Windows
Analysis Report
putty.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- putty.exe (PID: 6380 cmdline:
"C:\Users\ user\Deskt op\putty.e xe" MD5: 3BBAC642557B0AB934ADDBAC0594561C) - explorer.exe (PID: 1028 cmdline:
C:\Windows \Explorer. EXE MD5: 662F4F92FDE3557E86D110526BB578D5)
- hajefwb (PID: 7112 cmdline:
C:\Users\u ser\AppDat a\Roaming\ hajefwb MD5: 3BBAC642557B0AB934ADDBAC0594561C)
- hajefwb (PID: 3648 cmdline:
C:\Users\u ser\AppDat a\Roaming\ hajefwb MD5: 3BBAC642557B0AB934ADDBAC0594561C)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
SmokeLoader | The SmokeLoader family is a generic backdoor with a range of capabilities which depend on the modules included in any given build of the malware. The malware is delivered in a variety of ways and is broadly associated with criminal activity. The malware frequently tries to hide its C2 activity by generating requests to legitimate sites such as microsoft.com, bing.com, adobe.com, and others. Typically the actual Download returns an HTTP 404 but still contains data in the Response Body. |
{"Version": 2022, "C2 list": ["http://constractionscity1991.lat/", "http://restructurisationservice.ru/", "http://connecticutproperty.ru/"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Windows_Trojan_Smokeloader_4e31426e | unknown | unknown |
| |
Windows_Trojan_Smokeloader_3687686f | unknown | unknown |
| |
Click to see the 9 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
JoeSecurity_SmokeLoader_2 | Yara detected SmokeLoader | Joe Security | ||
Click to see the 1 entries |
System Summary |
---|
Source: | Author: Max Altgelt (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T10:58:12.359414+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49735 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:58:14.531297+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49741 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:58:16.781269+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49747 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:22.905776+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49897 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:24.608903+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49902 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:26.108877+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49908 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:27.827648+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49914 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:29.405803+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49915 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:30.843229+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49920 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:32.436950+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49926 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:33.936950+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49928 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:35.406095+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49933 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:37.327557+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49939 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:38.769169+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49942 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:40.327545+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49947 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:42.608756+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49953 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:44.093134+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49958 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:45.593136+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49964 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:48.139987+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49970 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:49.530677+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49973 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:50.905589+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49977 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:56.702432+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49993 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:58.202555+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 49995 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:59.640179+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50000 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:06.342983+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50001 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:07.905516+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50002 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:09.405517+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50003 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:15.530466+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50004 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:17.108580+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50005 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:18.608576+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50006 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:23.702267+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50007 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:25.139893+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50008 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:26.639752+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50009 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:31.936600+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50010 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:33.608454+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50011 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:35.030325+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50012 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:40.639665+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50013 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:42.092793+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50014 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:43.608439+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50015 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:49.327252+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50016 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:50.795846+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50017 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:52.295850+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50018 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:58.217739+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50019 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:59.702081+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50020 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:01.311427+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50021 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:06.592651+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50022 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:08.139529+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50023 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:09.639518+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50024 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:15.639488+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50025 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:17.108246+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50026 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:18.608254+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50027 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:24.327004+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50028 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:25.795658+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50029 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:27.405068+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50030 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:32.905000+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50031 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:34.394096+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50032 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:35.826874+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50033 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:41.326839+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50034 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:43.201831+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50035 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:44.639355+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50036 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:51.139377+0100 | 2039103 | 1 | A Network Trojan was detected | 192.168.2.5 | 50037 | 94.156.177.51 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T10:58:14.531297+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49741 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:24.608903+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49902 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:30.843229+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49920 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:33.936950+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49928 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:35.406095+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49933 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:38.769169+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49942 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:40.327545+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49947 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:58.202555+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 49995 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:59.640179+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50000 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:15.530466+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50004 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:25.139893+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50008 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:26.639752+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50009 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:33.608454+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50011 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:58.217739+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50019 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:01.311427+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50021 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:06.592651+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50022 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:08.139529+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50023 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:09.639518+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50024 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:27.405068+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50030 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:32.905000+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50031 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:34.394096+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50032 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:35.826874+0100 | 2851815 | 1 | A Network Trojan was detected | 192.168.2.5 | 50033 | 194.85.61.76 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00402F8F | |
Source: | Code function: | 0_2_004013BF | |
Source: | Code function: | 0_2_00401412 | |
Source: | Code function: | 0_2_004013CA | |
Source: | Code function: | 0_2_004014D3 | |
Source: | Code function: | 0_2_004013D9 | |
Source: | Code function: | 0_2_004013E0 | |
Source: | Code function: | 0_2_004013F0 | |
Source: | Code function: | 0_2_004013F4 | |
Source: | Code function: | 0_2_004014F7 | |
Source: | Code function: | 0_2_004014B5 | |
Source: | Code function: | 4_2_00402F8F | |
Source: | Code function: | 4_2_004013BF | |
Source: | Code function: | 4_2_00401412 | |
Source: | Code function: | 4_2_004013CA | |
Source: | Code function: | 4_2_004014D3 | |
Source: | Code function: | 4_2_004013D9 | |
Source: | Code function: | 4_2_004013E0 | |
Source: | Code function: | 4_2_004013F0 | |
Source: | Code function: | 4_2_004013F4 | |
Source: | Code function: | 4_2_004014F7 | |
Source: | Code function: | 4_2_004014B5 |
Source: | Code function: | 0_2_0041E7A0 | |
Source: | Code function: | 0_2_00421B7C | |
Source: | Code function: | 0_2_00420723 | |
Source: | Code function: | 0_2_004201DF | |
Source: | Code function: | 0_2_0041FC9B | |
Source: | Code function: | 4_2_0041E7A0 | |
Source: | Code function: | 4_2_00421B7C | |
Source: | Code function: | 4_2_00420723 | |
Source: | Code function: | 4_2_004201DF | |
Source: | Code function: | 4_2_0041FC9B |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_0084CB80 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Unpacked PE file: | ||
Source: | Unpacked PE file: |
Source: | Code function: | 0_2_0040106E | |
Source: | Code function: | 0_2_004010B5 | |
Source: | Code function: | 0_2_0084D690 | |
Source: | Code function: | 0_2_0084DDCB | |
Source: | Code function: | 0_2_0084D6D7 | |
Source: | Code function: | 0_2_008540ED | |
Source: | Code function: | 0_2_0084F652 | |
Source: | Code function: | 0_2_00851B75 | |
Source: | Code function: | 0_2_009418DD | |
Source: | Code function: | 0_2_009410D5 | |
Source: | Code function: | 0_2_0094111C | |
Source: | Code function: | 4_2_0040106E | |
Source: | Code function: | 4_2_004010B5 | |
Source: | Code function: | 4_2_008810D5 | |
Source: | Code function: | 4_2_008818DD | |
Source: | Code function: | 4_2_0088111C | |
Source: | Code function: | 4_2_00AB2BB5 | |
Source: | Code function: | 4_2_00AAC19F | |
Source: | Code function: | 4_2_00AAC893 | |
Source: | Code function: | 4_2_00AB063D | |
Source: | Code function: | 4_2_00AAE11A | |
Source: | Code function: | 4_2_00AAC158 |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File deleted: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior | ||
Source: | Key enumerated: | Jump to behavior |
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | Binary or memory string: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | System information queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging |
---|
Source: | System information queried: | Jump to behavior | ||
Source: | System information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 0_2_0084C45D | |
Source: | Code function: | 0_2_00940D90 | |
Source: | Code function: | 0_2_0094092B | |
Source: | Code function: | 4_2_00880D90 | |
Source: | Code function: | 4_2_0088092B | |
Source: | Code function: | 4_2_00AAAF25 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File created: | Jump to dropped file |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 6_2_004055EB |
Source: | Code function: | 0_2_0041E7A0 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 32 Process Injection | 11 Masquerading | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 12 Virtualization/Sandbox Evasion | LSASS Memory | 511 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 2 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 32 Process Injection | Security Account Manager | 12 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Hidden Files and Directories | NTDS | 3 Process Discovery | Distributed Component Object Model | Input Capture | 113 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 14 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 File Deletion | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
38% | Virustotal | Browse | ||
47% | ReversingLabs | |||
100% | Avira | HEUR/AGEN.1312567 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1312567 | ||
100% | Joe Sandbox ML | |||
47% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
constractionscity1991.lat | 94.156.177.51 | true | false | high | |
restructurisationservice.ru | 94.156.177.51 | true | false | high | |
connecticutproperty.ru | 194.85.61.76 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
94.156.177.51 | constractionscity1991.lat | Bulgaria | 43561 | NET1-ASBG | false | |
194.85.61.76 | connecticutproperty.ru | Russian Federation | 48287 | RU-CENTERRU | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578162 |
Start date and time: | 2024-12-19 10:56:48 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | putty.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@3/2@3/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 13.107.246.63, 4.245.163.56
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target hajefwb, PID 3648 because there are no executed function
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtEnumerateKey calls found.
