Windows
Analysis Report
2JSGOlbNym.dll
Overview
General Information
Sample name: | 2JSGOlbNym.dllrenamed because original name is a hash value |
Original sample name: | bc3a8653c59edabf91eb545f7d9dcf818f3ef003.dll |
Analysis ID: | 1578341 |
MD5: | e3f13188806c9a2ecabf5eab0cf7dc5f |
SHA1: | bc3a8653c59edabf91eb545f7d9dcf818f3ef003 |
SHA256: | ad2003c10fcffe449f3b5bd445dca19d789eac82d64f0b764104d7b6d0fb955f |
Tags: | dlluser-NDA0E |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- loaddll32.exe (PID: 1612 cmdline:
loaddll32. exe "C:\Us ers\user\D esktop\2JS GOlbNym.dl l" MD5: 51E6071F9CBA48E79F10C84515AAE618) - conhost.exe (PID: 3656 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 2864 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\2JS GOlbNym.dl l",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - rundll32.exe (PID: 2168 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\2JSG OlbNym.dll ",#1 MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 2372 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 2540 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 3124 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12) - rundll32.exe (PID: 1232 cmdline:
rundll32.e xe C:\User s\user\Des ktop\2JSGO lbNym.dll, ClassObjec t MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 6136 cmdline:
rundll32.e xe C:\User s\user\Des ktop\2JSGO lbNym.dll, InputFile MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 4356 cmdline:
rundll32.e xe C:\User s\user\Des ktop\2JSGO lbNym.dll, PrintFile MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 4868 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 4 356 -s 672 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 3648 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\2JSG OlbNym.dll ",ClassObj ect MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 3596 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 5820 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 5572 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12) - rundll32.exe (PID: 3800 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\2JSG OlbNym.dll ",InputFil e MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 3732 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\2JSG OlbNym.dll ",PrintFil e MD5: 889B99C52A60DD49227C5E485A016679) - WerFault.exe (PID: 3144 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 3 732 -s 672 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- rundll32.exe (PID: 5800 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\2J SGOlbNym.d ll",ClassO bject MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 4900 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 6572 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 6044 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- rundll32.exe (PID: 4592 cmdline:
"C:\Window s\SysWOW64 \rundll32. exe" "C:\U sers\user\ Desktop\2J SGOlbNym.d ll",ClassO bject MD5: 889B99C52A60DD49227C5E485A016679) - cmd.exe (PID: 5536 cmdline:
cmd.exe /c ping 127. 0.0.1 -n 3 &rd /s /q "C:\Users\ user\Deskt op" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - conhost.exe (PID: 7060 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - PING.EXE (PID: 416 cmdline:
ping 127.0 .0.1 -n 3 MD5: B3624DD758CCECF93A1226CEF252CA12)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
| |
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
| |
Winnti_NlaifSvc | Winnti sample - file NlaifSvc.dll | Florian Roth |
|
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:43.735600+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49726 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:45.672388+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49729 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:51.735632+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49736 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:55.876769+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49739 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:57.873519+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49742 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:02.039906+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49748 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:05.977914+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49752 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:09.958806+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49756 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:14.117837+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49760 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:20.048222+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49764 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:22.017200+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49766 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:26.194962+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49773 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:30.985896+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49777 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:34.273735+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49781 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:38.289440+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49785 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:43.137902+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49789 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:48.454782+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49793 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:52.606086+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49797 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:56.751441+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49800 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:00.871330+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49802 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:02.961800+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49805 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:06.978141+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49809 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:10.975339+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49815 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:17.492889+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49820 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:19.448678+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49823 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:25.306220+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49828 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:28.410219+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49830 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:32.408255+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49837 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:35.873635+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49841 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:39.809292+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49844 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:42.064075+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49848 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:44.107927+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49852 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:48.311762+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49856 | 116.133.8.92 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:33.497786+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49706 | 107.163.56.110 | 18530 | TCP |
2024-12-19T15:44:35.689380+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49705 | 107.163.56.231 | 18530 | TCP |
2024-12-19T15:44:43.735527+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49722 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:43.735567+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49723 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:47.735838+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49728 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:47.735838+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49730 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:51.735671+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49733 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:51.735763+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49734 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:55.876691+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49737 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:55.876728+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49738 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:00.001277+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49740 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:00.001293+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49741 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:04.001669+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49746 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:04.001696+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49747 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:08.020764+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49750 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:08.020792+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49751 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:12.016757+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49754 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:12.016797+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49755 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:16.032665+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49759 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:16.032697+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49758 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:20.048172+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49762 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:20.048204+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49763 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:24.174267+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49767 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:24.174362+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49765 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:28.298071+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49771 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:28.298130+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49772 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:32.322598+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49775 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:32.322671+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49776 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:36.314726+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49779 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:36.314797+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49780 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:40.317140+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49784 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:40.317164+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49783 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:44.438893+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49788 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:44.439103+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49787 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:48.454799+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49794 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:48.454799+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49792 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:52.605958+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49796 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:52.606082+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49795 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:56.751358+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49798 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:56.751404+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49799 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:00.871302+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49801 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:00.871372+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49803 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:05.001547+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49804 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:05.001579+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49806 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:09.017360+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49808 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:09.017413+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49810 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:13.146950+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49813 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:13.146988+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49814 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:17.492707+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49818 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:17.492956+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49819 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:21.518675+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49822 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:21.518681+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49821 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:25.658559+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49825 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:25.658612+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49827 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:29.782777+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49832 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:29.782813+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49831 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:33.798470+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49836 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:33.798506+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49835 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:37.814093+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49839 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:37.814098+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49840 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:41.527427+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49845 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:41.527474+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49843 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:42.064117+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49849 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:42.064125+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49847 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:46.220249+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49850 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:46.220304+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49851 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:50.349737+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49855 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:50.349757+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49854 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:47:12.377324+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49859 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:47:12.516866+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.11 | 49860 | 107.163.56.232 | 18963 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:36.833681+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49718 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:44:58.986252+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49745 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:21.291466+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49769 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:43.513998+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49791 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:05.655037+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49811 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:27.764083+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49833 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:49.914765+0100 | 2812406 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49858 | 107.163.56.251 | 6658 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:35.689380+0100 | 2812407 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49705 | 107.163.56.231 | 18530 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process created: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 4_2_10003F41 |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Code function: | 4_2_10008AD0 |
Source: | Code function: | 4_2_10003F63 | |
Source: | Code function: | 11_2_10003F63 | |
Source: | Code function: | 19_2_10003F63 |
Source: | Code function: | 4_2_1000B247 | |
Source: | Code function: | 4_2_1000B730 | |
Source: | Code function: | 4_2_1000AEE3 | |
Source: | Code function: | 11_2_1000B247 | |
Source: | Code function: | 11_2_1000B730 | |
Source: | Code function: | 11_2_1000AEE3 | |
Source: | Code function: | 19_2_1000B247 | |
Source: | Code function: | 19_2_1000B730 | |
Source: | Code function: | 19_2_1000AEE3 |
Source: | Process created: |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 4_2_1000404F | |
Source: | Code function: | 11_2_1000404F | |
Source: | Code function: | 19_2_1000404F |
Source: | Code function: | 4_2_10003FB7 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 4_2_10038D5D | |
Source: | Code function: | 4_2_1003A636 | |
Source: | Code function: | 4_2_1003A63E | |
Source: | Code function: | 4_2_1003A647 | |
Source: | Code function: | 4_2_10032CA7 | |
Source: | Code function: | 4_2_10029013 | |
Source: | Code function: | 4_2_10027895 | |
Source: | Code function: | 4_2_1002D027 | |
Source: | Code function: | 4_2_10025033 | |
Source: | Code function: | 4_2_1002503F | |
Source: | Code function: | 4_2_1002D027 | |
Source: | Code function: | 4_2_1003901E | |
Source: | Code function: | 4_2_1002903B | |
Source: | Code function: | 4_2_10031043 | |
Source: | Code function: | 4_2_10025033 | |
Source: | Code function: | 4_2_1002503F | |
Source: | Code function: | 4_2_10031043 | |
Source: | Code function: | 4_2_10037035 | |
Source: | Code function: | 4_2_10020172 | |
Source: | Code function: | 4_2_10021047 | |
Source: | Code function: | 4_2_1002A39A | |
Source: | Code function: | 4_2_1002B04E | |
