Windows
Analysis Report
WindowsUpdate.exe
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- WindowsUpdate.exe (PID: 6652 cmdline:
"C:\Users\ user\Deskt op\Windows Update.exe " MD5: 375049AE392572882D3402D0678389EF)
- cleanup
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-18T22:52:03.210751+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49731 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:07.200084+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49732 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:14.771106+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49733 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:21.964454+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49736 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:29.287463+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49741 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:36.776166+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49742 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:44.382950+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49743 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:51.956452+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49744 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:59.510929+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49746 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:06.936853+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49763 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:14.336190+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49779 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:21.968112+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49799 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:29.435887+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49816 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:36.668368+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49835 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:43.978487+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49853 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:51.218394+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49869 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:58.505604+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49886 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:54:05.618971+0100 | 2028765 | 3 | Unknown Traffic | 192.168.2.4 | 49905 | 146.56.219.146 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-18T22:52:07.947770+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49732 | TCP |
2024-12-18T22:52:15.525510+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49733 | TCP |
2024-12-18T22:52:22.696537+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49736 | TCP |
2024-12-18T22:52:30.023519+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49741 | TCP |
2024-12-18T22:52:37.532557+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49742 | TCP |
2024-12-18T22:52:45.142764+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49743 | TCP |
2024-12-18T22:52:52.708825+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49744 | TCP |
2024-12-18T22:53:00.248345+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49746 | TCP |
2024-12-18T22:53:07.673380+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49763 | TCP |
2024-12-18T22:53:15.082077+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49779 | TCP |
2024-12-18T22:53:22.780642+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49799 | TCP |
2024-12-18T22:53:30.195703+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49816 | TCP |
2024-12-18T22:53:37.399876+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49835 | TCP |
2024-12-18T22:53:44.714622+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49853 | TCP |
2024-12-18T22:53:51.994563+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49869 | TCP |
2024-12-18T22:53:59.239615+0100 | 2033009 | 1 | Malware Command and Control Activity Detected | 146.56.219.146 | 443 | 192.168.2.4 | 49886 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-18T22:52:04.652742+0100 | 2035442 | 1 | A Network Trojan was detected | 146.56.219.146 | 443 | 192.168.2.4 | 49731 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Binary or memory string: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00000217700B0B84 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00007FF7300A1190 |
Source: | Code function: | 0_2_00000217700D5FB0 | |
Source: | Code function: | 0_2_00000217700BA090 | |
Source: | Code function: | 0_2_00000217700CB1E0 | |
Source: | Code function: | 0_2_00000217700D8200 | |
Source: | Code function: | 0_2_00000217700B52D0 | |
Source: | Code function: | 0_2_00000217700D76A0 | |
Source: | Code function: | 0_2_00000217700BE350 | |
Source: | Code function: | 0_2_00000217700D6360 | |
Source: | Code function: | 0_2_00000217700D3370 | |
Source: | Code function: | 0_2_00000217700EF3A8 | |
Source: | Code function: | 0_2_00000217700B63F0 | |
Source: | Code function: | 0_2_00000217700D848B | |
Source: | Code function: | 0_2_00000217700D76B0 | |
Source: | Code function: | 0_2_00000217700B9500 | |
Source: | Code function: | 0_2_00000217700B6570 | |
Source: | Code function: | 0_2_00000217700D856F | |
Source: | Code function: | 0_2_00000217700D4660 | |
Source: | Code function: | 0_2_00000217700D8658 | |
Source: | Code function: | 0_2_00000217700D76C0 | |
Source: | Code function: | 0_2_00000217700B5700 | |
Source: | Code function: | 0_2_00000217700DE6F8 | |
Source: | Code function: | 0_2_00000217700C77A0 | |
Source: | Code function: | 0_2_00000217700D47E0 | |
Source: | Code function: | 0_2_00000217700CF820 | |
Source: | Code function: | 0_2_00000217700D8897 | |
Source: | Code function: | 0_2_00000217700DA8B0 | |
Source: | Code function: | 0_2_00000217700D09A0 | |
Source: | Code function: | 0_2_00000217700C09A0 | |
Source: | Code function: | 0_2_00000217700D69C0 | |
Source: | Code function: | 0_2_00000217700B59D0 | |
Source: | Code function: | 0_2_00000217700D7A20 | |
Source: | Code function: | 0_2_00000217700DAA44 | |
Source: | Code function: | 0_2_00000217700D76D0 | |
Source: | Code function: | 0_2_00000217700B4B50 | |
Source: | Code function: | 0_2_00000217700D2B80 | |
Source: | Code function: | 0_2_00000217700B6C50 | |
Source: | Code function: | 0_2_00000217700C7CC0 | |
Source: | Code function: | 0_2_00000217700D5CF0 | |
Source: | Code function: | 0_2_00000217700D7D40 | |
Source: | Code function: | 0_2_00000217700D4E70 |
Source: | Classification label: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_3_0000021771C540D4 | |
Source: | Code function: | 0_3_0000021771C56F7D | |
Source: | Code function: | 0_3_0000021771C56FAA | |
Source: | Code function: | 0_3_0000021771C54302 | |
Source: | Code function: | 0_3_0000021771C551C7 | |
Source: | Code function: | 0_3_0000021771C513B3 | |
Source: | Code function: | 0_3_0000021771C55881 | |
Source: | Code function: | 0_3_0000021771C51A35 | |
Source: | Code function: | 0_3_0000021771C58C48 | |
Source: | Code function: | 0_3_0000021771C57C43 | |
Source: | Code function: | 0_3_0000021771C58C5F | |
Source: | Code function: | 0_3_0000021771C58C27 | |
Source: | Code function: | 0_3_0000021771C52C4A | |
Source: | Code function: | 0_3_0000021771C51BB5 | |
Source: | Code function: | 0_3_0000021771C51BB5 | |
Source: | Code function: | 0_3_0000021771C55E7B | |
Source: | Code function: | 0_3_0000021771C51E26 | |
Source: | Code function: | 0_2_00000217700B0207 | |
Source: | Code function: | 0_2_00000217700AFEEA |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 0_2_00007FF7300A21A8 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF7300A21A8 | |
Source: | Code function: | 0_2_00007FF7300A2350 | |
Source: | Code function: | 0_2_00007FF7300A1CB4 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | NtProtectVirtualMemory: | Jump to behavior | ||
Source: | NtResumeThread: | Jump to behavior | ||
Source: | NtQueueApcThread: | Jump to behavior | ||
Source: | NtCreateThreadEx: | Jump to behavior | ||
Source: | NtProtectVirtualMemory: | Jump to behavior |
Source: | Code function: | 0_2_00007FF7300A2080 |
