Windows
Analysis Report
Z4D3XAZ2jB.exe
Overview
General Information
Sample name: | Z4D3XAZ2jB.exerenamed because original name is a hash value |
Original sample name: | 0a5d9cd0a4b6abdbb272262811774a8d.exe |
Analysis ID: | 1581018 |
MD5: | 0a5d9cd0a4b6abdbb272262811774a8d |
SHA1: | 9571472c5d0899e517e1c1f84c6c05dfd2abb2b5 |
SHA256: | 9c2ad3d80258af2508987d952dd5a7744bedbdd16260e4f76412ea6696774285 |
Tags: | exeZyklonuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Z4D3XAZ2jB.exe (PID: 2004 cmdline:
"C:\Users\ user\Deskt op\Z4D3XAZ 2jB.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D) - schtasks.exe (PID: 3616 cmdline:
schtasks.e xe /create /tn "serv icess" /sc MINUTE /m o 12 /tr " 'C:\Window s\GameBarP resenceWri ter\servic es.exe'" / f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 2188 cmdline:
schtasks.e xe /create /tn "serv ices" /sc ONLOGON /t r "'C:\Win dows\GameB arPresence Writer\ser vices.exe' " /rl HIGH EST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 6452 cmdline:
schtasks.e xe /create /tn "serv icess" /sc MINUTE /m o 13 /tr " 'C:\Window s\GameBarP resenceWri ter\servic es.exe'" / rl HIGHEST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 2120 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 14 /tr "'C:\Windo ws\BitLock erDiscover yVolumeCon tents\ZDtO zYsYYWKWEh NYzFc.exe' " /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 6412 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFc" /sc ONLOGON / tr "'C:\Wi ndows\BitL ockerDisco veryVolume Contents\Z DtOzYsYYWK WEhNYzFc.e xe'" /rl H IGHEST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 7128 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 14 /tr "'C:\Windo ws\BitLock erDiscover yVolumeCon tents\ZDtO zYsYYWKWEh NYzFc.exe' " /rl HIGH EST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 3368 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 8 /tr " 'C:\Progra m Files (x 86)\window s multimed ia platfor m\ZDtOzYsY YWKWEhNYzF c.exe'" /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 2308 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFc" /sc ONLOGON / tr "'C:\Pr ogram File s (x86)\wi ndows mult imedia pla tform\ZDtO zYsYYWKWEh NYzFc.exe' " /rl HIGH EST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 3616 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 6 /tr " 'C:\Progra m Files (x 86)\window s multimed ia platfor m\ZDtOzYsY YWKWEhNYzF c.exe'" /r l HIGHEST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 4144 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 6 /tr " 'C:\Progra m Files (x 86)\window s defender \en-GB\ZDt OzYsYYWKWE hNYzFc.exe '" /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 2120 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFc" /sc ONLOGON / tr "'C:\Pr ogram File s (x86)\wi ndows defe nder\en-GB \ZDtOzYsYY WKWEhNYzFc .exe'" /rl HIGHEST / f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 5480 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 5 /tr " 'C:\Progra m Files (x 86)\window s defender \en-GB\ZDt OzYsYYWKWE hNYzFc.exe '" /rl HIG HEST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 5252 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 10 /tr "'C:\Windo ws\twain_3 2\ZDtOzYsY YWKWEhNYzF c.exe'" /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 7132 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFc" /sc ONLOGON / tr "'C:\Wi ndows\twai n_32\ZDtOz YsYYWKWEhN YzFc.exe'" /rl HIGHE ST /f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - schtasks.exe (PID: 6412 cmdline:
schtasks.e xe /create /tn "ZDtO zYsYYWKWEh NYzFcZ" /s c MINUTE / mo 8 /tr " 'C:\Window s\twain_32 \ZDtOzYsYY WKWEhNYzFc .exe'" /rl HIGHEST / f MD5: 76CD6626DD8834BD4A42E6A565104DC2) - cmd.exe (PID: 5252 cmdline:
"C:\Window s\System32 \cmd.exe" /C "C:\Use rs\user\Ap pData\Loca l\Temp\7aQ 0YIT0mX.ba t" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3616 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - chcp.com (PID: 7220 cmdline:
chcp 65001 MD5: 33395C4732A49065EA72590B14B64F32) - w32tm.exe (PID: 7252 cmdline:
w32tm /str ipchart /c omputer:lo calhost /p eriod:5 /d ataonly /s amples:2 MD5: 81A82132737224D324A3E8DA993E2FB5) - ZDtOzYsYYWKWEhNYzFc.exe (PID: 7384 cmdline:
"C:\Progra m Files (x 86)\window s defender \en-GB\ZDt OzYsYYWKWE hNYzFc.exe " MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 2308 cmdline:
C:\Windows \GameBarPr esenceWrit er\service s.exe MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 7176 cmdline:
C:\Windows \GameBarPr esenceWrit er\service s.exe MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7208 cmdline:
C:\Windows \twain_32\ ZDtOzYsYYW KWEhNYzFc. exe MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7244 cmdline:
C:\Windows \twain_32\ ZDtOzYsYYW KWEhNYzFc. exe MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 7468 cmdline:
"C:\Window s\GameBarP resenceWri ter\servic es.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7964 cmdline:
"C:\Window s\twain_32 \ZDtOzYsYY WKWEhNYzFc .exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 8136 cmdline:
"C:\Window s\GameBarP resenceWri ter\servic es.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 2188 cmdline:
"C:\Window s\twain_32 \ZDtOzYsYY WKWEhNYzFc .exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 5296 cmdline:
"C:\Window s\GameBarP resenceWri ter\servic es.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 3916 cmdline:
"C:\Window s\twain_32 \ZDtOzYsYY WKWEhNYzFc .exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- services.exe (PID: 7192 cmdline:
"C:\Window s\GameBarP resenceWri ter\servic es.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7424 cmdline:
"C:\Window s\BitLocke rDiscovery VolumeCont ents\ZDtOz YsYYWKWEhN YzFc.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7540 cmdline:
"C:\Progra m Files (x 86)\window s multimed ia platfor m\ZDtOzYsY YWKWEhNYzF c.exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 7828 cmdline:
"C:\Progra m Files (x 86)\window s defender \en-GB\ZDt OzYsYYWKWE hNYzFc.exe " MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- ZDtOzYsYYWKWEhNYzFc.exe (PID: 2208 cmdline:
"C:\Window s\twain_32 \ZDtOzYsYY WKWEhNYzFc .exe" MD5: 0A5D9CD0A4B6ABDBB272262811774A8D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DCRat | DCRat is a typical RAT that has been around since at least June 2019. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
zgRAT | zgRAT is a Remote Access Trojan malware which sometimes drops other malware such as AgentTesla malware. zgRAT has an inforstealer use which targets browser information and cryptowallets.Usually spreads by USB or phishing emails with -zip/-lnk/.bat/.xlsx attachments and so on. | No Attribution |
{"C2 url": "http://durok.ru/JavascriptPacketgeoserverWindowsFlowerwordpresswpCentral", "Params": {"0": "{SYSTEMDRIVE}/Users/", "1": "false", "2": "false", "3": "true", "4": "true", "5": "false", "6": "true", "7": "true", "8": "true", "9": "true", "10": "true", "11": "false", "12": "true", "13": "true", "14": "true"}}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_DCRat_1 | Yara detected DCRat | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_DCRat_1 | Yara detected DCRat | Joe Security | ||
JoeSecurity_DCRat_1 | Yara detected DCRat | Joe Security | ||
Click to see the 5 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security | ||
JoeSecurity_zgRAT_1 | Yara detected zgRAT | Joe Security | ||
JoeSecurity_PureLogStealer | Yara detected PureLog Stealer | Joe Security |
System Summary |
---|
Source: | Author: Sander Wiebing, Tim Shelton, Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Patrick Bareiss, Anton Kutepov, oscd.community, Nasreddine Bencherchali: |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: vburov: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-26T17:17:12.161494+0100 | 2048095 | 1 | A Network Trojan was detected | 192.168.2.4 | 49730 | 104.21.93.162 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 0_2_00007FFD9B9194AD | |
Source: | Code function: | 16_2_00007FFD9B7A26AE | |
Source: | Code function: | 16_2_00007FFD9B9494AD | |
Source: | Code function: | 19_2_00007FFD9B7A26AE | |
Source: | Code function: | 28_2_00007FFD9B7826AE | |
Source: | Code function: | 31_2_00007FFD9B7826AE | |
Source: | Code function: | 32_2_00007FFD9B7A26AE | |
Source: | Code function: | 34_2_00007FFD9B7826AE | |
Source: | Code function: | 35_2_00007FFD9B7A26AE | |
Source: | Code function: | 36_2_00007FFD9B7826AE | |
Source: | Code function: | 37_2_00007FFD9B7826AE |
Networking |
---|
Source: | Suricata IDS: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Window created: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00007FFD9B761AC5 | |
Source: | Code function: | 0_2_00007FFD9B761300 | |
Source: | Code function: | 16_2_00007FFD9B79FE69 | |
Source: | Code function: | 16_2_00007FFD9B7AC84E | |
Source: | Code function: | 16_2_00007FFD9B7AC782 | |
Source: | Code function: | 16_2_00007FFD9B7AC735 | |
Source: | Code function: | 16_2_00007FFD9B7AC5A8 | |
Source: | Code function: | 16_2_00007FFD9B7AC90C | |
Source: | Code function: | 16_2_00007FFD9B7AC919 | |
Source: | Code function: | 16_2_00007FFD9B7AC926 | |
Source: | Code function: | 16_2_00007FFD9B7AC88B | |
Source: | Code function: | 16_2_00007FFD9B7AC87E | |
Source: | Code function: | 16_2_00007FFD9B7D594F | |
Source: | Code function: | 16_2_00007FFD9B791AC5 | |
Source: | Code function: | 16_2_00007FFD9BE6A04F | |
Source: | Code function: | 16_2_00007FFD9BE654D8 | |
Source: | Code function: | 16_2_00007FFD9B7AB0DD | |
Source: | Code function: | 19_2_00007FFD9B7D594F | |
Source: | Code function: | 19_2_00007FFD9B791AC5 | |
Source: | Code function: | 19_2_00007FFD9B79FE69 | |
Source: | Code function: | 19_2_00007FFD9B7AC84E | |
Source: | Code function: | 19_2_00007FFD9B7AC782 | |
Source: | Code function: | 19_2_00007FFD9B7AC735 | |
Source: | Code function: | 19_2_00007FFD9B7AC5A8 | |
Source: | Code function: | 19_2_00007FFD9B7AC90C | |
Source: | Code function: | 19_2_00007FFD9B7AC919 | |
Source: | Code function: | 19_2_00007FFD9B7AC926 | |
Source: | Code function: | 19_2_00007FFD9B7AC88B | |
Source: | Code function: | 19_2_00007FFD9B7AC87E | |
Source: | Code function: | 19_2_00007FFD9B7AB0DD | |
Source: | Code function: | 20_2_00007FFD9B7B594F | |
Source: | Code function: | 20_2_00007FFD9B771AC5 | |
Source: | Code function: | 20_2_00007FFD9B78C84E | |
Source: | Code function: | 20_2_00007FFD9B78C782 | |
Source: | Code function: | 20_2_00007FFD9B78C735 | |
Source: | Code function: | 20_2_00007FFD9B78C5AF | |
Source: | Code function: | 20_2_00007FFD9B78C90C | |
Source: | Code function: | 20_2_00007FFD9B78C919 | |
Source: | Code function: | 20_2_00007FFD9B78C926 | |
Source: | Code function: | 20_2_00007FFD9B78C88B | |
Source: | Code function: | 20_2_00007FFD9B78C87E | |
Source: | Code function: | 20_2_00007FFD9B77FE69 | |
Source: | Code function: | 20_2_00007FFD9B78B0DD | |
Source: | Code function: | 22_2_00007FFD9B771AC5 | |
Source: | Code function: | 22_2_00007FFD9B771300 | |
Source: | Code function: | 24_2_00007FFD9B751AC5 | |
Source: | Code function: | 24_2_00007FFD9B751300 | |
Source: | Code function: | 25_2_00007FFD9B791AC5 | |
Source: | Code function: | 25_2_00007FFD9B791300 | |
Source: | Code function: | 28_2_00007FFD9B77FE69 | |
Source: | Code function: | 28_2_00007FFD9B78C84E | |
Source: | Code function: | 28_2_00007FFD9B78C782 | |
Source: | Code function: | 28_2_00007FFD9B78C735 | |
Source: | Code function: | 28_2_00007FFD9B78C5AF | |
Source: | Code function: | 28_2_00007FFD9B78C90C | |
Source: | Code function: | 28_2_00007FFD9B78C919 | |
Source: | Code function: | 28_2_00007FFD9B78C926 | |
Source: | Code function: | 28_2_00007FFD9B78C88B | |
Source: | Code function: | 28_2_00007FFD9B78C87E | |
Source: | Code function: | 28_2_00007FFD9B7B594F | |
Source: | Code function: | 28_2_00007FFD9B771AC5 | |
Source: | Code function: | 28_2_00007FFD9B78B0DD | |
Source: | Code function: | 31_2_00007FFD9B7B594F | |
Source: | Code function: | 31_2_00007FFD9B77FE69 | |
Source: | Code function: | 31_2_00007FFD9B771AC5 | |
Source: | Code function: | 31_2_00007FFD9B78C84E | |
Source: | Code function: | 31_2_00007FFD9B78C782 | |
Source: | Code function: | 31_2_00007FFD9B78C735 | |
Source: | Code function: | 31_2_00007FFD9B78C5AF | |
Source: | Code function: | 31_2_00007FFD9B78C90C | |
Source: | Code function: | 31_2_00007FFD9B78C919 | |
Source: | Code function: | 31_2_00007FFD9B78C926 | |
Source: | Code function: | 31_2_00007FFD9B78C88B | |
Source: | Code function: | 31_2_00007FFD9B78C87E | |
Source: | Code function: | 31_2_00007FFD9B78B0DD | |
Source: | Code function: | 32_2_00007FFD9B7AC84E | |
Source: | Code function: | 32_2_00007FFD9B7AC782 | |
Source: | Code function: | 32_2_00007FFD9B7AC735 | |
Source: | Code function: | 32_2_00007FFD9B7AC5A8 | |
Source: | Code function: | 32_2_00007FFD9B7AC90C | |
Source: | Code function: | 32_2_00007FFD9B7AC919 | |
Source: | Code function: | 32_2_00007FFD9B7AC926 | |
Source: | Code function: | 32_2_00007FFD9B7AC88B | |
Source: | Code function: | 32_2_00007FFD9B7AC87E | |
Source: | Code function: | 32_2_00007FFD9B7D594F | |
Source: | Code function: | 32_2_00007FFD9B791AC5 | |
Source: | Code function: | 32_2_00007FFD9B79FE69 | |
Source: | Code function: | 32_2_00007FFD9B7AB0DD | |
Source: | Code function: | 33_2_00007FFD9B781AC5 | |
Source: | Code function: | 33_2_00007FFD9B781300 | |
Source: | Code function: | 34_2_00007FFD9B78C84E | |
Source: | Code function: | 34_2_00007FFD9B78C782 | |
Source: | Code function: | 34_2_00007FFD9B78C735 | |
Source: | Code function: | 34_2_00007FFD9B78C5AF | |
Source: | Code function: | 34_2_00007FFD9B78C90C | |
Source: | Code function: | 34_2_00007FFD9B78C919 | |
Source: | Code function: | 34_2_00007FFD9B78C926 | |
Source: | Code function: | 34_2_00007FFD9B78C88B | |
Source: | Code function: | 34_2_00007FFD9B78C87E | |
Source: | Code function: | 34_2_00007FFD9B771AC5 | |
Source: | Code function: | 34_2_00007FFD9B77FE69 | |
Source: | Code function: | 34_2_00007FFD9B7B594F | |
Source: | Code function: | 34_2_00007FFD9B78B0DD | |
Source: | Code function: | 35_2_00007FFD9B79FE69 | |
Source: | Code function: | 35_2_00007FFD9B791AC5 | |
Source: | Code function: | 35_2_00007FFD9B7D594F | |
Source: | Code function: | 35_2_00007FFD9B7AC84E | |
Source: | Code function: | 35_2_00007FFD9B7AC782 | |
Source: | Code function: | 35_2_00007FFD9B7AC735 | |
Source: | Code function: | 35_2_00007FFD9B7AC5A8 | |
Source: | Code function: | 35_2_00007FFD9B7AC90C | |
Source: | Code function: | 35_2_00007FFD9B7AC919 | |
Source: | Code function: | 35_2_00007FFD9B7AC926 | |
Source: | Code function: | 35_2_00007FFD9B7AC88B | |
Source: | Code function: | 35_2_00007FFD9B7AC87E | |
Source: | Code function: | 35_2_00007FFD9B7AB0DD | |
Source: | Code function: | 36_2_00007FFD9B77FE69 | |
Source: | Code function: | 36_2_00007FFD9B78C84E | |
Source: | Code function: | 36_2_00007FFD9B78C782 | |
Source: | Code function: | 36_2_00007FFD9B78C735 | |
Source: | Code function: | 36_2_00007FFD9B78C5AF | |
Source: | Code function: | 36_2_00007FFD9B78C90C | |
Source: | Code function: | 36_2_00007FFD9B78C919 | |
Source: | Code function: | 36_2_00007FFD9B78C926 | |
Source: | Code function: | 36_2_00007FFD9B78C88B | |
Source: | Code function: | 36_2_00007FFD9B78C87E | |
Source: | Code function: | 36_2_00007FFD9B7B594F | |
Source: | Code function: | 36_2_00007FFD9B771AC5 | |
Source: | Code function: | 36_2_00007FFD9B78B0DD | |
Source: | Code function: | 37_2_00007FFD9B77FE69 | |
Source: | Code function: | 37_2_00007FFD9B7B594F | |
Source: | Code function: | 37_2_00007FFD9B78C84E | |
Source: | Code function: | 37_2_00007FFD9B78C782 | |
Source: | Code function: | 37_2_00007FFD9B78C735 | |
Source: | Code function: | 37_2_00007FFD9B78C5AF | |
Source: | Code function: | 37_2_00007FFD9B78C90C | |
Source: | Code function: | 37_2_00007FFD9B78C919 | |
Source: | Code function: | 37_2_00007FFD9B78C926 | |
Source: | Code function: | 37_2_00007FFD9B78C88B | |
Source: | Code function: | 37_2_00007FFD9B78C87E | |
Source: | Code function: | 37_2_00007FFD9B771AC5 | |
Source: | Code function: | 37_2_00007FFD9B78B0DD |
Source: | Dropped File: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FFD9B7600C1 | |
Source: | Code function: | 0_2_00007FFD9B9167ED | |
Source: | Code function: | 0_2_00007FFD9B9B8AF9 | |
Source: | Code function: | 0_2_00007FFD9B9B5CB6 | |
Source: | Code function: | 16_2_00007FFD9B7AEE80 | |
Source: | Code function: | 16_2_00007FFD9B7D980D | |
Source: | Code function: | 16_2_00007FFD9B7DC74D | |
Source: | Code function: | 16_2_00007FFD9B7D756A | |
Source: | Code function: | 16_2_00007FFD9B7900C1 | |
Source: | Code function: | 16_2_00007FFD9B884662 | |
Source: | Code function: | 16_2_00007FFD9B9467ED | |
Source: | Code function: | 16_2_00007FFD9B9E5CB6 | |
Source: | Code function: | 16_2_00007FFD9BFE7BAC | |
Source: | Code function: | 19_2_00007FFD9B7D980D | |
Source: | Code function: | 19_2_00007FFD9B7DC74D | |
Source: | Code function: | 19_2_00007FFD9B7D756A | |
Source: | Code function: | 19_2_00007FFD9B7900C1 | |
Source: | Code function: | 19_2_00007FFD9B7AEE80 | |
Source: | Code function: | 20_2_00007FFD9B7B980D | |
Source: | Code function: | 20_2_00007FFD9B7BC74D | |
Source: | Code function: | 20_2_00007FFD9B7700C1 | |
Source: | Code function: | 22_2_00007FFD9B7700C1 | |
Source: | Code function: | 24_2_00007FFD9B7500C1 | |
Source: | Code function: | 25_2_00007FFD9B7900C1 | |
Source: | Code function: | 28_2_00007FFD9B7B980D | |
Source: | Code function: | 28_2_00007FFD9B7BC74D | |
Source: | Code function: | 28_2_00007FFD9B7700C1 | |
Source: | Code function: | 31_2_00007FFD9B7B980D | |
Source: | Code function: | 31_2_00007FFD9B7BC74D | |
Source: | Code function: | 31_2_00007FFD9B7700C1 | |
Source: | Code function: | 32_2_00007FFD9B7AEE80 |
Persistence and Installation Behavior |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File created: | Jump to dropped file |
Source: | Executable created and started: | ||
Source: | Executable created and started: | ||
Source: | Executable created and started: |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Registry value created or modified: | Jump to behavior |
Source: | Key value created or modified: | Jump to behavior | ||
Source: | Key value created or modified: | Jump to behavior | ||
Source: | Key value created or modified: | Jump to behavior | ||
Source: | Key value created or modified: | Jump to behavior | ||
Source: | Key value created or modified: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process created: |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: | |||
Source: | Process information set: |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: | |||
Source: | Memory allocated: |
Source: | Code function: | 16_2_00007FFD9B9414D0 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: | |||
Source: | Thread sleep time: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: | |||
Source: | File Volume queried: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: | |||
Source: | Thread delayed: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 16_2_00007FFD9B9414D0 |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: | |||
Source: | Process token adjusted: |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: | |||
Source: | Queries volume information: |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 241 Windows Management Instrumentation | 1 Scheduled Task/Job | 12 Process Injection | 232 Masquerading | 1 OS Credential Dumping | 351 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Scripting | 1 Scheduled Task/Job | 1 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | 2 Data from Local System | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 31 Registry Run Keys / Startup Folder | 31 Registry Run Keys / Startup Folder | 251 Virtualization/Sandbox Evasion | Security Account Manager | 251 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | 1 Clipboard Data | 12 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | 1 DLL Side-Loading | 1 DLL Side-Loading | 12 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 2 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | 134 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 11 Software Packing | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 1 DLL Side-Loading | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
60% | Virustotal | Browse | ||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1362695 | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Avira | HEUR/AGEN.1300079 | ||
100% | Avira | HEUR/AGEN.1362695 | ||
100% | Avira | TR/PSW.Agent.qngqt | ||
100% | Avira | HEUR/AGEN.1300079 | ||
100% | Avira | HEUR/AGEN.1300079 | ||
100% | Avira | HEUR/AGEN.1300079 | ||
100% | Avira | TR/PSW.Agent.qngqt | ||
100% | Avira | TR/Agent.jbwuj | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Avira | TR/Agent.jbwuj | ||
100% | Avira | TR/AVI.Agent.updqb | ||
100% | Avira | BAT/Delbat.C | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat | ||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat | ||
25% | ReversingLabs | |||
8% | ReversingLabs | |||
71% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
17% | ReversingLabs | ByteCode-MSIL.Trojan.Whispergate | ||
21% | ReversingLabs | |||
17% | ReversingLabs | ByteCode-MSIL.Trojan.Whispergate | ||
21% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
17% | ReversingLabs | |||
50% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
50% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
71% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
17% | ReversingLabs | |||
38% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
17% | ReversingLabs | |||
29% | ReversingLabs | |||
50% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
8% | ReversingLabs | |||
4% | ReversingLabs | |||
21% | ReversingLabs | |||
38% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
4% | ReversingLabs | |||
25% | ReversingLabs | |||
17% | ReversingLabs | |||
17% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
29% | ReversingLabs | Win32.Trojan.Generic | ||
17% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
29% | ReversingLabs | Win32.Trojan.Generic | ||
29% | ReversingLabs | |||
21% | ReversingLabs | ByteCode-MSIL.Trojan.Generic | ||
12% | ReversingLabs | |||
8% | ReversingLabs | |||
8% | ReversingLabs | |||
50% | ReversingLabs | ByteCode-MSIL.Trojan.DCRat | ||
8% | ReversingLabs | |||
12% | ReversingLabs | |||
21% | ReversingLabs | |||
8% | ReversingLabs | |||
21% | ReversingLabs | |||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat | ||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat | ||
63% | ReversingLabs | ByteCode-MSIL.Backdoor.DCRat |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
durok.ru | 104.21.93.162 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
false | high | |||
false | high | |||
true |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.93.162 | durok.ru | United States | 13335 | CLOUDFLARENETUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581018 |
Start date and time: | 2024-12-26 17:16:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 11m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 41 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Z4D3XAZ2jB.exerenamed because original name is a hash value |
Original Sample Name: | 0a5d9cd0a4b6abdbb272262811774a8d.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@37/74@1/1 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 4.175.87.197, 184.28.90.27, 13.107.246.63
- Excluded domains from analysis (whitelisted): fs.microsoft.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target ZDtOzYsYYWKWEhNYzFc.exe, PID 7244 because it is empty
- Execution Graph export aborted for target ZDtOzYsYYWKWEhNYzFc.exe, PID 7384 because it is empty
- Execution Graph export aborted for target services.exe, PID 5296 because it is empty
- Execution Graph export aborted for target services.exe, PID 7468 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report creation exceeded maximum time and may have missing disassembly code information.
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size exceeded maximum capacity and may have missing disassembly code.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
11:17:10 | API Interceptor | |
16:17:01 | Task Scheduler | |
16:17:01 | Task Scheduler | |
16:17:01 | Autostart | |
16:17:02 | Task Scheduler | |
16:17:02 | Task Scheduler | |
16:17:09 | Autostart | |
16:17:17 | Autostart | |
16:17:25 | Autostart | |
16:17:33 | Autostart | |
16:17:41 | Autostart | |
16:17:58 | Autostart | |
16:18:06 | Autostart | |
16:18:15 | Autostart | |
16:18:23 | Autostart | |
16:18:31 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\Desktop\ADqcsYvZ.log | Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | ||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse | |||
Get hash | malicious | DCRat, PureLog Stealer, zgRAT | Browse |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163910 |
Entropy (8bit): | 7.992391848855575 |
Encrypted: | true |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
MD5: | 0A5D9CD0A4B6ABDBB272262811774A8D |
SHA1: | 9571472C5D0899E517E1C1F84C6C05DFD2ABB2B5 |
SHA-256: | 9C2AD3D80258AF2508987D952DD5A7744BEDBDD16260E4F76412EA6696774285 |
SHA-512: | 439D108D086E6231513A7D40E01EA9C8D1B0D9948C9412F2828F694D94CCFA64E98D8A6956464CCCB632BB072AAE4E3C00154733BC3AF97A11CD7A57F0B0FB10 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 466 |
Entropy (8bit): | 5.862890432846636 |
Encrypted: | false |
SSDEEP: | 12:jmGp/SJBK/0JYmWSjLw1hf18Q+ssKSRdNUiLt196n/H4U:yW/SJBY05jLwr18QTrQAn/YU |
MD5: | DE97C6B68239112E04623640D92F20F3 |
SHA1: | FBAF697B269BF91AE56FB8593A62D3833559EFEA |