Source: | Code function: | 4_2_1003ADE1 | |
Source: | Code function: | 4_2_1003B079 | |
Source: | Code function: | 4_2_100370B8 | |
Source: | Code function: | 4_2_1003603D | |
Source: | Code function: | 4_2_1003A0D4 | |
Source: | Code function: | 4_2_1003B2C1 | |
Source: | Code function: | 4_2_1003B2D7 | |
Source: | Code function: | 4_2_10023076 | |
Source: | Code function: | 4_2_100270E0 |
Source: | Static PE information: |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | Evasive API call chain: | graph_4-29821 |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Code function: | 4_2_100086B3 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_4-30018 |
Source: | API coverage: | ||
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Code function: | 4_2_100086B3 |
Source: | Code function: | 11_2_1000CD1A |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior | ||
Source: | Registry key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior | ||
Source: | Device IO: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | OS Credential Dumping | 1 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 2 Ingress Tool Transfer | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 11 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 3 Obfuscated Files or Information | LSASS Memory | 111 System Information Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 111 Process Injection | 1 Software Packing | Security Account Manager | 31 Security Software Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 11 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 11 Registry Run Keys / Startup Folder | 1 DLL Side-Loading | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Masquerading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | 13 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 31 Virtualization/Sandbox Evasion | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Access Token Manipulation | DCSync | 1 Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 111 Process Injection | Proc Filesystem | 1 System Network Configuration Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | 1 Rundll32 | /etc/passwd and /etc/shadow | Network Sniffing | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
89% | ReversingLabs | Win32.Backdoor.Zegost | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
blogx.sina.com.cn | 116.133.8.92 | true | false | high | |
blog.sina.com.cn | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
false | high | ||
true | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high | |||
false | unknown | |||
false | unknown | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | unknown | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
107.163.56.232 | unknown | United States | 20248 | TAKE2US | true | |
116.133.8.92 | blogx.sina.com.cn | China | 4837 | CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | false | |
107.163.56.231 | unknown | United States | 20248 | TAKE2US | true | |
107.163.56.110 | unknown | United States | 20248 | TAKE2US | true | |
107.163.56.251 | unknown | United States | 20248 | TAKE2US | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1578341 |
Start date and time: | 2024-12-19 15:42:53 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 10m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 39 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2JSGOlbNym.dllrenamed because original name is a hash value |
Original Sample Name: | bc3a8653c59edabf91eb545f7d9dcf818f3ef003.dll |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winDLL@42/12@1/6 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, backgroundTaskHost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 199.232.214.172, 20.189.173.22, 23.193.114.18, 23.193.114.26, 20.190.147.11, 20.109.210.53
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, login.live.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, blobcollector.events.data.trafficmanager.net, onedsblobprdwus17.westus.cloudapp.azure.com, ctldl.windowsupdate.com, umwatson.events.data.microsoft.com, a767.dspw65.akamai.net, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 2JSGOlbNym.dll
Time | Type | Description |
---|---|---|
09:44:09 | API Interceptor | |
09:44:16 | API Interceptor | |
09:44:44 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
107.163.56.232 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
116.133.8.92 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
107.163.56.231 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
107.163.56.110 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
107.163.56.251 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
blogx.sina.com.cn | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | GhostRat | Browse |
| ||
Get hash | malicious | Virut | Browse |
| ||
Get hash | malicious | Virut | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | PDFPhish | Browse |
| ||
Get hash | malicious | Abobus Obfuscator, Braodo | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RHADAMANTHYS | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
TAKE2US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
TAKE2US | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
| ||
Get hash | malicious | GuLoader, RHADAMANTHYS | Browse |
|
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | modified |
Size (bytes): | 705 |
Entropy (8bit): | 4.955986925542614 |
Encrypted: | false |
SSDEEP: | 12:8DKH+vSE3epENs4KcGmfQ+n7BR7BR7BR7BR7BR7BR7BR7BR7BA:8DKH+vSaeENs4+mfQ+nPPPPPPPPe |
MD5: | DFE61BB0D430B43C78BB3419DB9B8D8F |
SHA1: | 6295EF17BE3B2B74BB898B90304F190257024558 |
SHA-256: | B958276D9E19D38BD659B360297BCF17CF450470180F7FE37DC340184E9F0A78 |
SHA-512: | 92C8EC39407AA396191C6F1AFD7CACC1B18DD36AB02C7089F98AA218E942F95557348A7030983F92D06F4796E9AFB7BB632FE993FCC80A23EE2E648C9A3E7839 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_d2d6a05f617930bde2d4c76b2a5555e299272ba9_7522e4b5_3541c327-8460-4f3e-a8e6-dc1b05cbe8dc\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.9509604707388567 |
Encrypted: | false |
SSDEEP: | 192:V8riROTD30BU/wjeTNW6ZYzuiFeZ24IO8dci:gio3EBU/wje57YzuiFeY4IO8dci |
MD5: | 9F329C0C19BF17BDE10EB684F0A3A9D2 |
SHA1: | 56430D514C128A5CF6B941C6E59BD368F1FB03E0 |
SHA-256: | BA84140DEE82597C6F5625352BFB1FC425FFB183017A64BCE4E7E3CE9E8930DA |
SHA-512: | E5E817CA1EBAE3FFA0B24D1C1D2BB4236DA0AC8A959D4C6BE3E73348A0C0F5FBB0EAF66A6FBD4378791729721408A66C8FFF0D1B025C20AA404AA14F38E70F35 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_rundll32.exe_fee72e296cfe876676a0f903eac30ffbede4e6_7522e4b5_a5c5fc65-7723-4f08-96ee-304caeedbc42\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.9505525066818328 |
Encrypted: | false |
SSDEEP: | 192:crfiOxiOBv0BU/wjeTtW6ZYzuiFeZ24IO8dci:YfiOlBcBU/wjeZ7YzuiFeY4IO8dci |
MD5: | 634BD457BCA0C5CCA23D47B314734EDD |
SHA1: | 0CC7F75E4648E162E7D4CA95AE75F647509A682F |
SHA-256: | 09DEA282FC0BCE1372178604AB7B8B9CF1692384C6180DD9D90381521116ED4B |
SHA-512: | A66B9F949BD5E099EC491C8A1CAFCDEF350463BFD6DEE2F939079C583BB58C6DDB5DF9CC38E2C81872C6238245FDCBA2BF1035437D1382DD7EA9A961010A6470 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 45142 |
Entropy (8bit): | 2.0268748562150543 |
Encrypted: | false |
SSDEEP: | 384:DtZ8ZwUH5H7yaFFD0yhQkCWL0j97nwhL:03H57rjhQkby7nw |
MD5: | F2FD094B1724695F3005A6C7AB74EE02 |
SHA1: | 138868ECC618A40E204F5622074797443C02C607 |
SHA-256: | 2DA85C81AED65F827E04BC83024E578EE7AB84F7935F342EC48B47F1E01DA067 |
SHA-512: | 3E0A468A5BD128102AC223F55154A031D9C82CF7DFDCB524F74A1336B143F17C9C9BCAEECCF434B706706EBFEBA8910AFBBC82BD421FCFEC24722BCDE9223944 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8268 |
Entropy (8bit): | 3.6913251362383805 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJQm6ZO6Y+Q06gdgmfTxqpr/89beOsf0MKm:R6lXJB6g6YT06SgmfTxfeNfJ |
MD5: | B747CF30A54004EAD2A8507D07A3A4EC |
SHA1: | 8FD35FF755ECD00A45B7BAB1D2CC6E2B5E1EA92B |
SHA-256: | E329FCE0649BE18790D010DB37D4E4CD07A334670214A32C22B7EBA404C8E607 |
SHA-512: | C319E3A167604F8CADF3CCE0D900E99BE70C79EF1E1973E052597FB1DAF6E56974E431F0F37971ED018240FA0ECBD83F85A162760818DCAA9567772BD92B1833 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.4615978525860305 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsMiJg77aI9xWWpW8VYrYm8M4JCdPOFfA+q8/AxRGScSUd:uIjfMwI7b37VXJkJRJ3Ud |
MD5: | 6328A58BAB041C58B31DDCAD0649E8D3 |
SHA1: | 872C1F64F85EDF8F2802404A193E404398272E8F |
SHA-256: | 7A9D65C3B79091D2D956EDB718BFC08D65560406FC08EC6E8E19078CFFCAD8CB |
SHA-512: | F16194EF4890D01BE6D2FBB1AD941C14662DB653CF07358682CB279F46A0BF8C39EA321E6D8F707382DD35DD34C581A5CD2BEB3CC624AA86A081571F139565D2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 44432 |
Entropy (8bit): | 2.048976631359992 |
Encrypted: | false |
SSDEEP: | 192:BAsZSZwaXzXClDO5H4qB3Zf3sJWuCr5rn/zi2otEfXyrV:jZSZwp65HLBJf8Jo7/zi2iEc |
MD5: | 863EB2E87DFE82D6C4582C0E8295DC8C |
SHA1: | 84CC16504FE7EFF2EC5ED0B965A303C7B4DA6A6A |
SHA-256: | 61A98BE670C585EAC4DD06237D995E4237A9C0C01993906D5555FDC985D36BA3 |
SHA-512: | CC90C557EBA2551269E800BBCAFEB13176C31FDE71880A219B27A92A999A172BC1F3860753D8D3891367930130A481A5A803EF99095BE9DCD70F43FDA970D0A7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8272 |
Entropy (8bit): | 3.691669945211612 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJhC626Yuq6mTgmfTZqprt89b6XsfFJv+m:R6lXJU626YD6mTgmfTZ16cfr |
MD5: | E150228A9B17F45AD0190ECE2B40C2FF |
SHA1: | 4614967DD1BD5A6591101E514B014E63B8BA3A7C |
SHA-256: | E1316C12B96F39D34A032C3C3EBBEF17CE3E090F426FDC6726DB0978DB5F9CB9 |
SHA-512: | B67CD4C4FDBEEE5387EB15350EFF324431F9E678709F95BF2354AAC0789EA374E559609380CA6BA553F1B9565011BDC4A145B02B8F8E66FA444EE0C8264A71F8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4654 |
Entropy (8bit): | 4.463136913363345 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsMiJg77aI9xWWpW8VYfYm8M4JCdPSFPMo+q8/A2L2GScS6d:uIjfMwI7b37VjJ3Mo5J36d |
MD5: | AC1E0D303951EB7EDA478ED2A632594A |
SHA1: | C12A59F941F96E6D1EFA2E82517DB15ACBDD942E |
SHA-256: | EB3B7A998C39D0DAD265400211B3F27B925CF64F1E9C7058E55D84A30C9A58F7 |
SHA-512: | 700E1E085D11A6A86450E3AE81F23A956D3BE383A39AC89414C5AEB4E70B6520D39E42B447AB691BC3747EED97AC29B19EBFA4FE9CF576455D95F397391DD154 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Windows\SysWOW64\rundll32.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.254427469235842 |
Encrypted: | false |
SSDEEP: | 6:kK+eV99UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:VVkDImsLNkPlE99SNxAhUe/3 |
MD5: | B5CE53E7E1E29A8A296639027185D75B |
SHA1: | 3154E861BF18AA192A509FE406429BC9EA1C9EF6 |
SHA-256: | 2861363EAC4547FE5C7E369A4D2959997404916FA4EE4B37D0964B97B4E26E69 |
SHA-512: | 37CF38D607BA3A28F2DA31ACF9CA570F949C46D7A75C770BAE57220DC3C1843C993C2F229826805257E8B1B2E92B1FD4ADEF96BF15CC7FF9F5F3A822F604823C |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.2988432393311555 |
Encrypted: | false |
SSDEEP: | 6144:dECqOEmWfd+WQFHy/9026ZTyaRsCDusBqD5dooi8lASD6VJSRrf:aCsL6seqD5SlSWVARD |
MD5: | D82D81E189FFDC8A8127BD98FBDBB842 |
SHA1: | E0F5764738AB07065E9EDBEE539B40C6C0363C49 |
SHA-256: | A21E68F33CDAC2E8B94EB3253A90BF1707DD4056F09AF38F38A8CB5AC0623551 |
SHA-512: | B116A830C2E9B98AE2FA8C19562C4C6E90CAC7CD3993B633477932ECC2A629BA408AD06AD114ED8B183EC3F866AD36A6D1C8E0D5FE591C7E03EFF1BC06A4BBC0 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.738266496763094 |
TrID: |
|
File name: | 2JSGOlbNym.dll |
File size: | 204'859 bytes |
MD5: | e3f13188806c9a2ecabf5eab0cf7dc5f |
SHA1: | bc3a8653c59edabf91eb545f7d9dcf818f3ef003 |
SHA256: | ad2003c10fcffe449f3b5bd445dca19d789eac82d64f0b764104d7b6d0fb955f |
SHA512: | 261711f8b6b002ac344c84afe01e38b4900ac3aae03da16ab049ac39e0c2fd8278bf95e8c53e25e825bcd0938d0b5dad3de584b5f65300fabedd4d3c2a677f0f |
SSDEEP: | 3072:BVkgEz4rVOfek2THpgQqqMkPtghomXHNoh2+fS8BpuSNXVACL7I1:LkgEz4sjOp1tyoGX+fzGM2Co |
TLSH: | 011412D059EA21BAC087C37014B7FD2DEA446575E9694C09EBCAF131BD33B20B86A356 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......... B..N...N...N...B...N.F.....N.......N.......N.......N...@...N.m.D...N...O.^.N.m.E...N.=.H...N.m.J...N.Rich..N................ |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x10062b8d |
Entrypoint Section: | .tyi1 |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL |
DLL Characteristics: | |
Time Stamp: | 0x5667D311 [Wed Dec 9 07:06:57 2015 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | e7361d096d72b868eab81a55f14cbe3a |
Instruction |
---|
jmp 00007FB760BDCCDCh |
inc ebx |
dec ebx |
xchg eax, ecx |
mov seg?, word ptr [ecx] |
add byte ptr [esp+eax*8], cl |
xor ah, ah |
add ah, ch |
xor al, ch |
adc ah, bl |
sbb ah, ah |
in al, 0Ch |
or bh, byte ptr [esi-2A605E18h] |
stc |
xor ecx, ebx |
xor ch, bh |
retn 0FB3h |
in eax, dx |
in eax, dx |
in eax, 1Bh |
cmp al, 96h |
stosd |
fdivr st(0), st(0) |
add byte ptr [eax+40h], cl |
fcmovu st(0), st(4) |
mov byte ptr [ebx+01h], cl |
pop es |
ret |
cdq |
wait |
retn CA45h |
bound ebx, dword ptr [eax] |
push ss |
add esi, dword ptr [ebp-1Eh] |
and eax, 7E7D35C7h |
pop esp |
mov al, byte ptr [A77A8284h] |
aaa |
mov dword ptr [edi], edi |
shr dword ptr [edi+3B26DB69h], FFFFFFEDh |
cmp dl, byte ptr [edi] |
dec ebx |
pop edx |
loop 00007FB760BF964Dh |
dec edi |
idiv byte ptr [edi+4AB2832Ah] |
cmpsd |
test dword ptr [ebx+3AC4381Bh], eax |
xor byte ptr [ebx+3Dh], dh |
adc ecx, esi |
aad 35h |
adc dword ptr [esi], esi |
les esp, eax |
aad 1Bh |
adc eax, ecx |
nop dword ptr [esi+7Ah] |
pushfd |
xchg eax, esp |
pop esp |
push edi |
xchg eax, esp |
test dword ptr [ebx+6EA66805h], 0049846Dh |
mov cl, 54h |
xchg eax, ecx |
pop esp |
test dword ptr [eax-4Fh], ebx |
inc esp |
inc eax |
xor byte ptr [eax-70809D72h], cl |
pop esp |
xchg eax, ebp |
test eax, 902FE9EFh |
xor dword ptr [eax], eax |
jmp far 1212h : F222CA3Ah |
ficomp dword ptr [esi] |
jmp far 393Dh : D602FA06h |
popad |
lodsb |
mov ecx, dword ptr [eax] |
sbb esp, ebx |
aaa |
loopne 00007FB760BF963Fh |
aaa |
lodsd |
xchg eax, edi |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x68fbc | 0x67 | .tyi1 |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x60da4 | 0x118 | .tyi1 |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x6f000 | 0x1000 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6e000 | 0x9c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x6ab88 | 0x7c | .tyi1 |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0xc50c | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0xe000 | 0x3571 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x12000 | 0x5fe8 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tyi0 | 0x18000 | 0x267e4 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.tyi1 | 0x3f000 | 0x2e918 | 0x2f000 | 778f5f322b37508c5946d05e9b738ec7 | False | 0.968256524268617 | data | 7.938472536073559 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.reloc | 0x6e000 | 0x9c | 0x1000 | 23ac04b865d4f4fbc6a3c604aa7f6f51 | False | 0.03759765625 | data | 0.26850651604269654 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x6f000 | 0x59c | 0x1000 | 9adb9cc8cac195f47b28f9ca61967dc1 | False | 0.125244140625 | data | 1.2011055032591231 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_DIALOG | 0x6f420 | 0x17c | data | English | United States | 0.034210526315789476 |
RT_VERSION | 0x6f0a0 | 0x380 | data | English | United States | 0.4732142857142857 |
DLL | Import |
---|---|
MFC42.DLL | |
MSVCRT.dll | strcspn |
KERNEL32.dll | GetModuleFileNameA |
USER32.dll | GetDesktopWindow |
ADVAPI32.dll | RegEnumValueA |
WS2_32.dll | htonl |
SHLWAPI.dll | PathIsDirectoryA |
ole32.dll | CoUninitialize |
OLEAUT32.dll | VariantClear |
MSVCP60.dll | ?_C@?1??_Nullstr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CAPBDXZ@4DB |
NETAPI32.dll | Netbios |
KERNEL32.dll | GetModuleFileNameW |
KERNEL32.dll | GetModuleHandleA, LoadLibraryA, LocalAlloc, LocalFree, GetModuleFileNameA, ExitProcess |
Name | Ordinal | Address |
---|---|---|
ClassObject | 1 | 0x10008668 |
InputFile | 2 | 0x1000679d |
PrintFile | 3 | 0x1000443d |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-19T15:44:33.497786+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49706 | 107.163.56.110 | 18530 | TCP |
2024-12-19T15:44:35.689380+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49705 | 107.163.56.231 | 18530 | TCP |
2024-12-19T15:44:35.689380+0100 | 2812407 | ETPRO MALWARE Win32/Venik HTTP CnC Beacon | 1 | 192.168.2.11 | 49705 | 107.163.56.231 | 18530 | TCP |