Source: | Code function: | 0_2_00000217700AB050 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Abuse Elevation Control Mechanism | 1 Abuse Elevation Control Mechanism | OS Credential Dumping | 1 System Time Discovery | Remote Services | 11 Archive Collected Data | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 2 Obfuscated Files or Information | LSASS Memory | 1 Query Registry | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 11 Security Software Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | 1 Account Discovery | Distributed Component Object Model | Input Capture | 12 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 1 System Owner/User Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 2 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
146.56.219.146 | unknown | China | 45090 | CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompa | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1577955 |
Start date and time: | 2024-12-18 22:51:06 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 17s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | WindowsUpdate.exe |
Detection: | MAL |
Classification: | mal64.evad.winEXE@1/0@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 20.12.23.50, 13.107.246.63
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
- VT rate limit hit for: WindowsUpdate.exe
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CNNIC-TENCENT-NET-APShenzhenTencentComputerSystemsCompa | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
51c64c77e60f3980eea90869b68c58a8 | Get hash | malicious | Socks5Systemz | Browse |
| |
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
| ||
Get hash | malicious | Socks5Systemz | Browse |
|
File type: | |
Entropy (8bit): | 5.591432751472315 |
TrID: |
|
File name: | WindowsUpdate.exe |
File size: | 15'360 bytes |
MD5: | 375049ae392572882d3402d0678389ef |
SHA1: | a3534e4451f28d4162e2d39dd70ef7b4496d4807 |
SHA256: | 7d598c046110849932052e38c67071473753e809cb5d55d2223226e810b1475a |
SHA512: | 5e37a2c009f43516f91ca4c0eef2bb7baea2392bd65005b183718ab2e9e5f07fa4d86e1b67abf0f6d3a49f1c228f0583fb4046167dbd84b0057778c0d0bf2a69 |
SSDEEP: | 192:G3TQOAzI2rxNQPJ8+JeuB3GlM3Q5tfroKD14W18gi6a0H1IjHd:W2zQPJ8i5B3t3SD1t3m7d |
TLSH: | DD625D8ABDA705FEF1180675CD334F55D2BA7510076253C70391A1650EA36E1367F6CE |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m..j)..9)..9)..9 .q9#..9...8*..9...8:..9...8#..9...8*..9Y .8+..9)..9...90..8/..90..8(..90..9(..90..8(..9Rich)..9............... |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x140001ca0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x67613436 [Tue Dec 17 08:20:06 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 4ff98788b6fefb0963649625d2cc7416 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F89D095788Ch |
dec eax |
add esp, 28h |
jmp 00007F89D0957327h |
int3 |
int3 |
inc eax |
push ebx |
dec eax |
sub esp, 20h |
dec eax |
mov ebx, ecx |
xor ecx, ecx |
call dword ptr [0000135Bh] |
dec eax |
mov ecx, ebx |
call dword ptr [0000134Ah] |
call dword ptr [00001354h] |
dec eax |
mov ecx, eax |
mov edx, C0000409h |
dec eax |
add esp, 20h |
pop ebx |
dec eax |
jmp dword ptr [00001388h] |
dec eax |
mov dword ptr [esp+08h], ecx |
dec eax |
sub esp, 38h |
mov ecx, 00000017h |
call dword ptr [0000136Ch] |
test eax, eax |
je 00007F89D09574B9h |
mov ecx, 00000002h |
int 29h |
dec eax |
lea ecx, dword ptr [00002C72h] |
call 00007F89D095755Eh |
dec eax |
mov eax, dword ptr [esp+38h] |
dec eax |
mov dword ptr [00002D59h], eax |
dec eax |
lea eax, dword ptr [esp+38h] |
dec eax |
add eax, 08h |
dec eax |
mov dword ptr [00002CE9h], eax |
dec eax |
mov eax, dword ptr [00002D42h] |
dec eax |
mov dword ptr [00002BB3h], eax |
dec eax |
mov eax, dword ptr [esp+40h] |
dec eax |
mov dword ptr [00002CB7h], eax |
mov dword ptr [00002B8Dh], C0000409h |
mov dword ptr [00002B87h], 00000001h |
mov dword ptr [00002B91h], 00000001h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3944 | 0xa0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6000 | 0x1e0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x5000 | 0x1b0 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x7000 | 0x30 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x33f0 | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x32b0 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x3000 | 0x190 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x178c | 0x1800 | a06bc94cdb2a6f8da2a0159bf699f626 | False | 0.6280924479166666 | zlib compressed data | 6.284198941816348 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x3000 | 0xfac | 0x1000 | 8b4abf84149e06006579064d111c9aaa | False | 0.389404296875 | data | 4.187288505810747 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x4000 | 0xed8 | 0xa00 | fb11ec925ba45e5f452bc5e581aee40c | False | 0.524609375 | Matlab v4 mat-file (little endian) f\324\377\3772\242\337-\231+, numeric, rows 0, columns 0 | 4.134903482212727 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x5000 | 0x1b0 | 0x200 | deab9599a6751e2b06aba87c8c398346 | False | 0.49609375 | data | 3.262649438066295 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x6000 | 0x1e0 | 0x200 | d223c232889289f7388583adeff234e1 | False | 0.525390625 | data | 4.697597008251789 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x7000 | 0x30 | 0x200 | 5baf708285fe24b733ca12b378119fa4 | False | 0.123046875 | data | 0.7128484083759542 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_MANIFEST | 0x6060 | 0x17d | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5931758530183727 |
DLL | Import |
---|---|
VCRUNTIME140.dll | __current_exception_context, __current_exception, __C_specific_handler, memset, memcpy |
api-ms-win-crt-runtime-l1-1-0.dll | terminate, _seh_filter_exe, _set_app_type, _initialize_onexit_table, _register_thread_local_exe_atexit_callback, _c_exit, _cexit, __p___argv, __p___argc, _crt_atexit, _exit, exit, _initterm_e, _initterm, _get_initial_narrow_environment, _initialize_narrow_environment, _configure_narrow_argv, _register_onexit_function |
api-ms-win-crt-math-l1-1-0.dll | __setusermatherr |
api-ms-win-crt-stdio-l1-1-0.dll | __p__commode, _set_fmode |
api-ms-win-crt-locale-l1-1-0.dll | _configthreadlocale |
api-ms-win-crt-heap-l1-1-0.dll | _set_new_mode |
KERNEL32.dll | GetCurrentThreadId, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcess, GetModuleHandleW, IsDebuggerPresent, InitializeSListHead, GetSystemTimeAsFileTime, RtlCaptureContext, GetCurrentProcessId, QueryPerformanceCounter, IsProcessorFeaturePresent, TerminateProcess |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-18T22:52:03.210751+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49731 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:04.652742+0100 | 2035442 | ET MALWARE Successful Cobalt Strike Shellcode Download (x64) M1 | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49731 | TCP |
2024-12-18T22:52:07.200084+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49732 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:07.947770+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49732 | TCP |
2024-12-18T22:52:14.771106+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49733 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:15.525510+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49733 | TCP |
2024-12-18T22:52:21.964454+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49736 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:22.696537+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49736 | TCP |
2024-12-18T22:52:29.287463+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49741 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:30.023519+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49741 | TCP |
2024-12-18T22:52:36.776166+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49742 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:37.532557+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49742 | TCP |
2024-12-18T22:52:44.382950+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49743 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:45.142764+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49743 | TCP |
