Windows
Analysis Report
4hSuRTwnWJ.dll
Overview
General Information
Sample name: | 4hSuRTwnWJ.dllrenamed because original name is a hash value |
Original sample name: | 0e275564dda101e8ea8a47cd5469a7f8ea90c77c.dll |
Analysis ID: | 1578337 |
MD5: | 8d7405be2b8547960e9c68184d273fa4 |
SHA1: | 0e275564dda101e8ea8a47cd5469a7f8ea90c77c |
SHA256: | 7f2b01e4a8eb8f0f1e7710f51dcad9963d1d4fd5be7a89b9115cb0176cf4f007 |
Tags: | dlluser-NDA0E |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- loaddll32.exe (PID: 7508 cmdline:
loaddll32. exe "C:\Us ers\user\D esktop\4hS uRTwnWJ.dl l" MD5: 51E6071F9CBA48E79F10C84515AAE618) - conhost.exe (PID: 7516 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 7560 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\4hS uRTwnWJ.dl l",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - rundll32.exe (PID: 7584 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\4hSu RTwnWJ.dll ",#1 MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 7568 cmdline:
rundll32.e xe C:\User s\user\Des ktop\4hSuR TwnWJ.dll, InputFile MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 7716 cmdline:
rundll32.e xe C:\User s\user\Des ktop\4hSuR TwnWJ.dll, PrintFile MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 7792 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 7 716 -s 672 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 7816 cmdline:
rundll32.e xe C:\User s\user\Des ktop\4hSuR TwnWJ.dll, WriteError Log MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 7992 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\4hSu RTwnWJ.dll ",InputFil e MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 8000 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\4hSu RTwnWJ.dll ",PrintFil e MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 8156 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 8 000 -s 676 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 8016 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\4hSu RTwnWJ.dll ",WriteErr orLog MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 8056 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 8064 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 8108 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- rundll32.exe (PID: 2056 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\4h SuRTwnWJ.d ll",WriteE rrorLog MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 1168 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5528 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 3020 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- rundll32.exe (PID: 2500 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\4h SuRTwnWJ.d ll",WriteE rrorLog MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 5484 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 3028 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 6964 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
| |
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
| |
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
|
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:05.594789+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49831 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:07.570858+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49835 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:11.622907+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49850 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:17.657602+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49869 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:19.604855+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49876 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:24.545572+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49890 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:29.845942+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49904 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:32.697810+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49918 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:35.942348+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49932 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:40.914476+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49948 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:45.786071+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49958 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:50.066130+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49971 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:52.138073+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49983 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:56.021161+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49996 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:00.168420+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50008 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:04.168789+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50022 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:08.217091+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50036 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:12.344300+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50050 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:16.332173+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50063 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:21.155101+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50076 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:24.700673+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50082 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:30.907926+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50089 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:35.048659+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50091 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:37.254137+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50095 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:43.281550+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50099 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:45.581284+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50101 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:49.602083+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50107 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:55.595696+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50112 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:57.543920+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50115 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:01.546959+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50119 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:07.590366+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50124 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:09.738406+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50129 | 116.133.8.92 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:43:57.329698+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49706 | 107.163.56.235 | 18530 | TCP |
2024-12-19T15:43:57.329783+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49707 | 107.163.56.110 | 18530 | TCP |
2024-12-19T15:44:05.594787+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49816 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:05.594788+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49817 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:09.594701+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49836 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:09.594868+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49834 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:13.638795+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49849 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:13.638840+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49848 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:17.657648+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49860 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:17.657676+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49861 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:21.658723+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49874 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:21.658747+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49875 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:25.829240+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49891 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:25.829314+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49889 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:29.845987+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49905 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:29.846026+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49903 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:33.860437+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49916 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:33.860453+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49917 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:37.876350+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49931 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:37.876495+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49933 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:41.891938+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49941 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:41.891944+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49942 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:45.892187+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49955 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:45.892217+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49957 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:50.066090+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49968 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:50.066134+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49970 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:54.079517+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49982 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:54.079535+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49981 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:58.095063+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49995 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:58.095139+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 49994 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:02.095750+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50009 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:02.095873+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50007 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:06.110726+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50021 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:06.110796+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50023 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:10.251760+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50034 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:10.251799+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50035 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:14.376757+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50049 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:14.376788+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50047 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:18.501796+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50062 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:18.501812+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50061 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:22.642349+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50074 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:22.642422+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50075 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:26.782816+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50083 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:26.782873+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50081 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:30.907815+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50088 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:30.907870+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50087 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:35.048602+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50090 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:35.048682+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50092 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:39.189229+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50094 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:39.189638+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50093 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:43.281393+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50098 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:43.281526+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50097 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:47.568847+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50100 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:47.568919+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50102 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:51.582882+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50106 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:51.583048+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50105 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:55.595606+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50111 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:55.595652+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50109 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:59.505622+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50113 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:59.505671+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50114 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:03.630963+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50118 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:03.631188+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50117 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:07.642525+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50122 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:07.642668+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50123 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:11.768467+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50127 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:11.768496+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50128 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:33.781862+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50131 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:33.922562+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.7 | 50132 | 107.163.56.236 | 18963 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:43:58.477678+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 49808 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:44:38.857491+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 49945 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:01.080211+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 50017 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:23.209488+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 50084 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:45.388903+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 50103 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:07.514473+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 50125 | 107.163.56.251 | 6658 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:43:57.329698+0100 | 2812407 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 49706 | 107.163.56.235 | 18530 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process created: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 7_2_10003F41 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Process Stats: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 7_2_10003F63 | |
Source: | Code function: | 11_2_10003F63 | |
Source: | Code function: | 14_2_10003F63 |
Source: | Code function: | 7_2_1000B224 | |
Source: | Code function: | 7_2_1000B70D | |
Source: | Code function: | 7_2_100121ED | |
Source: | Code function: | 7_2_1000AEC0 | |
Source: | Code function: | 11_2_1000B224 | |
Source: | Code function: | 11_2_1000B70D | |
Source: | Code function: | 11_2_100121ED | |
Source: | Code function: | 11_2_1000AEC0 | |
Source: | Code function: | 14_2_1000B224 | |
Source: | Code function: | 14_2_1000B70D | |
Source: | Code function: | 14_2_100121ED | |
Source: | Code function: | 14_2_1000AEC0 |
Source: | Process created: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 7_2_1000404F | |
Source: | Code function: | 11_2_1000404F | |
Source: | Code function: | 14_2_1000404F |
Source: | Code function: | 7_2_10003FB7 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 7_2_10039406 | |
Source: | Code function: | 7_2_1001F10A | |
Source: | Code function: | 7_2_1002707F | |
Source: | Code function: | 7_2_1002503A | |
Source: | Code function: | 7_2_10021033 | |
Source: | Code function: | 7_2_10036610 | |
Source: | Code function: | 7_2_10033057 | |
Source: | Code function: | 7_2_1003306B | |
Source: | Code function: | 7_2_1002D05B | |
Source: | Code function: | 7_2_1002D062 | |
Source: | Code function: | 7_2_1002506D | |
Source: | Code function: | 7_2_10031078 | |
Source: | Code function: | 7_2_1002506D | |
Source: | Code function: | 7_2_1002707F | |
Source: | Code function: | 7_2_10032FD1 | |
Source: | Code function: | 7_2_1002707F | |
Source: | Code function: | 7_2_1002B0C7 | |
Source: | Code function: | 7_2_1003109B | |
Source: | Code function: | 7_2_100270B6 | |
Source: | Code function: | 7_2_1002F0A0 | |
Source: | Code function: | 7_2_1002D0B7 | |
Source: | Code function: | 7_2_1002936A | |
Source: | Code function: | 7_2_100230BC | |
Source: | Code function: | 7_2_100370EB | |
Source: | Code function: | 7_2_100321F3 | |
