Windows
Analysis Report
Nueva orden de compra-836528268278278.xlsx.exe
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Nueva orden de compra-836528268278278.xlsx.exe (PID: 7408 cmdline:
"C:\Users\ user\Deskt op\Nueva o rden de co mpra-83652 8268278278 .xlsx.exe" MD5: 7808BA3C5C4B30B69F09C27C8F9CE102)
- cleanup
System Summary |
---|
Source: | Author: Florian Roth (Nextron Systems), @blu3_team (idea), Nasreddine Bencherchali (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-17T08:28:15.142386+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49700 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:18.038694+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49702 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:20.891626+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49708 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:23.756547+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49714 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:26.683834+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49727 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:29.365484+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49735 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:32.202119+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49742 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:35.086248+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49748 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:37.969383+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49759 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:40.699748+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49765 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:43.560484+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49771 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:46.396183+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49778 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:49.299672+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49788 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:51.934901+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49794 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:54.862830+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49800 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:57.521847+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49811 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:00.215479+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49817 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:03.168045+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49823 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:06.296447+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49830 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:09.202629+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49841 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:12.060265+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49847 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:15.131941+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49854 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:17.978153+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49862 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:20.816608+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49870 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:23.740060+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49876 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:26.590812+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49885 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:29.399390+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49893 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:32.256092+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49899 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:35.149572+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49906 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:38.023034+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49915 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:40.900717+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49921 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:43.719725+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49928 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:47.025284+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49935 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:49.872912+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49944 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:52.729996+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49951 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:55.851658+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49957 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:58.694559+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49964 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:01.541486+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49974 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:04.357567+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49980 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:07.022767+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49986 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:09.899877+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49993 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:12.620078+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 49999 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:15.450394+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50009 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:18.133739+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50015 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:20.798050+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50016 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:23.670881+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50017 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:26.512967+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50018 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:29.395556+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50019 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:32.054096+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50020 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:34.951072+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50021 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:37.795208+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50022 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:40.423677+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50023 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:43.066909+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50024 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:45.912184+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50025 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:48.787613+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50026 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:51.603032+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50027 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:54.255183+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50028 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:57.086657+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50029 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:59.915555+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50030 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:02.727522+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50031 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:05.571059+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50032 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:08.483517+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50033 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:11.316499+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.7 | 50034 | 103.191.208.122 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Static PE information: |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Software Packing | NTDS | 12 System Information Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Obfuscated Files or Information | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
56% | Virustotal | Browse | ||
47% | ReversingLabs | Win32.Trojan.Generic | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
rubberpartsmanufacturers.com | 103.191.208.122 | true | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
103.191.208.122 | rubberpartsmanufacturers.com | unknown | 7575 | AARNET-AS-APAustralianAcademicandResearchNetworkAARNe | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1576515 |
Start date and time: | 2024-12-17 08:27:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Run name: | Run with higher sleep bypass |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Nueva orden de compra-836528268278278.xlsx.exe |
Detection: | MAL |
Classification: | mal72.evad.winEXE@1/0@2/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.63, 20.109.210.53, 4.175.87.197
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, time.windows.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target Nueva orden de compra-836528268278278.xlsx.exe, PID 7408 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
103.191.208.122 | Get hash | malicious | MassLogger RAT | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
rubberpartsmanufacturers.com | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AARNET-AS-APAustralianAcademicandResearchNetworkAARNe | Get hash | malicious | MassLogger RAT | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RedLine, SectopRAT | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos | Browse |
| ||
Get hash | malicious | Cobalt Strike, Remcos | Browse |
| ||
Get hash | malicious | Cobalt Strike, FormBook | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 5.664267539604553 |
TrID: |
|
File name: | Nueva orden de compra-836528268278278.xlsx.exe |
File size: | 55'296 bytes |
MD5: | 7808ba3c5c4b30b69f09c27c8f9ce102 |
SHA1: | 06eedadc806872bde7301802c30303077582f0a0 |
SHA256: | 7ba88eaac7e95af49412331870d5f9d2152bdf6937234b0e873d9b17733cf65e |
SHA512: | 91fffa8817c4c011d8afb57383642b914afca137b66e30ebd570c0ad88de11827714e24cc96358c1b8ef2ccadf532835f3bd4e769014734826538236319fb3d3 |
SSDEEP: | 1536:4FpJvyJz6GZvEKI6NeEzB7DoFji9HqOYRDD6:43SZvEKIgeERDo1i5qOWD6 |