SHA-256: | 002392B18CB51235E8D1A03C1AC2ACBD3D8E3B0B6632B08E158E52C06A8C7807 |
SHA-512: | 1CCD4E450E0F04130A563914A716E1EDB74BC200C472BD543D82EA3C2AC42C4AD6A06FE1532ED0368160B1F5C172F10CF62E93AF0991AE26792E4A70C06BAE9E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163910 |
Entropy (8bit): | 7.992391848855575 |
Encrypted: | true |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
MD5: | 0A5D9CD0A4B6ABDBB272262811774A8D |
SHA1: | 9571472C5D0899E517E1C1F84C6C05DFD2ABB2B5 |
SHA-256: | 9C2AD3D80258AF2508987D952DD5A7744BEDBDD16260E4F76412EA6696774285 |
SHA-512: | 439D108D086E6231513A7D40E01EA9C8D1B0D9948C9412F2828F694D94CCFA64E98D8A6956464CCCB632BB072AAE4E3C00154733BC3AF97A11CD7A57F0B0FB10 |
Malicious: | true |
Antivirus: |
|
Preview: |
C:\Program Files (x86)\Windows Multimedia Platform\ZDtOzYsYYWKWEhNYzFc.exe:Zone.Identifier
Download File
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 507 |
Entropy (8bit): | 5.875279671400233 |
Encrypted: | false |
SSDEEP: | 12:1BMBUyuFaucBqZLexY7g84+Pg7ygyRn82MAwoHidJd4tdHL:rMBvuqsKY7njPgRAwoHidI1 |
MD5: | 7956B9F1EFD0F4D81B18B9DDC3F32F61 |
SHA1: | 213E111A366F92890B6E42254EDD7118F98BED65 |
SHA-256: | AE267E50F3602869528BF95C7A5E1ECC5B0E7FB8D65684466DFB46E8311A0E88 |
SHA-512: | EFF4BE6AB4BB776000EE2AD68FC3416B88BD4B8A6F84262FD10A5D88F85AC7B636DFA43DF3345EAF3A20952FBC7877244C72E981602F5E780952B55C11171582 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1830 |
Entropy (8bit): | 5.3661116947161815 |
Encrypted: | false |
SSDEEP: | 48:MxHKQ71qHGIs0HKCYHKGSI6oPtHTHhAHKKkrJHmHKlT4vHNpv:iq+wmj0qCYqGSI6oPtzHeqKktGqZ4vtd |
MD5: | 4E98592551BD0B069F525D5145C4AB1D |
SHA1: | F76B60DC100FAB739EB836650B112348ED7B9B97 |
SHA-256: | 171B3D8F6F3559D645DECCA2C9B750EBFD5511B6742C0157C60F46EAD6CC4F5E |
SHA-512: | E5C520597C414A3F73AF0C4F2E2A61CE594D8CEC7FF103D94CCAEA905E0D5F6AF32CFAB40026865AE86172904F927B928663C9FA4B0EBD397CC450BF124A318D |
Malicious: | true |
Preview: |
Process: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1281 |
Entropy (8bit): | 5.370111951859942 |
Encrypted: | false |
SSDEEP: | 24:ML9E4KQ71qE4GIs0E4KCKDE4KGKZI6KhPKIE4TKBGKoZAE4KKUNb:MxHKQ71qHGIs0HKCYHKGSI6oPtHTHhA2 |
MD5: | 12C61586CD59AA6F2A21DF30501F71BD |
SHA1: | E6B279DC134544867C868E3FF3C267A06CE340C7 |
SHA-256: | EC20A856DBBCF320F7F24C823D6E9D2FD10E9335F5DE2F56AB9A7DF1ED358543 |
SHA-512: | B0731F59C74C9D25A4C82E166B3DC300BBCF89F6969918EC748B867C641ED0D8E0DE81AAC68209EF140219861B4939F1B07D0885ACA112D494D23AAF9A9C03FE |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1281 |
Entropy (8bit): | 5.370111951859942 |
Encrypted: | false |
SSDEEP: | 24:ML9E4KQ71qE4GIs0E4KCKDE4KGKZI6KhPKIE4TKBGKoZAE4KKUNb:MxHKQ71qHGIs0HKCYHKGSI6oPtHTHhA2 |
MD5: | 12C61586CD59AA6F2A21DF30501F71BD |
SHA1: | E6B279DC134544867C868E3FF3C267A06CE340C7 |
SHA-256: | EC20A856DBBCF320F7F24C823D6E9D2FD10E9335F5DE2F56AB9A7DF1ED358543 |
SHA-512: | B0731F59C74C9D25A4C82E166B3DC300BBCF89F6969918EC748B867C641ED0D8E0DE81AAC68209EF140219861B4939F1B07D0885ACA112D494D23AAF9A9C03FE |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5707520969659783 |
Encrypted: | false |
SSDEEP: | 12:TLVlFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TLxF1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 9F6D153D934BCC50E8BC57E7014B201A |
SHA1: | 50B3F813A1A8186DE3F6E9791EC41D95A8DC205D |
SHA-256: | 2A7FC7F64938AD07F7249EC0BED6F48BC5302EA84FE9E61E276436EA942BA230 |
SHA-512: | B8CA2DCB8D62A0B2ED8795C3F67E4698F3BCB208C26FBD8BA9FD4DA82269E6DE9C5759F27F28DC108677DDEBBAC96D60C4ED2E64C90D51DB5B0F70331185B33F |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28672 |
Entropy (8bit): | 2.5793180405395284 |
Encrypted: | false |
SSDEEP: | 96:/xealJiylsMjLslk5nYPphZEhcR2hO2mOeVgN8tmKqWkh3qzRk4PeOhZ3hcR1hOI:/xGZR8wbtxq5uWRHKloIN7YItnb6Ggz |
MD5: | 41EA9A4112F057AE6BA17E2838AEAC26 |
SHA1: | F2B389103BFD1A1A050C4857A995B09FEAFE8903 |
SHA-256: | CE84656EAEFC842355D668E7141F84383D3A0C819AE01B26A04F9021EF0AC9DB |
SHA-512: | 29E848AD16D458F81D8C4F4E288094B4CFC103AD99B4511ED1A4846542F9128736A87AAC5F4BFFBEFE7DF99A05EB230911EDCE99FEE3877DEC130C2781962103 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 106496 |
Entropy (8bit): | 1.1358696453229276 |
Encrypted: | false |
SSDEEP: | 192:ZWTblyVZTnGtgTgabTanQeZVuSVumZa6c5/w4:MnlyfnGtxnfVuSVumEH544 |
MD5: | 28591AA4E12D1C4FC761BE7C0A468622 |
SHA1: | BC4968A84C19377D05A8BB3F208FBFAC49F4820B |
SHA-256: | 51624D124EFA3EE31EF43CB3D9ECFE98254D629957063747F4CA7061543B14B9 |
SHA-512: | 5DDC8C36538AB1415637B2FF6C35AED3A94639A0C2B0A36E256A1C4477AA5A356813D1368913BA3B6E8B770625CDCB94EE7BFC17FD7D324982CFE3BDEC2D32EB |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 245 |
Entropy (8bit): | 5.389148345240419 |
Encrypted: | false |
SSDEEP: | 6:hCijTg3Nou1SV+DER5SMLeAQf8fbSKOZG1wkn23f3q:HTg9uYDEfSMEfObIfS |
MD5: | B7B6FF3BC3BC7C559B5F22417FD50208 |
SHA1: | AC325AD5DC5697C4CB967C4E48834385EA0B43B8 |
SHA-256: | B19588F5CA7C1C1AF17113A563482AD9195EAFA0C51E7E5847AAE922A6F602CF |
SHA-512: | 8ED00ECA924C1B47B22A58C7E706A152A63EB7E5EF470315ECB965F9ABD12B59E91989DA67087533C00F88F4872FD614249201B28EB9A48C82D8294515FA6FCF |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 49152 |
Entropy (8bit): | 0.8180424350137764 |
Encrypted: | false |
SSDEEP: | 96:uRMKLyeymwxCn8MZyFlSynlbiXyKwt8hG:uRkxGOXnlbibhG |
MD5: | 349E6EB110E34A08924D92F6B334801D |
SHA1: | BDFB289DAFF51890CC71697B6322AA4B35EC9169 |
SHA-256: | C9FD7BE4579E4AA942E8C2B44AB10115FA6C2FE6AFD0C584865413D9D53F3B2A |
SHA-512: | 2A635B815A5E117EA181EE79305EE1BAF591459427ACC5210D8C6C7E447BE3513EAD871C605EB3D32E4AB4111B2A335F26520D0EF8C1245A4AF44E1FAEC44574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | modified |
Size (bytes): | 5242880 |
Entropy (8bit): | 0.037963276276857943 |
Encrypted: | false |
SSDEEP: | 192:58rJQaXoMXp0VW9FxWZWdgokBQNba9D3DO/JxW/QHI:58r54w0VW3xWZWdOBQFal3dQ |
MD5: | C0FDF21AE11A6D1FA1201D502614B622 |
SHA1: | 11724034A1CC915B061316A96E79E9DA6A00ADE8 |
SHA-256: | FD4EB46C81D27A9B3669C0D249DF5CE2B49E5F37B42F917CA38AB8831121ADAC |
SHA-512: | A6147C196B033725018C7F28C1E75E20C2113A0C6D8172F5EABCB8FF334EA6CE10B758FFD1D22D50B4DB5A0A21BCC15294AC44E94D973F7A3EB9F8558F31769B |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40960 |
Entropy (8bit): | 0.8553638852307782 |
Encrypted: | false |
SSDEEP: | 48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil |
MD5: | 28222628A3465C5F0D4B28F70F97F482 |
SHA1: | 1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14 |
SHA-256: | 93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4 |
SHA-512: | C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98304 |
Entropy (8bit): | 0.08235737944063153 |
Encrypted: | false |
SSDEEP: | 12:DQAsfWk73Fmdmc/OPVJXfPNn43etRRfYR5O8atLqxeYaNcDakMG/lO:DQAsff32mNVpP965Ra8KN0MG/lO |
MD5: | 369B6DD66F1CAD49D0952C40FEB9AD41 |
SHA1: | D05B2DE29433FB113EC4C558FF33087ED7481DD4 |
SHA-256: | 14150D582B5321D91BDE0841066312AB3E6673CA51C982922BC293B82527220D |
SHA-512: | 771054845B27274054B6C73776204C235C46E0C742ECF3E2D9B650772BA5D259C8867B2FA92C3A9413D3E1AD35589D8431AC683DF84A53E13CDE361789045928 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 114688 |
Entropy (8bit): | 0.9746603542602881 |
Encrypted: | false |
SSDEEP: | 192:CwbUJ6IH9xhomnGCTjHbRjCLqtzKWJaW:CfJ6a9xpnQLqtzKWJn |
MD5: | 780853CDDEAEE8DE70F28A4B255A600B |
SHA1: | AD7A5DA33F7AD12946153C497E990720B09005ED |
SHA-256: | 1055FF62DE3DEA7645C732583242ADF4164BDCFB9DD37D9B35BBB9510D59B0A3 |
SHA-512: | E422863112084BB8D11C682482E780CD63C2F20C8E3A93ED3B9EFD1B04D53EB5D3C8081851CA89B74D66F3D9AB48EB5F6C74550484F46E7C6E460A8250C9B1D8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40960 |
Entropy (8bit): | 0.8553638852307782 |
Encrypted: | false |
SSDEEP: | 48:2x7BA+IIF7CVEq8Ma0D0HOlf/6ykwp1EUwMHZq10bvJKLkw8s8LKvUf9KVyJ7h/f:QNDCn8MouB6wz8iZqmvJKLPeymwil |
MD5: | 28222628A3465C5F0D4B28F70F97F482 |
SHA1: | 1BAA3DEB7DFD7C9B4CA9FDB540F236C24917DD14 |
SHA-256: | 93A6AF6939B17143531FA4474DFC564FA55359308B910E6F0DCA774D322C9BE4 |
SHA-512: | C8FB93F658C1A654186FA6AA2039E40791E6B0A1260B223272BB01279A7B574E238B28217DADF3E1850C7083ADFA2FE5DA0CCE6F9BCABD59E1FFD1061B3A88F7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14 |
Entropy (8bit): | 3.378783493486176 |
Encrypted: | false |
SSDEEP: | 3:Y2Qt6eYYn:Y2Qt6eYYn |
MD5: | 6CA4960355E4951C72AA5F6364E459D5 |
SHA1: | 2FD90B4EC32804DFF7A41B6E63C8B0A40B592113 |
SHA-256: | 88301F0B7E96132A2699A8BCE47D120855C7F0A37054540019E3204D6BCBABA3 |
SHA-512: | 8544CD778717788B7484FAF2001F463320A357DB63CB72715C1395EF19D32EEC4278BAB07F15DE3F4FED6AF7E4F96C41908A0C45BE94D5CDD8121877ECCF310D |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 159744 |
Entropy (8bit): | 0.7873599747470391 |
Encrypted: | false |
SSDEEP: | 96:pn6pld6px0c2EDKFm5wTmN8ewmdaDKFmJ4ee7vuejzH+bF+UIYysX0IxQzh/tsVL:8Ys3QMmRtH+bF+UI3iN0RSV0k3qLyj9v |
MD5: | 6A6BAD38068B0F6F2CADC6464C4FE8F0 |
SHA1: | 4E3B235898D8E900548613DDB6EA59CDA5EB4E68 |
SHA-256: | 0998615B274171FC74AAB4E70FD355AF513186B74A4EB07AAA883782E6497982 |
SHA-512: | BFE41E5AB5851C92308A097FE9DA4F215875AC2C7D7A483B066585071EE6086B5A7BE6D80CEC18027A3B88AA5C0A477730B22A41406A6AB344FCD9C659B9CB0A |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 126976 |
Entropy (8bit): | 0.47147045728725767 |
Encrypted: | false |
SSDEEP: | 96:/WU+bDoYysX0uhnyTpvVjN9DLjGQLBE3u:/l+bDo3irhnyTpvVj3XBBE3u |
MD5: | A2D1F4CF66465F9F0CAC61C4A95C7EDE |
SHA1: | BA6A845E247B221AAEC96C4213E1FD3744B10A27 |
SHA-256: | B510DF8D67E38DCAE51FE97A3924228AD37CF823999FD3BC6BA44CA6535DE8FE |
SHA-512: | C571E5125C005EAC0F0B72B5F132AE03783AF8D621BFA32B366B0E8A825EF8F65E33CD330E42BDC722BFA012E3447A7218F05FDD4A5AD855C1CA22DFA2F79838 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.293660689688185 |
Encrypted: | false |
SSDEEP: | 3:xrn26tGqUIg:tn26tGz |
MD5: | 8596D21E3D9F915C6B369DB324B66BA1 |
SHA1: | 4FFF5D38B29770048274A895A60527AEDC71A36C |
SHA-256: | F0D3A272F34C9116B5C0580C2B38A4AC12682605D0D06F9CE22C20DD2D8611D8 |
SHA-512: | 12637CD0BBCD27A68DE1724FB7FA31347F02294ADAB11570FDE87031627190DD3688794CAD168001514B7DD8022A5E7A8D640283F71323EC0F26E9CCE0D02901 |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5707520969659783 |
Encrypted: | false |
SSDEEP: | 12:TLVlFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TLxF1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 9F6D153D934BCC50E8BC57E7014B201A |
SHA1: | 50B3F813A1A8186DE3F6E9791EC41D95A8DC205D |
SHA-256: | 2A7FC7F64938AD07F7249EC0BED6F48BC5302EA84FE9E61E276436EA942BA230 |
SHA-512: | B8CA2DCB8D62A0B2ED8795C3F67E4698F3BCB208C26FBD8BA9FD4DA82269E6DE9C5759F27F28DC108677DDEBBAC96D60C4ED2E64C90D51DB5B0F70331185B33F |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 25 |
Entropy (8bit): | 4.163856189774724 |
Encrypted: | false |
SSDEEP: | 3:5d82n:Ln |
MD5: | 02259ED05CEAF2B4DE9DE5614EF0FB1C |
SHA1: | 62BD3DEE56FEB97B5F8764AD8DF1005F11CD4E19 |
SHA-256: | 58E0AD63479DEC6801CACA1A09D59F52A4B8F8D841568631CF4EE911D1158831 |
SHA-512: | DA2E4162E987E48258DC5B8DF941F0EDB209265D50CBD3DE56EF153712A0C299B855C34E17E213910215D2BCFB690274FC35362A6B671759A6D9DEEDBB5A1DFE |
Malicious: | false |
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 20480 |
Entropy (8bit): | 0.5712781801655107 |
Encrypted: | false |
SSDEEP: | 12:TLVNFVP89GkwtwhuFdbXGwvfhowcFOaOmzdOtssh+bgc4Jp+FxOUwa5q0S9zXhZn:TL1F1kwNbXYFpFNYcw+6UwcQVXH5fB |
MD5: | 05A60B4620923FD5D53B9204391452AF |
SHA1: | DC12F90925033F25C70A720E01D5F8666D0B46E4 |
SHA-256: | 6F1CA729609806AF88218D0A35C3B9E34252900341A0E15D71F7F9199E422E13 |
SHA-512: | 068A954C0C7A68E603D72032A447E7652B1E9CED5522562FBCBD9EC0A5D2D943701100049FA0A750E71C4D3D84210B48D10855E7CC60919E04ED884983D3C3D6 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32256 |
Entropy (8bit): | 5.631194486392901 |
Encrypted: | false |
SSDEEP: | 384:lP/qZmINM9WPs9Q617EsO2m2g7udB2HEsrW+a4yiym4I16Gl:lP/imaPyQ4T5dsHSt9nQ |
MD5: | D8BF2A0481C0A17A634D066A711C12E9 |
SHA1: | 7CC01A58831ED109F85B64FE4920278CEDF3E38D |
SHA-256: | 2B93377EA087225820A9F8E4F331005A0C600D557242366F06E0C1EAE003D669 |
SHA-512: | 7FB4EB786528AD15DF044F16973ECA05F05F035491E9B1C350D6AA30926AAE438E98F37BE1BB80510310A91BC820BA3EDDAF7759D7D599BCDEBA0C9DF6302F60 |
Malicious: | true |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 38912 |
Entropy (8bit): | 5.679286635687991 |
Encrypted: | false |
SSDEEP: | 768:RH9nQF3DwRvGTYLOFbL79ed5l8UNebCPncg:TyDF0PybCPn |
MD5: | 9E910782CA3E88B3F87826609A21A54E |
SHA1: | 8DBC333244620EDA5D3F1C9EAA6B924455262303 |
SHA-256: | 3B311986251EE5A303671108AFBAF43E0255C4CAE1C26CC9600BB0C7D22D3864 |
SHA-512: | 592981359F46BBC577BE99DEFE3E2A17998BA2882AAAA20107841BCA97C2121CB97C45BC6EDBFC3F430D31450457CD855751727922AB4BB1A3C12DA050EEC057 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85504 |
Entropy (8bit): | 5.8769270258874755 |
Encrypted: | false |
SSDEEP: | 1536:p7Oc/sAwP1Q1wUww6vtZNthMx4SJ2ZgjlrL7BzZZmKYT:lOc/sAwP1Q1wUwhHBMx4a2iJjBzZZm9 |
MD5: | E9CE850DB4350471A62CC24ACB83E859 |
SHA1: | 55CDF06C2CE88BBD94ACDE82F3FEA0D368E7DDC6 |
SHA-256: | 7C95D3B38114E7E4126CB63AADAF80085ED5461AB0868D2365DD6A18C946EA3A |
SHA-512: | 9F4CBCE086D8A32FDCAEF333C4AE522074E3DF360354822AA537A434EB43FF7D79B5AF91E12FB62D57974B9ED5B4D201DDE2C22848070D920C9B7F5AE909E2CA |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294912 |
Entropy (8bit): | 6.010605469502259 |
Encrypted: | false |
SSDEEP: | 6144:f5M1rY+WGzK4NGSAhWj1dVV6cTl06YX6w/xHtRoNF:fuzzAWlvYXDRoNF |
MD5: | 00574FB20124EAFD40DC945EC86CA59C |
SHA1: | 8B96C4B6F450E711085AE7B22517C195222ACFDF |
SHA-256: | 3A0C38E5DC41A8D668EBDD9368CEE89F4991350E6967A9715CAE8F36E0D032BB |
SHA-512: | B578007ECDCEC0D7A3A09F7E5D681A724FE2749CB46B58F5D5C96E88CAAC03C4570BB67F47BC45F01B9A47966086CC08DACB691AA2D26AD0262DC1257F7CA837 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 126976 |
Entropy (8bit): | 6.057993947082715 |
Encrypted: | false |
SSDEEP: | 3072:V2IJq7YkHFJwBTZtHrC/0/FHkINvdF+nTCkjk1U+1:V2IJq7YbrFHkIrgnTQ |
MD5: | 16B480082780CC1D8C23FB05468F64E7 |
SHA1: | 6FDDF86F9F0FBAA189F5CB79E44999A3F1AC2B26 |
SHA-256: | 7A080D8BD178EC02C7F39F7F941479074C450C4FDD8E963C993D2FB5537C7708 |
SHA-512: | A165BB5D7972DE124F670BCAC20B4A46727B7CF27D1ED925D02F7CC7C79D7D04122D7C202C67D7EAE798348E8D481F085282EB5B89D84B902607D7EB1155BA19 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294912 |
Entropy (8bit): | 6.010605469502259 |
Encrypted: | false |
SSDEEP: | 6144:f5M1rY+WGzK4NGSAhWj1dVV6cTl06YX6w/xHtRoNF:fuzzAWlvYXDRoNF |
MD5: | 00574FB20124EAFD40DC945EC86CA59C |
SHA1: | 8B96C4B6F450E711085AE7B22517C195222ACFDF |
SHA-256: | 3A0C38E5DC41A8D668EBDD9368CEE89F4991350E6967A9715CAE8F36E0D032BB |
SHA-512: | B578007ECDCEC0D7A3A09F7E5D681A724FE2749CB46B58F5D5C96E88CAAC03C4570BB67F47BC45F01B9A47966086CC08DACB691AA2D26AD0262DC1257F7CA837 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 36352 |
Entropy (8bit): | 5.668291349855899 |
Encrypted: | false |
SSDEEP: | 384:3+GMbUL+1FjuuGWkgoCFvMiAAsSZH14gXO9XBKeRg3U7ixu8bqMle9dCe4i2+o06:3+T93kgoCFkid/O9sU7io8b1ocl+o |
MD5: | 94DA5073CCC14DCF4766DF6781485937 |
SHA1: | 57300CA6033974810B71CF1AB4F047A026924A7A |
SHA-256: | B81B9FA9B7017BE34F62D30CB16BAAB33757F04CC94EF4D6459C9D3BC768FD18 |
SHA-512: | 7D539ECED2F19166F0F6FAE6E2624C0440DEC87AA9751FA82387EECEF9945997ABAE58C886494633BA360B122BCA955B3DDAE26E5256E371A0528F48DFA17871 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 50176 |
Entropy (8bit): | 5.723168999026349 |
Encrypted: | false |
SSDEEP: | 768:7PCvZsxIexhaqgbv8yGk/A/4NPmAQeMeYzlP58gH8zGTCWxttXyZPM:7P4ZsxIelkY/O+DeuzYbM5xXiE |
MD5: | 2E116FC64103D0F0CF47890FD571561E |
SHA1: | 3EF08A9B057D1876C24FC76E937CDA461FAC6071 |
SHA-256: | 25EEEA99DCA05BF7651264FA0C07E0E91D89E0DA401C387284E9BE9AFDF79625 |
SHA-512: | 39D09DE00E738B01B6D8D423BA05C61D08E281482C83835F4C88D2F87E6E0536DDC0101872CBD97C30F977BC223DFAE9FCB3DB71DD8078B7EB5B5A4D0D5207A8 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342528 |
Entropy (8bit): | 6.170134230759619 |
Encrypted: | false |
SSDEEP: | 3072:YMRFbwlz0otnh0efcZBU/fbF+pzZDrpSToDxcLQcm+xCjNS3RaCtXAOZrNM1Ge6q:uhj/zQD9SocLQDchaUXAiNM1C3HuiH |
MD5: | 9DADB5C8A6FD5020275C31EE6BC61D63 |
SHA1: | ACE09D19F7DBB98F5C844E77F29A5D86E544CCC1 |
SHA-256: | 80E21E05386AB5BF7BCFD745146700E2A73D808CAFDE3F1DAA256D09BCF4522F |
SHA-512: | EDB9F8B4A3742AFD344B3E4957CD6A8574FA82EB49B45E75627180C42B51F9C019E241D695BAF0AAA36EE6959CE297C358BC592F2EE31B0BB5EA19FEED67FC7D |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69632 |
Entropy (8bit): | 5.932541123129161 |
Encrypted: | false |
SSDEEP: | 1536:yo63BdpcSWxaQ/RKd8Skwea/e+hTEqS/ABGegJBb07j:j+9W+p/LEqu6GegG |
MD5: | F4B38D0F95B7E844DD288B441EBC9AAF |
SHA1: | 9CBF5C6E865AE50CEC25D95EF70F3C8C0F2A6CBF |
SHA-256: | AAB95596475CA74CEDE5BA50F642D92FA029F6F74F6FAEAE82A9A07285A5FB97 |
SHA-512: | 2300D8FC857986DC9560225DE36C221C6ECB4F98ADB954D896ED6AFF305C3A3C05F5A9F1D5EF0FC9094355D60327DDDFAFC81A455596DCD28020A9A89EF50E1A |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85504 |
Entropy (8bit): | 5.8769270258874755 |
Encrypted: | false |
SSDEEP: | 1536:p7Oc/sAwP1Q1wUww6vtZNthMx4SJ2ZgjlrL7BzZZmKYT:lOc/sAwP1Q1wUwhHBMx4a2iJjBzZZm9 |
MD5: | E9CE850DB4350471A62CC24ACB83E859 |
SHA1: | 55CDF06C2CE88BBD94ACDE82F3FEA0D368E7DDC6 |
SHA-256: | 7C95D3B38114E7E4126CB63AADAF80085ED5461AB0868D2365DD6A18C946EA3A |
SHA-512: | 9F4CBCE086D8A32FDCAEF333C4AE522074E3DF360354822AA537A434EB43FF7D79B5AF91E12FB62D57974B9ED5B4D201DDE2C22848070D920C9B7F5AE909E2CA |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41472 |
Entropy (8bit): | 5.6808219961645605 |
Encrypted: | false |
SSDEEP: | 768:IUVSXpIia8xiZ7tRCoz79t6DrMhvUsJAnmboowvDG:IFXRa/Lzugszmboowb |
MD5: | 6CD78D07F9BD4FECC55CDB392BC5EC89 |
SHA1: | 094DE32070BED60A811D983740509054AD017CE4 |
SHA-256: | 16CC3B734E72A74F578B63D08D81CC75B6C2445FB631EFD19F8A70D786871AD4 |
SHA-512: | 5E25659A66E62F368ACD69790F0CF460008CAA3BB106E45CBA4755896B1872C02438C94E6FB5576891F29B3FEA95D8AAD9BCD7659C179D9619A1CDDB240AEB32 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33792 |
Entropy (8bit): | 5.541771649974822 |
Encrypted: | false |
SSDEEP: | 768:VA51bYJhOlZVuS6c4UvEEXLeeG+NOInR:VJEx6f2EEbee/Bn |
MD5: | 2D6975FD1CC3774916D8FF75C449EE7B |
SHA1: | 0C3A915F80D20BFF0BB4023D86ACAF80AF30F98D |
SHA-256: | 75CE6EB6CDDD67D47FB7C5782F45FDC497232F87A883650BA98679F92708A986 |
SHA-512: | 6B9792C609E0A3F729AE2F188DE49E66067E3808E5B412E6DC56A555BC95656DA62ECD07D931B05756303A65383B029E7862C04CA5EA879A3FDFB61789BD2580 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 50176 |
Entropy (8bit): | 5.723168999026349 |
Encrypted: | false |
SSDEEP: | 768:7PCvZsxIexhaqgbv8yGk/A/4NPmAQeMeYzlP58gH8zGTCWxttXyZPM:7P4ZsxIelkY/O+DeuzYbM5xXiE |
MD5: | 2E116FC64103D0F0CF47890FD571561E |
SHA1: | 3EF08A9B057D1876C24FC76E937CDA461FAC6071 |
SHA-256: | 25EEEA99DCA05BF7651264FA0C07E0E91D89E0DA401C387284E9BE9AFDF79625 |
SHA-512: | 39D09DE00E738B01B6D8D423BA05C61D08E281482C83835F4C88D2F87E6E0536DDC0101872CBD97C30F977BC223DFAE9FCB3DB71DD8078B7EB5B5A4D0D5207A8 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 70144 |
Entropy (8bit): | 5.909536568846014 |
Encrypted: | false |
SSDEEP: | 1536:3LM14SKtpfLarGzoQWaqaQ2n5YejqSRKnYdYPgh3c//npRwM:w7KtpTjNNn5YejqSRKnYdYPgJo/pRwM |
MD5: | E4FA63649F1DBD23DE91861BB39C317D |
SHA1: | 25F9115FAF40EC6736FACF2288CAA9B0E6AF9366 |
SHA-256: | CB4CD707305733ADDFCC54A69DF54A0C8D47C312D969B3E8D38B93E18CCBD8E4 |
SHA-512: | C4B5A9D66146D98D414BC84CD5C09588E2E02B800B21CE3172042AD7F48CC4AED54772D32C891A921FF102C0C3DB1FEAF52E4D4C714ABDB15F73BAEB9A6F5A39 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342528 |
Entropy (8bit): | 6.170134230759619 |
Encrypted: | false |
SSDEEP: | 3072:YMRFbwlz0otnh0efcZBU/fbF+pzZDrpSToDxcLQcm+xCjNS3RaCtXAOZrNM1Ge6q:uhj/zQD9SocLQDchaUXAiNM1C3HuiH |
MD5: | 9DADB5C8A6FD5020275C31EE6BC61D63 |
SHA1: | ACE09D19F7DBB98F5C844E77F29A5D86E544CCC1 |
SHA-256: | 80E21E05386AB5BF7BCFD745146700E2A73D808CAFDE3F1DAA256D09BCF4522F |
SHA-512: | EDB9F8B4A3742AFD344B3E4957CD6A8574FA82EB49B45E75627180C42B51F9C019E241D695BAF0AAA36EE6959CE297C358BC592F2EE31B0BB5EA19FEED67FC7D |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 39936 |
Entropy (8bit): | 5.660491370279985 |
Encrypted: | false |
SSDEEP: | 768:1Q8H1q0rErIq3y48wo5iJyNJZ+pkw82VhgwgKZ:brErIqxPJRkw/VOwbZ |
MD5: | 240E98D38E0B679F055470167D247022 |
SHA1: | 49888CCED719AE78EE3BAE2959402749668AA1C6 |
SHA-256: | C200E1BE39C35F8E57A0E1E241723FDB956089BC8EAD1235042456C7A3C4AD28 |
SHA-512: | 93C1B6396C65C9EDACEFD6606A9563935D3C1331454DA69FA75D9B1CCE4D102A5F1B27B63FC3A7E485A083D8DAB1E6C4ECD01DD3CFED9B58DA6F4E90CC4F2998 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28160 |
Entropy (8bit): | 5.570953308352568 |
Encrypted: | false |
SSDEEP: | 384:BBOVNMHHPrq2YQGpX0dx+D4uuMig590gQDhJvoKfqeXOWnKNey/B/HM/g/6Y70FB:LOCPAEdx+vuNgD0gQ/gCYoTyn+ |
MD5: | A4F19ADB89F8D88DBDF103878CF31608 |
SHA1: | 46267F43F0188DFD3248C18F07A46448D909BF9B |
SHA-256: | D0613773A711634434DB30F2E35C6892FF54EBEADF49CD254377CAECB204EAA4 |
SHA-512: | 23AA30D1CD92C4C69BA23C9D04CEBF4863A9EA20699194F9688B1051CE5A0FAD808BC27EE067A8AA86562F35C352824A53F7FB0A93F4A99470A1C97B31AF8C12 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34816 |
Entropy (8bit): | 5.636032516496583 |
Encrypted: | false |
SSDEEP: | 384:JS7LcTqpkHdmLrBmyOLkOPXVcqTZH0uZLSHtciyBDVGehpx3ZPyp1MoCy07G7:J+CaBoXTZH0mUfoGCzpapaFy07 |
MD5: | 996BD447A16F0A20F238A611484AFE86 |
SHA1: | CB0F51CE7FEEE1B5F02D3F13E60D67AF448C478D |
SHA-256: | 0CB182B9F8BD0804FC3BBA016926199C536BD7491BA577E089271DC1A63B07BE |
SHA-512: | 80924C19FAF3916DB5F71BE5723B6CB7BB7F731DBBA05B8218746F11FB9470F746B7AC581DB398E388377637811319EF8D6841504DC8EA39C510D7CFCD25184C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33792 |
Entropy (8bit): | 5.541771649974822 |
Encrypted: | false |
SSDEEP: | 768:VA51bYJhOlZVuS6c4UvEEXLeeG+NOInR:VJEx6f2EEbee/Bn |
MD5: | 2D6975FD1CC3774916D8FF75C449EE7B |
SHA1: | 0C3A915F80D20BFF0BB4023D86ACAF80AF30F98D |
SHA-256: | 75CE6EB6CDDD67D47FB7C5782F45FDC497232F87A883650BA98679F92708A986 |
SHA-512: | 6B9792C609E0A3F729AE2F188DE49E66067E3808E5B412E6DC56A555BC95656DA62ECD07D931B05756303A65383B029E7862C04CA5EA879A3FDFB61789BD2580 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 28160 |
Entropy (8bit): | 5.570953308352568 |
Encrypted: | false |
SSDEEP: | 384:BBOVNMHHPrq2YQGpX0dx+D4uuMig590gQDhJvoKfqeXOWnKNey/B/HM/g/6Y70FB:LOCPAEdx+vuNgD0gQ/gCYoTyn+ |
MD5: | A4F19ADB89F8D88DBDF103878CF31608 |
SHA1: | 46267F43F0188DFD3248C18F07A46448D909BF9B |
SHA-256: | D0613773A711634434DB30F2E35C6892FF54EBEADF49CD254377CAECB204EAA4 |
SHA-512: | 23AA30D1CD92C4C69BA23C9D04CEBF4863A9EA20699194F9688B1051CE5A0FAD808BC27EE067A8AA86562F35C352824A53F7FB0A93F4A99470A1C97B31AF8C12 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32256 |
Entropy (8bit): | 5.631194486392901 |
Encrypted: | false |
SSDEEP: | 384:lP/qZmINM9WPs9Q617EsO2m2g7udB2HEsrW+a4yiym4I16Gl:lP/imaPyQ4T5dsHSt9nQ |
MD5: | D8BF2A0481C0A17A634D066A711C12E9 |
SHA1: | 7CC01A58831ED109F85B64FE4920278CEDF3E38D |
SHA-256: | 2B93377EA087225820A9F8E4F331005A0C600D557242366F06E0C1EAE003D669 |
SHA-512: | 7FB4EB786528AD15DF044F16973ECA05F05F035491E9B1C350D6AA30926AAE438E98F37BE1BB80510310A91BC820BA3EDDAF7759D7D599BCDEBA0C9DF6302F60 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41472 |
Entropy (8bit): | 5.6808219961645605 |
Encrypted: | false |
SSDEEP: | 768:IUVSXpIia8xiZ7tRCoz79t6DrMhvUsJAnmboowvDG:IFXRa/Lzugszmboowb |
MD5: | 6CD78D07F9BD4FECC55CDB392BC5EC89 |
SHA1: | 094DE32070BED60A811D983740509054AD017CE4 |
SHA-256: | 16CC3B734E72A74F578B63D08D81CC75B6C2445FB631EFD19F8A70D786871AD4 |
SHA-512: | 5E25659A66E62F368ACD69790F0CF460008CAA3BB106E45CBA4755896B1872C02438C94E6FB5576891F29B3FEA95D8AAD9BCD7659C179D9619A1CDDB240AEB32 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 39936 |
Entropy (8bit): | 5.629584586954759 |
Encrypted: | false |
SSDEEP: | 768:tlPaJVGYXkJSMA2we8qlmau55wC1ND5kwcDl+y5X:chQZwalKdEfDld5 |
MD5: | D478E398EFCD2BD9BDBFEA958F7BEE4F |
SHA1: | 24CAA06949CDA52DB45F487EC2A8D3DE9C3FC1FC |
SHA-256: | 32E821193BE1D81BB3BE97F2719D28A0C7DD2E5BD94DC581D79A1497462EAC9B |
SHA-512: | 0705A42D2EE234D63DBE0A252A2048D85C817D8DF404EBFC12B583BF24AD84E111621727C7CB2369D1A22538354F725AADE067F0BDC4E2EBE2D61D937C130621 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 5.645950918301459 |
Encrypted: | false |
SSDEEP: | 384:fRDtCEPOaiRBCSzHADW8S3YVDOy6Vgh/UaFTKqrPd62GTB7ZyTG4sTaG:fR/IMEACDoJ86/UoTKqZwJ8TG4 |
MD5: | E84DCD8370FAC91DE71DEF8DCF09BFEC |
SHA1: | 2E73453750A36FD3611D5007BBB26A39DDF5F190 |
SHA-256: | DD7AC164E789CAD96D30930EFE9BBA99698473EDEA38252C2C0EA44043FB1DB5 |
SHA-512: | 77461BA74518E6AE9572EC916499058F45D0576535C20FAE74D0CB904DC79ED668B94885BFC38E24D5DEEAE7FBEF79B768216F1422B2178277DBD3209FC2AFD9 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 39936 |
Entropy (8bit): | 5.629584586954759 |
Encrypted: | false |
SSDEEP: | 768:tlPaJVGYXkJSMA2we8qlmau55wC1ND5kwcDl+y5X:chQZwalKdEfDld5 |
MD5: | D478E398EFCD2BD9BDBFEA958F7BEE4F |
SHA1: | 24CAA06949CDA52DB45F487EC2A8D3DE9C3FC1FC |
SHA-256: | 32E821193BE1D81BB3BE97F2719D28A0C7DD2E5BD94DC581D79A1497462EAC9B |
SHA-512: | 0705A42D2EE234D63DBE0A252A2048D85C817D8DF404EBFC12B583BF24AD84E111621727C7CB2369D1A22538354F725AADE067F0BDC4E2EBE2D61D937C130621 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32768 |
Entropy (8bit): | 5.645950918301459 |
Encrypted: | false |
SSDEEP: | 384:fRDtCEPOaiRBCSzHADW8S3YVDOy6Vgh/UaFTKqrPd62GTB7ZyTG4sTaG:fR/IMEACDoJ86/UoTKqZwJ8TG4 |
MD5: | E84DCD8370FAC91DE71DEF8DCF09BFEC |
SHA1: | 2E73453750A36FD3611D5007BBB26A39DDF5F190 |
SHA-256: | DD7AC164E789CAD96D30930EFE9BBA99698473EDEA38252C2C0EA44043FB1DB5 |
SHA-512: | 77461BA74518E6AE9572EC916499058F45D0576535C20FAE74D0CB904DC79ED668B94885BFC38E24D5DEEAE7FBEF79B768216F1422B2178277DBD3209FC2AFD9 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 70144 |
Entropy (8bit): | 5.909536568846014 |
Encrypted: | false |