Source: | Code function: | 7_2_10030851 | |
Source: | Code function: | 7_2_1003052B | |
Source: | Code function: | 7_2_10021A9B | |
Source: | Code function: | 7_2_1002CDEC | |
Source: | Code function: | 7_2_1001F10A | |
Source: | Code function: | 7_2_1002B266 |
Source: | Static PE information: |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | Evasive API call chain: | graph_11-16794 |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: |
Source: | Code function: | 7_2_1001C75E |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_11-16784 |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 7_2_1001C75E |
Source: | Code function: | 7_2_1000CCF8 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: |
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 11 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 4 Obfuscated Files or Information | LSASS Memory | 11 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 111 Process Injection | 1 Software Packing | Security Account Manager | 31 Security Software Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 11 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | 13 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 31 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | 1 Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 111 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Rundll32 | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
79% | ReversingLabs | Win32.Backdoor.Zegost | ||
100% | Avira | TR/Crypt.PEPM.Gen | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | 217.20.58.100 | true | false | high | |
blogx.sina.com.cn | 116.133.8.92 | true | false | high | |
blog.sina.com.cn | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true | unknown | ||
false | high | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.163.56.236 | unknown | United States | 20248 | TAKE2US | true | |
107.163.56.235 | unknown | United States | 20248 | TAKE2US | true | |
116.133.8.92 | blogx.sina.com.cn | China | 4837 | CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | false | |
107.163.56.110 | unknown | United States | 20248 | TAKE2US | true | |
107.163.56.251 | unknown | United States | 20248 | TAKE2US | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578337 |
Start date and time: | 2024-12-19 15:42:12 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 9m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 36 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 4hSuRTwnWJ.dllrenamed because original name is a hash value |
Original Sample Name: | 0e275564dda101e8ea8a47cd5469a7f8ea90c77c.dll |
Detection: | MAL |
Classification: | mal100.troj.evad.winDLL@37/12@2/6 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 199.232.214.172, 23.50.131.216, 23.50.131.221, 20.189.173.22, 217.20.58.100, 13.107.246.63, 20.190.147.12, 20.109.210.53
- Excluded domains from analysis (whitelisted): otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, onedsblobprdwus17.westus.cloudapp.azure.com, ctldl.windowsupdate.com, time.windows.com, a767.dspw65.akamai.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, login.live.com, blobcollector.events.data.trafficmanager.net, umwatson.events.data.microsoft.com, wu-b-net.trafficmanager.net
- Execution Graph export aborted for target rundll32.exe, PID 7716 because it is empty
- Execution Graph export aborted for target rundll32.exe, PID 8000 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 4hSuRTwnWJ.dll
Time | Type | Description |
---|---|---|
09:43:21 | API Interceptor | |
09:43:22 | API Interceptor | |
11:15:24 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
116.133.8.92 | Get hash | malicious | Unknown | Browse |
| |
107.163.56.110 | Get hash | malicious | Unknown | Browse |
| |
107.163.56.251 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
blogx.sina.com.cn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | Virut | Browse |
| |
Get hash | malicious | Virut | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PDFPhish | Browse |
| ||
Get hash | malicious | Abobus Obfuscator, Braodo | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | Abobus Obfuscator | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TAKE2US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
TAKE2US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger | Browse |
|
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | modified |
Size (bytes): | 512 |
Entropy (8bit): | 4.318938392629634 |
Encrypted: | false |
SSDEEP: | 6:yFD8eESeb43rcX3sVIKj5j+25V4dZ/XX+urVjBd55qWeeeeeeeeeeeeeA:8DXzes3rE/+5S25VG/H/BdohppppppA |
MD5: | B8CACBB7EA521952F7BB64A0FCAE758D |
SHA1: | 0C825C156DC016F9D67AF83351CC073B58B0F2F7 |
SHA-256: | 469FBD11FC971560A0C9A24CDEE404B21AF0DF88E3AA6EDC4D864CB8E2280F82 |
SHA-512: | BC0729AA41EFE84C58610309AF47F34EFB4A0923746EBA704C37F2610B10A4B463CBB3ED73D67CADB0F3FA19ECAE06ACE40095F1C78BFCB29B05CE645A721ACC |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_d2d6a05f617930bde2d4c76b2a5555e299272ba9_7522e4b5_5f1c7989-247a-4c50-9e06-04646fa13281\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.9517020163304682 |
Encrypted: | false |
SSDEEP: | 192:M4ri+OD30BU/wjeTYWaZYzuiF5Z24IO8dci:bri/DEBU/wjeMbYzuiF5Y4IO8dci |
MD5: | 6605C07F491D58D84631303E0EED2379 |
SHA1: | 4DA674EE5462E54378746698A42C95DD3F4D83AB |
SHA-256: | EC63D8D93B0ACBAFCAB74210FD182B203BB417D557901C0C33B9AFD8F906F96C |
SHA-512: | EAA2C9D16D86508D2CD343AA4346514D9993E291F8438C6352BC68DECF50938C2A8747306FF85029BA66601A7C39952D2B9717974171AD95453A021996991FA0 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_fee72e296cfe876676a0f903eac30ffbede4e6_7522e4b5_a426942b-9cc1-4632-ad20-a40ad980015f\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | modified |
Size (bytes): | 65536 |
Entropy (8bit): | 0.95110139476131 |
Encrypted: | false |
SSDEEP: | 192:mK2ixO9v0BU/wjeTIWaZYzuiF5Z24IO8dci:mziI9cBU/wje8bYzuiF5Y4IO8dci |
MD5: | 8A639D0657B936FED790168F99471FAA |
SHA1: | F90EB8B46EE8444AAE247B4204AB9081F88B37BB |
SHA-256: | C3AB4A992170FC4AA1D72144092530E30A3731E7EA0780026E93BC2884A1E153 |
SHA-512: | F9A88B395C44E3181C22184AB2F5BC3498514BDCBC2945BFF972E0E489DDD5719716E920D9B9FF6A35D8DD6AD6C210481644CE4632CF450F66FF465FCD557527 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 45656 |
Entropy (8bit): | 1.9807460023759487 |
Encrypted: | false |
SSDEEP: | 192:whd7sElZRYXtXDr1p1O5H4LPW/TLmGfN62v7:enlZRsr1pY5HKPW/XmGV7 |
MD5: | 89E869CE8D7782AA91359250C8328F41 |
SHA1: | 03CDB834687A882298F25A4109E974CB6B9B80AD |
SHA-256: | 83CF315C2CCD88970FB933963E507175CA31748CDC6E96C51FCF0B90917A5A5C |
SHA-512: | 985866E6115B19585E3795C00C1AAB0BEB09B2F6931C965536785142477DCBFD48FED681040042C6F1C9F0F603C21344731698834D4BA13AEB7A2B477EDBAA0D |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8270 |
Entropy (8bit): | 3.693794831606281 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJSJ6de6YYm67gmfTZYprE89bR9sfLbm:R6lXJM6E6Yx67gmfTZER2f2 |
MD5: | 77A2F35C8B44981C4E910278AC523636 |
SHA1: | 95D01B928FB85D036339F05CFC7D07A0388FEDE7 |
SHA-256: | E3CB929E3FF8AE6377F93996969E2C923B16588984DD8D6DD42B9347C40101D2 |
SHA-512: | C003310BB4B270DAC0730EAE15D2FE51F93B75E4A5EBAD06E28352FF1B7021A355E5D382E7A30DABB64E6900A9E0D27D9210F6BFE05F60C41C4B0605DF5DEF79 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.465563916177719 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsMiJg77aI9uBWpW8VYrYm8M4JCdPSFx1+q8/AQGScSNd:uIjfMwI7EQ7VnJp1IJ3Nd |
MD5: | C3133680F2160290D7AC8A9FD73C8FEB |
SHA1: | FC4418609140EA424157218F7FA28DC3D390B536 |
SHA-256: | 535DC7FD9C311A075FE78ABE626990365389CD4D3C721E55F6CAD946D3D226B7 |
SHA-512: | 128FED3E4D57B724E2E3F46AD440B93EA400495C0ED61B9D21C40188F9AE8615296991E1E3FA7AC5B9D50FD638FAC64AB74117AAC7B931A32089139A29C53785 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 44134 |
Entropy (8bit): | 2.030193676714978 |
Encrypted: | false |
SSDEEP: | 192:wkmELZRYXtXRm1O5H47HbZGA0kBUUlS1QZ5+:zLZRqmY5HaHbDTUiSO |
MD5: | 408C65C9077C928D27AA3EA5C1D8BFFC |
SHA1: | A47B66B348E8C204F9568848EE06055053576B25 |
SHA-256: | 7EE4F4998A6F78CF5C71368A85C668FF9E9398AF3B965626F401EC0DCEA4DD46 |
SHA-512: | B4FE8DD123089283B606750184BDAF52245660677D4D5944DFC217C0C1733A6FAA8C0B3DD7D39279F4E2A25CB5BDB9FCC0010C0C0409572A4CDD324168AB58DD |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8270 |
Entropy (8bit): | 3.6930834721870682 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJ1L6de6YYr67gmfTxYpr589bRjsf0zbm:R6lXJ56E6YM67gmfTxDRIfb |
MD5: | 26D8DB8482FCF14BF880935728888C66 |
SHA1: | 07F4657AB3943C0C3A758E9778D0DC080D0A03F5 |
SHA-256: | D9367FEFF74E95BF5A1A0C7406438DBCB14FF4E2156DF65ABF13E64235F7454F |
SHA-512: | 28293C31C7337CFDBB469738533B4ED901146391C486FE2E6C3F78632912382A8EF37E25FC29BDFBA7412195C2B6FDF7DF42C39A8217BA04B5D4E581ED3B9417 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.463345052467359 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsMiJg77aI9uBWpW8VYqYm8M4JCdPOFYT+q8/AxGScSUd:uIjfMwI7EQ7VqJSJJ3Ud |
MD5: | BA1D996487CB666A32951CFE2A9A216F |
SHA1: | B9DDF7D43090518069F5C1FD916F0FA922951538 |
SHA-256: | 1C3F247F30558E0EFEF13154AAB2B341694E761A9756FA30D0E7AF2C4A055614 |
SHA-512: | 688FBFB8C5B178913028748209AE5D6D3A4C6756F3D2EA05E35F0A19C5E3AE3B6B279E2C0F7C63EEA72FB316256A996B383A2B2BF372D8BEE5BFAD3043530246 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.1483147145857515 |
Encrypted: | false |
SSDEEP: | 6:kKwHH3l99UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:IHH3lkDnLNkPlE99SNxAhUe/3 |
MD5: | 259B84979B2DC6F1525C26394D999D37 |
SHA1: | 64D09F7F2D835764FFC7473A01ACC5829F46A545 |
SHA-256: | 8217180869810863B8AFBA25E6943C981277479198403FBB94127E78AD5C2D14 |
SHA-512: | 682681CE1976A2D0C802E4F1CC0A414DB64A0A47777E6C0CE5F02C1E225E2016A285CD24D6BAEDEE3915DA67F7D87893ED23C37CAF0B8A5DB8AA3E28F664FAF6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.4174667963889815 |
Encrypted: | false |
SSDEEP: | 6144:vcifpi6ceLPL9skLmb0moSWSPtaJG8nAgex285i2MMhA20X4WABlGuNo5+:Ui58oSWIZBk2MM6AFBWo |
MD5: | B9CB3FB5740B5C8DD26A1C5FE89A13EF |
SHA1: | 5C557774D15B7BEEB4EFFDD726F8ED54116E5867 |
SHA-256: | F6DF803626CC32C074A2E057D3710BFBB79F3AC2174EEA76880B61596785AE40 |
SHA-512: | F0895E4A61BCA5A14B70BC576A6DF053F910A7642F361DE7D01DBA832A3E8B358FB17C2CDFB26FA75BB3CC434CA60528A8D4141BCA853A0A35A95E7545689588 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 6.536809941748854 |
TrID: |
|
File name: | 4hSuRTwnWJ.dll |
File size: | 323'160 bytes |
MD5: | 8d7405be2b8547960e9c68184d273fa4 |
SHA1: | 0e275564dda101e8ea8a47cd5469a7f8ea90c77c |
SHA256: | 7f2b01e4a8eb8f0f1e7710f51dcad9963d1d4fd5be7a89b9115cb0176cf4f007 |
SHA512: | cc246999b22568de7db634852c5a2fb58b23f04b1cac72d831184cfbb20be7824d3c4e8590bdf07d7c1cb46b71c5013f2f317b0c09f392f8fe1c4cd95a9cce07 |
SSDEEP: | 6144:/u9FQ7867saFPJf3p2hjzM0hsf3e7nq87YvRC8BjVbdYC3u5SzKQNVzFqUsGczjE:cY9saFPhpd0hsfOjqjkEjRy9Qfzzc3E |
TLSH: | 8164AF01736293F6C8D709329EE5E72EE3346410ADD8EE62DFC214856CD345BA95A3CB |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......... B..N...N...N...B...N.F.....N.......N.......N.......N...@...N.m.D...N...O.^.N.m.E...N.=.H...N.m.J...N.Rich..N................ |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x10041ddd |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED, DLL |
DLL Characteristics: | |
Time Stamp: | 0x565BD507 [Mon Nov 30 04:48:07 2015 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | dbca5d324ec49b89414af308d3b9afbd |
Instruction |
---|
call 00007F66008B0E8Bh |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x4b10c | 0x68 | .rsrc |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3ee8c | 0x118 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4b000 | 0xf8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x47000 | 0x1660 | .text |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x4a000 | 0x49e00 | 3e190c534eb040f106a79d3a71ee0197 | False | 0.6108357127749577 | data | 6.54120189405413 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x4b000 | 0x2000 | 0x1400 | 62d5d64d04b31fa595ae5d1a3403902e | False | 0.859375 | data | 7.221275945709022 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x4d000 | 0x1000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
AVI | 0x49000 | 0x1caa | RIFF (little-endian) data, AVI, 92 x 76, 5.00 fps, video: RLE 8bpp | English | United States | 0.20059961842463886 |
RT_CURSOR | 0x4acb0 | 0x134 | data | English | United States | 0.5714285714285714 |
RT_GROUP_CURSOR | 0x4ade8 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.25 |
DLL | Import |
---|---|
MFC42.DLL | |
MSVCRT.dll | strcspn |
KERNEL32.dll | MultiByteToWideChar |
USER32.dll | wsprintfA |
ADVAPI32.dll | LookupPrivilegeValueA |
WS2_32.dll | socket |
SHLWAPI.dll | PathIsDirectoryA |
ole32.dll | CoSetProxyBlanket |
OLEAUT32.dll | SafeArrayUnaccessData |
MSVCP60.dll | ?substr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QBE?AV12@II@Z |
NETAPI32.dll | Netbios |
KERNEL32.dll | GetModuleFileNameW |
KERNEL32.dll | GetModuleHandleA, LoadLibraryA, LocalAlloc, LocalFree, GetModuleFileNameA, ExitProcess |
Name | Ordinal | Address |
---|---|---|
InputFile | 1 | 0x1000678b |
PrintFile | 2 | 0x1000443d |
WriteErrorLog | 3 | 0x10008645 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:43:57.329698+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49706 | 107.163.56.235 | 18530 | TCP |
2024-12-19T15:43:57.329698+0100 | 2812407 | ETPRO MALWARE Win32/Venik HTTP CnC Beacon | 1 | 192.168.2.7 | 49706 | 107.163.56.235 | 18530 | TCP |
2024-12-19T15:43:57.329783+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49707 | 107.163.56.110 | 18530 | TCP |
2024-12-19T15:43:58.477678+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 49808 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:44:05.594787+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49816 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:05.594788+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49817 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:05.594789+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49831 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:07.570858+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49835 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:09.594701+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49836 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:09.594868+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49834 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:11.622907+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49850 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:13.638795+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49849 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:13.638840+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49848 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:17.657602+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49869 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:17.657648+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49860 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:17.657676+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49861 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:19.604855+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49876 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:21.658723+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49874 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:21.658747+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49875 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:24.545572+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49890 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:25.829240+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49891 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:25.829314+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49889 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:29.845942+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49904 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:29.845987+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49905 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:29.846026+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49903 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:32.697810+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49918 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:33.860437+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49916 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:33.860453+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49917 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:35.942348+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49932 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:37.876350+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49931 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:37.876495+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49933 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:38.857491+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 49945 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:44:40.914476+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49948 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:41.891938+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49941 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:41.891944+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49942 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:45.786071+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49958 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:45.892187+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49955 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:45.892217+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49957 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:50.066090+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49968 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:50.066130+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49971 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:50.066134+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49970 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:52.138073+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49983 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:54.079517+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49982 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:54.079535+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49981 