2024-12-18T22:52:51.956452+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49744 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:52:52.708825+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49744 | TCP |
2024-12-18T22:52:59.510929+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49746 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:00.248345+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49746 | TCP |
2024-12-18T22:53:06.936853+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49763 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:07.673380+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49763 | TCP |
2024-12-18T22:53:14.336190+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49779 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:15.082077+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49779 | TCP |
2024-12-18T22:53:21.968112+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49799 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:22.780642+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49799 | TCP |
2024-12-18T22:53:29.435887+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49816 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:30.195703+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49816 | TCP |
2024-12-18T22:53:36.668368+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49835 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:37.399876+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49835 | TCP |
2024-12-18T22:53:43.978487+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49853 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:44.714622+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49853 | TCP |
2024-12-18T22:53:51.218394+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49869 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:51.994563+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49869 | TCP |
2024-12-18T22:53:58.505604+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49886 | 146.56.219.146 | 443 | TCP |
2024-12-18T22:53:59.239615+0100 | 2033009 | ET MALWARE Cobalt Strike Malleable C2 JQuery Custom Profile Response | 1 | 146.56.219.146 | 443 | 192.168.2.4 | 49886 | TCP |
2024-12-18T22:54:05.618971+0100 | 2028765 | ET JA3 Hash - [Abuse.ch] Possible Dridex | 3 | 192.168.2.4 | 49905 | 146.56.219.146 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 18, 2024 22:52:01.349164963 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:01.349199057 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:01.349323034 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:01.360709906 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:01.360727072 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:03.210597038 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:03.210751057 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:03.672658920 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:03.672684908 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:03.673738003 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:03.673810959 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:03.686572075 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:03.727359056 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.210458994 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.210558891 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.221580029 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.221602917 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.221681118 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.221693993 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.221743107 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.425523996 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.425774097 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.425789118 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.425851107 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.453901052 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.454140902 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.454149961 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.454226017 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.479160070 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.479331017 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.479341030 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.479394913 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.613475084 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.613672972 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.613704920 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.614113092 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.652745008 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.652935028 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.652955055 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.653033018 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.677866936 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.678062916 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.678073883 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.678241014 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.710832119 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.711010933 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.711020947 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.711081028 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.735569954 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.735663891 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.735675097 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.735827923 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.759457111 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.759638071 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.759648085 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.759726048 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.787254095 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.787503004 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.787513971 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.787563086 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.843909025 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.844219923 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.844253063 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.844345093 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.859724045 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.859899044 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.859910011 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.859965086 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.880713940 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.880872011 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.880881071 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.880932093 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.894196987 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.894330978 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.894340038 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.894530058 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.903481007 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.903583050 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.903592110 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.903779984 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.915386915 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.915543079 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.915576935 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.915751934 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.924407005 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.924597979 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.924607038 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.924665928 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.935447931 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.935551882 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.935561895 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.935606003 