TLSH: | 0943395EA3C936A3D9AE0D7BF6913362C331D220A757D357448C5E963CCF7A249A2A01 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....O`g................................. ........@.. .......................@............`................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x40ecea |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67604FA0 [Mon Dec 16 16:04:48 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xeca0 | 0x4a | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x10000 | 0x5ae | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x12000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xccf0 | 0xce00 | 94b4afc38ba0bc0a25d3d01255fb3736 | False | 0.49609375 | data | 5.733265160761475 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x10000 | 0x5ae | 0x600 | e71c8b06adc5752523a66ff6b9d2acba | False | 0.4251302083333333 | data | 4.114638919976024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x12000 | 0xc | 0x200 | f89eae36e648a7fbf4bf5524aa5ff31b | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x1005c | 0x32c | data | 0.4236453201970443 | ||
RT_MANIFEST | 0x103c4 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5489795918367347 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-17T08:28:15.142386+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49700 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:18.038694+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49702 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:20.891626+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49708 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:23.756547+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49714 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:26.683834+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49727 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:29.365484+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49735 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:32.202119+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49742 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:35.086248+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49748 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:37.969383+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49759 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:40.699748+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49765 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:43.560484+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49771 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:46.396183+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49778 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:49.299672+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49788 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:51.934901+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49794 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:54.862830+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49800 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:28:57.521847+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49811 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:00.215479+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49817 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:03.168045+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49823 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:06.296447+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49830 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:09.202629+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49841 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:12.060265+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49847 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:15.131941+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49854 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:17.978153+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49862 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:20.816608+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49870 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:23.740060+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49876 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:26.590812+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49885 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:29.399390+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49893 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:32.256092+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49899 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:35.149572+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49906 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:38.023034+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49915 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:40.900717+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49921 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:43.719725+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49928 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:47.025284+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49935 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:49.872912+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49944 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:52.729996+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49951 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:55.851658+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49957 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:29:58.694559+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49964 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:01.541486+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49974 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:04.357567+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49980 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:07.022767+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49986 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:09.899877+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49993 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:12.620078+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 49999 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:15.450394+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50009 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:18.133739+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50015 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:20.798050+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50016 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:23.670881+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50017 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:26.512967+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50018 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:29.395556+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50019 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:32.054096+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50020 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:34.951072+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50021 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:37.795208+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50022 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:40.423677+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50023 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:43.066909+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50024 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:45.912184+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50025 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:48.787613+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50026 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:51.603032+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50027 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:54.255183+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50028 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:57.086657+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50029 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:30:59.915555+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50030 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:02.727522+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50031 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:05.571059+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50032 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:08.483517+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50033 | 103.191.208.122 | 443 | TCP |
2024-12-17T08:31:11.316499+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.7 | 50034 | 103.191.208.122 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 17, 2024 08:28:08.827210903 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:08.827266932 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:08.827770948 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:09.298983097 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:09.299010038 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:11.293708086 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:11.293823004 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:11.297583103 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:11.297595978 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:11.297899008 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:11.349190950 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:11.370176077 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:11.411333084 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:12.191566944 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:12.191649914 CET | 443 | 49699 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:12.191714048 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:12.214627028 CET | 49699 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:12.220931053 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:12.220974922 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:12.221033096 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:12.221270084 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:12.221281052 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:14.236768007 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:14.239375114 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:14.239391088 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:15.142421961 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:15.142494917 CET | 443 | 49700 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:15.142570019 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:15.143203974 CET | 49700 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:15.143692970 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:15.143703938 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:15.143767118 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:15.144020081 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:15.144027948 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:17.132770061 