- Report size getting too big, too many NtOpenKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
04:58:00 | API Interceptor | |
10:58:11 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
94.156.177.51 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
194.85.61.76 | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
constractionscity1991.lat | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
restructurisationservice.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
connecticutproperty.ru | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
RU-CENTERRU | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | FormBook, PureLog Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
NET1-ASBG | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
|
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 245760 |
Entropy (8bit): | 5.638844672935597 |
Encrypted: | false |
SSDEEP: | 3072:VC2pwqpX3QufagAKaKkWvqMFh1KjP40ZZ6s5dM6Y273v9blsf:I4wqpX3qgAKaIvqRjBZVM/y |
MD5: | 3BBAC642557B0AB934ADDBAC0594561C |
SHA1: | 0787A06F1FFF51BDFDB129186DF44E73D8C7D5DE |
SHA-256: | BC887FCD6805824AC58A107917C6D083056D688EEF39E979DA25D16EB388E798 |
SHA-512: | C91CBC77B3A67F65082F5D8187F237B9DE0A6AAF1CBFB7BBD0E3157D2B8815F55A6ED71D6BDA88941DAED67AD6F0EE9A9E98149F11B053F81A462E17F7145730 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Windows\explorer.exe |
File Type: | |
Category: | modified |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.638844672935597 |
TrID: |
|
File name: | putty.exe |
File size: | 245'760 bytes |
MD5: | 3bbac642557b0ab934addbac0594561c |
SHA1: | 0787a06f1fff51bdfdb129186df44e73d8c7d5de |
SHA256: | bc887fcd6805824ac58a107917c6d083056d688eef39e979da25d16eb388e798 |
SHA512: | c91cbc77b3a67f65082f5d8187f237b9de0a6aaf1cbfb7bbd0e3157d2b8815f55a6ed71d6bda88941daed67ad6f0ee9a9e98149f11b053f81a462e17f7145730 |
SSDEEP: | 3072:VC2pwqpX3QufagAKaKkWvqMFh1KjP40ZZ6s5dM6Y273v9blsf:I4wqpX3qgAKaIvqRjBZVM/y |
TLSH: | 08347C1336F1E067E7B78A3079FCD6B02A3BB87B9B74814E1224279F19712908A5D753 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........B.AK#..K#..K#...lK.J#..UqY.U#..UqH._#..Uq^.%#..l...N#..K#..>#..UqW.J#..UqI.J#..UqL.J#..RichK#..................PE..L...F.&f... |
Icon Hash: | 151a131010911409 |
Entrypoint: | 0x401a92 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6626F246 [Mon Apr 22 23:27:02 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 5 |
OS Version Minor: | 0 |
File Version Major: | 5 |
File Version Minor: | 0 |
Subsystem Version Major: | 5 |
Subsystem Version Minor: | 0 |
Import Hash: | d4d3ffca50bc999994f856732f42114f |
Instruction |
---|
call 00007FEB2CDA73F9h |
jmp 00007FEB2CDA371Dh |
mov edi, edi |
push ebp |
mov ebp, esp |
sub esp, 00000328h |
mov dword ptr [00427C38h], eax |
mov dword ptr [00427C34h], ecx |
mov dword ptr [00427C30h], edx |
mov dword ptr [00427C2Ch], ebx |
mov dword ptr [00427C28h], esi |
mov dword ptr [00427C24h], edi |
mov word ptr [00427C50h], ss |
mov word ptr [00427C44h], cs |
mov word ptr [00427C20h], ds |
mov word ptr [00427C1Ch], es |
mov word ptr [00427C18h], fs |
mov word ptr [00427C14h], gs |
pushfd |
pop dword ptr [00427C48h] |
mov eax, dword ptr [ebp+00h] |
mov dword ptr [00427C3Ch], eax |
mov eax, dword ptr [ebp+04h] |
mov dword ptr [00427C40h], eax |
lea eax, dword ptr [ebp+08h] |
mov dword ptr [00427C4Ch], eax |
mov eax, dword ptr [ebp-00000320h] |
mov dword ptr [00427B88h], 00010001h |
mov eax, dword ptr [00427C40h] |
mov dword ptr [00427B3Ch], eax |
mov dword ptr [00427B30h], C0000409h |
mov dword ptr [00427B34h], 00000001h |
mov eax, dword ptr [00425004h] |
mov dword ptr [ebp-00000328h], eax |
mov eax, dword ptr [00425008h] |
mov dword ptr [ebp-00000324h], eax |
call dword ptr [000000C8h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x238fc | 0x3c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x403000 | 0x119b0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x22000 | 0x198 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x20dbc | 0x20e00 | 5c541c616f9b306ff42b3e4f234151f9 | False | 0.6227423954372624 | data | 6.440374416875712 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x22000 | 0x222a | 0x2400 | 7532422a3849ad26f5d656584a69be00 | False | 0.3527560763888889 | data | 5.379872759729207 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x25000 | 0x3dd13c | 0x7000 | c5455776ba3d819123800dd3a4929859 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x403000 | 0x119b0 | 0x11a00 | 2db4edf44b4628cb44c7dd6130a95d88 | False | 0.44549257535460995 | data | 4.756112777224745 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x4035e0 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colors | Turkmen | Turkmenistan | 0.511727078891258 |
RT_ICON | 0x404488 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | Turkmen | Turkmenistan | 0.5631768953068592 |
RT_ICON | 0x404d30 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colors | Turkmen | Turkmenistan | 0.6002304147465438 |
RT_ICON | 0x4053f8 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | Turkmen | Turkmenistan | 0.630057803468208 |
RT_ICON | 0x405960 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 9216 | Turkmen | Turkmenistan | 0.4050829875518672 |
RT_ICON | 0x407f08 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | Turkmen | Turkmenistan | 0.4732645403377111 |
RT_ICON | 0x408fb0 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 2304 | Turkmen | Turkmenistan | 0.4692622950819672 |
RT_ICON | 0x409938 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1024 | Turkmen | Turkmenistan | 0.5709219858156028 |
RT_ICON | 0x409e18 | 0xea8 | Device independent bitmap graphic, 48 x 96 x 8, image size 0 | Turkmen | Turkmenistan | 0.3443496801705757 |
RT_ICON | 0x40acc0 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 0 | Turkmen | Turkmenistan | 0.46796028880866425 |
RT_ICON | 0x40b568 | 0x6c8 | Device independent bitmap graphic, 24 x 48 x 8, image size 0 | Turkmen | Turkmenistan | 0.5028801843317973 |
RT_ICON | 0x40bc30 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 0 | Turkmen | Turkmenistan | 0.5245664739884393 |
RT_ICON | 0x40c198 | 0x25a8 | Device independent bitmap graphic, 48 x 96 x 32, image size 0 | Turkmen | Turkmenistan | 0.4254149377593361 |
RT_ICON | 0x40e740 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 0 | Turkmen | Turkmenistan | 0.4329268292682927 |
RT_ICON | 0x40f7e8 | 0x988 | Device independent bitmap graphic, 24 x 48 x 32, image size 0 | Turkmen | Turkmenistan | 0.4364754098360656 |
RT_ICON | 0x410170 | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 0 | Turkmen | Turkmenistan | 0.4512411347517731 |
RT_STRING | 0x410808 | 0x4ee | data | 0.43898573692551507 | ||
RT_STRING | 0x410cf8 | 0xee | data | 0.5546218487394958 | ||
RT_STRING | 0x410de8 | 0x6d6 | data | 0.42857142857142855 | ||
RT_STRING | 0x4114c0 | 0x748 | data | 0.4248927038626609 | ||
RT_STRING | 0x411c08 | 0x830 | data | 0.4193702290076336 | ||
RT_STRING | 0x412438 | 0x712 | data | 0.4298342541436464 | ||
RT_STRING | 0x412b50 | 0x78a | data | 0.4202072538860104 | ||
RT_STRING | 0x4132e0 | 0x754 | data | 0.4211087420042644 | ||
RT_STRING | 0x413a38 | 0x914 | data | 0.41179001721170394 | ||
RT_STRING | 0x414350 | 0x65e | data | 0.4306748466257669 | ||
RT_GROUP_ICON | 0x4105d8 | 0x76 | data | Turkmen | Turkmenistan | 0.6694915254237288 |
RT_GROUP_ICON | 0x409da0 | 0x76 | data | Turkmen | Turkmenistan | 0.6610169491525424 |
RT_VERSION | 0x410650 | 0x1b4 | data | 0.5688073394495413 |
DLL | Import |
---|---|
KERNEL32.dll | GetComputerNameA, SetDefaultCommConfigA, SetLocaleInfoA, SetErrorMode, WriteConsoleOutputW, DeleteVolumeMountPointA, InterlockedIncrement, InterlockedDecrement, ReadConsoleOutputAttribute, GetEnvironmentStringsW, GetTimeFormatA, GetModuleHandleW, GetDateFormatA, GetCommandLineA, SetProcessPriorityBoost, LoadLibraryW, GetConsoleAliasW, DisconnectNamedPipe, GetStartupInfoA, SetLastError, GetProcAddress, SearchPathA, SetFileAttributesA, GetNumaHighestNodeNumber, ResetEvent, GetAtomNameA, LoadLibraryA, LocalAlloc, GetFileType, AddAtomW, AddAtomA, FoldStringA, GetModuleHandleA, OpenFileMappingW, BuildCommDCBA, GetShortPathNameW, Module32Next, EndUpdateResourceA, GetVersionExA, FindFirstVolumeW, UnregisterWaitEx, GetLastError, HeapFree, HeapAlloc, MultiByteToWideChar, HeapReAlloc, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapCreate, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, SetHandleCount, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, GetCurrentThreadId, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, RtlUnwind, ReadFile, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, SetStdHandle, CloseHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA |
USER32.dll | GetProcessDefaultLayout |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkmen | Turkmenistan |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T10:58:12.359414+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49735 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:58:14.531297+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49741 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:58:14.531297+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49741 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:58:16.781269+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49747 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:22.905776+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49897 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:24.608903+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49902 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:24.608903+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49902 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:26.108877+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49908 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:27.827648+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49914 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:29.405803+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49915 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:30.843229+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49920 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:30.843229+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49920 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:32.436950+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49926 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:33.936950+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49928 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:33.936950+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49928 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:35.406095+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49933 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:35.406095+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49933 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:37.327557+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49939 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:38.769169+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49942 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:38.769169+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49942 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:40.327545+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49947 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:40.327545+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49947 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:42.608756+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49953 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:44.093134+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49958 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:45.593136+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49964 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:48.139987+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49970 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:49.530677+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49973 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:50.905589+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49977 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:56.702432+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49993 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:58.202555+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 49995 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:58.202555+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 49995 | 94.156.177.51 | 80 | TCP |
2024-12-19T10:59:59.640179+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50000 | 194.85.61.76 | 80 | TCP |