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.979587078 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.980062962 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.980076075 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.980144024 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.986665964 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.986958981 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.986968040 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.987042904 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.998096943 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.998209953 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:04.998223066 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:04.998275995 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.006747961 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.006839991 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.006851912 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.006941080 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.015728951 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.015819073 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.015827894 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.015938997 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.040385962 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.040601015 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.040611982 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.040673018 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.054730892 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.054878950 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.054902077 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.054970980 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.063452005 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.065241098 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.065258980 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.065320015 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.071693897 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.071788073 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.071820021 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.072004080 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.079427958 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.079519987 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.079530001 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.079610109 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.087055922 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.087204933 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.087215900 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.087284088 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.105724096 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.105871916 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.105881929 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.105973005 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.112473965 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.112750053 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.112759113 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.112813950 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.117882013 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.117965937 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.117974997 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.118076086 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.124408960 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.124685049 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.124695063 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.124815941 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.129239082 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.129365921 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.129374981 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.129484892 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.134758949 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.134859085 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.134869099 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.134917021 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.139260054 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.139338017 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.139354944 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.139461040 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.145045996 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.145334959 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.145344973 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.145402908 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.149619102 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.149738073 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.149749041 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.149808884 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.153737068 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.153915882 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.153923988 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.154004097 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.229001999 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.229304075 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.229317904 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.229425907 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.233251095 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.233575106 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.233584881 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.233669043 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.247896910 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.247997999 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.248008013 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.248157978 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.251378059 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.251462936 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.251472950 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.251616001 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.255568981 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.255656958 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.255666018 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.255754948 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.258732080 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.258807898 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.258816957 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.258858919 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.261837006 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.261914015 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.261924028 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.261966944 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.265924931 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.266000986 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.266010046 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.266055107 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.268784046 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.268857956 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.268867016 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.268912077 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.271778107 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.271851063 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.271858931 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.271919012 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.275504112 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.275583029 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.275598049 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.275641918 