SSDEEP: | 1536:3LM14SKtpfLarGzoQWaqaQ2n5YejqSRKnYdYPgh3c//npRwM:w7KtpTjNNn5YejqSRKnYdYPgJo/pRwM |
MD5: | E4FA63649F1DBD23DE91861BB39C317D |
SHA1: | 25F9115FAF40EC6736FACF2288CAA9B0E6AF9366 |
SHA-256: | CB4CD707305733ADDFCC54A69DF54A0C8D47C312D969B3E8D38B93E18CCBD8E4 |
SHA-512: | C4B5A9D66146D98D414BC84CD5C09588E2E02B800B21CE3172042AD7F48CC4AED54772D32C891A921FF102C0C3DB1FEAF52E4D4C714ABDB15F73BAEB9A6F5A39 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 36352 |
Entropy (8bit): | 5.668291349855899 |
Encrypted: | false |
SSDEEP: | 384:3+GMbUL+1FjuuGWkgoCFvMiAAsSZH14gXO9XBKeRg3U7ixu8bqMle9dCe4i2+o06:3+T93kgoCFkid/O9sU7io8b1ocl+o |
MD5: | 94DA5073CCC14DCF4766DF6781485937 |
SHA1: | 57300CA6033974810B71CF1AB4F047A026924A7A |
SHA-256: | B81B9FA9B7017BE34F62D30CB16BAAB33757F04CC94EF4D6459C9D3BC768FD18 |
SHA-512: | 7D539ECED2F19166F0F6FAE6E2624C0440DEC87AA9751FA82387EECEF9945997ABAE58C886494633BA360B122BCA955B3DDAE26E5256E371A0528F48DFA17871 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40448 |
Entropy (8bit): | 5.7028690200758465 |
Encrypted: | false |
SSDEEP: | 768:HjeDAXQDM/RgUK+1x85+CnTzP5KJcSdhRGPQPfnay:HjWB2CnTzUJcSdTdP/ |
MD5: | 51B1964F31C557AE8C2B01EA164ABD9F |
SHA1: | 97C6E8FD1F21D644281FAF82D017969FE22423E4 |
SHA-256: | AF584F142A9A5A79355B212F8D7A2E3793E33FF23D50FDE591FB2F3E49BF308C |
SHA-512: | 5D06650D77DD2D574A31664FE9CEAD5E13941F99B2CFA8ECAD972B9E999422816E43A2BE469D9BBDF2778654C22A52656D23B9F230D2F6DF3F2305ABAE779AC3 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33280 |
Entropy (8bit): | 5.634433516692816 |
Encrypted: | false |
SSDEEP: | 384:TVyNAbQWfDL/QwV/AnmqieB2Ht50uVVxg+94HoxMttjICAQgEYhfAcGQMrygg4Ty:TKWfYwV2u3xg+94HoSbTY4f2gfcab |
MD5: | 0D323E1CACEA89CAA5DDEAF2F37BCA69 |
SHA1: | 4769C3E947D02A1FD548BE64013F520D571D96E1 |
SHA-256: | 873E7688D95DCAA5468BF94063A94C548EF0D8BE9D4111F1917DA482DBC2A64C |
SHA-512: | 73F4EDE6D4C62997A4F11AD09A12DFD0BFD749026209E63E52F9D979F9423FDD640E96FA59D51556001C4BE22888E59C67781970649387AF090E26AC40C0C0DE |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 38912 |
Entropy (8bit): | 5.679286635687991 |
Encrypted: | false |
SSDEEP: | 768:RH9nQF3DwRvGTYLOFbL79ed5l8UNebCPncg:TyDF0PybCPn |
MD5: | 9E910782CA3E88B3F87826609A21A54E |
SHA1: | 8DBC333244620EDA5D3F1C9EAA6B924455262303 |
SHA-256: | 3B311986251EE5A303671108AFBAF43E0255C4CAE1C26CC9600BB0C7D22D3864 |
SHA-512: | 592981359F46BBC577BE99DEFE3E2A17998BA2882AAAA20107841BCA97C2121CB97C45BC6EDBFC3F430D31450457CD855751727922AB4BB1A3C12DA050EEC057 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 69632 |
Entropy (8bit): | 5.932541123129161 |
Encrypted: | false |
SSDEEP: | 1536:yo63BdpcSWxaQ/RKd8Skwea/e+hTEqS/ABGegJBb07j:j+9W+p/LEqu6GegG |
MD5: | F4B38D0F95B7E844DD288B441EBC9AAF |
SHA1: | 9CBF5C6E865AE50CEC25D95EF70F3C8C0F2A6CBF |
SHA-256: | AAB95596475CA74CEDE5BA50F642D92FA029F6F74F6FAEAE82A9A07285A5FB97 |
SHA-512: | 2300D8FC857986DC9560225DE36C221C6ECB4F98ADB954D896ED6AFF305C3A3C05F5A9F1D5EF0FC9094355D60327DDDFAFC81A455596DCD28020A9A89EF50E1A |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33280 |
Entropy (8bit): | 5.634433516692816 |
Encrypted: | false |
SSDEEP: | 384:TVyNAbQWfDL/QwV/AnmqieB2Ht50uVVxg+94HoxMttjICAQgEYhfAcGQMrygg4Ty:TKWfYwV2u3xg+94HoSbTY4f2gfcab |
MD5: | 0D323E1CACEA89CAA5DDEAF2F37BCA69 |
SHA1: | 4769C3E947D02A1FD548BE64013F520D571D96E1 |
SHA-256: | 873E7688D95DCAA5468BF94063A94C548EF0D8BE9D4111F1917DA482DBC2A64C |
SHA-512: | 73F4EDE6D4C62997A4F11AD09A12DFD0BFD749026209E63E52F9D979F9423FDD640E96FA59D51556001C4BE22888E59C67781970649387AF090E26AC40C0C0DE |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 40448 |
Entropy (8bit): | 5.7028690200758465 |
Encrypted: | false |
SSDEEP: | 768:HjeDAXQDM/RgUK+1x85+CnTzP5KJcSdhRGPQPfnay:HjWB2CnTzUJcSdTdP/ |
MD5: | 51B1964F31C557AE8C2B01EA164ABD9F |
SHA1: | 97C6E8FD1F21D644281FAF82D017969FE22423E4 |
SHA-256: | AF584F142A9A5A79355B212F8D7A2E3793E33FF23D50FDE591FB2F3E49BF308C |
SHA-512: | 5D06650D77DD2D574A31664FE9CEAD5E13941F99B2CFA8ECAD972B9E999422816E43A2BE469D9BBDF2778654C22A52656D23B9F230D2F6DF3F2305ABAE779AC3 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 126976 |
Entropy (8bit): | 6.057993947082715 |
Encrypted: | false |
SSDEEP: | 3072:V2IJq7YkHFJwBTZtHrC/0/FHkINvdF+nTCkjk1U+1:V2IJq7YbrFHkIrgnTQ |
MD5: | 16B480082780CC1D8C23FB05468F64E7 |
SHA1: | 6FDDF86F9F0FBAA189F5CB79E44999A3F1AC2B26 |
SHA-256: | 7A080D8BD178EC02C7F39F7F941479074C450C4FDD8E963C993D2FB5537C7708 |
SHA-512: | A165BB5D7972DE124F670BCAC20B4A46727B7CF27D1ED925D02F7CC7C79D7D04122D7C202C67D7EAE798348E8D481F085282EB5B89D84B902607D7EB1155BA19 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\GameBarPresenceWriter\services.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 39936 |
Entropy (8bit): | 5.660491370279985 |
Encrypted: | false |
SSDEEP: | 768:1Q8H1q0rErIq3y48wo5iJyNJZ+pkw82VhgwgKZ:brErIqxPJRkw/VOwbZ |
MD5: | 240E98D38E0B679F055470167D247022 |
SHA1: | 49888CCED719AE78EE3BAE2959402749668AA1C6 |
SHA-256: | C200E1BE39C35F8E57A0E1E241723FDB956089BC8EAD1235042456C7A3C4AD28 |
SHA-512: | 93C1B6396C65C9EDACEFD6606A9563935D3C1331454DA69FA75D9B1CCE4D102A5F1B27B63FC3A7E485A083D8DAB1E6C4ECD01DD3CFED9B58DA6F4E90CC4F2998 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34816 |
Entropy (8bit): | 5.636032516496583 |
Encrypted: | false |
SSDEEP: | 384:JS7LcTqpkHdmLrBmyOLkOPXVcqTZH0uZLSHtciyBDVGehpx3ZPyp1MoCy07G7:J+CaBoXTZH0mUfoGCzpapaFy07 |
MD5: | 996BD447A16F0A20F238A611484AFE86 |
SHA1: | CB0F51CE7FEEE1B5F02D3F13E60D67AF448C478D |
SHA-256: | 0CB182B9F8BD0804FC3BBA016926199C536BD7491BA577E089271DC1A63B07BE |
SHA-512: | 80924C19FAF3916DB5F71BE5723B6CB7BB7F731DBBA05B8218746F11FB9470F746B7AC581DB398E388377637811319EF8D6841504DC8EA39C510D7CFCD25184C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163910 |
Entropy (8bit): | 7.992391848855575 |
Encrypted: | true |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
MD5: | 0A5D9CD0A4B6ABDBB272262811774A8D |
SHA1: | 9571472C5D0899E517E1C1F84C6C05DFD2ABB2B5 |
SHA-256: | 9C2AD3D80258AF2508987D952DD5A7744BEDBDD16260E4F76412EA6696774285 |
SHA-512: | 439D108D086E6231513A7D40E01EA9C8D1B0D9948C9412F2828F694D94CCFA64E98D8A6956464CCCB632BB072AAE4E3C00154733BC3AF97A11CD7A57F0B0FB10 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 472 |
Entropy (8bit): | 5.85928305820468 |
Encrypted: | false |
SSDEEP: | 12:cZyrLxd9exp3iTKponyksBwQmqQeBEno0SUEGVgRsCN+22vmvQ:cZyrLxd9SyFGwdsEnkGYsSI |
MD5: | BC697A7BA014AD919BDDD7AF509B7DDB |
SHA1: | 7D485E9A0B90F41165EE172EDBB4060FB53BF365 |
SHA-256: | 2726F766572B0CD819EDDB64C8D8D8FACA3D326E671626C4A031463D8CB37BFD |
SHA-512: | FF377BCD8A6B90E5E9D13620ADD96110473F4C1C0558744B8161680E1BC5EBDC4BC9CC9BBEA55039F0C39856FF301B7968480FE04A26E9F22892C60B96E76401 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 280 |
Entropy (8bit): | 5.815524227334601 |
Encrypted: | false |
SSDEEP: | 6:zJC7kkwMt7oS2iPlvdDG9YEfuO6uKYmSPSl2xnaQXog3JC:zJC78MqS7VDGP76uJPdRUgI |
MD5: | 3CA8E6718E47252A98E4FF2FE4CB7985 |
SHA1: | 997850CF42CCDE8DFB45B082F4FA16E7761DF84F |
SHA-256: | 42398B9FA940037027AC56AEE852D4E6465B91D68C38DD9E13232B66AF806103 |
SHA-512: | 78EFCB76A8BA8BC5210F1059C3250B91AD27B1E2572281D6E71EE5F498E1766BDC4078495CD934335C23E0139093486A9E92A57EDD5C83FA6E580A9FE507FF7F |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163910 |
Entropy (8bit): | 7.992391848855575 |
Encrypted: | true |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
MD5: | 0A5D9CD0A4B6ABDBB272262811774A8D |
SHA1: | 9571472C5D0899E517E1C1F84C6C05DFD2ABB2B5 |
SHA-256: | 9C2AD3D80258AF2508987D952DD5A7744BEDBDD16260E4F76412EA6696774285 |
SHA-512: | 439D108D086E6231513A7D40E01EA9C8D1B0D9948C9412F2828F694D94CCFA64E98D8A6956464CCCB632BB072AAE4E3C00154733BC3AF97A11CD7A57F0B0FB10 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3163910 |
Entropy (8bit): | 7.992391848855575 |
Encrypted: | true |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
MD5: | 0A5D9CD0A4B6ABDBB272262811774A8D |
SHA1: | 9571472C5D0899E517E1C1F84C6C05DFD2ABB2B5 |
SHA-256: | 9C2AD3D80258AF2508987D952DD5A7744BEDBDD16260E4F76412EA6696774285 |
SHA-512: | 439D108D086E6231513A7D40E01EA9C8D1B0D9948C9412F2828F694D94CCFA64E98D8A6956464CCCB632BB072AAE4E3C00154733BC3AF97A11CD7A57F0B0FB10 |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 818 |
Entropy (8bit): | 5.924016653700528 |
Encrypted: | false |
SSDEEP: | 24:EUUoOPyb8v/TDn9szFLDoYzKsyhN6iD9oCjmugpKQ9tL:EUUoO6b49szBoYGFhnDxmfNj |
MD5: | EF2F3027760FB88DB2C9FB587BA69B41 |
SHA1: | E72B069DCF6AA7FD60397E4D7D18714EF47FED21 |
SHA-256: | 3C7AB06B4E292DA5A03933BA42988FB07B8CF3AED269C6C6D0C0BF43C925C21F |
SHA-512: | 26054CC58E36961D99DBA1C67005DAE5C8DD7636BB1D4CD47F99F42CD9FD7791C3DE80EC5437264D7E60225382F72AB21D0EDDB1A3BF18546E7079E386052BAF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\w32tm.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 151 |
Entropy (8bit): | 4.824038610531724 |
Encrypted: | false |
SSDEEP: | 3:VLV993J+miJWEoJ8FXlaKy6XaNvo41Nvj:Vx993DEUaLV47 |
MD5: | 0AB6577C3D92C4724BAB09B2D4A421AB |
SHA1: | B7AA3111CD54B430AC00FA77711302DE7361F5A8 |
SHA-256: | FA98CFC4659B678A5121398475A403A1F2742ABCF8038262D072733EEA44352F |
SHA-512: | D43040B6ECE1D4F9282A965EE8B7A6FF04DD8A48273B2F6541D0D7C1D445CCF07B9E60987446D7E18A297FA0B0AB7F6800A5CF45B60967500FD5009FEE182537 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.992391848855575 |
TrID: |
|
File name: | Z4D3XAZ2jB.exe |
File size: | 3'163'910 bytes |
MD5: | 0a5d9cd0a4b6abdbb272262811774a8d |
SHA1: | 9571472c5d0899e517e1c1f84c6c05dfd2abb2b5 |
SHA256: | 9c2ad3d80258af2508987d952dd5a7744bedbdd16260e4f76412ea6696774285 |
SHA512: | 439d108d086e6231513a7d40e01ea9c8d1b0d9948c9412f2828f694d94ccfa64e98d8a6956464cccb632bb072aae4e3c00154733bc3af97a11cd7a57f0b0fb10 |
SSDEEP: | 49152:ILfoFX5SJqMr60Ag4ErCKLYy3XxggNblydYuwVHlizQ/U4oiUT6JgcBKMzWpwneR:8AkqMrv4ErCKbfl/uwVHlNlzQUWWeWC |
TLSH: | 97E533C19638C452EEAE2A76E501804FA17CBBA04D4D4D3F73E153DFD9B74E685ACA02 |
File Content Preview: | MZ@.....................................!..L.!It's .NET EXE$@...PE..L....&.M............................^.... ...@....@.. ....................................@.....................................O....@..p....................`............................. |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x402e5e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x4D0126C5 [Thu Dec 9 18:58:13 2010 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x2e0c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x370 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xe64 | 0x1000 | 6b17f20c45d1294fc266eb14df869af7 | False | 0.552978515625 | data | 5.315832583359095 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4000 | 0x370 | 0x400 | 84c5330df637369dd4da3d84a91b8d66 | False | 0.3759765625 | data | 2.854832632722979 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6000 | 0xc | 0x200 | bdc0546adfb3b2dd2fed0ee2248951a7 | False | 1.005859375 | data | 6.526889622005003 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x4058 | 0x318 | data | 0.44823232323232326 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-26T17:17:12.161494+0100 | 2048095 | ET MALWARE [ANY.RUN] DarkCrystal Rat Check-in (POST) | 1 | 192.168.2.4 | 49730 | 104.21.93.162 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 26, 2024 17:17:10.654953003 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:10.774565935 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:10.774843931 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:10.795922995 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:10.916369915 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:11.175096989 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:11.294652939 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:11.952718019 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.161494017 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.211527109 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.211620092 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.211715937 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.255414963 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.326740026 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.375389099 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.446384907 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.449307919 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.449456930 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.569185972 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.588042021 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.590327024 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.710067987 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.802196980 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:12.921941042 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.921957016 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:12.921972990 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.083152056 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.106422901 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:13.225995064 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.439193964 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.441595078 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:13.561105967 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.561217070 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.626831055 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.802160025 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:13.878189087 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:13.934827089 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:14.099111080 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.180829048 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.647872925 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.648757935 CET | 49735 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.678751945 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.767754078 CET | 80 | 49730 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:14.767808914 CET | 49730 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.768316031 CET | 80 | 49735 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:14.768404961 CET | 49735 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.768544912 CET | 49735 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.798758984 CET | 80 | 49731 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:14.798851013 CET | 49731 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:14.888022900 CET | 80 | 49735 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:14.967722893 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.036266088 CET | 49735 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.087363005 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.087421894 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.087529898 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.193871975 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.199681044 CET | 80 | 49735 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.206943035 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.314383030 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.314455986 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.314666033 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.434160948 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.443037987 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.563760996 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.563800097 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.670962095 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.738765955 CET | 80 | 49735 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.738822937 CET | 49735 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:15.790544987 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.790563107 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:15.790611982 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.264548063 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.411495924 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:16.492837906 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.545506954 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.599003077 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:16.661506891 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:16.752651930 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.962876081 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:16.962925911 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.482254982 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.482315063 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.484941006 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.574867010 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.602263927 CET | 80 | 49736 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.602332115 CET | 49736 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.602722883 CET | 80 | 49738 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.602761030 CET | 49738 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.604527950 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.604589939 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.604784966 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.695684910 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.695765018 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.695915937 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:17.726121902 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.815511942 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:17.958554029 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:18.052509069 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:18.080580950 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.080641031 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.080682993 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.172214031 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.172401905 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.784296036 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.874296904 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:18.974240065 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.038444996 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.099021912 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.126353025 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.208378077 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.270883083 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.285165071 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.372037888 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.374177933 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.404721975 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.492584944 CET | 80 | 49741 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.492714882 CET | 49741 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.494355917 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.494478941 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.501445055 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.617876053 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.620965004 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.626833916 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.747658968 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.747677088 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.747709036 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.747725010 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.747776031 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.747850895 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.747889042 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748013973 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.748019934 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748045921 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748074055 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.748112917 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.748176098 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748187065 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748241901 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.748250961 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748265028 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.748481035 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.867444992 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.867489100 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.867589951 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.867664099 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.867795944 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.867876053 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.867994070 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868036032 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.868063927 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.868089914 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868235111 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868266106 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868299961 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.868321896 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.868412971 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868426085 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.868499041 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.962798119 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.987222910 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987323046 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987448931 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.987652063 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987723112 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987790108 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.987838984 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987919092 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.987967014 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:19.988060951 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988095045 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988106966 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988158941 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988238096 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988456011 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988467932 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988517046 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988528967 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988573074 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988600969 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988615990 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988629103 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988744974 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988759041 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988774061 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988858938 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988872051 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988903999 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.988977909 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989000082 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989012957 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989053965 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989068031 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989084959 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989159107 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989223003 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989234924 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989247084 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989325047 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989404917 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989418030 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:19.989429951 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.083712101 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.083740950 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.083765030 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107507944 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107522011 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107600927 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107614994 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107660055 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107701063 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107796907 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107820034 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107903004 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107916117 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107929945 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.107952118 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.108040094 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.108062983 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.674300909 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:20.869399071 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:20.930618048 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.005250931 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.058617115 