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:56.021161+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 49996 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:58.095063+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49995 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:44:58.095139+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 49994 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:00.168420+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50008 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:01.080211+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 50017 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:02.095750+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50009 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:02.095873+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50007 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:04.168789+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50022 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:06.110726+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50021 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:06.110796+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50023 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:08.217091+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50036 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:10.251760+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50034 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:10.251799+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50035 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:12.344300+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50050 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:14.376757+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50049 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:14.376788+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50047 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:16.332173+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50063 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:18.501796+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50062 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:18.501812+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50061 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:21.155101+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50076 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:22.642349+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50074 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:22.642422+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50075 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:23.209488+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 50084 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:24.700673+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50082 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:26.782816+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50083 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:26.782873+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50081 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:30.907815+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50088 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:30.907870+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50087 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:30.907926+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50089 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:35.048602+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50090 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:35.048659+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50091 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:35.048682+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50092 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:37.254137+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50095 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:39.189229+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50094 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:39.189638+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50093 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:43.281393+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50098 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:43.281526+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50097 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:43.281550+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50099 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:45.388903+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 50103 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:45.581284+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50101 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:47.568847+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50100 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:47.568919+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50102 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:49.602083+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50107 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:51.582882+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50106 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:51.583048+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50105 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:55.595606+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50111 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:55.595652+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50109 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:55.595696+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50112 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:57.543920+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50115 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:59.505622+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50113 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:45:59.505671+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50114 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:01.546959+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50119 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:03.630963+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50118 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:03.631188+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50117 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:07.514473+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.7 | 50125 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:07.590366+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50124 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:07.642525+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50122 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:07.642668+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50123 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:09.738406+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.7 | 50129 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:11.768467+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50127 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:11.768496+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50128 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:33.781862+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50131 | 107.163.56.236 | 18963 | TCP |
2024-12-19T15:46:33.922562+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.7 | 50132 | 107.163.56.236 | 18963 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 15:43:25.139002085 CET | 49706 | 18530 | 192.168.2.7 | 107.163.56.235 |
Dec 19, 2024 15:43:25.139678001 CET | 49707 | 18530 | 192.168.2.7 | 107.163.56.110 |
Dec 19, 2024 15:43:25.259524107 CET | 18530 | 49706 | 107.163.56.235 | 192.168.2.7 |
Dec 19, 2024 15:43:25.259624958 CET | 49706 | 18530 | 192.168.2.7 | 107.163.56.235 |
Dec 19, 2024 15:43:25.259949923 CET | 18530 | 49707 | 107.163.56.110 | 192.168.2.7 |
Dec 19, 2024 15:43:25.260027885 CET | 49707 | 18530 | 192.168.2.7 | 107.163.56.110 |
Dec 19, 2024 15:43:25.270073891 CET | 49706 | 18530 | 192.168.2.7 | 107.163.56.235 |
Dec 19, 2024 15:43:25.270653009 CET | 49707 | 18530 | 192.168.2.7 | 107.163.56.110 |
Dec 19, 2024 15:43:25.389642000 CET | 18530 | 49706 | 107.163.56.235 | 192.168.2.7 |
Dec 19, 2024 15:43:25.390156031 CET | 18530 | 49707 | 107.163.56.110 | 192.168.2.7 |
Dec 19, 2024 15:43:57.329698086 CET | 49706 | 18530 | 192.168.2.7 | 107.163.56.235 |
Dec 19, 2024 15:43:57.329782963 CET | 49707 | 18530 | 192.168.2.7 | 107.163.56.110 |
Dec 19, 2024 15:43:58.356725931 CET | 49808 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:43:58.476782084 CET | 6658 | 49808 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:43:58.476898909 CET | 49808 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:43:58.477678061 CET | 49808 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:43:58.597600937 CET | 6658 | 49808 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:44:01.465836048 CET | 49816 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.465987921 CET | 49817 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.585410118 CET | 18963 | 49816 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:01.585464954 CET | 18963 | 49817 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:01.585549116 CET | 49816 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.585561991 CET | 49817 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.585722923 CET | 49816 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.585844994 CET | 49817 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:01.706305027 CET | 18963 | 49816 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:01.706320047 CET | 18963 | 49817 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:05.254596949 CET | 49831 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.374200106 CET | 80 | 49831 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:05.374547005 CET | 49831 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.374687910 CET | 49831 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.494208097 CET | 80 | 49831 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:05.594788074 CET | 49817 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.594786882 CET | 49816 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.594789028 CET | 49831 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.595273018 CET | 49834 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.707403898 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.707803011 CET | 49836 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.715545893 CET | 18963 | 49834 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:05.715744019 CET | 49834 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.716157913 CET | 49834 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.827250004 CET | 80 | 49835 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:05.827500105 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.827575922 CET | 18963 | 49836 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:05.827719927 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:05.827765942 CET | 49836 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.827950954 CET | 49836 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:05.835628986 CET | 18963 | 49834 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:05.947415113 CET | 80 | 49835 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:05.947550058 CET | 18963 | 49836 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:07.570759058 CET | 80 | 49835 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:07.570858002 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:07.574418068 CET | 49842 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:07.574453115 CET | 443 | 49842 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:07.574520111 CET | 49842 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:07.584115982 CET | 49842 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:07.584131956 CET | 443 | 49842 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:09.594701052 CET | 49836 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.594764948 CET | 49842 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.594867945 CET | 49834 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.595771074 CET | 49848 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.708043098 CET | 49849 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.715251923 CET | 18963 | 49848 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:09.715337038 CET | 49848 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.715462923 CET | 49848 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.723378897 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.723741055 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.827555895 CET | 18963 | 49849 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:09.827699900 CET | 49849 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.834042072 CET | 49849 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:09.834969997 CET | 18963 | 49848 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:09.843318939 CET | 80 | 49850 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:09.843332052 CET | 80 | 49835 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:09.843427896 CET | 49835 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.843456030 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.843630075 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:09.953705072 CET | 18963 | 49849 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:09.963267088 CET | 80 | 49850 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:11.622842073 CET | 80 | 49850 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:11.622906923 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:11.647483110 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:11.647504091 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:11.647727966 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:11.648653030 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:11.648675919 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.589436054 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.589581013 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:13.590243101 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.593661070 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:13.638794899 CET | 49849 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.638839960 CET | 49848 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.664335012 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:13.664366961 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.664756060 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.664822102 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:13.667198896 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:13.670322895 CET | 49860 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.711328983 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:13.789907932 CET | 18963 | 49860 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:13.790004015 CET | 49860 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.803733110 CET | 49861 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.805699110 CET | 49860 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.923325062 CET | 18963 | 49861 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:13.923433065 CET | 49861 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:13.925431013 CET | 18963 | 49860 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:13.926978111 CET | 49861 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:14.046407938 CET | 18963 | 49861 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550076962 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550102949 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550159931 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550175905 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.550194979 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550224066 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.550230980 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.550281048 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.557266951 CET | 49856 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.557284117 CET | 443 | 49856 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.675322056 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.675642014 CET | 49869 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.795409918 CET | 80 | 49869 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.795458078 CET | 80 | 49850 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:15.795646906 CET | 49850 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.795748949 CET | 49869 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.795933008 CET | 49869 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:15.915494919 CET | 80 | 49869 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:17.657602072 CET | 49869 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:17.657648087 CET | 49860 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.657675982 CET | 49861 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.659166098 CET | 49874 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.689836025 CET | 80 | 49869 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:17.689908981 CET | 49869 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:17.772615910 CET | 49875 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.775923014 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:17.778778076 CET | 18963 | 49874 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:17.778888941 CET | 49874 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.779829025 CET | 49874 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.892268896 CET | 18963 | 49875 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:17.893701077 CET | 49875 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.893923044 CET | 49875 