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:17.140695095 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:17.140767097 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:18.038809061 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:18.039000034 CET | 443 | 49702 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:18.039252996 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:18.039571047 CET | 49702 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:18.040249109 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:18.040292025 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:18.040390015 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:18.040666103 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:18.040678978 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.010107040 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.038924932 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.038968086 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.891623020 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.891704082 CET | 443 | 49708 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.891748905 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.892550945 CET | 49708 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.893546104 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.893594027 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:20.893652916 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.894143105 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:20.894157887 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:22.870122910 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:22.871900082 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:22.871925116 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:23.756633997 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:23.756800890 CET | 443 | 49714 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:23.756889105 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:23.757396936 CET | 49714 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:23.757884979 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:23.757927895 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:23.757987022 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:23.759057045 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:23.759073019 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:25.792732000 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:25.800394058 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:25.800415039 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:26.683934927 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:26.684104919 CET | 443 | 49727 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:26.684156895 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:26.684480906 CET | 49727 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:26.684976101 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:26.685018063 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:26.685151100 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:26.685426950 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:26.685441017 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:28.477107048 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:28.521059036 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:28.640877962 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:28.640897036 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:29.365509987 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:29.365592003 CET | 443 | 49735 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:29.365684032 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:29.366291046 CET | 49735 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:29.366950035 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:29.366997957 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:29.367079973 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:29.367290020 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:29.367306948 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:31.325855970 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:31.333293915 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:31.333322048 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:32.202204943 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:32.202373028 CET | 443 | 49742 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:32.202450991 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:32.202825069 CET | 49742 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:32.203347921 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:32.203387022 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:32.203454971 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:32.203682899 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:32.203700066 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:34.179436922 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:34.188823938 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:34.188863039 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:35.086066008 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:35.086133003 CET | 443 | 49748 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:35.086194038 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:35.086632967 CET | 49748 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:35.087130070 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:35.087162018 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:35.087234020 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:35.087434053 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:35.087438107 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.083682060 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.085128069 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.085148096 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.969422102 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.969495058 CET | 443 | 49759 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.969597101 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.975873947 CET | 49759 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.976571083 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.976640940 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:37.976727962 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.977046013 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:37.977066994 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:39.779409885 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:39.819590092 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:39.819638014 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:40.699753046 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:40.699815989 CET | 443 | 49765 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:40.699856043 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:40.700438023 CET | 49765 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:40.701682091 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:40.701714993 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:40.701785088 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:40.702147961 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:40.702161074 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:42.673531055 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:42.676233053 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:42.676251888 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:43.560566902 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:43.560755014 CET | 443 | 49771 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:43.560874939 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:43.561255932 CET | 49771 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:43.561849117 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:43.561882019 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:43.561958075 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:43.562277079 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:43.562294960 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:45.518834114 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:45.521008015 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:45.521028996 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:46.396203995 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:46.396286964 CET | 443 | 49778 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:46.396358013 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:46.396817923 CET | 49778 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:46.397301912 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:46.397352934 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:46.397553921 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:46.397810936 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:46.397820950 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:48.363821030 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:48.385221958 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:48.385237932 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:49.299683094 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:49.299776077 CET | 443 | 49788 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:49.299843073 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:49.300314903 CET | 49788 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:49.300879002 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:49.301001072 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:49.301103115 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:49.301373005 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:49.301413059 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.068703890 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.077074051 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:51.077147961 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.934916019 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.934987068 CET | 443 | 49794 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.935101032 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:51.973783970 CET | 49794 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:51.980882883 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:51.980923891 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:51.980992079 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:52.006329060 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:52.006347895 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:53.977114916 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:53.978749037 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:53.978775024 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:54.862853050 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:54.862934113 