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.059855938 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.096920967 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.104305029 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.179470062 CET | 80 | 49745 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.179522991 CET | 49745 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.180031061 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.180136919 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.180239916 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.223967075 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.302418947 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.436883926 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.439676046 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.537386894 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:21.559401035 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.559433937 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.656975031 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.657004118 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.657084942 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:21.966892958 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:22.161504030 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:22.360797882 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:22.411500931 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:22.625031948 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:22.708400965 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.191121101 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.194875956 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.220407009 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.285518885 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.311078072 CET | 80 | 49740 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.311163902 CET | 49740 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.314721107 CET | 80 | 49748 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.314795971 CET | 49748 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.340027094 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.340104103 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.340255022 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.405249119 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.405313969 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.405401945 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.459672928 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.524914980 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.693658113 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.764278889 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:23.813425064 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.813440084 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.883976936 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.883991003 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:23.884004116 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:24.518815041 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:24.593673944 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:24.661498070 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:24.708374977 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:24.775172949 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:24.857208967 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:24.911499023 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:24.973198891 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:24.973414898 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:24.975009918 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.093178034 CET | 80 | 49750 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.093235016 CET | 49750 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.093748093 CET | 80 | 49751 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.093815088 CET | 49751 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.094698906 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.094877958 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.095046043 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.214656115 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.443231106 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.562953949 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.562999010 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.563040972 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.811477900 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:25.932774067 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:25.932866096 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.078680992 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.198406935 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.273561954 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.427242994 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.474025011 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.530343056 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.547190905 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.547204018 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.665170908 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.665973902 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.785216093 CET | 80 | 49752 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.785274029 CET | 49752 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.785629988 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:26.785696983 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.785809040 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:26.905265093 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.111509085 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.132946968 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:27.208415985 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:27.253267050 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.253782034 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.253801107 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.362562895 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:27.411510944 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:27.963182926 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:28.005275965 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:28.651643991 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:28.652121067 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:28.652245998 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:28.689425945 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:28.809536934 CET | 80 | 49753 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:28.813533068 CET | 49753 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:28.896300077 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:28.994937897 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:29.016000032 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.116868019 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.116955996 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:29.120820999 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:29.228991032 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.230411053 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:29.240390062 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.350491047 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.350611925 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.474538088 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:29.594450951 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.594484091 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.594531059 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.758949995 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:29.802149057 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.294440031 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.349015951 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.546041965 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.599010944 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.674765110 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.675106049 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.675883055 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.772138119 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.794816017 CET | 80 | 49754 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.795089006 CET | 49754 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.795155048 CET | 80 | 49755 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.795200109 CET | 49755 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.795367002 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.795442104 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.795567989 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.891792059 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:30.891870975 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.891957045 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:30.915019989 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.011512995 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.174789906 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:31.295108080 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.295129061 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.295141935 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.515649080 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:31.637450933 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.637768984 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:31.972302914 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.020896912 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.069612026 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.114834070 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.238660097 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.286511898 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.322053909 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.360115051 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.360161066 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.360836983 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.480097055 CET | 80 | 49756 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.480154991 CET | 49756 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.480492115 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.480552912 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.480612993 CET | 80 | 49757 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.480707884 CET | 49757 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.480792046 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.606611967 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.833529949 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:32.953466892 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.953514099 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:32.953547955 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.334677935 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.335572958 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.454880953 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.454984903 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.455077887 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.455463886 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.455809116 CET | 80 | 49758 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.455874920 CET | 49758 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.574877024 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.575205088 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.575280905 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.575426102 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.694997072 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.802400112 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:33.922521114 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.922540903 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:33.927407026 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:34.047180891 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.047348976 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.047395945 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.632436037 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.677215099 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:34.753442049 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.802159071 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:34.892355919 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:34.942784071 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.010122061 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.067787886 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.190648079 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.190891027 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.192099094 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.310650110 CET | 80 | 49759 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.310718060 CET | 49759 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.311104059 CET | 80 | 49760 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.311165094 CET | 49760 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.311652899 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.311733007 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.331481934 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.451453924 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.677690029 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:35.797758102 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.797802925 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.797832966 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:35.897252083 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:36.016900063 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.017318010 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:36.019506931 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:36.139143944 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.364778042 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:36.484749079 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.484791040 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.489032984 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.536539078 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:36.741995096 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:36.788295984 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.194664955 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.253283024 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.347393036 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.348673105 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.450087070 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.467797995 CET | 80 | 49761 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.467842102 CET | 49761 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.468318939 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.468378067 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.468619108 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.505283117 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.588148117 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.818181992 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:37.938894033 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.938954115 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:37.938983917 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.459095955 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.459667921 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.579408884 CET | 80 | 49762 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.579476118 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.579489946 CET | 49762 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.579601049 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.579726934 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.645522118 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.692816019 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.699635983 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.902192116 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:38.927218914 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:38.942888021 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.017855883 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.018445969 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.048856974 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.048890114 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.141123056 CET | 80 | 49763 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.141156912 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.141330004 CET | 49763 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.141375065 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.141527891 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.261044979 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.536778927 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:39.656681061 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.656724930 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.656754017 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.758711100 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:39.802156925 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.014126062 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.067774057 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.319360971 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.364654064 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.569905043 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.614655972 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.688704014 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.688725948 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.689407110 CET | 49766 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.808773994 CET | 80 | 49764 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.808825970 CET | 49764 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.809014082 CET | 80 | 49766 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.809211969 CET | 49766 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.809251070 CET | 80 | 49765 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:40.809300900 CET | 49765 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.809346914 CET | 49766 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:40.928960085 CET | 80 | 49766 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.084666967 CET | 49766 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.085163116 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.205024004 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.205717087 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.205760956 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.205862999 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.247615099 CET | 80 | 49766 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.325544119 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.325581074 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.325679064 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.325777054 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.445302010 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.552483082 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.672209978 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.672687054 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.677310944 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.774705887 CET | 80 | 49766 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.774887085 CET | 49766 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:41.797060013 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.797090054 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:41.797251940 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:42.384809017 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:42.429936886 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.504190922 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:42.552184105 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.638060093 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:42.692794085 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.762238979 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:42.802174091 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.892879009 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.893110991 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:42.893651009 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.013099909 CET | 80 | 49767 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.013154984 CET | 49767 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.013370991 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.013439894 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.013448954 CET | 80 | 49768 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.013500929 CET | 49768 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.013623953 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.133277893 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.369827986 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.489478111 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.489518881 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.489533901 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.647279024 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.647543907 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.767066956 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.767335892 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.767446995 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.784142971 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.807467937 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.887197018 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.903831005 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.903899908 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.903995037 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:43.978610039 CET | 80 | 49769 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:43.978677034 CET | 49769 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:44.023643970 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.114810944 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:44.234833956 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.234860897 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.261104107 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:44.520920038 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:44.558172941 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.558214903 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.558228016 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.640547037 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.947308064 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:44.989701033 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.081871033 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.130315065 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.198000908 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.239691973 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.338087082 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.395932913 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.631899118 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.631973982 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.636641979 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.751836061 CET | 80 | 49770 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.751907110 CET | 49770 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.752201080 CET | 80 | 49771 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.752260923 CET | 49771 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.756253004 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:45.757332087 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.757461071 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:45.878133059 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.114794016 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:46.210196018 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:46.234416962 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.234441042 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.234456062 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.329925060 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.330039978 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:46.330280066 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:46.449938059 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.677308083 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:46.796926975 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.796999931 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.937822104 