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.278976917 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.279053926 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.279068947 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.279113054 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.281470060 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.281548977 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.281557083 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.281600952 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.284251928 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.284342051 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.284360886 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.284403086 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.287674904 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.287754059 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.287765026 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.287807941 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290314913 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.290395975 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290402889 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.290446997 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290474892 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.290534019 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290664911 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290682077 CET | 443 | 49731 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.290698051 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.290735006 CET | 49731 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.315911055 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.316025019 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:05.316133022 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.316361904 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:05.316395998 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.199949980 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.200083971 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.201150894 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.201205015 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.202534914 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.202588081 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.946510077 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.946696997 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.947412968 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.947498083 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.947535038 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.947573900 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:07.947597980 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.947638988 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.959676981 CET | 49732 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:07.959709883 CET | 443 | 49732 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:12.898381948 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:12.898488998 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:12.898595095 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:12.898925066 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:12.898952961 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:14.770992041 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:14.771106005 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:14.771850109 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:14.771863937 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:14.773528099 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:14.773534060 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:15.524214983 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:15.524470091 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:15.525094986 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:15.525165081 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:15.525182009 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:15.525227070 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:15.525258064 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:15.525305033 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:15.537312031 CET | 49733 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:15.537333012 CET | 443 | 49733 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:20.117263079 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:20.117305040 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:20.117381096 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:20.117640018 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:20.117664099 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:21.964292049 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:21.964453936 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:21.965313911 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:21.965321064 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:21.966581106 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:21.966587067 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:22.695593119 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:22.695662975 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:22.696150064 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:22.696213961 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:22.696224928 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:22.696265936 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:22.696305990 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:22.696362972 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:22.710985899 CET | 49736 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:22.711004972 CET | 443 | 49736 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:27.445502996 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:27.445596933 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:27.445703983 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:27.445993900 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:27.446027040 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:29.287219048 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:29.287462950 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:29.287930965 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:29.287959099 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:29.293752909 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:29.293766975 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:30.022434950 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:30.022511005 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:30.023158073 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:30.023231983 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:30.023242950 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:30.023283005 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:30.023302078 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:30.023353100 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:30.042368889 CET | 49741 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:30.042390108 CET | 443 | 49741 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:34.867197037 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:34.867238045 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:34.867345095 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:34.867685080 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:34.867701054 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:36.775968075 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:36.776165962 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:36.776860952 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:36.776873112 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:36.780607939 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:36.780615091 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.531950951 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.532023907 