2024-12-19T15:44:36.833681+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49718 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:44:43.735527+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49722 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:43.735567+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49723 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:43.735600+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49726 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:45.672388+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49729 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:47.735838+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49728 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:47.735838+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49730 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:51.735632+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49736 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:51.735671+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49733 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:51.735763+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49734 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:55.876691+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49737 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:55.876728+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49738 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:44:55.876769+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49739 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:57.873519+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49742 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:44:58.986252+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49745 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:00.001277+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49740 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:00.001293+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49741 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:02.039906+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49748 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:04.001669+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49746 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:04.001696+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49747 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:05.977914+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49752 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:08.020764+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49750 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:08.020792+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49751 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:09.958806+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49756 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:12.016757+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49754 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:12.016797+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49755 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:14.117837+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49760 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:16.032665+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49759 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:16.032697+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49758 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:20.048172+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49762 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:20.048204+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49763 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:20.048222+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49764 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:21.291466+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49769 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:22.017200+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49766 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:24.174267+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49767 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:24.174362+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49765 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:26.194962+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49773 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:28.298071+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49771 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:28.298130+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49772 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:30.985896+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49777 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:32.322598+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49775 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:32.322671+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49776 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:34.273735+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49781 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:36.314726+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49779 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:36.314797+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49780 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:38.289440+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49785 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:40.317140+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49784 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:40.317164+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49783 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:43.137902+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49789 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:43.513998+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49791 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:45:44.438893+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49788 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:44.439103+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49787 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:48.454782+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49793 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:48.454799+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49794 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:48.454799+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49792 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:52.605958+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49796 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:52.606082+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49795 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:52.606086+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49797 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:45:56.751358+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49798 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:56.751404+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49799 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:45:56.751441+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49800 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:00.871302+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49801 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:00.871330+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49802 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:00.871372+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49803 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:02.961800+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49805 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:05.001547+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49804 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:05.001579+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49806 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:05.655037+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49811 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:06.978141+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49809 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:09.017360+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49808 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:09.017413+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49810 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:10.975339+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49815 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:13.146950+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49813 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:13.146988+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49814 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:17.492707+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49818 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:17.492889+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49820 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:17.492956+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49819 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:19.448678+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49823 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:21.518675+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49822 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:21.518681+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49821 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:25.306220+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49828 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:25.658559+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49825 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:25.658612+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49827 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:27.764083+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49833 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:28.410219+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49830 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:29.782777+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49832 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:29.782813+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49831 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:32.408255+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49837 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:33.798470+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49836 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:33.798506+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49835 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:35.873635+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49841 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:37.814093+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49839 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:37.814098+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49840 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:39.809292+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49844 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:41.527427+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49845 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:41.527474+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49843 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:42.064075+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49848 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:42.064117+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49849 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:42.064125+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49847 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:44.107927+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49852 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:46.220249+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49850 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:46.220304+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49851 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:48.311762+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.11 | 49856 | 116.133.8.92 | 80 | TCP |
2024-12-19T15:46:49.914765+0100 | 2812406 | ETPRO MALWARE Win32/Venik CnC Beacon | 1 | 192.168.2.11 | 49858 | 107.163.56.251 | 6658 | TCP |
2024-12-19T15:46:50.349737+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49855 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:46:50.349757+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49854 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:47:12.377324+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49859 | 107.163.56.232 | 18963 | TCP |
2024-12-19T15:47:12.516866+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.11 | 49860 | 107.163.56.232 | 18963 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 15:44:11.459093094 CET | 49705 | 18530 | 192.168.2.11 | 107.163.56.231 |
Dec 19, 2024 15:44:11.459219933 CET | 49706 | 18530 | 192.168.2.11 | 107.163.56.110 |
Dec 19, 2024 15:44:11.578677893 CET | 18530 | 49705 | 107.163.56.231 | 192.168.2.11 |
Dec 19, 2024 15:44:11.578689098 CET | 18530 | 49706 | 107.163.56.110 | 192.168.2.11 |
Dec 19, 2024 15:44:11.578747988 CET | 49705 | 18530 | 192.168.2.11 | 107.163.56.231 |
Dec 19, 2024 15:44:11.578803062 CET | 49706 | 18530 | 192.168.2.11 | 107.163.56.110 |
Dec 19, 2024 15:44:11.584388971 CET | 49705 | 18530 | 192.168.2.11 | 107.163.56.231 |
Dec 19, 2024 15:44:11.584470034 CET | 49706 | 18530 | 192.168.2.11 | 107.163.56.110 |
Dec 19, 2024 15:44:11.704094887 CET | 18530 | 49705 | 107.163.56.231 | 192.168.2.11 |
Dec 19, 2024 15:44:11.704148054 CET | 18530 | 49706 | 107.163.56.110 | 192.168.2.11 |
Dec 19, 2024 15:44:33.497725010 CET | 18530 | 49706 | 107.163.56.110 | 192.168.2.11 |
Dec 19, 2024 15:44:33.497786045 CET | 49706 | 18530 | 192.168.2.11 | 107.163.56.110 |
Dec 19, 2024 15:44:33.498579025 CET | 49706 | 18530 | 192.168.2.11 | 107.163.56.110 |
Dec 19, 2024 15:44:33.618077993 CET | 18530 | 49706 | 107.163.56.110 | 192.168.2.11 |
Dec 19, 2024 15:44:35.689379930 CET | 49705 | 18530 | 192.168.2.11 | 107.163.56.231 |
Dec 19, 2024 15:44:36.713486910 CET | 49718 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:36.833161116 CET | 6658 | 49718 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:44:36.833261013 CET | 49718 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:36.833681107 CET | 49718 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:36.953294039 CET | 6658 | 49718 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:44:39.728538036 CET | 49722 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.728916883 CET | 49723 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.851421118 CET | 18963 | 49722 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:39.851435900 CET | 18963 | 49723 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:39.851515055 CET | 49723 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.851516008 CET | 49722 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.858464003 CET | 49722 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.861032009 CET | 49723 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:39.978485107 CET | 18963 | 49722 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:39.980978012 CET | 18963 | 49723 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:43.178039074 CET | 49726 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.297776937 CET | 80 | 49726 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:43.297853947 CET | 49726 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.298105001 CET | 49726 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.417670965 CET | 80 | 49726 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:43.735527039 CET | 49722 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.735567093 CET | 49723 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.735599995 CET | 49726 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.736924887 CET | 49728 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.850420952 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.851982117 CET | 49730 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.856468916 CET | 18963 | 49728 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:43.856535912 CET | 49728 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.856717110 CET | 49728 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.970913887 CET | 80 | 49729 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:43.970997095 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.971196890 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:43.972306967 CET | 18963 | 49730 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:43.972383022 CET | 49730 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.972687006 CET | 49730 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:43.977124929 CET | 18963 | 49728 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:44.090599060 CET | 80 | 49729 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:44.092068911 CET | 18963 | 49730 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:45.672321081 CET | 80 | 49729 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:45.672388077 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:45.678965092 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:45.679007053 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:45.679068089 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:45.692616940 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:45.692656040 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.546588898 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.546735048 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:47.547368050 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.547420979 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:47.713342905 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:47.713377953 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.714451075 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.714556932 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:47.720319033 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:47.735837936 CET | 49730 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:47.735837936 CET | 49728 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:47.754435062 CET | 49733 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:47.763386011 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:47.873979092 CET | 18963 | 49733 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:47.874061108 CET | 49733 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:48.035053015 CET | 49733 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:48.154565096 CET | 18963 | 49733 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:48.258068085 CET | 49734 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:48.377677917 CET | 18963 | 49734 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:48.377767086 CET | 49734 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:48.378560066 CET | 49734 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:48.498056889 CET | 18963 | 49734 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:49.185419083 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.185518980 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.185524940 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.185558081 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.185590029 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.185642004 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.185653925 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.185761929 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.217828035 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.217916012 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.217950106 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.217997074 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.218019009 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.218050003 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.230931044 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.230963945 CET | 443 | 49731 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.230988026 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.231020927 CET | 49731 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.538954973 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.539362907 CET | 49736 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.661664009 CET | 80 | 49729 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.661681890 CET | 80 | 49736 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:49.661741018 CET | 49729 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.661781073 CET | 49736 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.684655905 CET | 49736 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:49.805475950 CET | 80 | 49736 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:51.735631943 CET | 49736 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:51.735671043 CET | 49733 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.735763073 CET | 49734 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.736170053 CET | 49737 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.856221914 CET | 18963 | 49737 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:51.856344938 CET | 49737 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.861542940 