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:17.896155119 CET | 80 | 49876 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:17.896244049 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:17.896368980 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:17.899724960 CET | 18963 | 49874 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:18.013463974 CET | 18963 | 49875 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:18.015816927 CET | 80 | 49876 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:19.604732990 CET | 80 | 49876 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:19.604855061 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:19.619478941 CET | 49882 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:19.619525909 CET | 443 | 49882 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:19.619677067 CET | 49882 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:19.619956017 CET | 49882 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:19.619965076 CET | 443 | 49882 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:21.658682108 CET | 49882 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.658723116 CET | 49874 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.658746958 CET | 49875 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.690306902 CET | 49889 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.810445070 CET | 18963 | 49889 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:21.813637018 CET | 49889 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.814888000 CET | 49889 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.865405083 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.865722895 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.866683960 CET | 49891 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.934429884 CET | 18963 | 49889 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:21.985356092 CET | 80 | 49890 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:21.985702991 CET | 80 | 49876 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:21.985729933 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.985759020 CET | 49876 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.986197948 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:21.986382961 CET | 18963 | 49891 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:21.989700079 CET | 49891 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:21.990005970 CET | 49891 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:22.105684996 CET | 80 | 49890 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:22.109539986 CET | 18963 | 49891 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:24.545500040 CET | 80 | 49890 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:24.545572042 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:24.549632072 CET | 49897 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:24.549673080 CET | 443 | 49897 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:24.549761057 CET | 49897 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:24.550085068 CET | 49897 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:24.550100088 CET | 443 | 49897 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:25.829240084 CET | 49891 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:25.829272032 CET | 49897 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:25.829313993 CET | 49889 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:25.831084967 CET | 49903 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:25.942919016 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:25.943305016 CET | 49904 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:25.943682909 CET | 49905 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:25.950598955 CET | 18963 | 49903 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:25.950735092 CET | 49903 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:25.950902939 CET | 49903 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:26.063003063 CET | 80 | 49904 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:26.063021898 CET | 80 | 49890 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:26.063199997 CET | 49890 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:26.063211918 CET | 49904 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:26.063460112 CET | 18963 | 49905 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:26.063525915 CET | 49905 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:26.065944910 CET | 49904 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:26.066159964 CET | 49905 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:26.070430994 CET | 18963 | 49903 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:26.185528994 CET | 80 | 49904 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:26.185668945 CET | 18963 | 49905 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:29.845942020 CET | 49904 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:29.845987082 CET | 49905 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:29.846025944 CET | 49903 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:29.846751928 CET | 49916 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:29.958270073 CET | 49917 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:29.961352110 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:29.966382027 CET | 18963 | 49916 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:29.966480970 CET | 49916 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:29.966614008 CET | 49916 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:30.079833984 CET | 18963 | 49917 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:30.079967976 CET | 49917 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:30.080513954 CET | 49917 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:30.080929041 CET | 80 | 49918 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:30.080990076 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:30.081068039 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:30.089689016 CET | 18963 | 49916 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:30.200867891 CET | 18963 | 49917 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:30.201683044 CET | 80 | 49918 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:32.696099997 CET | 80 | 49918 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:32.697809935 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:32.700773954 CET | 49925 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:32.700830936 CET | 443 | 49925 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:32.700970888 CET | 49925 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:32.701271057 CET | 49925 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:32.701286077 CET | 443 | 49925 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:33.860436916 CET | 49916 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:33.860452890 CET | 49917 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:33.860481977 CET | 49925 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:33.861788988 CET | 49931 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:33.974404097 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:33.974920988 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:33.977386951 CET | 49933 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:33.983946085 CET | 18963 | 49931 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:33.984067917 CET | 49931 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:33.984309912 CET | 49931 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:34.095704079 CET | 80 | 49918 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:34.095756054 CET | 80 | 49932 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:34.095940113 CET | 49918 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:34.096035004 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:34.096609116 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:34.098579884 CET | 18963 | 49933 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:34.098690987 CET | 49933 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:34.098803043 CET | 49933 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:34.106734037 CET | 18963 | 49931 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:34.216125011 CET | 80 | 49932 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:34.218255997 CET | 18963 | 49933 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:35.942162991 CET | 80 | 49932 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:35.942348003 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:35.944744110 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:35.944787025 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:35.944856882 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:35.945074081 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:35.945089102 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.815800905 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.816004038 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:37.816648006 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.816725016 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:37.827132940 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:37.827157021 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.827466965 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.827524900 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:37.828140020 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:37.875329971 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:37.876349926 CET | 49931 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:37.876494884 CET | 49933 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:37.877017975 CET | 49941 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:37.994467974 CET | 49942 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:37.996601105 CET | 18963 | 49941 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:37.996714115 CET | 49941 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:37.996845961 CET | 49941 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:38.114084005 CET | 18963 | 49942 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:38.114183903 CET | 49942 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:38.114346027 CET | 49942 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:38.117132902 CET | 18963 | 49941 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:38.234997034 CET | 18963 | 49942 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:38.622896910 CET | 6658 | 49808 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:44:38.623016119 CET | 49808 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:44:38.736982107 CET | 49945 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:44:38.819076061 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.819104910 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.819142103 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.819166899 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.819183111 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.819219112 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.856878042 CET | 6658 | 49945 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:44:38.857033968 CET | 49945 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:44:38.857491016 CET | 49945 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:44:38.860982895 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.861056089 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.861072063 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.861112118 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.864301920 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.864321947 CET | 443 | 49937 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:38.864336014 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.864372969 CET | 49937 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:38.977159023 CET | 6658 | 49945 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:44:39.016561985 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:39.017699003 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:39.137042999 CET | 80 | 49932 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:39.137114048 CET | 49932 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:39.137370110 CET | 80 | 49948 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:39.137701988 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:39.137862921 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:39.258212090 CET | 80 | 49948 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:40.914382935 CET | 80 | 49948 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:40.914475918 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:40.984940052 CET | 49953 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:40.984992027 CET | 443 | 49953 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:40.985064030 CET | 49953 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:40.985567093 CET | 49953 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:40.985579014 CET | 443 | 49953 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:41.891937971 CET | 49941 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:41.891943932 CET | 49942 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:41.891977072 CET | 49953 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:41.893091917 CET | 49955 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.005234003 CET | 49957 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.005667925 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:42.005714893 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:42.012782097 CET | 18963 | 49955 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:42.013787031 CET | 49955 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.014028072 CET | 49955 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.125686884 CET | 18963 | 49957 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:42.125807047 CET | 49957 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.126000881 CET | 80 | 49958 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:42.126342058 CET | 80 | 49948 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:42.126363039 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:42.126410961 CET | 49957 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:42.126411915 CET | 49948 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:42.126972914 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:42.133472919 CET | 18963 | 49955 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:42.245903015 CET | 18963 | 49957 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:42.246414900 CET | 80 | 49958 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:45.785994053 CET | 80 | 49958 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:45.786071062 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:45.791655064 CET | 49967 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:45.791697025 CET | 443 | 49967 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:45.791778088 CET | 49967 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:45.792244911 CET | 49967 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:45.792258978 CET | 443 | 49967 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:45.892187119 CET | 49955 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:45.892189026 CET | 49967 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:45.892216921 CET | 49957 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:45.893035889 CET | 49968 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.012872934 CET | 18963 | 49968 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:46.013020992 CET | 49968 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.075443983 CET | 49968 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.195672989 CET | 18963 | 49968 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:46.251287937 CET | 49970 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.252057076 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:46.252660990 CET | 49971 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:46.370908976 CET | 18963 | 49970 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:46.371063948 CET | 49970 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.371279001 CET | 49970 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:46.371861935 CET | 80 | 49958 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:46.371916056 CET | 49958 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:46.372176886 CET | 80 | 49971 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:46.372243881 CET | 49971 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:46.372374058 CET | 49971 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:46.490757942 CET | 18963 | 49970 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:46.491810083 CET | 80 | 49971 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:50.066090107 CET | 49968 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.066129923 CET | 49971 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:50.066133976 CET | 49970 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.066642046 CET | 49981 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.177200079 CET | 49982 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.178608894 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:50.186290979 CET | 18963 | 49981 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:50.186518908 CET | 49981 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.186664104 CET | 49981 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.297799110 CET | 18963 | 49982 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:50.298006058 CET | 49982 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.299334049 CET | 49982 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:50.299355984 CET | 80 | 49983 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:50.299432039 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:50.299508095 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:50.306622028 CET | 18963 | 49981 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:50.418874979 CET | 18963 | 49982 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:50.420331955 