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:37.532305002 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.532370090 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:37.532386065 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.532413006 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.532428980 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:37.532442093 CET | 443 | 49742 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:37.532457113 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:37.532475948 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:37.532490969 CET | 49742 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:42.508128881 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:42.508220911 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:42.508336067 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:42.508658886 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:42.508692026 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:44.382865906 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:44.382950068 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:44.398631096 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:44.398658991 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:44.411221981 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:44.411235094 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:45.141917944 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:45.142039061 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:45.142611027 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:45.142678022 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:45.142702103 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:45.142750978 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:45.160672903 CET | 49743 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:45.160712004 CET | 443 | 49743 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:49.997499943 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:49.997591972 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:49.997699022 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:50.080321074 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:50.080363035 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:51.956331968 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:51.956451893 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:51.956911087 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:51.956939936 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:51.958188057 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:51.958201885 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:52.708034992 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:52.708141088 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:52.708400965 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:52.708481073 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:52.708523989 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:52.708579063 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:52.708581924 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:52.708631039 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:52.783193111 CET | 49744 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:52.783231020 CET | 443 | 49744 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:57.664016008 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:57.664093018 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:57.664195061 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:57.664468050 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:57.664499998 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:59.510831118 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:59.510929108 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:59.511466980 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:59.511488914 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:52:59.512758017 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:52:59.512769938 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.247515917 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.247629881 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.247968912 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.248049021 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.248080015 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.248126030 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.248136044 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.248188019 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.248244047 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.248281002 CET | 443 | 49746 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:00.248332977 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:00.248333931 CET | 49746 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:05.086261034 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:05.086297035 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:05.086373091 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:05.086745024 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:05.086760044 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:06.936750889 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:06.936852932 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:06.937474012 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:06.937484026 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:06.938821077 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:06.938827038 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.672385931 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.672451973 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:07.673171043 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.673233986 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:07.673245907 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.673263073 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.673312902 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:07.673451900 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:07.673466921 CET | 443 | 49763 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:07.673480034 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:07.673511028 CET | 49763 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:12.476519108 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:12.476557970 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:12.476628065 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:12.477087975 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:12.477099895 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:14.336107016 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:14.336189985 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:14.336678982 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:14.336688042 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:14.337959051 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:14.337963104 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:15.081264019 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:15.081660032 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:15.081803083 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:15.081887960 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:15.081917048 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:15.081990957 CET | 49779 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:15.082007885 CET | 443 | 49779 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:19.836158037 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:19.836227894 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:19.836365938 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:19.836649895 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:19.836685896 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:21.968029976 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:21.968111992 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:21.968753099 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:21.968784094 