CET | 443 | 49800 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:54.862987995 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:54.863424063 CET | 49800 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:54.863929987 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:54.863960028 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:54.864037037 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:54.864248991 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:54.864263058 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:56.639103889 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:56.640733004 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:56.640779972 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:57.521838903 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:57.521918058 CET | 443 | 49811 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:57.521967888 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:57.522413015 CET | 49811 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:57.522906065 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:57.522942066 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:57.523011923 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:57.523226023 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:57.523240089 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:59.319410086 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:28:59.321185112 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:28:59.321213961 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:00.215507030 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:00.215579033 CET | 443 | 49817 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:00.215639114 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:00.216140985 CET | 49817 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:00.216654062 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:00.216707945 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:00.216784954 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:00.216993093 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:00.217006922 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:02.284487009 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:02.286077976 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:02.286102057 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:03.168073893 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:03.168157101 CET | 443 | 49823 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:03.168236971 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:03.168704033 CET | 49823 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:03.169250011 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:03.169286966 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:03.169353008 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:03.169615984 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:03.169629097 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:05.131449938 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:05.138765097 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:05.138782024 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:06.296473026 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:06.296557903 CET | 443 | 49830 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:06.296607018 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:06.297147036 CET | 49830 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:06.297771931 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:06.297797918 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:06.297871113 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:06.298255920 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:06.298273087 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:08.279983044 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:08.286519051 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:08.286561012 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:09.202656031 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:09.202733040 CET | 443 | 49841 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:09.202796936 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:09.203193903 CET | 49841 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:09.203680038 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:09.203736067 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:09.203814030 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:09.204009056 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:09.204024076 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:11.201328993 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:11.214951038 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:11.214975119 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:12.060308933 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:12.060411930 CET | 443 | 49847 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:12.060470104 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:12.068418026 CET | 49847 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:12.090212107 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:12.090246916 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:12.090333939 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:12.099383116 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:12.099406958 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:13.909575939 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:13.924428940 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:13.924448013 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:15.131949902 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:15.132020950 CET | 443 | 49854 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:15.132088900 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:15.139025927 CET | 49854 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:15.149436951 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:15.149477959 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:15.149585009 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:15.153312922 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:15.153325081 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.117089987 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.119330883 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.119349957 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.978163958 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.978250027 CET | 443 | 49862 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.978557110 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.979173899 CET | 49862 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.979527950 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.979574919 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:17.979651928 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.979939938 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:17.979953051 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:19.952899933 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:19.954474926 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:19.954495907 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:20.816689014 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:20.816878080 CET | 443 | 49870 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:20.816962957 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:20.817398071 CET | 49870 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:20.817971945 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:20.817989111 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:20.818063974 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:20.818325996 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:20.818334103 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:22.855732918 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:22.857292891 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:22.857323885 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:23.740106106 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:23.740191936 CET | 443 | 49876 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:23.740240097 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:23.740603924 CET | 49876 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:23.741096020 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:23.741134882 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:23.741210938 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:23.741400957 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:23.741410971 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:25.707818985 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:25.710350990 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:25.710375071 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:26.590837955 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:26.590924978 CET | 443 | 49885 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:26.591099977 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:26.591520071 CET | 49885 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:26.592150927 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:26.592206001 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:26.592313051 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:26.592555046 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:26.592583895 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:28.538824081 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:28.540371895 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:28.540410042 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:29.399426937 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:29.399523973 CET | 443 | 49893 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:29.399588108 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:29.400039911 CET | 49893 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:29.400527954 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:29.400578976 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:29.400662899 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:29.400876045 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:29.400895119 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:31.371275902 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:31.390599966 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:31.390613079 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:32.256154060 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:32.256258011 CET | 443 | 49899 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:32.256335020 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:32.256987095 CET | 49899 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:32.257347107 