2024-12-19T10:59:59.640179+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50000 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:06.342983+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50001 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:07.905516+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50002 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:09.405517+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50003 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:15.530466+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50004 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:15.530466+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50004 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:17.108580+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50005 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:18.608576+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50006 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:23.702267+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50007 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:25.139893+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50008 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:25.139893+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50008 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:26.639752+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50009 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:26.639752+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50009 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:31.936600+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50010 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:33.608454+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50011 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:33.608454+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50011 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:35.030325+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50012 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:40.639665+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50013 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:42.092793+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50014 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:43.608439+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50015 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:49.327252+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50016 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:50.795846+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50017 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:52.295850+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50018 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:00:58.217739+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50019 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:58.217739+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50019 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:00:59.702081+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50020 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:01.311427+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50021 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:01.311427+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50021 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:06.592651+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50022 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:06.592651+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50022 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:08.139529+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50023 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:08.139529+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50023 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:09.639518+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50024 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:09.639518+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50024 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:15.639488+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50025 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:17.108246+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50026 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:18.608254+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50027 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:24.327004+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50028 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:25.795658+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50029 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:27.405068+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50030 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:27.405068+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50030 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:32.905000+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50031 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:32.905000+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50031 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:34.394096+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50032 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:34.394096+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50032 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:35.826874+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50033 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:35.826874+0100 | 2851815 | ETPRO MALWARE Sharik/Smokeloader CnC Beacon 18 | 1 | 192.168.2.5 | 50033 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:41.326839+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50034 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:43.201831+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50035 | 94.156.177.51 | 80 | TCP |
2024-12-19T11:01:44.639355+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50036 | 194.85.61.76 | 80 | TCP |
2024-12-19T11:01:51.139377+0100 | 2039103 | ET MALWARE Suspected Smokeloader Activity (POST) | 1 | 192.168.2.5 | 50037 | 94.156.177.51 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 10:58:10.839359045 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:10.959048033 CET | 80 | 49735 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:10.959218979 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:10.959477901 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:10.959510088 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:11.079178095 CET | 80 | 49735 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:11.079210997 CET | 80 | 49735 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:12.319236040 CET | 80 | 49735 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:12.359414101 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:12.978580952 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:13.098649025 CET | 80 | 49741 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:13.098784924 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:13.098994970 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:13.099046946 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:13.218497038 CET | 80 | 49741 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:13.218553066 CET | 80 | 49741 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:14.481053114 CET | 80 | 49741 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:14.531296968 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:15.282855988 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:15.402512074 CET | 80 | 49747 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:58:15.402591944 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:15.402757883 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:15.402770042 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:15.522356033 CET | 80 | 49747 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:58:15.522391081 CET | 80 | 49747 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:58:16.737190962 CET | 80 | 49747 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:58:16.781269073 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:54.187532902 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:54.187580109 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:54.187639952 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:54.307543039 CET | 80 | 49747 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:58:54.307636023 CET | 49747 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:58:54.308120966 CET | 80 | 49735 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:54.308154106 CET | 80 | 49741 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:58:54.308192968 CET | 49735 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:58:54.308217049 CET | 49741 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:21.382364988 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:21.502018929 CET | 80 | 49897 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:21.502330065 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:21.502511978 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:21.502590895 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:21.622014046 CET | 80 | 49897 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:21.622117996 CET | 80 | 49897 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:22.860023022 CET | 80 | 49897 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:22.866456032 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:22.905776024 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:22.986102104 CET | 80 | 49902 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:22.986206055 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:22.987339020 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:22.987365007 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:23.107152939 CET | 80 | 49902 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:23.107204914 CET | 80 | 49902 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:24.480494976 CET | 80 | 49902 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:24.488054991 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:24.607825994 CET | 80 | 49908 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:24.608902931 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:24.608963966 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:24.609102964 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:24.609158039 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:24.728601933 CET | 80 | 49908 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:24.728732109 CET | 80 | 49908 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:25.943614960 CET | 80 | 49908 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:26.108876944 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:26.192203999 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.196321011 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.312272072 CET | 80 | 49897 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:26.312463045 CET | 49897 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.316028118 CET | 80 | 49914 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:26.316113949 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.316266060 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.316322088 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:26.435937881 CET | 80 | 49914 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:26.436100006 CET | 80 | 49914 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:27.281039953 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.281049967 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:27.401098013 CET | 80 | 49902 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:27.401241064 CET | 49902 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.401571035 CET | 80 | 49908 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:27.401771069 CET | 49908 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:27.673820019 CET | 80 | 49914 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:27.695483923 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.816472054 CET | 80 | 49915 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:27.818660021 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.820787907 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.820805073 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.827647924 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:27.940386057 CET | 80 | 49915 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:27.940440893 CET | 80 | 49915 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:29.184083939 CET | 80 | 49915 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:29.195331097 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:29.314913988 CET | 80 | 49920 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:29.315105915 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:29.315151930 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:29.315171957 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:29.405802965 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:29.434762955 CET | 80 | 49920 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:29.434788942 CET | 80 | 49920 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:30.651345015 CET | 80 | 49920 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:30.795676947 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:30.796197891 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:30.843229055 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:30.915870905 