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:21.971152067 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:21.971164942 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.779733896 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.779838085 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:22.780252934 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.780327082 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:22.780343056 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.780401945 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.780453920 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:22.780498981 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:22.780519962 CET | 443 | 49799 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:22.780530930 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:22.781013012 CET | 49799 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:27.570372105 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:27.570462942 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:27.570554972 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:27.570858955 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:27.570894957 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:29.435770988 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:29.435887098 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:29.436444044 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:29.436470032 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:29.437769890 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:29.437782049 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.194819927 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.195097923 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:30.195282936 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.195372105 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:30.195389986 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.195441008 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.195478916 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:30.195501089 CET | 443 | 49816 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:30.195530891 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:30.195530891 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:30.195590973 CET | 49816 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:34.804744005 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:34.804775953 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:34.804862976 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:34.805120945 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:34.805136919 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:36.668251991 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:36.668368101 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:36.668749094 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:36.668756008 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:36.669976950 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:36.669982910 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:37.398691893 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:37.398763895 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:37.399461031 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:37.399534941 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:37.399558067 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:37.399604082 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:37.399610996 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:37.399662018 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:37.406042099 CET | 49835 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:37.406053066 CET | 443 | 49835 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:42.133281946 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:42.133354902 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:42.133459091 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:42.133737087 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:42.133758068 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:43.978401899 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:43.978487015 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:43.978959084 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:43.978987932 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:43.980150938 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:43.980165958 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:44.713480949 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:44.713748932 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:44.714238882 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:44.714313984 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:44.714346886 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:44.714384079 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:44.714442015 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:44.734730959 CET | 49853 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:44.734761953 CET | 443 | 49853 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:49.305309057 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:49.305373907 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:49.305484056 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:49.305809021 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:49.305824995 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.218111038 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.218394041 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.219022989 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.219033957 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.220444918 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.220454931 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.993292093 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.993386984 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.994168997 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.994247913 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.994256973 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.994306087 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:51.994313955 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:51.994368076 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:52.006045103 CET | 49869 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:52.006057978 CET | 443 | 49869 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:56.664669991 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:56.664721012 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:56.664825916 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:56.665266991 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:56.665282011 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:58.505497932 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:58.505604029 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:58.507895947 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:58.507901907 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:58.509628057 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:58.509634018 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:59.238643885 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:59.238797903 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:59.239408970 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:59.239490986 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:53:59.239628077 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:59.247819901 CET | 49886 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:53:59.247844934 CET | 443 | 49886 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:54:03.773993015 CET | 49905 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:54:03.774029016 CET | 443 | 49905 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:54:03.774113894 CET | 49905 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:54:03.774346113 CET | 49905 | 443 | 192.168.2.4 | 146.56.219.146 |