CET | 80 | 49983 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:52.138010025 CET | 80 | 49983 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:52.138072968 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:52.141153097 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:52.141218901 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:52.141299009 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:52.141563892 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:52.141578913 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.008619070 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.008713007 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.009423971 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.009471893 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.012588024 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.012614012 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.012937069 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.012988091 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.013420105 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.055368900 CET | 443 | 49989 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.079495907 CET | 49989 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.079516888 CET | 49982 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.079535007 CET | 49981 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.080269098 CET | 49994 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.193977118 CET | 49995 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.194056034 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.194248915 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.199845076 CET | 18963 | 49994 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:54.199934959 CET | 49994 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.200027943 CET | 49994 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.313800097 CET | 18963 | 49995 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:54.313920021 CET | 49995 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.314186096 CET | 80 | 49996 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.314253092 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.314419985 CET | 49995 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:54.314544916 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.314692974 CET | 80 | 49983 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:54.314739943 CET | 49983 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:54.320791006 CET | 18963 | 49994 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:54.434046984 CET | 18963 | 49995 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:54.434273958 CET | 80 | 49996 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:56.020998001 CET | 80 | 49996 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:56.021161079 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:56.023509979 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:56.023550987 CET | 443 | 50001 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:56.023622036 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:56.023873091 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:56.023886919 CET | 443 | 50001 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:57.860440016 CET | 443 | 50001 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:57.861339092 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:57.861339092 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:57.861361027 CET | 443 | 50001 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:57.863142967 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:57.863149881 CET | 443 | 50001 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:58.095010042 CET | 50001 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.095062971 CET | 49995 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.095139027 CET | 49994 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.095849037 CET | 50007 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.208694935 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.209060907 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.209434986 CET | 50009 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.217524052 CET | 18963 | 50007 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:58.217622995 CET | 50007 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.217772961 CET | 50007 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.330967903 CET | 80 | 49996 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:58.331017017 CET | 80 | 50008 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:58.331110001 CET | 49996 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.331186056 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.331365108 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:44:58.331413031 CET | 18963 | 50009 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:58.331471920 CET | 50009 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.331553936 CET | 50009 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:44:58.339555025 CET | 18963 | 50007 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:44:58.451296091 CET | 80 | 50008 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:44:58.451356888 CET | 18963 | 50009 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:00.168304920 CET | 80 | 50008 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:00.168420076 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:00.171067953 CET | 50014 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:00.171129942 CET | 443 | 50014 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:00.171196938 CET | 50014 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:00.171535015 CET | 50014 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:00.171546936 CET | 443 | 50014 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:00.748408079 CET | 6658 | 49945 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:00.748496056 CET | 49945 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:00.940012932 CET | 50017 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:01.059699059 CET | 6658 | 50017 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:01.059901953 CET | 50017 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:01.080210924 CET | 50017 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:01.200001955 CET | 6658 | 50017 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:02.095750093 CET | 50009 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.095873117 CET | 50007 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.095968962 CET | 50014 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.097135067 CET | 50021 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.210568905 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.210875988 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.212924004 CET | 50023 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.217088938 CET | 18963 | 50021 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:02.217189074 CET | 50021 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.217436075 CET | 50021 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.330424070 CET | 80 | 50022 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:02.330523014 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.330830097 CET | 80 | 50008 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:02.330876112 CET | 50008 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.331999063 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:02.332480907 CET | 18963 | 50023 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:02.332544088 CET | 50023 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.333841085 CET | 50023 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:02.337816954 CET | 18963 | 50021 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:02.453293085 CET | 80 | 50022 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:02.453919888 CET | 18963 | 50023 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:04.168651104 CET | 80 | 50022 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:04.168788910 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:04.183799982 CET | 50028 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:04.183928013 CET | 443 | 50028 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:04.184026003 CET | 50028 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:04.184293032 CET | 50028 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:04.184334040 CET | 443 | 50028 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:06.110726118 CET | 50021 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.110776901 CET | 50028 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.110795975 CET | 50023 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.111298084 CET | 50034 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.233069897 CET | 18963 | 50034 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:06.233208895 CET | 50034 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.244977951 CET | 50034 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.252770901 CET | 50035 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.253417015 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.253663063 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.367958069 CET | 18963 | 50034 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:06.377278090 CET | 18963 | 50035 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:06.377319098 CET | 80 | 50036 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:06.377362967 CET | 50035 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.377391100 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.377504110 CET | 50035 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:06.377635956 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.378549099 CET | 80 | 50022 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:06.378593922 CET | 50022 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:06.497041941 CET | 18963 | 50035 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:06.497139931 CET | 80 | 50036 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:08.216953993 CET | 80 | 50036 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:08.217091084 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:08.219592094 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:08.219635963 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:08.219706059 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:08.220098972 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:08.220114946 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.068905115 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.068984985 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.069684029 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.069736004 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.072788000 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.072798014 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.073038101 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.073092937 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.073498011 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.115367889 CET | 443 | 50041 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.251724005 CET | 50041 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.251760006 CET | 50034 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.251799107 CET | 50035 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.252383947 CET | 50047 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.374124050 CET | 18963 | 50047 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:10.376691103 CET | 50047 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.377417088 CET | 50047 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.423861027 CET | 50049 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.424381971 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.424530029 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.497059107 CET | 18963 | 50047 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:10.543493986 CET | 18963 | 50049 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:10.544266939 CET | 80 | 50050 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.544461966 CET | 50049 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.544470072 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.544595957 CET | 50049 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:10.544713974 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.545116901 CET | 80 | 50036 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:10.545883894 CET | 50036 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:10.664510965 CET | 18963 | 50049 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:10.664926052 CET | 80 | 50050 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:12.343481064 CET | 80 | 50050 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:12.344300032 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:12.347178936 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:12.347330093 CET | 443 | 50055 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:12.347455025 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:12.347628117 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:12.347665071 CET | 443 | 50055 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.313711882 CET | 443 | 50055 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.313951015 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.314631939 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.314656019 CET | 443 | 50055 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.316539049 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.316555023 CET | 443 | 50055 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.376756907 CET | 50049 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.376787901 CET | 50055 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.376787901 CET | 50047 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.378103018 CET | 50061 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.497905016 CET | 18963 | 50061 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:14.500910997 CET | 50061 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.502003908 CET | 50061 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.505887032 CET | 50062 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.506484985 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.506680965 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.622998953 CET | 18963 | 50061 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:14.626645088 CET | 18963 | 50062 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:14.626977921 CET | 50062 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.627084970 CET | 80 | 50063 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.627245903 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.627757072 CET | 50062 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:14.627959013 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.630552053 CET | 80 | 50050 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:14.630660057 CET | 50050 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:14.747253895 CET | 18963 | 50062 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:14.747508049 CET | 80 | 50063 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:16.332056046 CET | 80 | 50063 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:16.332173109 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:16.495088100 CET | 50069 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:16.495130062 CET | 443 | 50069 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:16.495198011 CET | 50069 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:16.541349888 CET | 50069 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:16.541368008 CET | 443 | 50069 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:18.501754045 CET | 50069 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.501796007 CET | 50062 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.501811981 CET | 50061 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.502576113 CET | 50074 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.622394085 CET | 18963 | 50074 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:18.622482061 CET | 50074 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.626888037 CET | 50074 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.630290031 CET | 50075 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.632178068 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.632448912 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.748209953 CET | 18963 | 50074 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:18.751641989 CET | 18963 | 50075 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:18.751707077 CET | 50075 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.751976967 CET | 50075 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:18.752964020 CET | 80 | 50076 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:18.753019094 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.753139019 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.753478050 CET | 80 | 50063 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:18.753526926 CET | 50063 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:18.871839046 CET | 18963 | 50075 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:18.873028040 CET | 80 | 50076 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:21.154957056 CET | 80 | 50076 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:21.155101061 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:21.158211946 CET | 50080 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:21.158279896 CET | 443 | 50080 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:21.158371925 CET | 50080 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:21.158627987 CET | 50080 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:21.158647060 CET | 443 | 50080 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:22.642349005 CET | 50074 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.642388105 CET | 50080 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.642421961 CET | 50075 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.643331051 CET | 50081 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.762909889 CET | 18963 | 50081 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:22.763205051 CET | 50081 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.781579971 CET | 50081 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.783571005 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.783860922 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.784874916 CET | 50083 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.901667118 CET | 18963 | 50081 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:22.903495073 CET | 80 | 50082 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:22.903584003 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.903887033 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.904068947 CET | 80 | 50076 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:22.904134989 CET | 50076 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:22.904375076 CET | 18963 | 50083 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:22.904433012 CET | 50083 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.904586077 CET | 50083 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:22.952277899 CET | 6658 | 50017 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:22.952353001 CET | 50017 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:23.023519039 CET | 80 | 50082 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:23.024023056 CET | 18963 | 50083 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:23.088705063 CET | 50084 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:23.209011078 CET | 6658 | 50084 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:23.209109068 CET | 50084 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:23.209487915 CET | 50084 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:23.329303980 CET | 6658 | 50084 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:24.700570107 CET | 80 | 50082 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:24.700673103 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:24.705903053 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:24.705952883 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:24.706027985 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:24.706451893 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:24.706465006 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.550719976 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.550813913 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.551522017 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.551578999 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.559245110 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.559329987 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.559557915 CET | 443 | 50085 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.559561014 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.559602022 CET | 50085 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.680836916 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.681205034 CET | 50086 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.782815933 CET | 50083 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:26.782872915 CET | 50081 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:26.800976992 CET | 80 | 50086 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.801031113 CET | 50086 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.801352024 CET | 80 | 50082 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:26.801414013 CET | 50082 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:26.902228117 CET | 50087 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:26.903506041 CET | 50088 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:27.022941113 CET | 18963 | 50087 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:27.023044109 CET | 50087 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:27.023336887 CET | 50087 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:27.023883104 CET | 18963 | 50088 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:27.023950100 CET | 50088 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:27.024148941 CET | 50088 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:27.143253088 CET | 18963 | 50087 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:27.143853903 CET | 18963 | 50088 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:27.643168926 CET | 50089 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:27.764019012 CET | 80 | 50089 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:27.764106989 CET | 50089 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:27.764269114 CET | 50089 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:27.886048079 CET | 80 | 50089 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:30.907814980 CET | 50088 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:30.907870054 CET | 50087 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:30.907926083 CET | 50089 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:30.908483982 CET | 50090 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.028357983 CET | 18963 | 50090 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:31.028436899 CET | 50090 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.050149918 CET | 50090 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.056180954 CET | 50091 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:31.059505939 CET | 50092 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.169950962 CET | 18963 | 50090 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:31.176034927 CET | 80 | 50091 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:31.176115036 CET | 50091 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:31.179280996 CET | 18963 | 50092 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:31.179351091 CET | 50092 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.193454027 CET | 50091 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:31.193579912 CET | 50092 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:31.313112020 CET | 80 | 50091 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:31.313160896 CET | 18963 | 50092 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:35.048602104 CET | 50090 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.048659086 CET | 50091 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:35.048681974 CET | 50092 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.049475908 CET | 50093 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.168970108 CET | 18963 | 50093 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:35.169045925 CET | 50093 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.169203043 CET | 50093 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.189779997 CET | 50094 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.192229033 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:35.446683884 CET | 18963 | 50093 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:35.446751118 CET | 18963 | 50094 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:35.446762085 CET | 80 | 50095 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:35.446873903 CET | 50094 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.449943066 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:35.463093996 CET | 50094 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:35.463205099 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:35.582676888 CET | 18963 | 50094 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:35.582730055 CET | 80 | 50095 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:37.253882885 CET | 80 | 50095 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:37.254137039 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:37.256635904 CET | 50096 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:37.256664038 CET | 443 | 50096 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:37.256766081 CET | 50096 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:37.257550955 CET | 50096 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:37.257564068 CET | 443 | 50096 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:39.189229012 CET | 50094 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.189233065 CET | 50096 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.189637899 CET | 50093 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.192918062 CET | 50097 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.311285019 CET | 50098 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.311489105 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.311711073 CET | 50099 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.312649965 CET | 18963 | 50097 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:39.312721014 CET | 50097 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.313093901 CET | 50097 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.430943012 CET | 18963 | 50098 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:39.431019068 CET | 50098 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.431165934 CET | 50098 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:39.431227922 CET | 80 | 50099 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:39.431333065 CET | 80 | 50095 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:39.431334019 CET | 50099 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.431457043 CET | 50095 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.431503057 CET | 50099 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:39.432578087 CET | 18963 | 50097 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:39.550582886 CET | 18963 | 50098 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:39.550925970 CET | 80 | 50099 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:43.281393051 CET | 50098 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.281526089 CET | 50097 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.281549931 CET | 50099 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:43.294508934 CET | 50100 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.414138079 CET | 18963 | 50100 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:43.414266109 CET | 50100 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.560668945 CET | 50100 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.646528959 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:43.679088116 CET | 50102 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.682734013 CET | 18963 | 50100 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:43.766252995 CET | 80 | 50101 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:43.766328096 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:43.767142057 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:43.798664093 CET | 18963 | 50102 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:43.798733950 CET | 50102 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.799233913 CET | 50102 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:43.886800051 CET | 80 | 50101 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:43.919610023 CET | 18963 | 50102 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:45.140158892 CET | 6658 | 50084 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:45.144503117 CET | 50084 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:45.268703938 CET | 50103 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:45.388401985 CET | 6658 | 50103 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:45.388561010 CET | 50103 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:45.388902903 CET | 50103 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:45:45.508354902 CET | 6658 | 50103 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:45:45.581228971 CET | 80 | 50101 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:45.581284046 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:45.593522072 CET | 50104 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:45.593576908 CET | 443 | 50104 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:45.593638897 CET | 50104 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:45.597158909 CET | 50104 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:45.597182989 CET | 443 | 50104 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:47.568846941 CET | 50100 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.568892002 CET | 50104 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.568918943 CET | 50102 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.569685936 CET | 50105 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.678879976 CET | 50106 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.680932999 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.681194067 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.689194918 CET | 18963 | 50105 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:47.689265966 CET | 50105 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.689435959 CET | 50105 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.798517942 CET | 18963 | 50106 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:47.798584938 CET | 50106 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.800693035 CET | 80 | 50107 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:47.800772905 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.800923109 CET | 80 | 50101 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:47.800991058 CET | 50101 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.802362919 CET | 50106 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:47.802673101 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:47.808923006 CET | 18963 | 50105 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:47.921833992 CET | 18963 | 50106 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:47.922173977 CET | 80 | 50107 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:49.600500107 CET | 80 | 50107 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:49.602082968 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:49.607189894 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:49.607230902 CET | 443 | 50108 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:49.607296944 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:49.607635021 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:49.607650042 CET | 443 | 50108 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:51.446863890 CET | 443 | 50108 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:51.446969032 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:51.449716091 CET | 443 | 50108 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:51.449788094 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:51.582881927 CET | 50106 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.583048105 CET | 50105 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.583345890 CET | 50109 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.695914984 CET | 50111 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.702908993 CET | 18963 | 50109 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:51.702974081 CET | 50109 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.703155994 CET | 50109 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.815702915 CET | 18963 | 50111 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:51.815773964 CET | 50111 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.816128969 CET | 50111 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:51.822679043 CET | 18963 | 50109 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:51.935849905 CET | 18963 | 50111 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:53.656071901 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.656271935 CET | 443 | 50108 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:53.656348944 CET | 50108 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.782067060 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.782370090 CET | 50112 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.902018070 CET | 80 | 50112 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:53.902230978 CET | 80 | 50107 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:53.902358055 CET | 50112 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.902370930 CET | 50107 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:53.902689934 CET | 50112 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:54.023005009 CET | 80 | 50112 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:55.595606089 CET | 50111 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.595652103 CET | 50109 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.595695972 CET | 50112 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:55.596395016 CET | 50113 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.711719990 CET | 50114 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.712182045 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:55.716008902 CET | 18963 | 50113 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:55.716121912 CET | 50113 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.716362000 CET | 50113 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.831829071 CET | 18963 | 50114 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:55.831902027 CET | 50114 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.831908941 CET | 80 | 50115 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:55.831979036 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:55.832550049 CET | 50114 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:55.833029985 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:55.836091042 CET | 18963 | 50113 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:55.952205896 CET | 18963 | 50114 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:55.952545881 CET | 80 | 50115 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:57.543801069 CET | 80 | 50115 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:57.543920040 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:57.546363115 CET | 50116 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:57.546418905 CET | 443 | 