CET | 49737 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.865968943 CET | 49738 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.867158890 CET | 49739 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:51.987478971 CET | 18963 | 49737 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:51.991960049 CET | 18963 | 49738 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:51.992950916 CET | 80 | 49739 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:51.993125916 CET | 49739 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:51.993135929 CET | 49738 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.993258953 CET | 49738 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:51.993359089 CET | 49739 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:52.113106966 CET | 18963 | 49738 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:52.113198042 CET | 80 | 49739 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:55.876691103 CET | 49737 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:55.876728058 CET | 49738 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:55.876769066 CET | 49739 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:55.877469063 CET | 49740 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:55.997936964 CET | 18963 | 49740 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:55.998008013 CET | 49740 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:55.998133898 CET | 49740 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:56.042659044 CET | 49741 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:56.043706894 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:56.120145082 CET | 18963 | 49740 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:56.163830042 CET | 18963 | 49741 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:56.163929939 CET | 49741 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:56.164062023 CET | 49741 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:44:56.164145947 CET | 80 | 49742 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:56.164196014 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:56.164269924 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:56.283565998 CET | 18963 | 49741 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:44:56.283915997 CET | 80 | 49742 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:57.873430967 CET | 80 | 49742 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:57.873518944 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:58.006002903 CET | 49743 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:58.006071091 CET | 443 | 49743 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:58.006182909 CET | 49743 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:58.171061039 CET | 49743 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:44:58.171118021 CET | 443 | 49743 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:44:58.748452902 CET | 6658 | 49718 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:44:58.748617887 CET | 49718 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:58.864900112 CET | 49745 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:58.985594988 CET | 6658 | 49745 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:44:58.985666990 CET | 49745 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:58.986252069 CET | 49745 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:44:59.106630087 CET | 6658 | 49745 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:00.001261950 CET | 49743 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.001276970 CET | 49740 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.001292944 CET | 49741 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.002334118 CET | 49746 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.114377975 CET | 49747 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.114633083 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.114847898 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.122132063 CET | 18963 | 49746 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:00.122421026 CET | 49746 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.123146057 CET | 49746 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.235196114 CET | 18963 | 49747 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:00.235213041 CET | 80 | 49748 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:00.235224962 CET | 80 | 49742 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:00.235260963 CET | 49747 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.235295057 CET | 49742 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.235308886 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.240134954 CET | 49747 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:00.243367910 CET | 18963 | 49746 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:00.256176949 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:00.360061884 CET | 18963 | 49747 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:00.376441956 CET | 80 | 49748 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:02.036578894 CET | 80 | 49748 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:02.039906025 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:02.042395115 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:02.042443037 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:02.042543888 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:02.042793989 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:02.042804003 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:03.970573902 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:03.970650911 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:03.971354961 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:03.971421957 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:03.975466013 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:03.975477934 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:03.975724936 CET | 443 | 49749 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:03.975775957 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:03.976349115 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.001668930 CET | 49746 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.001696110 CET | 49747 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.001769066 CET | 49749 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.002545118 CET | 49750 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.115040064 CET | 49751 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.116533041 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.116779089 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.122126102 CET | 18963 | 49750 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:04.122195959 CET | 49750 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.122564077 CET | 49750 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.234925985 CET | 18963 | 49751 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:04.235038996 CET | 49751 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.235218048 CET | 49751 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:04.236285925 CET | 80 | 49752 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:04.236357927 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.236376047 CET | 80 | 49748 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:04.236432076 CET | 49748 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.236861944 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:04.242095947 CET | 18963 | 49750 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:04.354942083 CET | 18963 | 49751 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:04.356379032 CET | 80 | 49752 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:05.974081039 CET | 80 | 49752 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:05.977914095 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:05.980225086 CET | 49753 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:05.980262995 CET | 443 | 49753 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:05.981874943 CET | 49753 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:05.982116938 CET | 49753 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:05.982129097 CET | 443 | 49753 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:08.020762920 CET | 49753 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.020764112 CET | 49750 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.020792007 CET | 49751 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.022562027 CET | 49754 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.131123066 CET | 49755 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.131643057 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.131860971 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.148371935 CET | 18963 | 49754 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:08.148478031 CET | 49754 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.148576021 CET | 49754 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.250797987 CET | 18963 | 49755 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:08.250942945 CET | 49755 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.251167059 CET | 49755 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:08.251543999 CET | 80 | 49756 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:08.251597881 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.251693964 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.251771927 CET | 80 | 49752 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:08.251821041 CET | 49752 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:08.268310070 CET | 18963 | 49754 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:08.370815992 CET | 18963 | 49755 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:08.371170044 CET | 80 | 49756 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:09.958744049 CET | 80 | 49756 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:09.958806038 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:10.014695883 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:10.014738083 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:10.014792919 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:10.016031027 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:10.016041040 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:11.914894104 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:11.915170908 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:11.915682077 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:11.915854931 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:11.918890953 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:11.918900013 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:11.919153929 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:11.919285059 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:11.919704914 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:11.967324972 CET | 443 | 49757 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:12.016757011 CET | 49754 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.016797066 CET | 49755 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.016870022 CET | 49757 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.017647982 CET | 49758 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.130232096 CET | 49759 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.139076948 CET | 18963 | 49758 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:12.139204025 CET | 49758 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.139372110 CET | 49758 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.143503904 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.143788099 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.249927998 CET | 18963 | 49759 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:12.250027895 CET | 49759 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.258850098 CET | 18963 | 49758 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:12.260761976 CET | 49759 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:12.263497114 CET | 80 | 49760 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:12.263576984 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.263819933 CET | 80 | 49756 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:12.263871908 CET | 49756 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.264594078 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:12.380728006 CET | 18963 | 49759 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:12.384120941 CET | 80 | 49760 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:14.117769003 CET | 80 | 49760 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:14.117836952 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:14.168390036 CET | 49761 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:14.168437004 CET | 443 | 49761 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:14.168505907 CET | 49761 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:14.168740034 CET | 49761 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:14.168757915 CET | 443 | 49761 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:16.032665014 CET | 49759 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.032696962 CET | 49758 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.032696962 CET | 49761 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.033297062 CET | 49762 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.145051003 CET | 49763 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.146867990 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.147102118 CET | 49764 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.153388977 CET | 18963 | 49762 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:16.153474092 CET | 49762 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.153583050 CET | 49762 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.264580011 CET | 18963 | 49763 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:16.264782906 CET | 49763 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.264883041 CET | 49763 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:16.266572952 CET | 80 | 49764 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:16.266658068 CET | 49764 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.266760111 CET | 80 | 49760 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:16.266824007 CET | 49760 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.267159939 CET | 49764 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:16.273319006 CET | 18963 | 49762 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:16.384722948 CET | 18963 | 49763 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:16.387288094 CET | 80 | 49764 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:20.048171997 CET | 49762 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.048203945 CET | 49763 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.048222065 CET | 49764 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:20.051182032 CET | 49765 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.171016932 CET | 18963 | 49765 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:20.171106100 CET | 49765 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.171262026 CET | 49765 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.180697918 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:20.181297064 CET | 49767 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.290837049 CET | 18963 | 49765 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:20.300484896 CET | 80 | 49766 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:20.300565958 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:20.300904036 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:20.301244974 CET | 18963 | 49767 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:20.301309109 CET | 49767 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.312871933 CET | 49767 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:20.420370102 CET | 80 | 49766 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:20.433653116 CET | 18963 | 49767 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:20.905200958 CET | 6658 | 49745 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:20.905294895 CET | 49745 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:21.170860052 CET | 49769 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:21.290963888 CET | 6658 | 49769 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:21.291037083 CET | 49769 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:21.291465998 CET | 49769 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:21.410979986 CET | 6658 | 49769 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:22.017090082 CET | 80 | 49766 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:22.017199993 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:22.034096003 CET | 49770 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:22.034172058 CET | 443 | 49770 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:22.034245968 CET | 49770 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:22.034579039 CET | 49770 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:22.034591913 CET | 443 | 49770 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:24.174267054 CET | 49767 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.174361944 CET | 49765 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.174361944 CET | 49770 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.174952030 CET | 49771 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.294574976 CET | 18963 | 49771 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:24.294663906 CET | 49771 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.294791937 CET | 49771 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.349034071 CET | 49772 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.350399971 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.350641966 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.414549112 CET | 18963 | 49771 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:24.469080925 CET | 18963 | 49772 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:24.469244957 CET | 49772 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.472295046 CET | 80 | 49773 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:24.473217010 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.481132984 CET | 49772 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:24.481162071 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.483217955 CET | 80 | 49766 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:24.483411074 CET | 49766 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:24.600698948 CET | 18963 | 49772 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:24.600790024 CET | 80 | 49773 