CET | 80 | 49926 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:30.916008949 CET | 80 | 49914 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:30.916069984 CET | 49914 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:30.916121006 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:30.916336060 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:30.918894053 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:31.036005974 CET | 80 | 49926 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:31.038445950 CET | 80 | 49926 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.322904110 CET | 80 | 49926 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.325926065 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.355108023 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.436949968 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.445911884 CET | 80 | 49915 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.446002960 CET | 49915 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.474831104 CET | 80 | 49928 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.474948883 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.475130081 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.475718021 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:32.594723940 CET | 80 | 49928 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.595302105 CET | 80 | 49928 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:32.969177008 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:33.089389086 CET | 80 | 49920 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:33.089467049 CET | 49920 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:33.845381975 CET | 80 | 49928 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:33.850738049 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:33.936949968 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:33.970352888 CET | 80 | 49933 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:33.970453024 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:33.970565081 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:33.970581055 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:34.090051889 CET | 80 | 49933 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:34.090212107 CET | 80 | 49933 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:35.310946941 CET | 80 | 49933 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:35.406095028 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:35.733346939 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.734225035 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.853265047 CET | 80 | 49926 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:35.853334904 CET | 49926 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.853770971 CET | 80 | 49939 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:35.853851080 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.854039907 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.854075909 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:35.973634958 CET | 80 | 49939 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:35.973671913 CET | 80 | 49939 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:37.220084906 CET | 80 | 49939 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:37.228251934 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.228992939 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.327557087 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.353039026 CET | 80 | 49942 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:37.353202105 CET | 80 | 49928 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:37.353221893 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.353260040 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.353266001 CET | 49928 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.354517937 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:37.472774982 CET | 80 | 49942 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:37.474114895 CET | 80 | 49942 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:38.727760077 CET | 80 | 49942 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:38.738086939 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.739397049 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.769169092 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:38.859175920 CET | 80 | 49947 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:38.861947060 CET | 80 | 49933 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:38.862045050 CET | 49933 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.862231970 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.862231970 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.862231970 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:38.981775999 CET | 80 | 49947 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:38.981884956 CET | 80 | 49947 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:40.196259022 CET | 80 | 49947 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:40.327544928 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:41.074060917 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.075006008 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.194243908 CET | 80 | 49939 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:41.194318056 CET | 49939 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.194569111 CET | 80 | 49953 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:41.194637060 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.194796085 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.194829941 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:41.315465927 CET | 80 | 49953 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:41.315479994 CET | 80 | 49953 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:42.558610916 CET | 80 | 49953 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:42.566088915 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.568147898 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.608756065 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.686050892 CET | 80 | 49942 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:42.686219931 CET | 49942 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.687757015 CET | 80 | 49958 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:42.687834978 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.688040018 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.688106060 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:42.807682037 CET | 80 | 49958 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:42.807718992 CET | 80 | 49958 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:44.049314976 CET | 80 | 49958 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:44.058936119 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.074624062 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.093133926 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:44.179299116 CET | 80 | 49947 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:44.179383993 CET | 49947 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.194212914 CET | 80 | 49964 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:44.194283962 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.194433928 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.194447041 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:44.314183950 CET | 80 | 49964 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:44.314227104 CET | 80 | 49964 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:45.534571886 CET | 80 | 49964 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:45.593136072 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:46.436528921 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.437567949 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.557374001 CET | 80 | 49953 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:46.557488918 CET | 49953 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.557879925 CET | 80 | 49970 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:46.557977915 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.558182001 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.558239937 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:46.677725077 CET | 80 | 49970 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:46.677782059 CET | 80 | 49970 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:47.910084963 CET | 80 | 49970 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:47.916546106 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:47.920754910 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.036920071 CET | 80 | 49958 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:48.038925886 CET | 49958 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.040302038 CET | 80 | 49973 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:48.040513992 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.040641069 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.040652037 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.139986992 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:48.160137892 CET | 80 | 49973 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:48.160317898 CET | 80 | 49973 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:49.390717983 CET | 80 | 49973 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:49.395833015 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.402512074 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.515894890 CET | 80 | 49964 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:49.515965939 CET | 49964 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.522192955 CET | 80 | 49977 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:49.522279024 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.522432089 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.522479057 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:49.530677080 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:49.642723083 CET | 80 | 49977 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:49.642961979 CET | 80 | 49977 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:50.862988949 CET | 80 | 49977 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:50.905589104 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:55.115282059 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.119046926 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.235294104 CET | 80 | 49970 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:55.235364914 CET | 49970 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.238712072 CET | 80 | 49993 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:55.238826036 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.240689993 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.241559029 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:55.360591888 CET | 80 | 49993 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:55.361350060 CET | 80 | 49993 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:56.609649897 CET | 80 | 49993 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:56.617108107 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.617672920 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.702431917 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.737185955 CET | 80 | 49973 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:56.737236023 CET | 80 | 49995 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:56.737261057 CET | 49973 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.737313986 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.737485886 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.737519979 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:56.857055902 CET | 80 | 49995 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:56.857136011 CET | 80 | 49995 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:58.091754913 CET | 80 | 49995 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:58.100172043 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.111203909 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.202554941 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:58.220653057 CET | 80 | 49977 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:58.220774889 CET | 49977 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.231797934 CET | 80 | 50000 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:58.232036114 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.232085943 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.232085943 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:58.352044106 CET | 80 | 50000 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:58.352062941 CET | 80 | 50000 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:59.568881035 CET | 80 | 50000 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 10:59:59.640173912 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:59.640178919 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 10:59:59.640253067 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:59.760396004 CET | 80 | 49993 