Dec 18, 2024 22:54:03.774354935 CET | 443 | 49905 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:54:05.618865013 CET | 443 | 49905 | 146.56.219.146 | 192.168.2.4 |
Dec 18, 2024 22:54:05.618971109 CET | 49905 | 443 | 192.168.2.4 | 146.56.219.146 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49731 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:03 UTC | 242 | OUT | |
2024-12-18 21:52:04 UTC | 170 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN | |
2024-12-18 21:52:04 UTC | 8192 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49732 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:07 UTC | 431 | OUT | |
2024-12-18 21:52:07 UTC | 595 | IN | |
2024-12-18 21:52:07 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49733 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:14 UTC | 431 | OUT | |
2024-12-18 21:52:15 UTC | 595 | IN | |
2024-12-18 21:52:15 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49736 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:21 UTC | 431 | OUT | |
2024-12-18 21:52:22 UTC | 595 | IN | |
2024-12-18 21:52:22 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49741 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:29 UTC | 431 | OUT | |
2024-12-18 21:52:30 UTC | 595 | IN | |
2024-12-18 21:52:30 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49742 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:36 UTC | 431 | OUT | |
2024-12-18 21:52:37 UTC | 595 | IN | |
2024-12-18 21:52:37 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49743 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:44 UTC | 431 | OUT | |
2024-12-18 21:52:45 UTC | 595 | IN | |
2024-12-18 21:52:45 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49744 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:51 UTC | 431 | OUT | |
2024-12-18 21:52:52 UTC | 595 | IN | |
2024-12-18 21:52:52 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49746 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:52:59 UTC | 431 | OUT | |
2024-12-18 21:53:00 UTC | 595 | IN | |
2024-12-18 21:53:00 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49763 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:06 UTC | 431 | OUT | |
2024-12-18 21:53:07 UTC | 595 | IN | |
2024-12-18 21:53:07 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49779 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:14 UTC | 431 | OUT | |
2024-12-18 21:53:15 UTC | 595 | IN | |
2024-12-18 21:53:15 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49799 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:21 UTC | 431 | OUT | |
2024-12-18 21:53:22 UTC | 595 | IN | |
2024-12-18 21:53:22 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49816 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:29 UTC | 431 | OUT | |
2024-12-18 21:53:30 UTC | 595 | IN | |
2024-12-18 21:53:30 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49835 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:36 UTC | 431 | OUT | |
2024-12-18 21:53:37 UTC | 595 | IN | |
2024-12-18 21:53:37 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49853 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:43 UTC | 431 | OUT | |
2024-12-18 21:53:44 UTC | 595 | IN | |
2024-12-18 21:53:44 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49869 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:51 UTC | 431 | OUT | |
2024-12-18 21:53:51 UTC | 595 | IN | |
2024-12-18 21:53:51 UTC | 5537 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49886 | 146.56.219.146 | 443 | 6652 | C:\Users\user\Desktop\WindowsUpdate.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-18 21:53:58 UTC | 431 | OUT | |
2024-12-18 21:53:59 UTC | 595 | IN | |
2024-12-18 21:53:59 UTC | 5537 | IN |
Target ID: | 0 |
Start time: | 16:52:00 |
Start date: | 18/12/2024 |
Path: | C:\Users\user\Desktop\WindowsUpdate.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7300a0000 |
File size: | 15'360 bytes |
MD5 hash: | 375049AE392572882D3402D0678389EF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 1.5% |
Dynamic/Decrypted Code Coverage: | 15.4% |
Signature Coverage: | 19.2% |
Total number of Nodes: | 26 |
Total number of Limit Nodes: | 4 |
Graph
Function 00000217700AB050 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 189COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700E2574 Relevance: 1.5, APIs: 1, Instructions: 25memoryCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7300A2080 Relevance: 6.0, APIs: 4, Instructions: 39timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700EF3A8 Relevance: 1.8, APIs: 1, Instructions: 321COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DE6F8 Relevance: 1.5, Strings: 1, Instructions: 251COMMONLIBRARYCODE
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700C7CC0 Relevance: .8, Instructions: 829COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D69C0 Relevance: .7, Instructions: 672COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D47E0 Relevance: .7, Instructions: 661COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700BE350 Relevance: .5, Instructions: 530COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D76D0 Relevance: .5, Instructions: 504COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DAA44 Relevance: .5, Instructions: 503COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700C77A0 Relevance: .5, Instructions: 485COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D4E70 Relevance: .5, Instructions: 481COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700B52D0 Relevance: .4, Instructions: 449COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700B9500 Relevance: .4, Instructions: 425COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D7A20 Relevance: .4, Instructions: 407COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700BA090 Relevance: .4, Instructions: 377COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700CB1E0 Relevance: .4, Instructions: 374COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D8200 Relevance: .3, Instructions: 326COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D5FB0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D6360 Relevance: .3, Instructions: 261COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700B5700 Relevance: .3, Instructions: 253COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D5CF0 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D76B0 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D76C0 Relevance: .2, Instructions: 224COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D2B80 Relevance: .2, Instructions: 211COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D76A0 Relevance: .2, Instructions: 190COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D09A0 Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700B63F0 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700CF820 Relevance: .2, Instructions: 159COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D3370 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D4660 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DA8B0 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700C09A0 Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D7D40 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D8897 Relevance: .1, Instructions: 94COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D848B Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D856F Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700D8658 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700B0B84 Relevance: .0, Instructions: 10COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7300A2350 Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DF598 Relevance: 9.1, APIs: 3, Strings: 2, Instructions: 371COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700E56F0 Relevance: 9.0, APIs: 1, Strings: 4, Instructions: 245COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DE058 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 182COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700DE26C Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 169COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00000217700E77C0 Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 275COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|