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:32.257369041 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:32.257467985 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:32.257750034 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:32.257761002 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:34.235955000 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:34.237447023 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:34.237466097 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:35.149590969 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:35.149687052 CET | 443 | 49906 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:35.149806023 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:35.150402069 CET | 49906 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:35.151068926 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:35.151103020 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:35.151207924 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:35.151488066 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:35.151498079 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:37.131699085 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:37.134078026 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:37.134098053 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:38.023065090 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:38.023159981 CET | 443 | 49915 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:38.023205042 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:38.023747921 CET | 49915 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:38.024296999 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:38.024336100 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:38.024411917 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:38.024601936 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:38.024620056 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.004534960 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.052702904 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.061309099 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.061336040 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.900831938 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.901032925 CET | 443 | 49921 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.901081085 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.904167891 CET | 49921 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.905180931 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.905245066 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:40.905307055 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.905791998 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:40.905812025 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:42.861203909 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:42.862966061 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:42.863058090 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:43.719760895 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:43.719862938 CET | 443 | 49928 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:43.719940901 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:43.720546007 CET | 49928 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:43.721021891 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:43.721067905 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:43.721138000 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:43.721396923 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:43.721407890 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:45.706558943 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:45.708524942 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:45.708612919 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:47.025307894 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:47.025398970 CET | 443 | 49935 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:47.025464058 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:47.025861025 CET | 49935 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:47.026628971 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:47.026675940 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:47.026820898 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:47.027195930 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:47.027218103 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:48.991569042 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:48.994592905 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:48.994611979 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:49.872890949 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:49.872992039 CET | 443 | 49944 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:49.873189926 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:49.873640060 CET | 49944 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:49.874510050 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:49.874557018 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:49.874646902 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:49.874972105 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:49.874986887 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:51.845410109 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:51.847774029 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:51.847796917 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:52.730015039 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:52.730098009 CET | 443 | 49951 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:52.730187893 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:52.733777046 CET | 49951 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:52.739902973 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:52.739993095 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:52.740082979 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:52.746123075 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:52.746161938 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:54.729358912 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:54.730907917 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:54.730933905 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:55.851753950 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:55.851922989 CET | 443 | 49957 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:55.852065086 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:55.852315903 CET | 49957 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:55.852806091 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:55.852854967 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:55.852936983 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:55.853143930 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:55.853156090 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:57.815752983 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:57.817759037 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:57.817770958 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:58.694544077 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:58.694639921 CET | 443 | 49964 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:58.694708109 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:58.695180893 CET | 49964 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:58.695816040 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:58.695868969 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:29:58.696177959 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:58.696177959 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:29:58.696213007 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:00.670151949 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:00.672281027 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:00.672327995 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:01.541625977 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:01.541829109 CET | 443 | 49974 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:01.541898966 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:01.542265892 CET | 49974 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:01.542794943 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:01.542844057 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:01.542926073 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:01.543169975 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:01.543184996 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:03.493976116 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:03.496478081 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:03.496512890 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:04.357527971 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:04.357620955 CET | 443 | 49980 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:04.357726097 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:04.358422995 CET | 49980 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:04.358937979 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:04.358975887 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:04.359066010 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:04.359287024 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:04.359299898 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:06.141633987 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:06.143631935 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:06.143667936 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:07.022897005 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:07.023093939 CET | 443 | 49986 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:07.023174047 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:07.023492098 CET | 49986 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:07.024029970 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:07.024090052 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:07.024180889 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:07.024384022 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:07.024400949 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.010992050 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.013405085 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.013432026 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.899902105 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.899977922 CET | 443 | 49993 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.900049925 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.900476933 CET | 49993 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.901475906 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.901515961 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:09.901597977 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.901797056 