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:59.760485888 CET | 49993 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 10:59:59.760824919 CET | 80 | 49995 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 10:59:59.760878086 CET | 49995 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:04.717565060 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:04.837373018 CET | 80 | 50001 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:04.837668896 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:04.837919950 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:04.837968111 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:04.957659006 CET | 80 | 50001 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:04.957700014 CET | 80 | 50001 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:06.200352907 CET | 80 | 50001 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:06.204482079 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:06.324212074 CET | 80 | 50002 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:06.324533939 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:06.324534893 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:06.324534893 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:06.342983007 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:06.445079088 CET | 80 | 50002 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:06.445362091 CET | 80 | 50002 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:07.849044085 CET | 80 | 50002 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:07.852830887 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:07.853585005 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:07.905515909 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:07.972789049 CET | 80 | 50000 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:07.972882986 CET | 50000 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:07.973180056 CET | 80 | 50003 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:07.973251104 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:07.973406076 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:07.973427057 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:08.093837023 CET | 80 | 50003 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:08.093905926 CET | 80 | 50003 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:09.309182882 CET | 80 | 50003 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:09.405517101 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:13.927354097 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:13.928138971 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:14.047334909 CET | 80 | 50001 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:14.047413111 CET | 50001 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:14.047704935 CET | 80 | 50004 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:14.047790051 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:14.047979116 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:14.048084021 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:14.167612076 CET | 80 | 50004 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:14.167670012 CET | 80 | 50004 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:15.431368113 CET | 80 | 50004 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:15.434993029 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.435705900 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.530466080 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.555548906 CET | 80 | 50002 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:15.555661917 CET | 50002 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.555840969 CET | 80 | 50005 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:15.555943012 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.556154013 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.556154966 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:15.675779104 CET | 80 | 50005 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:15.675836086 CET | 80 | 50005 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:16.925323009 CET | 80 | 50005 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:16.932225943 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:16.932898998 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:17.052246094 CET | 80 | 50003 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:17.052334070 CET | 50003 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:17.052470922 CET | 80 | 50006 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:17.052629948 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:17.052778959 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:17.052819967 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:17.108580112 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:17.173132896 CET | 80 | 50006 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:17.173167944 CET | 80 | 50006 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:18.093194962 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:18.093214035 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:18.213327885 CET | 80 | 50005 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:18.213409901 CET | 50005 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:18.213768959 CET | 80 | 50004 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:18.213839054 CET | 50004 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:18.386399984 CET | 80 | 50006 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:18.608576059 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:22.127229929 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:22.246999025 CET | 80 | 50007 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:22.247164965 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:22.247304916 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:22.247355938 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:22.366899014 CET | 80 | 50007 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:22.367010117 CET | 80 | 50007 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:23.618141890 CET | 80 | 50007 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:23.623651981 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:23.702266932 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:23.743330956 CET | 80 | 50008 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:23.743562937 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:23.743700027 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:23.743736982 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:23.863380909 CET | 80 | 50008 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:23.863420010 CET | 80 | 50008 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:25.092927933 CET | 80 | 50008 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:25.096931934 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.099350929 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.139893055 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:25.216953039 CET | 80 | 50006 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:25.217127085 CET | 50006 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.218894005 CET | 80 | 50009 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:25.219010115 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.219163895 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.219197035 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:25.338969946 CET | 80 | 50009 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:25.339015961 CET | 80 | 50009 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:26.560724974 CET | 80 | 50009 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:26.639751911 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:30.412332058 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.413017035 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.532826900 CET | 80 | 50010 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:30.532876968 CET | 80 | 50007 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:30.532952070 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.532974005 CET | 50007 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.533154964 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.533186913 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:30.653083086 CET | 80 | 50010 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:30.653198004 CET | 80 | 50010 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:31.889817953 CET | 80 | 50010 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:31.893731117 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:31.894496918 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:31.936599970 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:32.014002085 CET | 80 | 50008 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:32.014081001 CET | 80 | 50011 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:32.014091969 CET | 50008 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:32.014151096 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:32.014364004 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:32.014384985 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:32.133869886 CET | 80 | 50011 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:32.134037018 CET | 80 | 50011 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:33.379775047 CET | 80 | 50011 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:33.384870052 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.385530949 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.504926920 CET | 80 | 50009 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:33.505012989 CET | 50009 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.505090952 CET | 80 | 50012 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:33.505172968 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.505337000 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.510246992 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:33.608453989 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:33.625281096 CET | 80 | 50012 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:33.630229950 CET | 80 | 50012 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:34.846632957 CET | 80 | 50012 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:35.030324936 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:39.078705072 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.079343081 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.198887110 CET | 80 | 50010 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:39.198909998 CET | 80 | 50013 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:39.198972940 CET | 50010 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.199024916 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.199218035 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.199258089 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:39.318814993 CET | 80 | 50013 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:39.318877935 CET | 80 | 50013 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:40.565376997 CET | 80 | 50013 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:40.577049971 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.577833891 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.639664888 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.697760105 CET | 80 | 50011 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:40.697801113 CET | 80 | 50014 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:40.697835922 CET | 50011 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.697911024 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.698086977 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.698121071 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:40.818715096 CET | 80 | 50014 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:40.818759918 CET | 80 | 50014 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:42.052089930 CET | 80 | 50014 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:42.066133022 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.066770077 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.092792988 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:42.186614990 CET | 80 | 50012 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:42.186654091 CET | 80 | 50015 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:42.186687946 CET | 50012 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.186741114 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.186908960 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.186943054 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:42.306554079 CET | 80 | 50015 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:42.306631088 CET | 80 | 50015 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:43.521437883 CET | 80 | 50015 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:43.608438969 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:47.655689955 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.656384945 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.776156902 