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:46.989674091 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.189898014 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.239783049 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.316591978 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.317454100 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.436510086 CET | 80 | 49772 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.437135935 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.437196970 CET | 49772 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.437233925 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.437378883 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.507642984 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.552184105 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.556801081 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.762006998 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.786729097 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.817806005 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:47.906375885 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.906460047 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:47.906475067 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:48.620069027 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:48.661551952 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.771569967 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.772212982 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.869940996 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:48.891499043 CET | 80 | 49773 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:48.891557932 CET | 49773 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.891758919 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:48.891916037 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.892041922 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.911561012 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.987032890 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:48.987796068 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.011487961 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.107215881 CET | 80 | 49774 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.107275009 CET | 49774 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.107434988 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.107510090 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.107618093 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.227118015 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.239886999 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.359632969 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.359652996 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.458512068 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:49.578294992 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.578305006 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:49.578309059 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.068927050 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.114798069 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.286545038 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.321949005 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.333425045 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.364675999 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.537935019 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.583451986 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.658158064 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.658160925 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.659102917 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.778275013 CET | 80 | 49775 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.778423071 CET | 49775 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.778734922 CET | 80 | 49776 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.778800011 CET | 49776 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.778971910 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:50.779057026 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.815862894 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:50.935462952 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.181303978 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:51.301047087 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.301058054 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.301068068 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.409895897 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:51.529479980 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.529541016 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:51.532876015 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:51.652416945 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:51.880644083 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:51.957221031 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.000324965 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.000334024 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.005321026 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.220014095 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.270945072 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.358006001 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.358669043 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.478004932 CET | 80 | 49777 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.478075981 CET | 49777 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.478147984 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.478622913 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.478810072 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.598557949 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.707736015 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.755315065 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.833553076 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:52.955986977 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.956023932 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.956070900 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:52.961911917 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:53.005311012 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:53.656728029 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:53.710942030 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:53.910047054 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:53.958439112 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.056623936 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.056976080 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.145752907 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.176520109 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.176683903 CET | 80 | 49778 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.176734924 CET | 49778 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.265279055 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.265346050 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.265453100 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.384949923 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.391046047 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.391237974 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.510942936 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.510952950 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.614887953 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:54.734488964 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.734509945 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.734538078 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.913439035 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:54.958442926 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.445168972 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:55.489713907 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.698139906 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:55.739695072 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.813164949 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.813214064 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.813846111 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:55.928699970 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.114733934 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.115302086 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.381490946 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381542921 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381576061 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381599903 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.381632090 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381639957 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.381668091 CET | 80 | 49779 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381719112 CET | 49779 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.381742001 CET | 80 | 49780 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.381789923 CET | 49780 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.502676964 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.502757072 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.622329950 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.622471094 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.849900961 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.850047112 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:56.969548941 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.969614029 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.969640970 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.969769001 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:56.969783068 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:57.558933020 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:57.559779882 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:57.614700079 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.614701033 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.809720993 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:57.814156055 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:57.864707947 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.864741087 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.940097094 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.940211058 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:57.940917015 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.059947968 CET | 80 | 49781 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.060013056 CET | 49781 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.060446024 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.060461998 CET | 80 | 49782 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.060519934 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.060540915 CET | 49782 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.060703039 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.180386066 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.411860943 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.531563997 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.531611919 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.531661987 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.818692923 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.819075108 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.938659906 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:58.938739061 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.939213037 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:58.979437113 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.009201050 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.058751106 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.113287926 CET | 80 | 49785 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.114820957 CET | 49785 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.128760099 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.131361008 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.140369892 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.260056973 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.311815023 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.431384087 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.431515932 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.614674091 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:17:59.734523058 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.734540939 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:17:59.734555960 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.162339926 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.208451033 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.309576035 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.351903915 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.422095060 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.474083900 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.561847925 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.614696026 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.823390961 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.823587894 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.826668978 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.943430901 CET | 80 | 49786 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.943481922 CET | 49786 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.945780993 CET | 80 | 49787 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.945848942 CET | 49787 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.946254015 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:00.946647882 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:00.950109959 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.069645882 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.304847956 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.424885988 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.424906015 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.424936056 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.428519964 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.428742886 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.548119068 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.551521063 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.555041075 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.566036940 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.595362902 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.674567938 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.685585976 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.687335014 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.687414885 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.806994915 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.897756100 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:01.912244081 CET | 80 | 49793 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:01.912306070 CET | 49793 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:02.018106937 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.018145084 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.059895039 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:02.180385113 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.180437088 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.180469990 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.728480101 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.857037067 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:02.868697882 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:02.911595106 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.023091078 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.144517899 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.145966053 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.192838907 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.272926092 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.272941113 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.273679972 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.392905951 CET | 80 | 49794 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.393064022 CET | 49794 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.393147945 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.393229961 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.393332958 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.393407106 CET | 80 | 49795 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.393459082 CET | 49795 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.512742996 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.739891052 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:03.859723091 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.859791040 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:03.859806061 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.037597895 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.037971973 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.157664061 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.157777071 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.157877922 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.157877922 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.199321032 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.277487040 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.277513981 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.277717113 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.277775049 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.373378038 CET | 80 | 49801 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.373440981 CET | 49801 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.397346020 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.505635023 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.625194073 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.625276089 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.641232967 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:04.760938883 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.760956049 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:04.760972977 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:05.597209930 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:05.646059990 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:05.828226089 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:05.853837967 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:05.880388021 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:05.895963907 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.082776070 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.130429983 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.204674959 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.205472946 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.205475092 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.324903965 CET | 80 | 49802 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.325064898 CET | 49802 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.325185061 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.325247049 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.325381041 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.325484037 CET | 80 | 49803 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.325535059 CET | 49803 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.445070028 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.677433014 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.798048019 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.798065901 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.798124075 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.865695000 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.865955114 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.985654116 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:06.985740900 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.985853910 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:06.986083984 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.027530909 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.196484089 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.196508884 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.196681976 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.196902990 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.316523075 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.333637953 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.453332901 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.453517914 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.508546114 CET | 80 | 49809 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.508658886 CET | 49809 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.552474022 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:07.672245026 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.672266006 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:07.672281027 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:08.265398026 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:08.317831039 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.567361116 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:08.583554029 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:08.614711046 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.630350113 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.850842953 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:08.895956039 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.969388008 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.969441891 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:08.970052958 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.089405060 CET | 80 | 49810 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.089464903 CET | 49810 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.089520931 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.089618921 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.089729071 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.089879990 CET | 80 | 49811 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.089924097 CET | 49811 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.209171057 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.443401098 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.563136101 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.563195944 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.563213110 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.584671021 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.704227924 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:09.707345963 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.707442999 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:09.826905012 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.052357912 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:10.171926022 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.172070980 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.349991083 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.395986080 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:10.605757952 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.663125038 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:10.892121077 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:10.895824909 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:10.921268940 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:10.974102020 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.012083054 CET | 80 | 49817 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.012130976 CET | 49817 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.015383005 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.015439034 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.015789032 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.135262966 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.173861027 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.224092960 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.364842892 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:11.484545946 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.484570980 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:11.484580040 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.178330898 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.179029942 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.230376005 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.271162987 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.298285961 CET | 80 | 49818 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.298358917 CET | 49818 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.298533916 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.298593998 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.298702002 