50116 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:57.546494007 CET | 50116 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:57.546825886 CET | 50116 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:57.546843052 CET | 443 | 50116 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:59.505621910 CET | 50113 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.505652905 CET | 50116 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.505671024 CET | 50114 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.618047953 CET | 50117 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.619409084 CET | 50118 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.619707108 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.619951963 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.737639904 CET | 18963 | 50117 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:59.737705946 CET | 50117 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.738114119 CET | 50117 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.739011049 CET | 18963 | 50118 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:59.739077091 CET | 50118 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.739207029 CET | 50118 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:45:59.739603996 CET | 80 | 50119 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:59.739638090 CET | 80 | 50115 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:45:59.739659071 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.739681959 CET | 50115 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.739854097 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:45:59.859539986 CET | 18963 | 50117 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:59.860579967 CET | 18963 | 50118 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:45:59.861274004 CET | 80 | 50119 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:01.546864986 CET | 80 | 50119 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:01.546958923 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:01.551202059 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:01.551309109 CET | 443 | 50120 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:01.551424026 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:01.551745892 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:01.551774979 CET | 443 | 50120 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:03.493973970 CET | 443 | 50120 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:03.494051933 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:03.494771957 CET | 443 | 50120 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:03.494834900 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:03.630963087 CET | 50118 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.631187916 CET | 50117 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.635078907 CET | 50122 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.741336107 CET | 50123 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.754647017 CET | 18963 | 50122 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:03.754714012 CET | 50122 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.754858017 CET | 50122 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.861396074 CET | 18963 | 50123 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:03.861491919 CET | 50123 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.861747026 CET | 50123 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:03.874732971 CET | 18963 | 50122 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:03.982212067 CET | 18963 | 50123 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:05.543173075 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.543266058 CET | 443 | 50120 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:05.543322086 CET | 50120 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.664037943 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.664351940 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.785804987 CET | 80 | 50124 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:05.785885096 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.785947084 CET | 80 | 50119 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:05.785995007 CET | 50119 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.787271023 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:05.906850100 CET | 80 | 50124 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.281105995 CET | 6658 | 50103 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:46:07.282154083 CET | 50103 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:46:07.393902063 CET | 50125 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:46:07.513695002 CET | 6658 | 50125 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:46:07.513839960 CET | 50125 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:46:07.514472961 CET | 50125 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:46:07.590286016 CET | 80 | 50124 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.590365887 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.594192982 CET | 50126 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.594233036 CET | 443 | 50126 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.594312906 CET | 50126 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.595048904 CET | 50126 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.595057964 CET | 443 | 50126 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.634589911 CET | 6658 | 50125 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:46:07.642524958 CET | 50122 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.642631054 CET | 50126 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.642668009 CET | 50123 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.643687010 CET | 50127 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.763367891 CET | 18963 | 50127 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:07.763444901 CET | 50127 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.765124083 CET | 50127 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.775531054 CET | 50128 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.798075914 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.798563004 CET | 50129 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.884990931 CET | 18963 | 50127 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:07.895288944 CET | 18963 | 50128 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:07.898238897 CET | 50128 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.898623943 CET | 50128 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:07.918349028 CET | 80 | 50129 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.918426991 CET | 50129 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.918586969 CET | 80 | 50124 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:07.918632984 CET | 50124 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:07.918735981 CET | 50129 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:08.018259048 CET | 18963 | 50128 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:08.038220882 CET | 80 | 50129 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:09.738346100 CET | 80 | 50129 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:09.738405943 CET | 50129 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:09.742819071 CET | 50130 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:09.742868900 CET | 443 | 50130 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:09.742925882 CET | 50130 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:09.743679047 CET | 50130 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:09.743695974 CET | 443 | 50130 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:11.768466949 CET | 50127 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:11.768496037 CET | 50128 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:11.768512011 CET | 50130 | 443 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:46:11.771035910 CET | 50131 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:11.886506081 CET | 50132 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:11.890755892 CET | 18963 | 50131 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:11.890841007 CET | 50131 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:11.891078949 CET | 50131 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:12.006351948 CET | 18963 | 50132 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:12.006427050 CET | 50132 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:12.006628036 CET | 50132 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:12.010618925 CET | 18963 | 50131 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:12.126216888 CET | 18963 | 50132 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:29.407032013 CET | 6658 | 50125 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:46:29.407121897 CET | 50125 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:46:33.781785011 CET | 18963 | 50131 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:33.781862020 CET | 50131 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:33.922447920 CET | 18963 | 50132 | 107.163.56.236 | 192.168.2.7 |
Dec 19, 2024 15:46:33.922561884 CET | 50132 | 18963 | 192.168.2.7 | 107.163.56.236 |
Dec 19, 2024 15:46:39.739101887 CET | 80 | 50129 | 116.133.8.92 | 192.168.2.7 |
Dec 19, 2024 15:46:39.739197016 CET | 50129 | 80 | 192.168.2.7 | 116.133.8.92 |
Dec 19, 2024 15:47:38.627120018 CET | 49808 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:47:38.747354984 CET | 6658 | 49808 | 107.163.56.251 | 192.168.2.7 |
Dec 19, 2024 15:48:00.752263069 CET | 49945 | 6658 | 192.168.2.7 | 107.163.56.251 |
Dec 19, 2024 15:48:00.872345924 CET | 6658 | 49945 | 107.163.56.251 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 15:44:04.538868904 CET | 64593 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 19, 2024 15:44:05.253429890 CET | 53 | 64593 | 1.1.1.1 | 192.168.2.7 |
Dec 19, 2024 15:45:26.905390024 CET | 55359 | 53 | 192.168.2.7 | 1.1.1.1 |
Dec 19, 2024 15:45:27.642301083 CET | 53 | 55359 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 19, 2024 15:44:04.538868904 CET | 192.168.2.7 | 1.1.1.1 | 0xc79c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Dec 19, 2024 15:45:26.905390024 CET | 192.168.2.7 | 1.1.1.1 | 0x9870 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 19, 2024 15:43:30.822602987 CET | 1.1.1.1 | 192.168.2.7 | 0xc9c4 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:43:30.822602987 CET | 1.1.1.1 | 192.168.2.7 | 0xc9c4 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:05.253429890 CET | 1.1.1.1 | 192.168.2.7 | 0xc79c | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:05.253429890 CET | 1.1.1.1 | 192.168.2.7 | 0xc79c | No error (0) | 116.133.8.92 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:14.891725063 CET | 1.1.1.1 | 192.168.2.7 | 0x3b86 | No error (0) | default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:14.891725063 CET | 1.1.1.1 | 192.168.2.7 | 0x3b86 | No error (0) | 217.20.58.100 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:14.891725063 CET | 1.1.1.1 | 192.168.2.7 | 0x3b86 | No error (0) | 217.20.58.101 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:14.891725063 CET | 1.1.1.1 | 192.168.2.7 | 0x3b86 | No error (0) | 217.20.58.99 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:14.891725063 CET | 1.1.1.1 | 192.168.2.7 | 0x3b86 | No error (0) | 217.20.58.98 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:27.642301083 CET | 1.1.1.1 | 192.168.2.7 | 0x9870 | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:27.642301083 CET | 1.1.1.1 | 192.168.2.7 | 0x9870 | No error (0) | 116.133.8.92 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:51.648130894 CET | 1.1.1.1 | 192.168.2.7 | 0xf368 | No error (0) | default.qdr.p1.ds-c7110-microsoft.global.dns.qwilted-cds.cqloud.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:51.648130894 CET | 1.1.1.1 | 192.168.2.7 | 0xf368 | No error (0) | 217.20.58.100 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:51.648130894 CET | 1.1.1.1 | 192.168.2.7 | 0xf368 | No error (0) | 217.20.58.101 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:51.648130894 CET | 1.1.1.1 | 192.168.2.7 | 0xf368 | No error (0) | 217.20.58.99 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:45:51.648130894 CET | 1.1.1.1 | 192.168.2.7 | 0xf368 | No error (0) | 217.20.58.98 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49706 | 107.163.56.235 | 18530 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:43:25.270073891 CET | 170 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49707 | 107.163.56.110 | 18530 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:43:25.270653009 CET | 185 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49816 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:01.585722923 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 49817 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:01.585844994 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 49831 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:05.374687910 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 49834 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:05.716157913 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.7 | 49835 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:05.827719927 CET | 118 | OUT | |
Dec 19, 2024 15:44:07.570759058 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.7 | 49836 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:05.827950954 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.7 | 49848 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:09.715462923 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.7 | 49849 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:09.834042072 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.7 | 49850 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:09.843630075 CET | 118 | OUT | |
Dec 19, 2024 15:44:11.622842073 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.7 | 49860 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:13.805699110 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.7 | 49861 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:13.926978111 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.7 | 49869 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:15.795933008 CET | 118 | OUT | |
Dec 19, 2024 15:44:17.689836025 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.7 | 49874 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:17.779829025 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.7 | 49875 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:17.893923044 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.7 | 49876 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:17.896368980 CET | 118 | OUT | |
Dec 19, 2024 15:44:19.604732990 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.7 | 49889 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:21.814888000 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.7 | 49890 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:21.986197948 CET | 118 | OUT | |
Dec 19, 2024 15:44:24.545500040 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.7 | 49891 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:21.990005970 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.7 | 49903 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:25.950902939 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.7 | 49904 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:26.065944910 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.7 | 49905 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:26.066159964 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.7 | 49916 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:29.966614008 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.7 | 49917 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:30.080513954 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.7 | 49918 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:30.081068039 CET | 118 | OUT | |
Dec 19, 2024 15:44:32.696099997 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.7 | 49931 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:33.984309912 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.7 | 49932 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:34.096609116 CET | 118 | OUT | |
Dec 19, 2024 15:44:35.942162991 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.7 | 49933 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:34.098803043 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.7 | 49941 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:37.996845961 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.7 | 49942 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:38.114346027 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.7 | 49948 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:39.137862921 CET | 118 | OUT | |
Dec 19, 2024 15:44:40.914382935 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.7 | 49955 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:42.014028072 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.7 | 49957 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:42.126410961 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.7 | 49958 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:42.126972914 CET | 118 | OUT | |
Dec 19, 2024 15:44:45.785994053 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.7 | 49968 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:46.075443983 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.7 | 49970 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:46.371279001 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.7 | 49971 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:46.372374058 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.7 | 49981 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:50.186664104 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.7 | 49982 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:50.299334049 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.7 | 49983 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:50.299508095 CET | 118 | OUT | |