CET | 80 | 50013 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:47.776182890 CET | 80 | 50016 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:47.776212931 CET | 50013 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.776276112 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.776496887 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.776541948 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:47.896007061 CET | 80 | 50016 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:47.896152973 CET | 80 | 50016 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:49.147445917 CET | 80 | 50016 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:49.154002905 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.154767990 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.274190903 CET | 80 | 50014 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:49.274291992 CET | 50014 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.274439096 CET | 80 | 50017 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:49.274527073 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.274692059 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.274730921 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.327251911 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:49.395951986 CET | 80 | 50017 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:49.395987988 CET | 80 | 50017 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:50.646676064 CET | 80 | 50017 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:50.652403116 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.653104067 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.772900105 CET | 80 | 50015 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:50.772950888 CET | 80 | 50018 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:50.772995949 CET | 50015 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.773039103 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.773264885 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.773303032 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:50.795845985 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:50.892791033 CET | 80 | 50018 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:50.892930031 CET | 80 | 50018 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:52.117582083 CET | 80 | 50018 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:52.295850039 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:56.639198065 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.639919996 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.760374069 CET | 80 | 50019 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:56.760425091 CET | 80 | 50016 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:56.760519028 CET | 50016 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.760525942 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.760693073 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.760725975 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:56.880178928 CET | 80 | 50019 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:56.880338907 CET | 80 | 50019 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:58.140840054 CET | 80 | 50019 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:58.150202036 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.151030064 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.217739105 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.270863056 CET | 80 | 50020 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:58.271347046 CET | 80 | 50017 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:58.271486044 CET | 50017 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.271836042 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.271836042 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.271836042 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:58.391464949 CET | 80 | 50020 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:58.391597033 CET | 80 | 50020 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:59.638279915 CET | 80 | 50020 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:00:59.651143074 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.652076006 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.702080965 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:00:59.771333933 CET | 80 | 50018 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:59.771433115 CET | 50018 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.771645069 CET | 80 | 50021 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:59.771718979 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.771935940 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.771965981 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:00:59.891478062 CET | 80 | 50021 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:00:59.891544104 CET | 80 | 50021 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:01.112617016 CET | 80 | 50021 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:01.311427116 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:05.006011963 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.006716967 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.126434088 CET | 80 | 50022 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:05.126519918 CET | 80 | 50019 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:05.126616001 CET | 50019 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.126651049 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.126802921 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.126802921 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:05.246325016 CET | 80 | 50022 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:05.246593952 CET | 80 | 50022 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:06.509078026 CET | 80 | 50022 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:06.513267994 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.514122963 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.592650890 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.633316040 CET | 80 | 50020 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:06.633399963 CET | 50020 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.633765936 CET | 80 | 50023 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:06.633841991 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.634035110 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.634068966 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:06.753649950 CET | 80 | 50023 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:06.753715992 CET | 80 | 50023 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:08.004259109 CET | 80 | 50023 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:08.015645027 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.016199112 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.135987997 CET | 80 | 50021 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:08.136029959 CET | 80 | 50024 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:08.136046886 CET | 50021 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.136239052 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.136343956 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.136374950 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:08.139528990 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:08.255911112 CET | 80 | 50024 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:08.256128073 CET | 80 | 50024 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:09.477787971 CET | 80 | 50024 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:09.639518023 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:14.032356977 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.032726049 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.152539968 CET | 80 | 50025 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:14.152673006 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.152776957 CET | 80 | 50022 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:14.152865887 CET | 50022 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.152884960 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.152934074 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:14.272593021 CET | 80 | 50025 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:14.272628069 CET | 80 | 50025 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:15.514272928 CET | 80 | 50025 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:15.522825956 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.523394108 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.639487982 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.642899036 CET | 80 | 50023 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:15.643064976 CET | 80 | 50026 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:15.643173933 CET | 50023 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.643224955 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.643481016 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.643481016 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:15.763120890 CET | 80 | 50026 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:15.763158083 CET | 80 | 50026 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:17.013854027 CET | 80 | 50026 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:17.019367933 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.026079893 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.108246088 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:17.139561892 CET | 80 | 50024 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:17.139687061 CET | 50024 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.145685911 CET | 80 | 50027 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:17.145761013 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.145970106 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.145992994 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:17.265918970 CET | 80 | 50027 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:17.265953064 CET | 80 | 50027 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:17.939521074 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:17.948889017 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:18.059510946 CET | 80 | 50025 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:18.059595108 CET | 50025 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:18.068747997 CET | 80 | 50026 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:18.068820000 CET | 50026 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:18.481949091 CET | 80 | 50027 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:18.608253956 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:22.729553938 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:22.849565029 CET | 80 | 50028 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:22.849688053 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:22.850096941 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:22.850096941 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:22.969711065 CET | 80 | 50028 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:22.970042944 CET | 80 | 50028 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:24.212259054 CET | 80 | 50028 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:24.218524933 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:24.327003956 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:24.338701010 CET | 80 | 50029 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:24.338783026 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:24.338927984 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:24.338943005 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:24.458914995 CET | 80 | 50029 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:24.459129095 CET | 80 | 50029 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:25.693094015 CET | 80 | 50029 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:25.706688881 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.714620113 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.795658112 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:25.827770948 CET | 80 | 50027 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:25.827843904 CET | 50027 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.834424973 CET | 80 | 50030 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:25.834745884 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.834745884 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.834745884 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:25.954453945 CET | 80 | 50030 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:25.954538107 CET | 80 | 50030 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:27.174427986 CET | 80 | 50030 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:27.405067921 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:31.186304092 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.186778069 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.306435108 CET | 80 | 50031 