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:26.194787025 CET | 80 | 49773 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:26.194962025 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:26.244735956 CET | 49774 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:26.244785070 CET | 443 | 49774 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:26.244895935 CET | 49774 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:26.245129108 CET | 49774 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:26.245148897 CET | 443 | 49774 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:28.298070908 CET | 49771 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.298106909 CET | 49774 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.298130035 CET | 49772 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.298552036 CET | 49775 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.411101103 CET | 49776 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.420247078 CET | 18963 | 49775 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:28.420322895 CET | 49775 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.420633078 CET | 49775 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.462570906 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.462971926 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.531059980 CET | 18963 | 49776 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:28.531207085 CET | 49776 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.541662931 CET | 49776 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:28.541704893 CET | 18963 | 49775 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:28.586168051 CET | 80 | 49773 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:28.586280107 CET | 49773 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.586317062 CET | 80 | 49777 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:28.586380005 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.586559057 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:28.662987947 CET | 18963 | 49776 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:28.707547903 CET | 80 | 49777 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:30.985765934 CET | 80 | 49777 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:30.985896111 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:31.028386116 CET | 49778 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:31.028422117 CET | 443 | 49778 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:31.028522015 CET | 49778 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:31.029102087 CET | 49778 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:31.029120922 CET | 443 | 49778 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:32.322597980 CET | 49775 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.322670937 CET | 49776 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.322757959 CET | 49778 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.323266983 CET | 49779 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.443006992 CET | 49780 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.443046093 CET | 18963 | 49779 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:32.443125010 CET | 49779 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.443223000 CET | 49779 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.444278002 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.444554090 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.562797070 CET | 18963 | 49780 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:32.562812090 CET | 18963 | 49779 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:32.562918901 CET | 49780 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.563079119 CET | 49780 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:32.564373970 CET | 80 | 49781 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:32.564591885 CET | 80 | 49777 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:32.564639091 CET | 49777 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.565167904 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.565167904 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:32.682490110 CET | 18963 | 49780 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:32.684633970 CET | 80 | 49781 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:34.273015022 CET | 80 | 49781 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:34.273735046 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:34.287338972 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:34.287395000 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:34.287549973 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:34.287847042 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:34.287863016 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.127737999 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.127856016 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.128490925 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.128566027 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.139190912 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.139204979 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.139606953 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.139758110 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.141937971 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.183322906 CET | 443 | 49782 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.314726114 CET | 49779 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.314748049 CET | 49782 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.314796925 CET | 49780 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.315207005 CET | 49783 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.426955938 CET | 49784 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.427072048 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.427252054 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.434693098 CET | 18963 | 49783 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:36.434782028 CET | 49783 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.434906006 CET | 49783 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.546614885 CET | 18963 | 49784 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:36.546720982 CET | 80 | 49785 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.546746969 CET | 49784 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.546789885 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.547027111 CET | 49784 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:36.547036886 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.547120094 CET | 80 | 49781 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:36.547188997 CET | 49781 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:36.554456949 CET | 18963 | 49783 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:36.666650057 CET | 18963 | 49784 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:36.666666031 CET | 80 | 49785 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:38.289331913 CET | 80 | 49785 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:38.289439917 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:38.291739941 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:38.291785955 CET | 443 | 49786 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:38.291866064 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:38.292090893 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:38.292104006 CET | 443 | 49786 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.156505108 CET | 443 | 49786 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.156579018 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.157077074 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.157088995 CET | 443 | 49786 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.158787966 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.158793926 CET | 443 | 49786 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.317140102 CET | 49784 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.317163944 CET | 49783 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.317163944 CET | 49786 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.318038940 CET | 49787 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.437675953 CET | 18963 | 49787 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:40.437757015 CET | 49787 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.437948942 CET | 49787 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.487214088 CET | 49788 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.489962101 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.490236044 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.557529926 CET | 18963 | 49787 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:40.606892109 CET | 18963 | 49788 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:40.607034922 CET | 49788 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.609720945 CET | 49788 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:40.609736919 CET | 80 | 49789 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.609824896 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.609944105 CET | 80 | 49785 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:40.610004902 CET | 49785 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.610619068 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:40.729398012 CET | 18963 | 49788 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:40.730122089 CET | 80 | 49789 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:43.137818098 CET | 80 | 49789 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:43.137902021 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:43.163882971 CET | 49790 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:43.163933039 CET | 443 | 49790 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:43.164036036 CET | 49790 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:43.164645910 CET | 49790 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:43.164657116 CET | 443 | 49790 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:43.280642033 CET | 6658 | 49769 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:43.280750036 CET | 49769 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:43.393899918 CET | 49791 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:43.513494968 CET | 6658 | 49791 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:43.513618946 CET | 49791 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:43.513998032 CET | 49791 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:45:43.633455992 CET | 6658 | 49791 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:45:44.438855886 CET | 49790 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.438893080 CET | 49788 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.439102888 CET | 49787 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.439578056 CET | 49792 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.552165985 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.552447081 CET | 49793 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.553246021 CET | 49794 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.559290886 CET | 18963 | 49792 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:44.559426069 CET | 49792 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.559549093 CET | 49792 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.672012091 CET | 80 | 49793 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:44.672154903 CET | 80 | 49789 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:44.672187090 CET | 49793 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.672235012 CET | 49789 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.672339916 CET | 49793 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:44.672696114 CET | 18963 | 49794 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:44.672746897 CET | 49794 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.672871113 CET | 49794 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:44.679150105 CET | 18963 | 49792 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:44.791898012 CET | 80 | 49793 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:44.792366982 CET | 18963 | 49794 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:48.454782009 CET | 49793 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:48.454798937 CET | 49792 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.454798937 CET | 49794 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.455338955 CET | 49795 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.574901104 CET | 18963 | 49795 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:48.574990988 CET | 49795 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.575156927 CET | 49795 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.631555080 CET | 49796 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.632101059 CET | 49797 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:48.694691896 CET | 18963 | 49795 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:48.751197100 CET | 18963 | 49796 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:48.751367092 CET | 49796 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.751569986 CET | 49796 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:48.751619101 CET | 80 | 49797 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:48.751694918 CET | 49797 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:48.752084970 CET | 49797 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:48.871206045 CET | 18963 | 49796 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:48.872225046 CET | 80 | 49797 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:52.605957985 CET | 49796 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.606081963 CET | 49795 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.606086016 CET | 49797 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:52.630383968 CET | 49798 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.750653982 CET | 18963 | 49798 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:52.750746965 CET | 49798 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.753252983 CET | 49798 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.786315918 CET | 49799 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.787664890 CET | 49800 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:52.872805119 CET | 18963 | 49798 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:52.906363010 CET | 18963 | 49799 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:52.906650066 CET | 49799 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.906728029 CET | 49799 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:52.907522917 CET | 80 | 49800 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:52.907629967 CET | 49800 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:52.910507917 CET | 49800 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:53.026410103 CET | 18963 | 49799 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:53.030112982 CET | 80 | 49800 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:56.751358032 CET | 49798 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.751404047 CET | 49799 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.751441002 CET | 49800 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:56.751966000 CET | 49801 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.872003078 CET | 18963 | 49801 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:56.872100115 CET | 49801 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.872338057 CET | 49801 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.903697014 CET | 49802 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:56.907773972 CET | 49803 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:56.991991997 CET | 18963 | 49801 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:57.023830891 CET | 80 | 49802 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:57.023936987 CET | 49802 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:57.024122000 CET | 49802 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:45:57.027542114 CET | 18963 | 49803 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:45:57.027609110 CET | 49803 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:57.027714014 CET | 49803 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:45:57.143819094 CET | 80 | 49802 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:45:57.147520065 CET | 18963 | 49803 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:00.871301889 CET | 49801 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:00.871330023 CET | 49802 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:00.871371984 CET | 49803 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:00.871884108 CET | 49804 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:00.992042065 CET | 18963 | 49804 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:00.992108107 CET | 49804 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:00.992532969 CET | 49804 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:01.112251043 CET | 18963 | 49804 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:01.133941889 CET | 49806 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:01.136033058 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:01.253685951 CET | 18963 | 49806 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:01.253850937 CET | 49806 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:01.254297972 CET | 49806 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:01.255878925 CET | 80 | 49805 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:01.256052971 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:01.256083965 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:01.373806953 CET | 18963 | 49806 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:01.375690937 CET | 80 | 49805 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:02.961694002 CET | 80 | 49805 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:02.961800098 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:03.083643913 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:03.083703041 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:03.084063053 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:03.084321976 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:03.084342003 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:04.926124096 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:04.926374912 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:04.927217960 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:04.927335024 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:04.930289984 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:04.930341005 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:04.930505991 CET | 443 | 49807 