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:09.901803970 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:11.735527039 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:11.737160921 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:11.737171888 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:12.620107889 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:12.620209932 CET | 443 | 49999 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:12.620269060 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:12.620743990 CET | 49999 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:12.621227026 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:12.621270895 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:12.621346951 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:12.621577024 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:12.621589899 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:14.578255892 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:14.579716921 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:14.579745054 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:15.450419903 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:15.450494051 CET | 443 | 50009 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:15.450617075 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:15.451083899 CET | 50009 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:15.451656103 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:15.451708078 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:15.451780081 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:15.452020884 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:15.452038050 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:17.242954969 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:17.244581938 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:17.244611979 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:18.133760929 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:18.133831978 CET | 443 | 50015 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:18.133903980 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:18.134430885 CET | 50015 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:18.135123014 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:18.135180950 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:18.135265112 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:18.135538101 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:18.135559082 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:19.912827015 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:19.915213108 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:19.915241957 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:20.797815084 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:20.797885895 CET | 443 | 50016 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:20.798031092 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:20.798553944 CET | 50016 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:20.802860022 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:20.802907944 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:20.803016901 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:20.806854963 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:20.806866884 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:22.780560970 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:22.784214020 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:22.784240961 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:23.670922041 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:23.671009064 CET | 443 | 50017 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:23.671107054 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:23.671633005 CET | 50017 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:23.672398090 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:23.672455072 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:23.672554970 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:23.672831059 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:23.672842979 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:25.634857893 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:25.638997078 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:25.639039993 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:26.513001919 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:26.513083935 CET | 443 | 50018 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:26.513189077 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:26.513684988 CET | 50018 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:26.514240980 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:26.514282942 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:26.514367104 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:26.514576912 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:26.514585018 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:28.525108099 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:28.535691023 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:28.535718918 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:29.395586014 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:29.395667076 CET | 443 | 50019 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:29.396070957 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:29.400377035 CET | 50019 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:29.401068926 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:29.401125908 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:29.401197910 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:29.402086020 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:29.402098894 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:31.174665928 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:31.177154064 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:31.177242994 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:32.054080009 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:32.054148912 CET | 443 | 50020 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:32.054438114 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:32.054847002 CET | 50020 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:32.055481911 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:32.055521011 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:32.055685997 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:32.056118965 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:32.056138992 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.061141014 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.062948942 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.062964916 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.951092005 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.951168060 CET | 443 | 50021 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.951251030 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.951839924 CET | 50021 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.952393055 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.952434063 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:34.952495098 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.952764988 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:34.952779055 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:36.916573048 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:36.920593023 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:36.920612097 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:37.795223951 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:37.795300961 CET | 443 | 50022 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:37.795499086 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:37.795872927 CET | 50022 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:37.796535015 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:37.796581030 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:37.797383070 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:37.797383070 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:37.797420979 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:39.556442976 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:39.558227062 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:39.558242083 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:40.423628092 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:40.423693895 CET | 443 | 50023 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:40.423747063 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:40.424181938 CET | 50023 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:40.424688101 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:40.424814939 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:40.424906969 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:40.425265074 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:40.425302982 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:42.192281008 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:42.194444895 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:42.194511890 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:43.066740036 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:43.066800117 CET | 443 | 50024 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:43.066975117 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:43.067384005 CET | 50024 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:43.067858934 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:43.067900896 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:43.067981005 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:43.068186045 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:43.068200111 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.036724091 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.039274931 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.039285898 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.912193060 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.912262917 CET | 443 | 50025 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.912458897 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.913309097 CET | 50025 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.914686918 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.914792061 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:45.914957047 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.915592909 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:45.915627003 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:47.910722017 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:47.912281036 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:47.912350893 