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:31.306494951 CET | 80 | 50028 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:31.306597948 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.306633949 CET | 50028 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.331737995 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.334003925 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:31.451493025 CET | 80 | 50031 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:31.453659058 CET | 80 | 50031 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:32.784692049 CET | 80 | 50031 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:32.790004015 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.790667057 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.904999971 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.910073996 CET | 80 | 50029 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:32.910155058 CET | 50029 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.910269976 CET | 80 | 50032 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:32.910490990 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.910561085 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:32.910592079 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:33.030103922 CET | 80 | 50032 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:33.030350924 CET | 80 | 50032 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:34.291301012 CET | 80 | 50032 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:34.300523043 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.301254988 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.394095898 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:34.421077967 CET | 80 | 50030 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:34.421317101 CET | 50030 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.421447039 CET | 80 | 50033 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:34.421528101 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.421761990 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.421787977 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:34.541438103 CET | 80 | 50033 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:34.541663885 CET | 80 | 50033 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:35.755727053 CET | 80 | 50033 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:35.826874018 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:39.752383947 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.753259897 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.872502089 CET | 80 | 50031 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:39.872576952 CET | 50031 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.872857094 CET | 80 | 50034 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:39.872936964 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.873128891 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.873186111 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:39.992650032 CET | 80 | 50034 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:39.992850065 CET | 80 | 50034 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:41.227861881 CET | 80 | 50034 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:41.326838970 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.559287071 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.595247030 CET | 50035 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.679421902 CET | 80 | 50032 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:41.679573059 CET | 50032 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.715002060 CET | 80 | 50035 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:41.715082884 CET | 50035 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.715229988 CET | 50035 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.715244055 CET | 50035 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:41.834784031 CET | 80 | 50035 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:41.834892035 CET | 80 | 50035 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:43.091700077 CET | 80 | 50035 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:43.098989010 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.099733114 CET | 50036 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.201831102 CET | 50035 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:43.222151995 CET | 80 | 50033 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:43.222215891 CET | 50033 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.222803116 CET | 80 | 50036 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:43.222882032 CET | 50036 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.223036051 CET | 50036 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.223078012 CET | 50036 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:43.342860937 CET | 80 | 50036 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:43.342977047 CET | 80 | 50036 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:44.556948900 CET | 80 | 50036 | 194.85.61.76 | 192.168.2.5 |
Dec 19, 2024 11:01:44.639354944 CET | 50036 | 80 | 192.168.2.5 | 194.85.61.76 |
Dec 19, 2024 11:01:49.604857922 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.605623960 CET | 50037 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.725018024 CET | 80 | 50034 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:49.725275993 CET | 50034 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.725279093 CET | 80 | 50037 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:49.725372076 CET | 50037 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.725538015 CET | 50037 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.725586891 CET | 50037 | 80 | 192.168.2.5 | 94.156.177.51 |
Dec 19, 2024 11:01:49.846126080 CET | 80 | 50037 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:49.846189976 CET | 80 | 50037 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:51.089430094 CET | 80 | 50037 | 94.156.177.51 | 192.168.2.5 |
Dec 19, 2024 11:01:51.139377117 CET | 50037 | 80 | 192.168.2.5 | 94.156.177.51 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 10:58:10.189366102 CET | 62897 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 19, 2024 10:58:10.835478067 CET | 53 | 62897 | 1.1.1.1 | 192.168.2.5 |
Dec 19, 2024 10:58:12.325762033 CET | 52325 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 19, 2024 10:58:12.970824957 CET | 53 | 52325 | 1.1.1.1 | 192.168.2.5 |
Dec 19, 2024 10:58:14.483879089 CET | 64375 | 53 | 192.168.2.5 | 1.1.1.1 |
Dec 19, 2024 10:58:15.282099962 CET | 53 | 64375 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 19, 2024 10:58:10.189366102 CET | 192.168.2.5 | 1.1.1.1 | 0xc04c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 10:58:12.325762033 CET | 192.168.2.5 | 1.1.1.1 | 0xe875 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 10:58:14.483879089 CET | 192.168.2.5 | 1.1.1.1 | 0x336d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 19, 2024 10:58:10.835478067 CET | 1.1.1.1 | 192.168.2.5 | 0xc04c | No error (0) | 94.156.177.51 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 10:58:12.970824957 CET | 1.1.1.1 | 192.168.2.5 | 0xe875 | No error (0) | 94.156.177.51 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 10:58:15.282099962 CET | 1.1.1.1 | 192.168.2.5 | 0x336d | No error (0) | 194.85.61.76 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 10:58:15.282099962 CET | 1.1.1.1 | 192.168.2.5 | 0x336d | No error (0) | 109.70.26.37 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49735 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:58:10.959477901 CET | 282 | OUT | |
Dec 19, 2024 10:58:10.959510088 CET | 367 | OUT | |
Dec 19, 2024 10:58:12.319236040 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.5 | 49741 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:58:13.098994970 CET | 284 | OUT | |
Dec 19, 2024 10:58:13.099046946 CET | 280 | OUT | |
Dec 19, 2024 10:58:14.481053114 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.5 | 49747 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:58:15.402757883 CET | 281 | OUT | |
Dec 19, 2024 10:58:15.402770042 CET | 252 | OUT | |
Dec 19, 2024 10:58:16.737190962 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.5 | 49897 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:21.502511978 CET | 286 | OUT | |
Dec 19, 2024 10:59:21.502590895 CET | 361 | OUT | |
Dec 19, 2024 10:59:22.860023022 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.5 | 49902 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:22.987339020 CET | 283 | OUT | |
Dec 19, 2024 10:59:22.987365007 CET | 268 | OUT | |
Dec 19, 2024 10:59:24.480494976 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.5 | 49908 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:24.609102964 CET | 281 | OUT | |
Dec 19, 2024 10:59:24.609158039 CET | 171 | OUT | |
Dec 19, 2024 10:59:25.943614960 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.5 | 49914 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:26.316266060 CET | 282 | OUT | |
Dec 19, 2024 10:59:26.316322088 CET | 156 | OUT | |
Dec 19, 2024 10:59:27.673820019 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.5 | 49915 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:27.820787907 CET | 285 | OUT | |
Dec 19, 2024 10:59:27.820805073 CET | 306 | OUT | |
Dec 19, 2024 10:59:29.184083939 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.5 | 49920 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:29.315151930 CET | 279 | OUT | |
Dec 19, 2024 10:59:29.315171957 CET | 298 | OUT | |
Dec 19, 2024 10:59:30.651345015 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.5 | 49926 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:30.916336060 CET | 285 | OUT | |
Dec 19, 2024 10:59:30.918894053 CET | 177 | OUT | |
Dec 19, 2024 10:59:32.322904110 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.5 | 49928 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:32.475130081 CET | 284 | OUT | |
Dec 19, 2024 10:59:32.475718021 CET | 295 | OUT | |
Dec 19, 2024 10:59:33.845381975 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.5 | 49933 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:33.970565081 CET | 278 | OUT | |
Dec 19, 2024 10:59:33.970581055 CET | 258 | OUT | |
Dec 19, 2024 10:59:35.310946941 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.5 | 49939 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:35.854039907 CET | 283 | OUT | |
Dec 19, 2024 10:59:35.854075909 CET | 322 | OUT | |
Dec 19, 2024 10:59:37.220084906 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.5 | 49942 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:37.353260040 CET | 284 | OUT | |
Dec 19, 2024 10:59:37.354517937 CET | 289 | OUT | |
Dec 19, 2024 10:59:38.727760077 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.5 | 49947 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:38.862231970 CET | 278 | OUT | |
Dec 19, 2024 10:59:38.862231970 CET | 265 | OUT | |
Dec 19, 2024 10:59:40.196259022 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.5 | 49953 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:41.194796085 CET | 285 | OUT | |
Dec 19, 2024 10:59:41.194829941 CET | 316 | OUT | |
Dec 19, 2024 10:59:42.558610916 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.5 | 49958 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:42.688040018 CET | 287 | OUT | |
Dec 19, 2024 10:59:42.688106060 CET | 324 | OUT | |
Dec 19, 2024 10:59:44.049314976 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.5 | 49964 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:44.194433928 CET | 281 | OUT | |
Dec 19, 2024 10:59:44.194447041 CET | 264 | OUT | |
Dec 19, 2024 10:59:45.534571886 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.5 | 49970 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:46.558182001 CET | 284 | OUT | |
Dec 19, 2024 10:59:46.558239937 CET | 130 | OUT | |
Dec 19, 2024 10:59:47.910084963 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.5 | 49973 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:48.040641069 CET | 285 | OUT | |
Dec 19, 2024 10:59:48.040652037 CET | 273 | OUT | |
Dec 19, 2024 10:59:49.390717983 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.5 | 49977 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:49.522432089 CET | 280 | OUT | |
Dec 19, 2024 10:59:49.522479057 CET | 200 | OUT | |
Dec 19, 2024 10:59:50.862988949 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.5 | 49993 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:55.240689993 CET | 283 | OUT | |
Dec 19, 2024 10:59:55.241559029 CET | 264 | OUT | |
Dec 19, 2024 10:59:56.609649897 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.5 | 49995 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:56.737485886 CET | 284 | OUT | |
Dec 19, 2024 10:59:56.737519979 CET | 166 | OUT | |
Dec 19, 2024 10:59:58.091754913 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.5 | 50000 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 10:59:58.232085943 CET | 279 | OUT | |
Dec 19, 2024 10:59:58.232085943 CET | 116 | OUT | |
Dec 19, 2024 10:59:59.568881035 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.5 | 50001 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:04.837919950 CET | 285 | OUT | |