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.418140888 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.481782913 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.536597967 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.594577074 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.595268011 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.647907019 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.715039015 CET | 80 | 49824 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.715127945 CET | 49824 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.715296984 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.715364933 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.715503931 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:12.767527103 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.767642975 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:12.836734056 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.071080923 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:13.190764904 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.190807104 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.190815926 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.477473021 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.520989895 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:13.733740091 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.786621094 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:13.894951105 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:13.942866087 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.145729065 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.192879915 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.267211914 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.267323971 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.267975092 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.387337923 CET | 80 | 49825 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.387475014 CET | 80 | 49831 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.387523890 CET | 49825 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.387540102 CET | 49831 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.387959957 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.388025045 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.388128042 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.507623911 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.739933968 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.741359949 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.741576910 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.859906912 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.859920979 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.859930038 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.860881090 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.860948086 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.861882925 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.865513086 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.903264046 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.982569933 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.985835075 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:14.986001015 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:14.986026049 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:15.105494976 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.209330082 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:15.328943968 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.328964949 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.333659887 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:15.353271961 CET | 80 | 49832 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.353439093 CET | 49832 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:15.453311920 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.453332901 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:15.453381062 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.047468901 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.099104881 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.162266970 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.208478928 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.305658102 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.349107027 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.413836002 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.458473921 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.582145929 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.582351923 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.582910061 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.702188969 CET | 80 | 49834 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.702238083 CET | 49834 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.702663898 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.702722073 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.703099966 CET | 80 | 49839 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:16.703145981 CET | 49839 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.711566925 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:16.831106901 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.067986012 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.187685966 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.187705040 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.187726021 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.334969997 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.335469007 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.454700947 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.454771042 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.454895020 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.458483934 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.499237061 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.574636936 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.578174114 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.578258991 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.578418970 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.669034958 CET | 80 | 49840 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.669095039 CET | 49840 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.697880983 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.802299023 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:17.922282934 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.922322989 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:17.927375078 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:18.047224998 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.047266006 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.047383070 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.634217978 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.677349091 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:18.756412029 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.802329063 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:18.905492067 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:18.958492994 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.009543896 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.052233934 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.184974909 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.185157061 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.185679913 CET | 49848 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.489727020 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.489728928 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.748042107 CET | 80 | 49848 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.748102903 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.748106003 CET | 49848 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.748161077 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.748524904 CET | 80 | 49846 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.748574972 CET | 49846 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.748641014 CET | 80 | 49847 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.748684883 CET | 49847 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.749393940 CET | 49848 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.868927002 CET | 80 | 49848 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:19.975251913 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:19.975320101 CET | 49848 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.094898939 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.094959021 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.095247984 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.115006924 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.139429092 CET | 80 | 49848 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.214678049 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.234642029 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.234705925 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.234801054 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.354274988 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.443094015 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.562836885 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.562880993 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.583687067 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:20.703389883 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.703403950 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.703418970 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.718513012 CET | 80 | 49848 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:20.721366882 CET | 49848 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:21.275500059 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:21.317872047 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:21.412446976 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:21.458498955 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:21.529951096 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:21.583491087 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:21.665853977 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:21.708529949 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.020227909 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.020296097 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.050484896 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.140188932 CET | 80 | 49854 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.140259981 CET | 49854 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.140778065 CET | 80 | 49855 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.140826941 CET | 49855 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.170058012 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.170124054 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.182106972 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.301642895 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.536703110 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.538559914 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.656636000 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.656667948 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.656713009 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.658067942 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:22.658128977 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.658243895 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:22.777791023 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.005599976 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.125377893 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.125396967 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.347927094 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.396003008 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.633919001 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.677304029 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.752964973 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.753858089 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.836373091 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.872879028 CET | 80 | 49857 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.873051882 CET | 49857 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.873349905 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:23.873434067 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.873538971 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.880378962 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:23.992995024 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:24.089777946 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:24.145997047 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:24.282423973 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:24.402543068 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:24.402553082 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:24.402560949 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.050838947 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.099143028 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.259921074 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.266379118 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.308357000 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.349209070 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.380040884 CET | 80 | 49862 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.380093098 CET | 49862 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.386042118 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.386105061 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.386233091 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.423261881 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.423805952 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.505762100 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.543190002 CET | 80 | 49863 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.543342113 CET | 49863 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.543641090 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.543699980 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.543854952 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.664308071 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.740341902 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:25.859942913 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.859977961 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:25.896209002 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:26.015857935 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.016124010 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.016285896 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.564126015 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.614742994 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:26.721941948 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.771006107 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:26.821748972 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:26.864752054 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:26.973664045 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.021044970 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.654218912 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.654434919 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.655255079 CET | 49876 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.774169922 CET | 80 | 49869 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.774240017 CET | 49869 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.774666071 CET | 80 | 49876 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.774724007 CET | 49876 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.774842024 CET | 49876 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.774863958 CET | 80 | 49870 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.774924040 CET | 49870 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.834882021 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.834984064 CET | 49876 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.894306898 CET | 80 | 49876 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.954200029 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.954504013 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:27.954576015 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.954663992 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:27.995136023 CET | 80 | 49876 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.073790073 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.073873997 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:28.073951006 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:28.074199915 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.193445921 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.302345037 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:28.422066927 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.422076941 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.427303076 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:28.546977997 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.547035933 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.547174931 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.739649057 CET | 80 | 49876 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:28.739711046 CET | 49876 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.132710934 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.177267075 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.261287928 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.302300930 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.407362938 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.458508968 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.514007092 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.568002939 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.641275883 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.641326904 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.642694950 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.761362076 CET | 80 | 49877 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.761825085 CET | 80 | 49878 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.761933088 CET | 49877 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.762322903 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:29.762355089 CET | 49878 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.762428045 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.770255089 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:29.889748096 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.115520954 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:30.235244036 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.235255003 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.235296965 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.413589954 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:30.533139944 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.533245087 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:30.533382893 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:30.652940035 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:30.880510092 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:30.952878952 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.000514030 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.000525951 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.005403042 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.205693960 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.255589962 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.329921007 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.330703974 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.450196028 CET | 80 | 49884 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.450284958 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.450360060 CET | 49884 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.450387955 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.452398062 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.571976900 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.710469961 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.755389929 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.803553104 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:31.923481941 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.923508883 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.923537970 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:31.961982012 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:32.005393028 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:32.628463030 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:32.677400112 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:32.881541014 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:32.927273035 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.131354094 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.131807089 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.153187037 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.251434088 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.252212048 CET | 80 | 49885 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.252465010 CET | 49885 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.273067951 CET | 80 | 49889 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.273113966 CET | 49889 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.319582939 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.439188957 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.439254045 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.445492983 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.565222979 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.802706003 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:33.922723055 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.922734976 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:33.922743082 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.319284916 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:34.438946009 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.439038038 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:34.442589045 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:34.562156916 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.624866009 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.677265882 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:34.786797047 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:34.870090008 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.907489061 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.907499075 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:34.927345991 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.020493031 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.024590015 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.140430927 CET | 80 | 49892 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.140486002 CET | 49892 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.144377947 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.144450903 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.144561052 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.264204025 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.489938974 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.609697104 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.609708071 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.609716892 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.623749971 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.677397966 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:35.869573116 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:35.911653042 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.322590113 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.380486965 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.573695898 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.614799023 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.710114002 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.710164070 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.710916042 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.830492973 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.830653906 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.830749035 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.830761909 CET | 80 | 49898 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.830831051 CET | 49898 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.830949068 CET | 80 | 49899 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.831001043 CET | 49899 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.850162983 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.950710058 