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:48.787571907 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:48.787626982 CET | 443 | 50026 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:48.787801027 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:48.788135052 CET | 50026 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:48.788655043 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:48.788757086 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:48.788846970 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:48.789066076 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:48.789103031 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:50.737798929 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:50.739784002 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:50.739816904 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:51.603063107 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:51.603194952 CET | 443 | 50027 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:51.603262901 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:51.603641033 CET | 50027 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:51.604171991 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:51.604202986 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:51.604274035 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:51.604487896 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:51.604496956 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:53.378511906 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:53.380335093 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:53.380371094 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:54.255153894 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:54.255239964 CET | 443 | 50028 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:54.255290985 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:54.267950058 CET | 50028 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:54.268548012 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:54.268600941 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:54.268726110 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:54.273981094 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:54.273998976 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:56.222362995 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:56.224407911 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:56.224436045 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:57.086654902 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:57.086735964 CET | 443 | 50029 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:57.086807013 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:57.087342978 CET | 50029 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:57.087937117 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:57.087985039 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:57.088068962 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:57.088306904 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:57.088320017 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.039237976 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.040844917 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.040887117 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.915597916 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.915676117 CET | 443 | 50030 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.915735960 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.916158915 CET | 50030 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.916697025 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.916749954 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:30:59.916851997 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.917057037 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:30:59.917072058 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:01.864816904 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:01.866708040 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:01.866739035 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:02.727523088 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:02.727601051 CET | 443 | 50031 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:02.727689028 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:02.728167057 CET | 50031 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:02.728733063 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:02.728782892 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:02.728869915 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:02.729213953 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:02.729223967 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:04.692608118 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:04.696465969 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:04.696500063 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:05.571088076 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:05.571151972 CET | 443 | 50032 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:05.571208000 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:05.571722984 CET | 50032 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:05.572346926 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:05.572448015 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:05.572540045 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:05.572875977 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:05.572915077 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:07.532674074 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:07.534456968 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:07.534499884 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:08.483545065 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:08.483632088 CET | 443 | 50033 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:08.483773947 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:08.484364033 CET | 50033 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:08.485102892 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:08.485150099 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:08.485238075 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:08.485513926 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:08.485527992 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:10.443398952 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:10.451415062 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:10.451447964 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:11.316510916 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:11.316585064 CET | 443 | 50034 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:11.316648006 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:11.317193031 CET | 50034 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:11.317914009 CET | 50035 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:11.317976952 CET | 443 | 50035 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:11.318053961 CET | 50035 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:11.318330050 CET | 50035 | 443 | 192.168.2.7 | 103.191.208.122 |
Dec 17, 2024 08:31:11.318347931 CET | 443 | 50035 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:13.266385078 CET | 443 | 50035 | 103.191.208.122 | 192.168.2.7 |
Dec 17, 2024 08:31:13.318644047 CET | 50035 | 443 | 192.168.2.7 | 103.191.208.122 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 17, 2024 08:28:07.253300905 CET | 63131 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 17, 2024 08:28:08.240236044 CET | 63131 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 17, 2024 08:28:08.692390919 CET | 53 | 63131 | 1.1.1.1 | 192.168.2.7 |
Dec 17, 2024 08:28:08.692404032 CET | 53 | 63131 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 17, 2024 08:28:07.253300905 CET | 192.168.2.7 | 1.1.1.1 | 0x30c8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 17, 2024 08:28:08.240236044 CET | 192.168.2.7 | 1.1.1.1 | 0x30c8 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 17, 2024 08:28:08.692390919 CET | 1.1.1.1 | 192.168.2.7 | 0x30c8 | No error (0) | 103.191.208.122 | A (IP address) | IN (0x0001) | false | ||
Dec 17, 2024 08:28:08.692404032 CET | 1.1.1.1 | 192.168.2.7 | 0x30c8 | No error (0) | 103.191.208.122 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49699 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:11 UTC | 96 | OUT | |
2024-12-17 07:28:12 UTC | 164 | IN | |
2024-12-17 07:28:12 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49700 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:14 UTC | 72 | OUT | |
2024-12-17 07:28:15 UTC | 164 | IN | |
2024-12-17 07:28:15 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49702 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:17 UTC | 72 | OUT | |
2024-12-17 07:28:18 UTC | 164 | IN | |
2024-12-17 07:28:18 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49708 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:20 UTC | 72 | OUT | |
2024-12-17 07:28:20 UTC | 164 | IN | |
2024-12-17 07:28:20 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49714 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:22 UTC | 72 | OUT | |
2024-12-17 07:28:23 UTC | 164 | IN | |
2024-12-17 07:28:23 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49727 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:25 UTC | 72 | OUT | |
2024-12-17 07:28:26 UTC | 164 | IN | |
2024-12-17 07:28:26 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49735 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:28 UTC | 72 | OUT | |
2024-12-17 07:28:29 UTC | 164 | IN | |
2024-12-17 07:28:29 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49742 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:31 UTC | 72 | OUT | |
2024-12-17 07:28:32 UTC | 164 | IN | |
2024-12-17 07:28:32 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49748 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:34 UTC | 72 | OUT | |
2024-12-17 07:28:35 UTC | 164 | IN | |
2024-12-17 07:28:35 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49759 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:37 UTC | 72 | OUT | |
2024-12-17 07:28:37 UTC | 164 | IN | |
2024-12-17 07:28:37 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49765 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:39 UTC | 72 | OUT | |
2024-12-17 07:28:40 UTC | 164 | IN | |
2024-12-17 07:28:40 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49771 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:42 UTC | 72 | OUT | |
2024-12-17 07:28:43 UTC | 164 | IN | |
2024-12-17 07:28:43 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49778 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:45 UTC | 72 | OUT | |
2024-12-17 07:28:46 UTC | 164 | IN | |
2024-12-17 07:28:46 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49788 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:48 UTC | 72 | OUT | |