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:04.930558920 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:04.930588007 CET | 49807 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.001547098 CET | 49804 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.001579046 CET | 49806 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.002130032 CET | 49808 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.036871910 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.038273096 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.162765026 CET | 18963 | 49808 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:05.162781954 CET | 80 | 49809 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:05.162838936 CET | 49808 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.162939072 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.162971973 CET | 49808 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.163181067 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.163345098 CET | 80 | 49805 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:05.163389921 CET | 49805 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:05.216474056 CET | 49810 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.282500982 CET | 18963 | 49808 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:05.282619953 CET | 80 | 49809 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:05.337049961 CET | 18963 | 49810 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:05.337127924 CET | 49810 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.353919029 CET | 49810 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:05.421430111 CET | 6658 | 49791 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:05.421494961 CET | 49791 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:05.473624945 CET | 18963 | 49810 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:05.534624100 CET | 49811 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:05.654582024 CET | 6658 | 49811 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:05.654654026 CET | 49811 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:05.655036926 CET | 49811 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:05.775880098 CET | 6658 | 49811 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:06.978075027 CET | 80 | 49809 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:06.978141069 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:07.166304111 CET | 49812 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:07.166343927 CET | 443 | 49812 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:07.166408062 CET | 49812 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:07.205805063 CET | 49812 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:07.205826044 CET | 443 | 49812 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:09.017330885 CET | 49812 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.017359972 CET | 49808 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.017412901 CET | 49810 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.018241882 CET | 49813 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.137847900 CET | 18963 | 49813 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:09.137963057 CET | 49813 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.139760017 CET | 49813 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.147962093 CET | 49814 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.148384094 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.148606062 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.260190010 CET | 18963 | 49813 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:09.267826080 CET | 18963 | 49814 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:09.267918110 CET | 49814 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.268102884 CET | 80 | 49815 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:09.268117905 CET | 49814 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:09.268151999 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.268300056 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.268337965 CET | 80 | 49809 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:09.268385887 CET | 49809 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:09.387607098 CET | 18963 | 49814 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:09.387790918 CET | 80 | 49815 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:10.975152016 CET | 80 | 49815 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:10.975338936 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:11.067007065 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:11.067073107 CET | 443 | 49816 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:11.067217112 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:11.067517996 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:11.067533970 CET | 443 | 49816 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:12.895088911 CET | 443 | 49816 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:12.895359039 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:12.896184921 CET | 443 | 49816 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:12.896460056 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:13.146950006 CET | 49813 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.146987915 CET | 49814 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.303086996 CET | 49818 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.304027081 CET | 49819 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.422743082 CET | 18963 | 49818 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:13.422818899 CET | 49818 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.423002005 CET | 49818 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.423583031 CET | 18963 | 49819 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:13.423657894 CET | 49819 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.426078081 CET | 49819 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:13.542841911 CET | 18963 | 49818 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:13.545819044 CET | 18963 | 49819 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:15.512242079 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.512339115 CET | 443 | 49816 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:15.512399912 CET | 49816 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.661114931 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.661407948 CET | 49820 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.781276941 CET | 80 | 49820 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:15.781443119 CET | 49820 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.781487942 CET | 80 | 49815 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:15.781534910 CET | 49815 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.781593084 CET | 49820 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:15.901906967 CET | 80 | 49820 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:17.492707014 CET | 49818 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.492888927 CET | 49820 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:17.492955923 CET | 49819 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.509908915 CET | 49821 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.624013901 CET | 49822 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.625360966 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:17.630269051 CET | 18963 | 49821 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:17.630354881 CET | 49821 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.631674051 CET | 49821 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.743797064 CET | 18963 | 49822 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:17.743922949 CET | 49822 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.744081974 CET | 49822 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:17.744999886 CET | 80 | 49823 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:17.745083094 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:17.745194912 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:17.751297951 CET | 18963 | 49821 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:17.866477966 CET | 18963 | 49822 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:17.867511034 CET | 80 | 49823 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:19.448597908 CET | 80 | 49823 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:19.448678017 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:19.451289892 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:19.451351881 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:19.451535940 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:19.452012062 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:19.452043056 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:21.282916069 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:21.283061981 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:21.283679008 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:21.283725977 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:21.518675089 CET | 49822 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.518681049 CET | 49821 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.519321918 CET | 49825 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.639065981 CET | 18963 | 49825 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:21.641330957 CET | 49825 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.657778978 CET | 49825 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.663160086 CET | 49827 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.777674913 CET | 18963 | 49825 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:21.783030987 CET | 18963 | 49827 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:21.783130884 CET | 49827 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.783348083 CET | 49827 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:21.903434992 CET | 18963 | 49827 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:23.306061983 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.306169033 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:23.306380033 CET | 443 | 49824 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:23.306453943 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.306473017 CET | 49824 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.411082983 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.411362886 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.531280994 CET | 80 | 49828 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:23.531302929 CET | 80 | 49823 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:23.531375885 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.531404018 CET | 49823 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.531599045 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:23.651278973 CET | 80 | 49828 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.304503918 CET | 80 | 49828 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.306220055 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.308777094 CET | 49829 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.308829069 CET | 443 | 49829 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.308960915 CET | 49829 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.309207916 CET | 49829 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.309216976 CET | 443 | 49829 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.658559084 CET | 49825 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.658580065 CET | 49829 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.658612013 CET | 49827 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.775021076 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.775347948 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.776381016 CET | 49831 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.779928923 CET | 49832 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.895262957 CET | 80 | 49830 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.895333052 CET | 80 | 49828 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:25.895365000 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.895395041 CET | 49828 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.895533085 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:25.895992041 CET | 18963 | 49831 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:25.896054029 CET | 49831 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.896173954 CET | 49831 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.899585962 CET | 18963 | 49832 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:25.899641991 CET | 49832 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:25.899857998 CET | 49832 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:26.015300035 CET | 80 | 49830 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:26.015671015 CET | 18963 | 49831 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:26.019438028 CET | 18963 | 49832 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:27.531708002 CET | 6658 | 49811 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:27.531847000 CET | 49811 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:27.643812895 CET | 49833 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:27.763575077 CET | 6658 | 49833 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:27.763704062 CET | 49833 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:27.764082909 CET | 49833 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:27.883701086 CET | 6658 | 49833 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:28.409642935 CET | 80 | 49830 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:28.410218954 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:28.412872076 CET | 49834 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:28.412935972 CET | 443 | 49834 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:28.413024902 CET | 49834 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:28.413367987 CET | 49834 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:28.413379908 CET | 443 | 49834 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:29.782747984 CET | 49834 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:29.782777071 CET | 49832 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:29.782813072 CET | 49831 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:29.783443928 CET | 49835 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:29.898111105 CET | 49836 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:29.898813963 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:29.899068117 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:29.903127909 CET | 18963 | 49835 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:29.903224945 CET | 49835 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:29.903470993 CET | 49835 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:30.018502951 CET | 18963 | 49836 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:30.018596888 CET | 49836 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:30.018723011 CET | 49836 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:30.018906116 CET | 80 | 49837 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:30.018966913 CET | 80 | 49830 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:30.018973112 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:30.019015074 CET | 49830 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:30.019153118 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:30.023008108 CET | 18963 | 49835 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:30.138820887 CET | 18963 | 49836 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:30.138849020 CET | 80 | 49837 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:32.407851934 CET | 80 | 49837 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:32.408255100 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:32.411051989 CET | 49838 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:32.411106110 CET | 443 | 49838 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:32.412540913 CET | 49838 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:32.413048983 CET | 49838 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:32.413064957 CET | 443 | 49838 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:33.798470020 CET | 49836 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:33.798506021 CET | 49835 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:33.798511982 CET | 49838 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:33.799065113 CET | 49839 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:33.917476892 CET | 49840 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:33.917623997 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:33.917826891 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:33.918709993 CET | 18963 | 49839 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:33.918798923 CET | 49839 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:33.919154882 CET | 49839 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:34.039750099 CET | 18963 | 49840 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:34.039813995 CET | 80 | 49841 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:34.039861917 CET | 49840 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:34.039912939 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:34.040075064 CET | 49840 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:34.040092945 CET | 80 | 49837 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:34.040200949 CET | 49837 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:34.040631056 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:34.041311026 CET | 18963 | 49839 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:34.159811974 CET | 18963 | 49840 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:34.160343885 CET | 80 | 49841 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:35.873550892 CET | 80 | 49841 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:35.873635054 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:35.876296043 CET | 49842 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:35.876348019 CET | 443 | 49842 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:35.876446962 CET | 49842 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:35.876902103 CET | 49842 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:35.876916885 CET | 443 | 49842 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:37.814063072 CET | 49842 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:37.814093113 CET | 49839 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:37.814097881 CET | 49840 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:37.814944029 CET | 49843 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:37.930440903 