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.970168114 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:36.970242977 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:36.970320940 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:37.089906931 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:37.177422047 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:37.299699068 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:37.299768925 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:37.299798965 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:37.318070889 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:37.437980890 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:37.438014030 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.008965969 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.052297115 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.149158955 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.192929983 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.262115955 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.302290916 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.579509974 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.579664946 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.579716921 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.728148937 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.728271961 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:38.848088026 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.848417997 CET | 80 | 49905 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:38.848491907 CET | 49905 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.061249018 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.061434984 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.181955099 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.181987047 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.182022095 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.579225063 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.599834919 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.600544930 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.703912020 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.719854116 CET | 80 | 49906 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.719938993 CET | 49906 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.720094919 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.720164061 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.720262051 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.823728085 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.823828936 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.825892925 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:39.839814901 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:39.945653915 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.068140984 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:40.177405119 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:40.188564062 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.188673973 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.297118902 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.297137976 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.297159910 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.897283077 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:40.942914009 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.001554012 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.067914963 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.149702072 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.192914009 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.253739119 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.302299023 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.497581959 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.497639894 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.498364925 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.617966890 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.618032932 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.618165016 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.626816034 CET | 80 | 49912 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.626847982 CET | 80 | 49913 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.626862049 CET | 49912 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.626895905 CET | 49913 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:41.737720966 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:41.974330902 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:42.069330931 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:42.095406055 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.095423937 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.095437050 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.192243099 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.195386887 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:42.195533037 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:42.315010071 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.552436113 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:42.672344923 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.672374010 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.795603991 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:42.849160910 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.285592079 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.333524942 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.374866962 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.427287102 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.435101986 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.436470985 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.488003969 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.590105057 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.607925892 CET | 80 | 49919 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.609452963 CET | 49919 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.625386000 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.677283049 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.709908009 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:43.713586092 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.717396975 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:43.836921930 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.068008900 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.187815905 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.187851906 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.187935114 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.506572962 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.507762909 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.817915916 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.845474005 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.845752001 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.845799923 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.845803976 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.845887899 CET | 49920 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.891454935 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.937874079 CET | 80 | 49920 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:44.943011999 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:44.965400934 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.149710894 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.192915916 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.193017960 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.265377045 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.266058922 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.312680960 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.312827110 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.386312962 CET | 80 | 49922 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.386385918 CET | 49922 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.386893034 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.387000084 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.387126923 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.507354975 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.740107059 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:45.859810114 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.859819889 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:45.859828949 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:46.024354935 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:46.068505049 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:46.286910057 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:46.333548069 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:46.565474987 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:46.614797115 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:46.835933924 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:46.880420923 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.046119928 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.099183083 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.148227930 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.148435116 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.149400949 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.178862095 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.268395901 CET | 80 | 49927 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.268486023 CET | 49927 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.268940926 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.269030094 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.269145012 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.269334078 CET | 80 | 49928 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.269382954 CET | 49928 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.298904896 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.298979044 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.299079895 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.388715982 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.418690920 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.614980936 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.646269083 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:47.734550953 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.734586000 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.766190052 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.766233921 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:47.766347885 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:48.452908993 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:48.505450010 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.516638994 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:48.567925930 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.705521107 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:48.755425930 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.773500919 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:48.818085909 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.892213106 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.892333984 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:48.893282890 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.012213945 CET | 80 | 49934 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.012273073 CET | 49934 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.012654066 CET | 80 | 49935 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.012708902 CET | 49935 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.014230013 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.014300108 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.014398098 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.133985996 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.364878893 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.484534979 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.484580040 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.484613895 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.538149118 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.657798052 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:49.657980919 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.658101082 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:49.777640104 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.005574942 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.126002073 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.126012087 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.192792892 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.239825010 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.446396112 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.489828110 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.565181017 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.565937996 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.685045958 CET | 80 | 49940 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.685401917 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.685581923 CET | 49940 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.685585022 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.685636997 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:50.805315018 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.839406967 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:50.896044970 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:51.036808968 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:51.093485117 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:51.146146059 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:51.156443119 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:51.156476021 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:51.156487942 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:51.863084078 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:51.896785975 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:51.897422075 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:51.911772013 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.016911983 CET | 80 | 49941 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.017081022 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.017147064 CET | 49941 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.017308950 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.038904905 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.117490053 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.158626080 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.161782026 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.404848099 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.457179070 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.458381891 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.526022911 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.526073933 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.577203989 CET | 80 | 49944 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.577275991 CET | 49944 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.577914000 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.577989101 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.578778982 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:52.698477030 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:52.927421093 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:53.047149897 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.047223091 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.047257900 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.195504904 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.239829063 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:53.473581076 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.521153927 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:53.755889893 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:53.802311897 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.013592005 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.067928076 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.141237020 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.141329050 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.142041922 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.256427050 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.261512041 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.261575937 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.261609077 CET | 80 | 49948 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.261662006 CET | 49948 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.261763096 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.262294054 CET | 80 | 49949 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.262357950 CET | 49949 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.376142025 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.376216888 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.376370907 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.381239891 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.496159077 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.615606070 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.724273920 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:54.735511065 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.735522985 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.735531092 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.843857050 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:54.843945980 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.439224958 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.489799023 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:55.569037914 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.614797115 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:55.711705923 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.758420944 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:55.821434021 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.830194950 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:55.830271006 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:55.950078011 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.950385094 CET | 80 | 49954 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:55.950488091 CET | 49954 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.163384914 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.165584087 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.285238028 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.285270929 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.285314083 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.569264889 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.649712086 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.689757109 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.689843893 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.690002918 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.692929029 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.766957998 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.766999006 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.809533119 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.886814117 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.886969090 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.887049913 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:56.887198925 CET | 80 | 49955 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:56.887264967 CET | 49955 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:57.009643078 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.036798000 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:57.156459093 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.156547070 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.240035057 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:57.359765053 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.359775066 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.359782934 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.867057085 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:57.974216938 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.067847013 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.115392923 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.146224976 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.325517893 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.380440950 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.380443096 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.440989971 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.440990925 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.443388939 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.561167002 CET | 80 | 49960 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.561650991 CET | 80 | 49961 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.561744928 CET | 49960 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.561749935 CET | 49961 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.562952042 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.563047886 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.563220024 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.682703018 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.867372990 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.911910057 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.986928940 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:58.986994028 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:58.987138987 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:59.031615019 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.031627893 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.031636953 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.106921911 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.333756924 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:18:59.453500986 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.453542948 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.740767002 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:18:59.841703892 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.235456944 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.235542059 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.235574961 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.238207102 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.286705971 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.363387108 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.363389969 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.417484045 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.459163904 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.482952118 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.483072042 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.483310938 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.483359098 CET | 80 | 49966 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.483573914 CET | 49966 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.604106903 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.833734035 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:00.953378916 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.953434944 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:00.953483105 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.115629911 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.116643906 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.235430002 CET | 80 | 49968 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.235477924 CET | 49968 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.236176968 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.236257076 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.236841917 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.356352091 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.588527918 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.661772966 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.708678007 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:01.709075928 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.709132910 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.913671017 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:01.965584040 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.375240088 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.375958920 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.417151928 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.458570004 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.495166063 CET | 80 | 49971 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.495223999 CET | 49971 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.495502949 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.495560884 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.495732069 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.615302086 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.697639942 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.739819050 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.849327087 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:02.969027996 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.969039917 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:02.969049931 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.365837097 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.366646051 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.486402035 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.486505985 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.486768007 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.486841917 CET | 80 | 49974 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.486895084 CET | 49974 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.606385946 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.672945023 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.833610058 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.833729029 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:03.925323009 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.953315973 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:03.953444004 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.061783075 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.078461885 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.184561968 CET | 80 | 49976 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.184753895 CET | 49976 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.199285030 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.199397087 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.199542999 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.319013119 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.552719116 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.664607048 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.672435045 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.672444105 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.672475100 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:04.833576918 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:04.917418003 CET | 80 | 49981 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:05.146074057 CET | 49981 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:05.377367973 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:05.432230949 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Dec 26, 2024 17:19:05.673398972 CET | 80 | 49983 | 104.21.93.162 | 192.168.2.4 |