Dec 19, 2024 15:44:52.138010025 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.7 | 49994 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:54.200027943 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.7 | 49995 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:54.314419985 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.7 | 49996 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:54.314544916 CET | 118 | OUT | |
Dec 19, 2024 15:44:56.020998001 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.7 | 50007 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:58.217772961 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.7 | 50008 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:58.331365108 CET | 118 | OUT | |
Dec 19, 2024 15:45:00.168304920 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.7 | 50009 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:58.331553936 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.7 | 50021 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:02.217436075 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.7 | 50022 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:02.331999063 CET | 118 | OUT | |
Dec 19, 2024 15:45:04.168651104 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.7 | 50023 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:02.333841085 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.7 | 50034 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:06.244977951 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.7 | 50035 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:06.377504110 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.7 | 50036 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:06.377635956 CET | 118 | OUT | |
Dec 19, 2024 15:45:08.216953993 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.7 | 50047 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:10.377417088 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.7 | 50049 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:10.544595957 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.7 | 50050 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:10.544713974 CET | 118 | OUT | |
Dec 19, 2024 15:45:12.343481064 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.7 | 50061 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:14.502003908 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.7 | 50062 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:14.627757072 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.7 | 50063 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:14.627959013 CET | 118 | OUT | |
Dec 19, 2024 15:45:16.332056046 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.7 | 50074 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:18.626888037 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.7 | 50075 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:18.751976967 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.7 | 50076 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:18.753139019 CET | 118 | OUT | |
Dec 19, 2024 15:45:21.154957056 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.7 | 50081 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:22.781579971 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.7 | 50082 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:22.903887033 CET | 118 | OUT | |
Dec 19, 2024 15:45:24.700570107 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.7 | 50083 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:22.904586077 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.7 | 50087 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:27.023336887 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.7 | 50088 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:27.024148941 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.7 | 50089 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:27.764269114 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.7 | 50090 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:31.050149918 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.7 | 50091 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:31.193454027 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
70 | 192.168.2.7 | 50092 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:31.193579912 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
71 | 192.168.2.7 | 50093 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:35.169203043 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
72 | 192.168.2.7 | 50094 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:35.463093996 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
73 | 192.168.2.7 | 50095 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:35.463205099 CET | 118 | OUT | |
Dec 19, 2024 15:45:37.253882885 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
74 | 192.168.2.7 | 50097 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:39.313093901 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
75 | 192.168.2.7 | 50098 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:39.431165934 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
76 | 192.168.2.7 | 50099 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:39.431503057 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
77 | 192.168.2.7 | 50100 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:43.560668945 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
78 | 192.168.2.7 | 50101 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:43.767142057 CET | 118 | OUT | |
Dec 19, 2024 15:45:45.581228971 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
79 | 192.168.2.7 | 50102 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:43.799233913 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
80 | 192.168.2.7 | 50105 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:47.689435959 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
81 | 192.168.2.7 | 50106 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:47.802362919 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
82 | 192.168.2.7 | 50107 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:47.802673101 CET | 118 | OUT | |
Dec 19, 2024 15:45:49.600500107 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
83 | 192.168.2.7 | 50109 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:51.703155994 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
84 | 192.168.2.7 | 50111 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:51.816128969 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
85 | 192.168.2.7 | 50112 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:53.902689934 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
86 | 192.168.2.7 | 50113 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:55.716362000 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
87 | 192.168.2.7 | 50114 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:55.832550049 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
88 | 192.168.2.7 | 50115 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:55.833029985 CET | 118 | OUT | |
Dec 19, 2024 15:45:57.543801069 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
89 | 192.168.2.7 | 50117 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:59.738114119 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
90 | 192.168.2.7 | 50118 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:59.739207029 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
91 | 192.168.2.7 | 50119 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:59.739854097 CET | 118 | OUT | |
Dec 19, 2024 15:46:01.546864986 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
92 | 192.168.2.7 | 50122 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:03.754858017 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
93 | 192.168.2.7 | 50123 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:03.861747026 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
94 | 192.168.2.7 | 50124 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:05.787271023 CET | 118 | OUT | |
Dec 19, 2024 15:46:07.590286016 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
95 | 192.168.2.7 | 50127 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:07.765124083 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
96 | 192.168.2.7 | 50128 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:07.898623943 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
97 | 192.168.2.7 | 50129 | 116.133.8.92 | 80 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:07.918735981 CET | 118 | OUT | |
Dec 19, 2024 15:46:09.738346100 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
98 | 192.168.2.7 | 50131 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:11.891078949 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
99 | 192.168.2.7 | 50132 | 107.163.56.236 | 18963 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:12.006628036 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49856 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:44:13 UTC | 142 | OUT | |
2024-12-19 14:44:15 UTC | 653 | IN | |
2024-12-19 14:44:15 UTC | 7579 | IN | |
2024-12-19 14:44:15 UTC | 5260 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49937 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:44:37 UTC | 142 | OUT | |
2024-12-19 14:44:38 UTC | 653 | IN | |
2024-12-19 14:44:38 UTC | 7579 | IN | |
2024-12-19 14:44:38 UTC | 5260 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49989 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:44:54 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.7 | 50001 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:44:57 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.7 | 50041 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:10 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.7 | 50055 | 116.133.8.92 | 443 | 7816 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:14 UTC | 142 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:43:12 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\loaddll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe30000 |
File size: | 126'464 bytes |
MD5 hash: | 51E6071F9CBA48E79F10C84515AAE618 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 09:43:12 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:43:12 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x410000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 09:43:12 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 09:43:12 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 09:43:15 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 09:43:18 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x360000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 09:43:18 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 09:43:21 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 09:43:21 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 15 |
Start time: | 09:43:22 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 09:43:22 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x410000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 09:43:22 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 09:43:22 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfc0000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 09:43:24 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x360000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 24 |
Start time: | 11:15:25 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 25 |
Start time: | 11:15:25 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x410000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 26 |
Start time: | 11:15:25 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 11:15:25 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfc0000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 30 |
Start time: | 11:15:33 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x220000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 31 |
Start time: | 11:15:33 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x410000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 32 |
Start time: | 11:15:33 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 33 |
Start time: | 11:15:33 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xfc0000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Function 1000CCF8 Relevance: .0, Instructions: 2COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000B224 Relevance: 1.6, Strings: 1, Instructions: 400COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000AEC0 Relevance: 1.5, Strings: 1, Instructions: 266COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F63 Relevance: 1.5, APIs: 1, Instructions: 4shutdownCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FB7 Relevance: 1.5, APIs: 1, Instructions: 4processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100121ED Relevance: 1.5, Strings: 1, Instructions: 216COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000B70D Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1001C75E Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 229sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006EDE Relevance: 24.7, APIs: 7, Strings: 7, Instructions: 174sleeplibraryfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 145librarysleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 103filethreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006499 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 271timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000600F Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 97libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 12.4, APIs: 1, Strings: 6, Instructions: 109timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000436F Relevance: 10.6, APIs: 3, Strings: 4, Instructions: 72sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005318 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 53libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004630 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 103libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 64sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008086 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 117sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004192 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 100libraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 5.8% |
Dynamic/Decrypted Code Coverage: | 99.8% |
Signature Coverage: | 0% |
Total number of Nodes: | 558 |
Total number of Limit Nodes: | 14 |
Graph
Function 10006EDE Relevance: 21.2, APIs: 5, Strings: 7, Instructions: 174sleepfileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 72timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 12.4, APIs: 1, Strings: 6, Instructions: 109timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008007 Relevance: 12.2, APIs: 1, Strings: 7, Instructions: 195sleepCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 145sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008567 Relevance: 10.6, APIs: 3, Strings: 4, Instructions: 82sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 64sleepthreadCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10007101 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 95sleepCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008566 Relevance: 4.5, APIs: 2, Strings: 1, Instructions: 32sleepCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100081F7 Relevance: 3.0, APIs: 1, Strings: 1, Instructions: 48sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10023A16 Relevance: 1.5, APIs: 1, Instructions: 36threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F0A Relevance: 1.5, APIs: 1, Instructions: 10networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FF7 Relevance: 1.5, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004104 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004115 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FB7 Relevance: 1.5, APIs: 1, Instructions: 4processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000400A Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004092 Relevance: 1.5, APIs: 1, Instructions: 3registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003EB4 Relevance: 1.5, APIs: 1, Instructions: 3networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F72 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10021083 Relevance: 1.3, APIs: 1, Instructions: 3sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 229sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 103filethreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000436F Relevance: 10.6, APIs: 3, Strings: 4, Instructions: 72sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100087F4 Relevance: 6.0, APIs: 2, Strings: 2, Instructions: 32sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053B7 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 229sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006EDE Relevance: 24.7, APIs: 7, Strings: 7, Instructions: 174sleeplibraryfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000826C Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 145librarysleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000570F Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 103filethreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006499 Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 271timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000600F Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 97libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DB4 Relevance: 12.4, APIs: 1, Strings: 6, Instructions: 109timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000436F Relevance: 10.6, APIs: 3, Strings: 4, Instructions: 72sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006CF7 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005318 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 53libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004630 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 103libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A6E Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 64sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008086 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 117sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004192 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 100libraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|