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:37.930794954 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:37.931157112 CET | 49845 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:37.935432911 CET | 18963 | 49843 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:37.935518980 CET | 49843 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:37.935661077 CET | 49843 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:38.054399967 CET | 80 | 49844 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:38.054450989 CET | 18963 | 49845 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:38.054490089 CET | 80 | 49841 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:38.054553032 CET | 49845 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:38.054569006 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:38.054578066 CET | 49841 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:38.057023048 CET | 18963 | 49843 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:38.058943033 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:38.059036970 CET | 49845 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:38.179455042 CET | 80 | 49844 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:38.179498911 CET | 18963 | 49845 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:39.809197903 CET | 80 | 49844 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:39.809292078 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:39.821691036 CET | 49846 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:39.821768045 CET | 443 | 49846 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:39.821841002 CET | 49846 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:39.822706938 CET | 49846 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:39.822741032 CET | 443 | 49846 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:41.527410984 CET | 49846 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.527426958 CET | 49845 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.527473927 CET | 49843 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.528561115 CET | 49847 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.648176908 CET | 18963 | 49847 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:41.648257017 CET | 49847 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.652415037 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.652764082 CET | 49848 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.653532982 CET | 49847 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.653573036 CET | 49849 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.772516012 CET | 80 | 49848 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:41.772598028 CET | 49848 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.772763014 CET | 80 | 49844 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:41.772815943 CET | 49844 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.773075104 CET | 18963 | 49847 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:41.773247004 CET | 18963 | 49849 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:41.773252010 CET | 49848 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:41.773299932 CET | 49849 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.773751974 CET | 49849 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:41.894203901 CET | 80 | 49848 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:41.894682884 CET | 18963 | 49849 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:42.064074993 CET | 49848 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:42.064116955 CET | 49849 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.064125061 CET | 49847 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.219966888 CET | 49850 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.221236944 CET | 49851 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.236319065 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:42.340899944 CET | 18963 | 49850 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:42.341866970 CET | 18963 | 49851 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:42.342317104 CET | 49850 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.342484951 CET | 49850 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.342487097 CET | 49851 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.342596054 CET | 49851 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:42.357253075 CET | 80 | 49852 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:42.357429981 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:42.357618093 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:42.462362051 CET | 18963 | 49850 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:42.462398052 CET | 18963 | 49851 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:42.477220058 CET | 80 | 49852 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:44.107714891 CET | 80 | 49852 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:44.107927084 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:44.110707998 CET | 49853 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:44.110750914 CET | 443 | 49853 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:44.110847950 CET | 49853 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:44.111535072 CET | 49853 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:44.111553907 CET | 443 | 49853 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:46.220248938 CET | 49850 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.220304012 CET | 49851 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.220324993 CET | 49853 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.344710112 CET | 49854 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.344769955 CET | 49855 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.344909906 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.345016003 CET | 49856 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.467216969 CET | 18963 | 49854 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:46.467253923 CET | 18963 | 49855 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:46.467274904 CET | 80 | 49856 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:46.467375040 CET | 49855 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.467381001 CET | 49854 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.467387915 CET | 49856 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.467431068 CET | 80 | 49852 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:46.467531919 CET | 49854 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.467609882 CET | 49852 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.467701912 CET | 49855 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:46.467892885 CET | 49856 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:46.589394093 CET | 18963 | 49854 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:46.589639902 CET | 18963 | 49855 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:46.589756012 CET | 80 | 49856 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:48.311642885 CET | 80 | 49856 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:48.311762094 CET | 49856 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:48.334960938 CET | 49857 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:48.335016012 CET | 443 | 49857 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:48.335091114 CET | 49857 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:48.335483074 CET | 49857 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:48.335494995 CET | 443 | 49857 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:46:49.657000065 CET | 6658 | 49833 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:49.657114029 CET | 49833 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:49.793963909 CET | 49858 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:49.914196968 CET | 6658 | 49858 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:49.914294004 CET | 49858 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:49.914764881 CET | 49858 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:46:50.034431934 CET | 6658 | 49858 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:46:50.349687099 CET | 49857 | 443 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:46:50.349736929 CET | 49855 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.349756956 CET | 49854 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.351196051 CET | 49859 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.470736980 CET | 18963 | 49859 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:50.470843077 CET | 49859 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.482780933 CET | 49859 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.496740103 CET | 49860 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.603751898 CET | 18963 | 49859 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:50.617999077 CET | 18963 | 49860 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:46:50.618263960 CET | 49860 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.618869066 CET | 49860 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:46:50.738507032 CET | 18963 | 49860 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:47:11.814074039 CET | 6658 | 49858 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:47:11.814129114 CET | 49858 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:47:12.377253056 CET | 18963 | 49859 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:47:12.377324104 CET | 49859 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:47:12.516796112 CET | 18963 | 49860 | 107.163.56.232 | 192.168.2.11 |
Dec 19, 2024 15:47:12.516865969 CET | 49860 | 18963 | 192.168.2.11 | 107.163.56.232 |
Dec 19, 2024 15:47:18.310847044 CET | 80 | 49856 | 116.133.8.92 | 192.168.2.11 |
Dec 19, 2024 15:47:18.310911894 CET | 49856 | 80 | 192.168.2.11 | 116.133.8.92 |
Dec 19, 2024 15:47:58.751765966 CET | 49718 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:47:58.871602058 CET | 6658 | 49718 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:48:20.908514977 CET | 49745 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:48:21.028791904 CET | 6658 | 49745 | 107.163.56.251 | 192.168.2.11 |
Dec 19, 2024 15:48:43.283144951 CET | 49769 | 6658 | 192.168.2.11 | 107.163.56.251 |
Dec 19, 2024 15:48:43.402744055 CET | 6658 | 49769 | 107.163.56.251 | 192.168.2.11 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 19, 2024 15:44:43.040047884 CET | 54135 | 53 | 192.168.2.11 | 1.1.1.1 |
Dec 19, 2024 15:44:43.177288055 CET | 53 | 54135 | 1.1.1.1 | 192.168.2.11 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 19, 2024 15:44:43.040047884 CET | 192.168.2.11 | 1.1.1.1 | 0xa47c | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 19, 2024 15:44:18.897058010 CET | 1.1.1.1 | 192.168.2.11 | 0xf60c | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:18.897058010 CET | 1.1.1.1 | 192.168.2.11 | 0xf60c | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:43.177288055 CET | 1.1.1.1 | 192.168.2.11 | 0xa47c | No error (0) | blogx.sina.com.cn | CNAME (Canonical name) | IN (0x0001) | false | ||
Dec 19, 2024 15:44:43.177288055 CET | 1.1.1.1 | 192.168.2.11 | 0xa47c | No error (0) | 116.133.8.92 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:46:21.533853054 CET | 1.1.1.1 | 192.168.2.11 | 0x57ec | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Dec 19, 2024 15:46:21.533853054 CET | 1.1.1.1 | 192.168.2.11 | 0x57ec | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.11 | 49705 | 107.163.56.231 | 18530 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:11.584388971 CET | 170 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.11 | 49706 | 107.163.56.110 | 18530 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:11.584470034 CET | 185 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.11 | 49722 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:39.858464003 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.11 | 49723 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:39.861032009 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.11 | 49726 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:43.298105001 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.11 | 49728 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:43.856717110 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.11 | 49729 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:43.971196890 CET | 118 | OUT | |
Dec 19, 2024 15:44:45.672321081 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.11 | 49730 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:43.972687006 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.11 | 49733 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:48.035053015 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.11 | 49734 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:48.378560066 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.11 | 49736 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:49.684655905 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.11 | 49737 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:51.861542940 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.11 | 49738 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:51.993258953 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.11 | 49739 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:51.993359089 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.11 | 49740 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:55.998133898 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.11 | 49741 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:56.164062023 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.11 | 49742 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:44:56.164269924 CET | 118 | OUT | |
Dec 19, 2024 15:44:57.873430967 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.11 | 49746 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:00.123146057 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.11 | 49747 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:00.240134954 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.11 | 49748 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:00.256176949 CET | 118 | OUT | |
Dec 19, 2024 15:45:02.036578894 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.11 | 49750 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:04.122564077 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.11 | 49751 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:04.235218048 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.11 | 49752 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:04.236861944 CET | 118 | OUT | |
Dec 19, 2024 15:45:05.974081039 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.11 | 49754 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:08.148576021 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.11 | 49755 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:08.251167059 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.11 | 49756 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:08.251693964 CET | 118 | OUT | |
Dec 19, 2024 15:45:09.958744049 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.11 | 49758 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:12.139372110 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.11 | 49759 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:12.260761976 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.11 | 49760 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:12.264594078 CET | 118 | OUT | |
Dec 19, 2024 15:45:14.117769003 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.11 | 49762 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:16.153583050 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.11 | 49763 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:16.264883041 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.11 | 49764 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:16.267159939 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.11 | 49765 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:20.171262026 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.11 | 49766 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:20.300904036 CET | 118 | OUT | |
Dec 19, 2024 15:45:22.017090082 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.11 | 49767 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:20.312871933 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.11 | 49771 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:24.294791937 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.11 | 49772 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:24.481132984 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.11 | 49773 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:24.481162071 CET | 118 | OUT | |
Dec 19, 2024 15:45:26.194787025 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.11 | 49775 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:28.420633078 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.11 | 49776 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:28.541662931 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.11 | 49777 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:28.586559057 CET | 118 | OUT | |
Dec 19, 2024 15:45:30.985765934 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.11 | 49779 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:32.443223000 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.11 | 49780 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:32.563079119 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.11 | 49781 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:32.565167904 CET | 118 | OUT | |
Dec 19, 2024 15:45:34.273015022 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.11 | 49783 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:36.434906006 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.11 | 49784 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:36.547027111 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.11 | 49785 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:36.547036886 CET | 118 | OUT | |
Dec 19, 2024 15:45:38.289331913 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.11 | 49787 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:40.437948942 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.11 | 49788 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:40.609720945 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.11 | 49789 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:40.610619068 CET | 118 | OUT | |