Dec 19, 2024 11:00:04.837968111 CET | 326 | OUT | |
Dec 19, 2024 11:00:06.200352907 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.5 | 50002 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:06.324534893 CET | 287 | OUT | |
Dec 19, 2024 11:00:06.324534893 CET | 260 | OUT | |
Dec 19, 2024 11:00:07.849044085 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.5 | 50003 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:07.973406076 CET | 281 | OUT | |
Dec 19, 2024 11:00:07.973427057 CET | 306 | OUT | |
Dec 19, 2024 11:00:09.309182882 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.5 | 50004 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:14.047979116 CET | 282 | OUT | |
Dec 19, 2024 11:00:14.048084021 CET | 269 | OUT | |
Dec 19, 2024 11:00:15.431368113 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.5 | 50005 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:15.556154013 CET | 286 | OUT | |
Dec 19, 2024 11:00:15.556154966 CET | 244 | OUT | |
Dec 19, 2024 11:00:16.925323009 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.5 | 50006 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:17.052778959 CET | 280 | OUT | |
Dec 19, 2024 11:00:17.052819967 CET | 125 | OUT | |
Dec 19, 2024 11:00:18.386399984 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.5 | 50007 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:22.247304916 CET | 284 | OUT | |
Dec 19, 2024 11:00:22.247355938 CET | 266 | OUT | |
Dec 19, 2024 11:00:23.618141890 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.5 | 50008 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:23.743700027 CET | 283 | OUT | |
Dec 19, 2024 11:00:23.743736982 CET | 166 | OUT | |
Dec 19, 2024 11:00:25.092927933 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.5 | 50009 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:25.219163895 CET | 279 | OUT | |
Dec 19, 2024 11:00:25.219197035 CET | 333 | OUT | |
Dec 19, 2024 11:00:26.560724974 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.5 | 50010 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:30.533154964 CET | 284 | OUT | |
Dec 19, 2024 11:00:30.533186913 CET | 248 | OUT | |
Dec 19, 2024 11:00:31.889817953 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.5 | 50011 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:32.014364004 CET | 283 | OUT | |
Dec 19, 2024 11:00:32.014384985 CET | 331 | OUT | |
Dec 19, 2024 11:00:33.379775047 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.5 | 50012 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:33.505337000 CET | 280 | OUT | |
Dec 19, 2024 11:00:33.510246992 CET | 335 | OUT | |
Dec 19, 2024 11:00:34.846632957 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.5 | 50013 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:39.199218035 CET | 286 | OUT | |
Dec 19, 2024 11:00:39.199258089 CET | 335 | OUT | |
Dec 19, 2024 11:00:40.565376997 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.5 | 50014 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:40.698086977 CET | 285 | OUT | |
Dec 19, 2024 11:00:40.698121071 CET | 230 | OUT | |
Dec 19, 2024 11:00:42.052089930 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.5 | 50015 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:42.186908960 CET | 280 | OUT | |
Dec 19, 2024 11:00:42.186943054 CET | 150 | OUT | |
Dec 19, 2024 11:00:43.521437883 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.5 | 50016 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:47.776496887 CET | 286 | OUT | |
Dec 19, 2024 11:00:47.776541948 CET | 217 | OUT | |
Dec 19, 2024 11:00:49.147445917 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.5 | 50017 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:49.274692059 CET | 285 | OUT | |
Dec 19, 2024 11:00:49.274730921 CET | 297 | OUT | |
Dec 19, 2024 11:00:50.646676064 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.5 | 50018 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:50.773264885 CET | 281 | OUT | |
Dec 19, 2024 11:00:50.773303032 CET | 192 | OUT | |
Dec 19, 2024 11:00:52.117582083 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.5 | 50019 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:56.760693073 CET | 282 | OUT | |
Dec 19, 2024 11:00:56.760725975 CET | 160 | OUT | |
Dec 19, 2024 11:00:58.140840054 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.5 | 50020 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:58.271836042 CET | 287 | OUT | |
Dec 19, 2024 11:00:58.271836042 CET | 202 | OUT | |
Dec 19, 2024 11:00:59.638279915 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.5 | 50021 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:00:59.771935940 CET | 279 | OUT | |
Dec 19, 2024 11:00:59.771965981 CET | 223 | OUT | |
Dec 19, 2024 11:01:01.112617016 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.5 | 50022 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:05.126802921 CET | 282 | OUT | |
Dec 19, 2024 11:01:05.126802921 CET | 245 | OUT | |
Dec 19, 2024 11:01:06.509078026 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.5 | 50023 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:06.634035110 CET | 284 | OUT | |
Dec 19, 2024 11:01:06.634068966 CET | 205 | OUT | |
Dec 19, 2024 11:01:08.004259109 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.5 | 50024 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:08.136343956 CET | 278 | OUT | |
Dec 19, 2024 11:01:08.136374950 CET | 119 | OUT | |
Dec 19, 2024 11:01:09.477787971 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.5 | 50025 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:14.152884960 CET | 283 | OUT | |
Dec 19, 2024 11:01:14.152934074 CET | 319 | OUT | |
Dec 19, 2024 11:01:15.514272928 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.5 | 50026 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:15.643481016 CET | 286 | OUT | |
Dec 19, 2024 11:01:15.643481016 CET | 325 | OUT | |
Dec 19, 2024 11:01:17.013854027 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.5 | 50027 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:17.145970106 CET | 283 | OUT | |
Dec 19, 2024 11:01:17.145992994 CET | 332 | OUT | |
Dec 19, 2024 11:01:18.481949091 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.5 | 50028 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:22.850096941 CET | 283 | OUT | |
Dec 19, 2024 11:01:22.850096941 CET | 237 | OUT | |
Dec 19, 2024 11:01:24.212259054 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.5 | 50029 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:24.338927984 CET | 286 | OUT | |
Dec 19, 2024 11:01:24.338943005 CET | 230 | OUT | |
Dec 19, 2024 11:01:25.693094015 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.5 | 50030 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:25.834745884 CET | 279 | OUT | |
Dec 19, 2024 11:01:25.834745884 CET | 167 | OUT | |
Dec 19, 2024 11:01:27.174427986 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.5 | 50031 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:31.331737995 CET | 281 | OUT | |
Dec 19, 2024 11:01:31.334003925 CET | 270 | OUT | |
Dec 19, 2024 11:01:32.784692049 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.5 | 50032 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:32.910561085 CET | 283 | OUT | |
Dec 19, 2024 11:01:32.910592079 CET | 169 | OUT | |
Dec 19, 2024 11:01:34.291301012 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.5 | 50033 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:34.421761990 CET | 278 | OUT | |
Dec 19, 2024 11:01:34.421787977 CET | 145 | OUT | |
Dec 19, 2024 11:01:35.755727053 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.5 | 50034 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:39.873128891 CET | 285 | OUT | |
Dec 19, 2024 11:01:39.873186111 CET | 234 | OUT | |
Dec 19, 2024 11:01:41.227861881 CET | 595 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.5 | 50035 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:41.715229988 CET | 288 | OUT | |
Dec 19, 2024 11:01:41.715244055 CET | 338 | OUT | |
Dec 19, 2024 11:01:43.091700077 CET | 597 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.5 | 50036 | 194.85.61.76 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:43.223036051 CET | 283 | OUT | |
Dec 19, 2024 11:01:43.223078012 CET | 281 | OUT | |
Dec 19, 2024 11:01:44.556948900 CET | 300 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.5 | 50037 | 94.156.177.51 | 80 | 1028 | C:\Windows\explorer.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 11:01:49.725538015 CET | 284 | OUT | |
Dec 19, 2024 11:01:49.725586891 CET | 317 | OUT | |
Dec 19, 2024 11:01:51.089430094 CET | 595 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:57:43 |
Start date: | 19/12/2024 |
Path: | C:\Users\user\Desktop\putty.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 245'760 bytes |
MD5 hash: | 3BBAC642557B0AB934ADDBAC0594561C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 04:57:51 |
Start date: | 19/12/2024 |
Path: | C:\Windows\explorer.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff674740000 |
File size: | 5'141'208 bytes |
MD5 hash: | 662F4F92FDE3557E86D110526BB578D5 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 4 |
Start time: | 04:58:11 |
Start date: | 19/12/2024 |
Path: | C:\Users\user\AppData\Roaming\hajefwb |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 245'760 bytes |
MD5 hash: | 3BBAC642557B0AB934ADDBAC0594561C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 05:00:01 |
Start date: | 19/12/2024 |
Path: | C:\Users\user\AppData\Roaming\hajefwb |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 245'760 bytes |
MD5 hash: | 3BBAC642557B0AB934ADDBAC0594561C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 7.9% |
Dynamic/Decrypted Code Coverage: | 25.5% |
Signature Coverage: | 42.7% |
Total number of Nodes: | 192 |
Total number of Limit Nodes: | 6 |
Graph
Function 0041E7A0 Relevance: 34.8, APIs: 23, Instructions: 305timeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013BF Relevance: 10.8, APIs: 7, Instructions: 299COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084CB80 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0094003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E420 Relevance: 4.6, APIs: 3, Instructions: 60librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00940E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E560 Relevance: 1.5, APIs: 1, Instructions: 17libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401891 Relevance: 1.3, APIs: 1, Instructions: 58sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018A9 Relevance: 1.3, APIs: 1, Instructions: 53sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040189C Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018B1 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0084C83F Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018D0 Relevance: 1.3, APIs: 1, Instructions: 43sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0094092B Relevance: 3.8, Strings: 3, Instructions: 90COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0084C45D Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004013CA Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013D9 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013E0 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013F0 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013F4 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401412 Relevance: .0, Instructions: 43nativeCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00940D90 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E710 Relevance: 6.0, APIs: 4, Instructions: 37COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 7.9% |
Dynamic/Decrypted Code Coverage: | 25.5% |
Signature Coverage: | 0% |
Total number of Nodes: | 192 |
Total number of Limit Nodes: | 6 |
Graph
Function 0041E7A0 Relevance: 34.8, APIs: 23, Instructions: 305timeCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013BF Relevance: 10.8, APIs: 7, Instructions: 299COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0088003C Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 515memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E420 Relevance: 4.6, APIs: 3, Instructions: 60librarymemoryloaderCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00AAB648 Relevance: 3.0, APIs: 2, Instructions: 41processCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00880E0F Relevance: 3.0, APIs: 2, Instructions: 15COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0041E560 Relevance: 1.5, APIs: 1, Instructions: 17libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401891 Relevance: 1.3, APIs: 1, Instructions: 58sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018A9 Relevance: 1.3, APIs: 1, Instructions: 53sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040189C Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004018B1 Relevance: 1.3, APIs: 1, Instructions: 52sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00AAB307 Relevance: 1.3, APIs: 1, Instructions: 48memoryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004018D0 Relevance: 1.3, APIs: 1, Instructions: 43sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E710 Relevance: 6.0, APIs: 4, Instructions: 37COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|