 1.1.1.1 | 192.168.2.10 | 0xaa8c | No error (0) | 185.166.143.48 | A (IP address) | IN (0x0001) | false | ||
Dec 12, 2024 17:52:51.537967920 CET | 1.1.1.1 | 192.168.2.10 | 0xaa8c | No error (0) | 185.166.143.50 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49772 | 185.166.143.49 | 443 | 7552 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\csc.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-12 16:52:53 UTC | 101 | OUT | |
2024-12-12 16:52:53 UTC | 5940 | IN |