2024-12-17 07:28:49 UTC | 164 | IN | |
2024-12-17 07:28:49 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 49794 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:51 UTC | 72 | OUT | |
2024-12-17 07:28:51 UTC | 164 | IN | |
2024-12-17 07:28:51 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 49800 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:53 UTC | 72 | OUT | |
2024-12-17 07:28:54 UTC | 164 | IN | |
2024-12-17 07:28:54 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.7 | 49811 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:56 UTC | 72 | OUT | |
2024-12-17 07:28:57 UTC | 164 | IN | |
2024-12-17 07:28:57 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.7 | 49817 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:28:59 UTC | 72 | OUT | |
2024-12-17 07:29:00 UTC | 164 | IN | |
2024-12-17 07:29:00 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.7 | 49823 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:02 UTC | 72 | OUT | |
2024-12-17 07:29:03 UTC | 164 | IN | |
2024-12-17 07:29:03 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.7 | 49830 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:05 UTC | 72 | OUT | |
2024-12-17 07:29:06 UTC | 164 | IN | |
2024-12-17 07:29:06 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.7 | 49841 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:08 UTC | 72 | OUT | |
2024-12-17 07:29:09 UTC | 164 | IN | |
2024-12-17 07:29:09 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.7 | 49847 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:11 UTC | 72 | OUT | |
2024-12-17 07:29:12 UTC | 164 | IN | |
2024-12-17 07:29:12 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.7 | 49854 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:13 UTC | 72 | OUT | |
2024-12-17 07:29:15 UTC | 164 | IN | |
2024-12-17 07:29:15 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.7 | 49862 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:17 UTC | 72 | OUT | |
2024-12-17 07:29:17 UTC | 164 | IN | |
2024-12-17 07:29:17 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.7 | 49870 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:19 UTC | 72 | OUT | |
2024-12-17 07:29:20 UTC | 164 | IN | |
2024-12-17 07:29:20 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.7 | 49876 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:22 UTC | 72 | OUT | |
2024-12-17 07:29:23 UTC | 164 | IN | |
2024-12-17 07:29:23 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.7 | 49885 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:25 UTC | 72 | OUT | |
2024-12-17 07:29:26 UTC | 164 | IN | |
2024-12-17 07:29:26 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.7 | 49893 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:28 UTC | 72 | OUT | |
2024-12-17 07:29:29 UTC | 164 | IN | |
2024-12-17 07:29:29 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.7 | 49899 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:31 UTC | 72 | OUT | |
2024-12-17 07:29:32 UTC | 164 | IN | |
2024-12-17 07:29:32 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.7 | 49906 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:34 UTC | 72 | OUT | |
2024-12-17 07:29:35 UTC | 164 | IN | |
2024-12-17 07:29:35 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.7 | 49915 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:37 UTC | 72 | OUT | |
2024-12-17 07:29:38 UTC | 164 | IN | |
2024-12-17 07:29:38 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.7 | 49921 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:40 UTC | 72 | OUT | |
2024-12-17 07:29:40 UTC | 164 | IN | |
2024-12-17 07:29:40 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.7 | 49928 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:42 UTC | 72 | OUT | |
2024-12-17 07:29:43 UTC | 164 | IN | |
2024-12-17 07:29:43 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.7 | 49935 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:45 UTC | 72 | OUT | |
2024-12-17 07:29:47 UTC | 164 | IN | |
2024-12-17 07:29:47 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.7 | 49944 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:48 UTC | 72 | OUT | |
2024-12-17 07:29:49 UTC | 164 | IN | |
2024-12-17 07:29:49 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.7 | 49951 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:51 UTC | 72 | OUT | |
2024-12-17 07:29:52 UTC | 164 | IN | |
2024-12-17 07:29:52 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.7 | 49957 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:54 UTC | 72 | OUT | |
2024-12-17 07:29:55 UTC | 164 | IN | |
2024-12-17 07:29:55 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.7 | 49964 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:29:57 UTC | 72 | OUT | |
2024-12-17 07:29:58 UTC | 164 | IN | |
2024-12-17 07:29:58 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.7 | 49974 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:00 UTC | 72 | OUT | |
2024-12-17 07:30:01 UTC | 164 | IN | |
2024-12-17 07:30:01 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.7 | 49980 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:03 UTC | 72 | OUT | |
2024-12-17 07:30:04 UTC | 164 | IN | |
2024-12-17 07:30:04 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.7 | 49986 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:06 UTC | 72 | OUT | |
2024-12-17 07:30:07 UTC | 164 | IN | |
2024-12-17 07:30:07 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.7 | 49993 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:09 UTC | 72 | OUT | |
2024-12-17 07:30:09 UTC | 164 | IN | |
2024-12-17 07:30:09 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.7 | 49999 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:11 UTC | 72 | OUT | |
2024-12-17 07:30:12 UTC | 164 | IN | |
2024-12-17 07:30:12 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.7 | 50009 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:14 UTC | 72 | OUT | |
2024-12-17 07:30:15 UTC | 164 | IN | |
2024-12-17 07:30:15 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.7 | 50015 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:17 UTC | 72 | OUT | |
2024-12-17 07:30:18 UTC | 164 | IN | |
2024-12-17 07:30:18 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.7 | 50016 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:19 UTC | 72 | OUT | |
2024-12-17 07:30:20 UTC | 164 | IN | |
2024-12-17 07:30:20 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.7 | 50017 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:22 UTC | 72 | OUT | |
2024-12-17 07:30:23 UTC | 164 | IN | |
2024-12-17 07:30:23 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.7 | 50018 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:25 UTC | 72 | OUT | |
2024-12-17 07:30:26 UTC | 164 | IN | |
2024-12-17 07:30:26 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.7 | 50019 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:28 UTC | 72 | OUT | |
2024-12-17 07:30:29 UTC | 164 | IN | |
2024-12-17 07:30:29 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.7 | 50020 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:31 UTC | 72 | OUT | |
2024-12-17 07:30:32 UTC | 164 | IN | |
2024-12-17 07:30:32 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.7 | 50021 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:34 UTC | 72 | OUT | |
2024-12-17 07:30:34 UTC | 164 | IN | |
2024-12-17 07:30:34 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.7 | 50022 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:36 UTC | 72 | OUT | |
2024-12-17 07:30:37 UTC | 164 | IN | |
2024-12-17 07:30:37 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.7 | 50023 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:39 UTC | 72 | OUT | |
2024-12-17 07:30:40 UTC | 164 | IN | |
2024-12-17 07:30:40 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.7 | 50024 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:42 UTC | 72 | OUT | |
2024-12-17 07:30:43 UTC | 164 | IN | |
2024-12-17 07:30:43 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.7 | 50025 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:45 UTC | 72 | OUT | |
2024-12-17 07:30:45 UTC | 164 | IN | |
2024-12-17 07:30:45 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.7 | 50026 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:47 UTC | 72 | OUT | |
2024-12-17 07:30:48 UTC | 164 | IN | |
2024-12-17 07:30:48 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.7 | 50027 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:50 UTC | 72 | OUT | |
2024-12-17 07:30:51 UTC | 164 | IN | |
2024-12-17 07:30:51 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.7 | 50028 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:53 UTC | 72 | OUT | |
2024-12-17 07:30:54 UTC | 164 | IN | |
2024-12-17 07:30:54 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.7 | 50029 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:56 UTC | 72 | OUT | |
2024-12-17 07:30:57 UTC | 164 | IN | |
2024-12-17 07:30:57 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.7 | 50030 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:30:59 UTC | 72 | OUT | |
2024-12-17 07:30:59 UTC | 164 | IN | |
2024-12-17 07:30:59 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.7 | 50031 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:31:01 UTC | 72 | OUT | |
2024-12-17 07:31:02 UTC | 164 | IN | |
2024-12-17 07:31:02 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.7 | 50032 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:31:04 UTC | 72 | OUT | |
2024-12-17 07:31:05 UTC | 164 | IN | |
2024-12-17 07:31:05 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.7 | 50033 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:31:07 UTC | 72 | OUT | |
2024-12-17 07:31:08 UTC | 164 | IN | |
2024-12-17 07:31:08 UTC | 315 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.7 | 50034 | 103.191.208.122 | 443 | 7408 | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-17 07:31:10 UTC | 72 | OUT | |
2024-12-17 07:31:11 UTC | 164 | IN | |
2024-12-17 07:31:11 UTC | 315 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 02:28:06 |
Start date: | 17/12/2024 |
Path: | C:\Users\user\Desktop\Nueva orden de compra-836528268278278.xlsx.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd30000 |
File size: | 55'296 bytes |
MD5 hash: | 7808BA3C5C4B30B69F09C27C8F9CE102 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Function 0175098E Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01750860 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01750870 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 017508D7 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0175090F Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01750920 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01750985 Relevance: .0, Instructions: 7COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0175084B Relevance: .0, Instructions: 4COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|