Dec 19, 2024 15:45:43.137818098 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.11 | 49792 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:44.559549093 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.11 | 49793 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:44.672339916 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.11 | 49794 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:44.672871113 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.11 | 49795 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:48.575156927 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.11 | 49796 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:48.751569986 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.11 | 49797 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:48.752084970 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.11 | 49798 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:52.753252983 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.11 | 49799 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:52.906728029 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.11 | 49800 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:52.910507917 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.11 | 49801 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:56.872338057 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.11 | 49802 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:57.024122000 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.11 | 49803 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:45:57.027714014 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.11 | 49804 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:00.992532969 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.11 | 49806 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:01.254297972 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.11 | 49805 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:01.256083965 CET | 118 | OUT | |
Dec 19, 2024 15:46:02.961694002 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.11 | 49808 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:05.162971973 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.11 | 49809 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:05.163181067 CET | 118 | OUT | |
Dec 19, 2024 15:46:06.978075027 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.11 | 49810 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:05.353919029 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.11 | 49813 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:09.139760017 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.11 | 49814 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:09.268117905 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
70 | 192.168.2.11 | 49815 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:09.268300056 CET | 118 | OUT | |
Dec 19, 2024 15:46:10.975152016 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
71 | 192.168.2.11 | 49818 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:13.423002005 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
72 | 192.168.2.11 | 49819 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:13.426078081 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
73 | 192.168.2.11 | 49820 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:15.781593084 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
74 | 192.168.2.11 | 49821 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:17.631674051 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
75 | 192.168.2.11 | 49822 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:17.744081974 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
76 | 192.168.2.11 | 49823 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:17.745194912 CET | 118 | OUT | |
Dec 19, 2024 15:46:19.448597908 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
77 | 192.168.2.11 | 49825 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:21.657778978 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
78 | 192.168.2.11 | 49827 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:21.783348083 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
79 | 192.168.2.11 | 49828 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:23.531599045 CET | 118 | OUT | |
Dec 19, 2024 15:46:25.304503918 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
80 | 192.168.2.11 | 49830 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:25.895533085 CET | 118 | OUT | |
Dec 19, 2024 15:46:28.409642935 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
81 | 192.168.2.11 | 49831 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:25.896173954 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
82 | 192.168.2.11 | 49832 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:25.899857998 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
83 | 192.168.2.11 | 49835 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:29.903470993 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
84 | 192.168.2.11 | 49836 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:30.018723011 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
85 | 192.168.2.11 | 49837 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:30.019153118 CET | 118 | OUT | |
Dec 19, 2024 15:46:32.407851934 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
86 | 192.168.2.11 | 49839 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:33.919154882 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
87 | 192.168.2.11 | 49840 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:34.040075064 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
88 | 192.168.2.11 | 49841 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:34.040631056 CET | 118 | OUT | |
Dec 19, 2024 15:46:35.873550892 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
89 | 192.168.2.11 | 49843 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:37.935661077 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
90 | 192.168.2.11 | 49844 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:38.058943033 CET | 118 | OUT | |
Dec 19, 2024 15:46:39.809197903 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
91 | 192.168.2.11 | 49845 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:38.059036970 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
92 | 192.168.2.11 | 49847 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:41.653532982 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
93 | 192.168.2.11 | 49848 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:41.773252010 CET | 118 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
94 | 192.168.2.11 | 49849 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:41.773751974 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
95 | 192.168.2.11 | 49850 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:42.342484951 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
96 | 192.168.2.11 | 49851 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:42.342596054 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
97 | 192.168.2.11 | 49852 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:42.357618093 CET | 118 | OUT | |
Dec 19, 2024 15:46:44.107714891 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
98 | 192.168.2.11 | 49854 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:46.467531919 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
99 | 192.168.2.11 | 49855 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:46.467701912 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
100 | 192.168.2.11 | 49856 | 116.133.8.92 | 80 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:46.467892885 CET | 118 | OUT | |
Dec 19, 2024 15:46:48.311642885 CET | 371 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
101 | 192.168.2.11 | 49859 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:50.482780933 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
102 | 192.168.2.11 | 49860 | 107.163.56.232 | 18963 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 19, 2024 15:46:50.618869066 CET | 183 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.11 | 49731 | 116.133.8.92 | 443 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:44:47 UTC | 142 | OUT | |
2024-12-19 14:44:49 UTC | 653 | IN | |
2024-12-19 14:44:49 UTC | 7579 | IN | |
2024-12-19 14:44:49 UTC | 5260 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.11 | 49749 | 116.133.8.92 | 443 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:03 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.11 | 49757 | 116.133.8.92 | 443 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:11 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.11 | 49782 | 116.133.8.92 | 443 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:36 UTC | 142 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.11 | 49786 | 116.133.8.92 | 443 | 1232 | C:\Windows\SysWOW64\rundll32.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-19 14:45:40 UTC | 142 | OUT |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\loaddll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2a0000 |
File size: | 126'464 bytes |
MD5 hash: | 51E6071F9CBA48E79F10C84515AAE618 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 09:44:07 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa50000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 09:44:10 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 09:44:13 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 14 |
Start time: | 09:44:13 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe90000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 21 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xe90000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 24 |
Start time: | 09:44:16 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa50000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 26 |
Start time: | 09:44:44 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 27 |
Start time: | 09:44:45 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 28 |
Start time: | 09:44:45 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 29 |
Start time: | 09:44:45 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa50000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 32 |
Start time: | 09:44:53 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xbd0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 33 |
Start time: | 09:44:53 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 34 |
Start time: | 09:44:53 |
Start date: | 19/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68cce0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 35 |
Start time: | 09:44:53 |
Start date: | 19/12/2024 |
Path: | C:\Windows\SysWOW64\PING.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa50000 |
File size: | 18'944 bytes |
MD5 hash: | B3624DD758CCECF93A1226CEF252CA12 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 3.9% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0.8% |
Total number of Nodes: | 360 |
Total number of Limit Nodes: | 22 |
Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FB7 Relevance: 1.5, APIs: 1, Instructions: 4processCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008AD0 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006F01 Relevance: 19.4, APIs: 5, Strings: 6, Instructions: 174sleepfileCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004921 Relevance: 17.8, APIs: 4, Strings: 6, Instructions: 337networksleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100064AB Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 271timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DC6 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 113timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006D1A Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 72timeCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000828F Relevance: 12.1, APIs: 2, Strings: 6, Instructions: 144sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002875F Relevance: 10.6, APIs: 2, Strings: 5, Instructions: 92sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000858A Relevance: 9.1, APIs: 3, Strings: 3, Instructions: 83sleepCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100062F3 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 162stringCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A91 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 65sleepthreadCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10007124 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 95sleepCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10008589 Relevance: 4.5, APIs: 2, Strings: 1, Instructions: 32sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10024849 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 20threadCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000821A Relevance: 3.0, APIs: 1, Strings: 1, Instructions: 48sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100327F4 Relevance: 1.5, APIs: 1, Instructions: 36threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002A39D Relevance: 1.5, APIs: 1, Instructions: 31threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1003281C Relevance: 1.5, APIs: 1, Instructions: 12threadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F0A Relevance: 1.5, APIs: 1, Instructions: 10networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003FF7 Relevance: 1.5, APIs: 1, Instructions: 5COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004104 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004115 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003EB4 Relevance: 1.5, APIs: 1, Instructions: 3networkCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F72 Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000400A Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004092 Relevance: 1.5, APIs: 1, Instructions: 3registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000AEE3 Relevance: 1.5, Strings: 1, Instructions: 266COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10003F63 Relevance: 1.5, APIs: 1, Instructions: 4shutdownCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000B247 Relevance: .4, Instructions: 400COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000B730 Relevance: .1, Instructions: 104COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100086B3 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053C9 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 227sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002B195 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 59sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100080A9 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 117sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002AEDC Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 51sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10032FA9 Relevance: 6.0, APIs: 2, Strings: 2, Instructions: 47sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10033A47 Relevance: 6.0, APIs: 2, Strings: 2, Instructions: 43sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 0.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 28 |
Total number of Limit Nodes: | 0 |
Graph
Function 1000CD1A Relevance: .0, Instructions: 2COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053C9 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 227sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006F01 Relevance: 22.9, APIs: 7, Strings: 6, Instructions: 174sleeplibraryfileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000828F Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 144librarysleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100064AB Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 271timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DC6 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 113timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006021 Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 96libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004921 Relevance: 12.3, APIs: 2, Strings: 6, Instructions: 337sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006D1A Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000532A Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 53libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002875F Relevance: 9.1, APIs: 2, Strings: 4, Instructions: 92sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000858A Relevance: 9.1, APIs: 3, Strings: 3, Instructions: 83sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100062F3 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 162stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004642 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 102libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A91 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 65sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004139 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 130libraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100080A9 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 117sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002B195 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 59sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 0.6% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 28 |
Total number of Limit Nodes: | 0 |
Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100053C9 Relevance: 28.2, APIs: 12, Strings: 4, Instructions: 227sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006F01 Relevance: 22.9, APIs: 7, Strings: 6, Instructions: 174sleeplibraryfileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000828F Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 144librarysleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100064AB Relevance: 14.3, APIs: 5, Strings: 3, Instructions: 271timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10005DC6 Relevance: 14.1, APIs: 1, Strings: 7, Instructions: 113timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006021 Relevance: 12.3, APIs: 3, Strings: 4, Instructions: 96libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004921 Relevance: 12.3, APIs: 2, Strings: 6, Instructions: 337sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006D1A Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 72timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000532A Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 53libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002875F Relevance: 9.1, APIs: 2, Strings: 4, Instructions: 92sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000858A Relevance: 9.1, APIs: 3, Strings: 3, Instructions: 83sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100062F3 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 162stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004642 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 102libraryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10006A91 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 65sleepthreadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10004139 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 130libraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100080A9 Relevance: 6.1, APIs: 1, Strings: 3, Instructions: 117sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1002B195 Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 59sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|