Dec 26, 2024 17:19:05.826234102 CET | 49983 | 80 | 192.168.2.4 | 104.21.93.162 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 26, 2024 17:17:10.278554916 CET | 51862 | 53 | 192.168.2.4 | 1.1.1.1 |
Dec 26, 2024 17:17:10.650877953 CET | 53 | 51862 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 26, 2024 17:17:10.278554916 CET | 192.168.2.4 | 1.1.1.1 | 0x52aa | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 26, 2024 17:17:10.650877953 CET | 1.1.1.1 | 192.168.2.4 | 0x52aa | No error (0) | 104.21.93.162 | A (IP address) | IN (0x0001) | false | ||
Dec 26, 2024 17:17:10.650877953 CET | 1.1.1.1 | 192.168.2.4 | 0x52aa | No error (0) | 172.67.212.19 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:10.795922995 CET | 330 | OUT | |
Dec 26, 2024 17:17:11.175096989 CET | 344 | OUT | |
Dec 26, 2024 17:17:11.952718019 CET | 25 | IN | |
Dec 26, 2024 17:17:12.211527109 CET | 1236 | IN | |
Dec 26, 2024 17:17:12.211620092 CET | 880 | IN | |
Dec 26, 2024 17:17:12.255414963 CET | 306 | OUT | |
Dec 26, 2024 17:17:12.588042021 CET | 25 | IN | |
Dec 26, 2024 17:17:12.590327024 CET | 384 | OUT | |
Dec 26, 2024 17:17:13.083152056 CET | 947 | IN | |
Dec 26, 2024 17:17:13.106422901 CET | 307 | OUT | |
Dec 26, 2024 17:17:13.439193964 CET | 25 | IN | |
Dec 26, 2024 17:17:13.441595078 CET | 1916 | OUT | |
Dec 26, 2024 17:17:13.934827089 CET | 951 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49731 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:12.449456930 CET | 307 | OUT | |
Dec 26, 2024 17:17:12.802196980 CET | 2548 | OUT | |
Dec 26, 2024 17:17:13.626831055 CET | 25 | IN | |
Dec 26, 2024 17:17:13.878189087 CET | 798 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49735 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:14.768544912 CET | 307 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49736 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:15.087529898 CET | 331 | OUT | |
Dec 26, 2024 17:17:15.443037987 CET | 2124 | OUT | |
Dec 26, 2024 17:17:16.264548063 CET | 25 | IN | |
Dec 26, 2024 17:17:16.545506954 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49738 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:15.314666033 CET | 331 | OUT | |
Dec 26, 2024 17:17:15.670962095 CET | 2548 | OUT | |
Dec 26, 2024 17:17:16.492837906 CET | 25 | IN | |
Dec 26, 2024 17:17:16.752651930 CET | 789 | IN | |
Dec 26, 2024 17:17:16.962876081 CET | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49740 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:17.604784966 CET | 307 | OUT | |
Dec 26, 2024 17:17:17.958554029 CET | 2548 | OUT | |
Dec 26, 2024 17:17:18.784296036 CET | 25 | IN | |
Dec 26, 2024 17:17:19.038444996 CET | 796 | IN | |
Dec 26, 2024 17:17:19.285165071 CET | 353 | OUT | |
Dec 26, 2024 17:17:19.617876053 CET | 25 | IN | |
Dec 26, 2024 17:17:19.626833916 CET | 14832 | OUT | |
Dec 26, 2024 17:17:19.747776031 CET | 9888 | OUT | |
Dec 26, 2024 17:17:19.748013973 CET | 4944 | OUT | |
Dec 26, 2024 17:17:19.748074055 CET | 2472 | OUT | |
Dec 26, 2024 17:17:19.748112917 CET | 2472 | OUT | |
Dec 26, 2024 17:17:19.748241901 CET | 4944 | OUT | |
Dec 26, 2024 17:17:19.748481035 CET | 4944 | OUT | |
Dec 26, 2024 17:17:19.867589951 CET | 4944 | OUT | |
Dec 26, 2024 17:17:19.868036032 CET | 22248 | OUT | |
Dec 26, 2024 17:17:21.096920967 CET | 808 | IN | |
Dec 26, 2024 17:17:21.104305029 CET | 307 | OUT | |
Dec 26, 2024 17:17:21.436883926 CET | 25 | IN | |
Dec 26, 2024 17:17:21.966892958 CET | 952 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49741 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:17.695915937 CET | 307 | OUT | |
Dec 26, 2024 17:17:18.052509069 CET | 2128 | OUT | |
Dec 26, 2024 17:17:18.874296904 CET | 25 | IN | |
Dec 26, 2024 17:17:19.126353025 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49745 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:19.501445055 CET | 307 | OUT | |
Dec 26, 2024 17:17:19.962798119 CET | 2548 | OUT | |
Dec 26, 2024 17:17:20.674300909 CET | 25 | IN | |
Dec 26, 2024 17:17:20.930618048 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49748 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:21.180239916 CET | 307 | OUT | |
Dec 26, 2024 17:17:21.537386894 CET | 2548 | OUT | |
Dec 26, 2024 17:17:22.360797882 CET | 25 | IN | |
Dec 26, 2024 17:17:22.625031948 CET | 791 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49750 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:23.340255022 CET | 307 | OUT | |
Dec 26, 2024 17:17:23.693658113 CET | 2116 | OUT | |
Dec 26, 2024 17:17:24.518815041 CET | 25 | IN | |
Dec 26, 2024 17:17:24.775172949 CET | 951 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49751 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:23.405401945 CET | 307 | OUT | |
Dec 26, 2024 17:17:23.764278889 CET | 2548 | OUT | |
Dec 26, 2024 17:17:24.593673944 CET | 25 | IN | |
Dec 26, 2024 17:17:24.857208967 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49752 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:25.095046043 CET | 307 | OUT | |
Dec 26, 2024 17:17:25.443231106 CET | 2548 | OUT | |
Dec 26, 2024 17:17:26.273561954 CET | 25 | IN | |
Dec 26, 2024 17:17:26.530343056 CET | 790 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49753 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:26.078680992 CET | 307 | OUT | |
Dec 26, 2024 17:17:26.427242994 CET | 2128 | OUT | |
Dec 26, 2024 17:17:27.111509085 CET | 25 | IN | |
Dec 26, 2024 17:17:27.362562895 CET | 944 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49754 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:26.785809040 CET | 307 | OUT | |
Dec 26, 2024 17:17:27.132946968 CET | 2548 | OUT | |
Dec 26, 2024 17:17:27.963182926 CET | 25 | IN | |
Dec 26, 2024 17:17:28.651643991 CET | 800 | IN | |
Dec 26, 2024 17:17:28.652121067 CET | 800 | IN | |
Dec 26, 2024 17:17:28.896300077 CET | 307 | OUT | |
Dec 26, 2024 17:17:29.228991032 CET | 25 | IN | |
Dec 26, 2024 17:17:29.230411053 CET | 2092 | OUT | |
Dec 26, 2024 17:17:29.758949995 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49755 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:29.120820999 CET | 307 | OUT | |
Dec 26, 2024 17:17:29.474538088 CET | 2548 | OUT | |
Dec 26, 2024 17:17:30.294440031 CET | 25 | IN | |
Dec 26, 2024 17:17:30.546041965 CET | 802 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49756 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:30.795567989 CET | 307 | OUT | |
Dec 26, 2024 17:17:31.174789906 CET | 2548 | OUT | |
Dec 26, 2024 17:17:31.972302914 CET | 25 | IN | |
Dec 26, 2024 17:17:32.238660097 CET | 805 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49757 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:30.891957045 CET | 307 | OUT | |
Dec 26, 2024 17:17:31.515649080 CET | 2108 | OUT | |
Dec 26, 2024 17:17:32.069612026 CET | 25 | IN | |
Dec 26, 2024 17:17:32.322053909 CET | 950 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49758 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:32.480792046 CET | 307 | OUT | |
Dec 26, 2024 17:17:32.833529949 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49759 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:33.455077887 CET | 331 | OUT | |
Dec 26, 2024 17:17:33.802400112 CET | 2128 | OUT | |
Dec 26, 2024 17:17:34.632436037 CET | 25 | IN | |
Dec 26, 2024 17:17:34.892355919 CET | 951 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49760 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:33.575426102 CET | 331 | OUT | |
Dec 26, 2024 17:17:33.927407026 CET | 2548 | OUT | |
Dec 26, 2024 17:17:34.753442049 CET | 25 | IN | |
Dec 26, 2024 17:17:35.010122061 CET | 797 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49761 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:35.331481934 CET | 307 | OUT | |
Dec 26, 2024 17:17:35.677690029 CET | 2548 | OUT | |
Dec 26, 2024 17:17:36.489032984 CET | 25 | IN | |
Dec 26, 2024 17:17:36.741995096 CET | 803 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49762 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:36.019506931 CET | 307 | OUT | |
Dec 26, 2024 17:17:36.364778042 CET | 2108 | OUT | |
Dec 26, 2024 17:17:37.194664955 CET | 25 | IN | |
Dec 26, 2024 17:17:37.450087070 CET | 943 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49763 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:37.468619108 CET | 307 | OUT | |
Dec 26, 2024 17:17:37.818181992 CET | 2548 | OUT | |
Dec 26, 2024 17:17:38.645522118 CET | 25 | IN | |
Dec 26, 2024 17:17:38.902192116 CET | 802 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49764 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:38.579726934 CET | 307 | OUT | |
Dec 26, 2024 17:17:38.927218914 CET | 2128 | OUT | |
Dec 26, 2024 17:17:39.758711100 CET | 25 | IN | |
Dec 26, 2024 17:17:40.014126062 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49765 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:39.141527891 CET | 307 | OUT | |
Dec 26, 2024 17:17:39.536778927 CET | 2548 | OUT | |
Dec 26, 2024 17:17:40.319360971 CET | 25 | IN | |
Dec 26, 2024 17:17:40.569905043 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49766 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:40.809346914 CET | 307 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49767 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:41.205862999 CET | 331 | OUT | |
Dec 26, 2024 17:17:41.552483082 CET | 2128 | OUT | |
Dec 26, 2024 17:17:42.384809017 CET | 25 | IN | |
Dec 26, 2024 17:17:42.638060093 CET | 953 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49768 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:41.325777054 CET | 331 | OUT | |
Dec 26, 2024 17:17:41.677310944 CET | 2548 | OUT | |
Dec 26, 2024 17:17:42.504190922 CET | 25 | IN | |
Dec 26, 2024 17:17:42.762238979 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49769 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:43.013623953 CET | 307 | OUT | |
Dec 26, 2024 17:17:43.369827986 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49770 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:43.767446995 CET | 331 | OUT | |
Dec 26, 2024 17:17:44.114810944 CET | 2108 | OUT | |
Dec 26, 2024 17:17:44.947308064 CET | 25 | IN | |
Dec 26, 2024 17:17:45.198000908 CET | 943 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49771 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:43.903995037 CET | 331 | OUT | |
Dec 26, 2024 17:17:44.261104107 CET | 2548 | OUT | |
Dec 26, 2024 17:17:44.520920038 CET | 1236 | OUT | |
Dec 26, 2024 17:17:45.081871033 CET | 25 | IN | |
Dec 26, 2024 17:17:45.338087082 CET | 793 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49772 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:45.757461071 CET | 307 | OUT | |
Dec 26, 2024 17:17:46.114794016 CET | 2548 | OUT | |
Dec 26, 2024 17:17:46.937822104 CET | 25 | IN | |
Dec 26, 2024 17:17:47.189898014 CET | 805 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49773 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:46.330280066 CET | 307 | OUT | |
Dec 26, 2024 17:17:46.677308083 CET | 2128 | OUT | |
Dec 26, 2024 17:17:47.507642984 CET | 25 | IN | |
Dec 26, 2024 17:17:47.762006998 CET | 951 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49774 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:47.437378883 CET | 307 | OUT | |
Dec 26, 2024 17:17:47.786729097 CET | 2548 | OUT | |
Dec 26, 2024 17:17:48.620069027 CET | 25 | IN | |
Dec 26, 2024 17:17:48.869940996 CET | 805 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49775 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:48.892041922 CET | 307 | OUT | |
Dec 26, 2024 17:17:49.239886999 CET | 2116 | OUT | |
Dec 26, 2024 17:17:50.068927050 CET | 25 | IN | |
Dec 26, 2024 17:17:50.321949005 CET | 945 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49776 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:49.107618093 CET | 307 | OUT | |
Dec 26, 2024 17:17:49.458512068 CET | 2544 | OUT | |
Dec 26, 2024 17:17:50.286545038 CET | 25 | IN | |
Dec 26, 2024 17:17:50.537935019 CET | 804 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49777 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:50.815862894 CET | 307 | OUT | |
Dec 26, 2024 17:17:51.181303978 CET | 2548 | OUT | |
Dec 26, 2024 17:17:51.957221031 CET | 25 | IN | |
Dec 26, 2024 17:17:52.220014095 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49778 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:51.532876015 CET | 307 | OUT | |
Dec 26, 2024 17:17:51.880644083 CET | 2108 | OUT | |
Dec 26, 2024 17:17:52.707736015 CET | 25 | IN | |
Dec 26, 2024 17:17:52.961911917 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49779 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:52.478810072 CET | 307 | OUT | |
Dec 26, 2024 17:17:52.833553076 CET | 2548 | OUT | |
Dec 26, 2024 17:17:53.656728029 CET | 25 | IN | |
Dec 26, 2024 17:17:53.910047054 CET | 793 | IN | |
Dec 26, 2024 17:17:54.056976080 CET | 307 | OUT | |
Dec 26, 2024 17:17:54.391046047 CET | 25 | IN | |
Dec 26, 2024 17:17:54.391237974 CET | 2108 | OUT | |
Dec 26, 2024 17:17:54.913439035 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49780 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:54.265453100 CET | 307 | OUT | |
Dec 26, 2024 17:17:54.614887953 CET | 2548 | OUT | |
Dec 26, 2024 17:17:55.445168972 CET | 25 | IN | |
Dec 26, 2024 17:17:55.698139906 CET | 800 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49781 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:56.502676964 CET | 307 | OUT | |
Dec 26, 2024 17:17:56.850047112 CET | 2548 | OUT | |
Dec 26, 2024 17:17:57.559779882 CET | 25 | IN | |
Dec 26, 2024 17:17:57.814156055 CET | 802 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49782 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:56.502757072 CET | 307 | OUT | |
Dec 26, 2024 17:17:56.849900961 CET | 2108 | OUT | |
Dec 26, 2024 17:17:57.558933020 CET | 25 | IN | |
Dec 26, 2024 17:17:57.809720993 CET | 951 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49785 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:58.060703039 CET | 307 | OUT | |
Dec 26, 2024 17:17:58.411860943 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49786 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:58.939213037 CET | 331 | OUT | |
Dec 26, 2024 17:17:59.311815023 CET | 2128 | OUT | |
Dec 26, 2024 17:18:00.162339926 CET | 25 | IN | |
Dec 26, 2024 17:18:00.422095060 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49787 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:17:59.140369892 CET | 331 | OUT | |
Dec 26, 2024 17:17:59.614674091 CET | 2548 | OUT | |
Dec 26, 2024 17:18:00.309576035 CET | 25 | IN | |
Dec 26, 2024 17:18:00.561847925 CET | 798 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49793 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:00.950109959 CET | 307 | OUT | |
Dec 26, 2024 17:18:01.304847956 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49794 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:01.555041075 CET | 331 | OUT | |
Dec 26, 2024 17:18:01.897756100 CET | 2108 | OUT | |
Dec 26, 2024 17:18:02.728480101 CET | 25 | IN | |
Dec 26, 2024 17:18:03.023091078 CET | 953 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 49795 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:01.687414885 CET | 331 | OUT | |
Dec 26, 2024 17:18:02.059895039 CET | 2548 | OUT | |
Dec 26, 2024 17:18:02.868697882 CET | 25 | IN | |
Dec 26, 2024 17:18:03.144517899 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 49801 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:03.393332958 CET | 307 | OUT | |
Dec 26, 2024 17:18:03.739891052 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 49802 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:04.157877922 CET | 331 | OUT | |
Dec 26, 2024 17:18:04.505635023 CET | 2128 | OUT | |
Dec 26, 2024 17:18:05.597209930 CET | 25 | IN | |
Dec 26, 2024 17:18:05.853837967 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 49803 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:04.277775049 CET | 331 | OUT | |
Dec 26, 2024 17:18:04.641232967 CET | 2548 | OUT | |
Dec 26, 2024 17:18:05.828226089 CET | 25 | IN | |
Dec 26, 2024 17:18:06.082776070 CET | 803 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 49809 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:06.325381041 CET | 307 | OUT | |
Dec 26, 2024 17:18:06.677433014 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 49810 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:06.985853910 CET | 331 | OUT | |
Dec 26, 2024 17:18:07.333637953 CET | 2128 | OUT | |
Dec 26, 2024 17:18:08.265398026 CET | 25 | IN | |
Dec 26, 2024 17:18:08.567361116 CET | 950 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 49811 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:07.196902990 CET | 331 | OUT | |
Dec 26, 2024 17:18:07.552474022 CET | 2548 | OUT | |
Dec 26, 2024 17:18:08.583554029 CET | 25 | IN | |
Dec 26, 2024 17:18:08.850842953 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 49817 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:09.089729071 CET | 307 | OUT | |
Dec 26, 2024 17:18:09.443401098 CET | 2548 | OUT | |
Dec 26, 2024 17:18:10.349991083 CET | 25 | IN | |
Dec 26, 2024 17:18:10.605757952 CET | 795 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 49818 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:09.707442999 CET | 307 | OUT | |
Dec 26, 2024 17:18:10.052357912 CET | 2128 | OUT | |
Dec 26, 2024 17:18:10.921268940 CET | 25 | IN | |
Dec 26, 2024 17:18:11.173861027 CET | 952 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 49824 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:11.015789032 CET | 307 | OUT | |
Dec 26, 2024 17:18:11.364842892 CET | 2548 | OUT | |
Dec 26, 2024 17:18:12.230376005 CET | 25 | IN | |
Dec 26, 2024 17:18:12.481782913 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.4 | 49825 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:12.298702002 CET | 307 | OUT | |
Dec 26, 2024 17:18:12.647907019 CET | 2128 | OUT | |
Dec 26, 2024 17:18:13.477473021 CET | 25 | IN | |
Dec 26, 2024 17:18:13.733740091 CET | 945 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.4 | 49831 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:12.715503931 CET | 307 | OUT | |
Dec 26, 2024 17:18:13.071080923 CET | 2548 | OUT | |
Dec 26, 2024 17:18:13.894951105 CET | 25 | IN | |
Dec 26, 2024 17:18:14.145729065 CET | 799 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.4 | 49832 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:14.388128042 CET | 307 | OUT | |
Dec 26, 2024 17:18:14.739933968 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.4 | 49834 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:14.861882925 CET | 331 | OUT | |
Dec 26, 2024 17:18:15.209330082 CET | 2128 | OUT | |
Dec 26, 2024 17:18:16.047468901 CET | 25 | IN | |
Dec 26, 2024 17:18:16.305658102 CET | 952 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.4 | 49839 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:14.986026049 CET | 331 | OUT | |
Dec 26, 2024 17:18:15.333659887 CET | 2548 | OUT | |
Dec 26, 2024 17:18:16.162266970 CET | 25 | IN | |
Dec 26, 2024 17:18:16.413836002 CET | 807 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.4 | 49840 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:16.711566925 CET | 307 | OUT | |
Dec 26, 2024 17:18:17.067986012 CET | 2548 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.4 | 49846 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:17.454895020 CET | 331 | OUT | |
Dec 26, 2024 17:18:17.802299023 CET | 2108 | OUT | |
Dec 26, 2024 17:18:18.634217978 CET | 25 | IN | |
Dec 26, 2024 17:18:18.905492067 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.4 | 49847 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:17.578418970 CET | 331 | OUT | |
Dec 26, 2024 17:18:17.927375078 CET | 2548 | OUT | |
Dec 26, 2024 17:18:18.756412029 CET | 25 | IN | |
Dec 26, 2024 17:18:19.009543896 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.4 | 49848 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:19.749393940 CET | 307 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.4 | 49854 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:20.095247984 CET | 331 | OUT | |
Dec 26, 2024 17:18:20.443094015 CET | 2092 | OUT | |
Dec 26, 2024 17:18:21.275500059 CET | 25 | IN | |
Dec 26, 2024 17:18:21.529951096 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.4 | 49855 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:20.234801054 CET | 331 | OUT | |
Dec 26, 2024 17:18:20.583687067 CET | 2548 | OUT | |
Dec 26, 2024 17:18:21.412446976 CET | 25 | IN | |
Dec 26, 2024 17:18:21.665853977 CET | 800 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.4 | 49857 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:22.182106972 CET | 307 | OUT | |
Dec 26, 2024 17:18:22.536703110 CET | 2548 | OUT | |
Dec 26, 2024 17:18:23.347927094 CET | 25 | IN | |
Dec 26, 2024 17:18:23.633919001 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.4 | 49862 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:22.658243895 CET | 307 | OUT | |
Dec 26, 2024 17:18:23.005599976 CET | 2128 | OUT | |
Dec 26, 2024 17:18:23.836373091 CET | 25 | IN | |
Dec 26, 2024 17:18:24.089777946 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
70 | 192.168.2.4 | 49863 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:23.873538971 CET | 307 | OUT | |
Dec 26, 2024 17:18:24.282423973 CET | 2548 | OUT | |
Dec 26, 2024 17:18:25.050838947 CET | 25 | IN | |
Dec 26, 2024 17:18:25.308357000 CET | 806 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
71 | 192.168.2.4 | 49869 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:25.386233091 CET | 307 | OUT | |
Dec 26, 2024 17:18:25.740341902 CET | 2108 | OUT | |
Dec 26, 2024 17:18:26.564126015 CET | 25 | IN | |
Dec 26, 2024 17:18:26.821748972 CET | 948 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
72 | 192.168.2.4 | 49870 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:25.543854952 CET | 307 | OUT | |
Dec 26, 2024 17:18:25.896209002 CET | 2548 | OUT | |
Dec 26, 2024 17:18:26.721941948 CET | 25 | IN | |
Dec 26, 2024 17:18:26.973664045 CET | 806 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
73 | 192.168.2.4 | 49876 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:27.774842024 CET | 307 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
74 | 192.168.2.4 | 49877 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:27.954663992 CET | 331 | OUT | |
Dec 26, 2024 17:18:28.302345037 CET | 2128 | OUT | |
Dec 26, 2024 17:18:29.132710934 CET | 25 | IN | |
Dec 26, 2024 17:18:29.407362938 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
75 | 192.168.2.4 | 49878 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:28.073951006 CET | 331 | OUT | |
Dec 26, 2024 17:18:28.427303076 CET | 2548 | OUT | |
Dec 26, 2024 17:18:29.261287928 CET | 25 | IN | |
Dec 26, 2024 17:18:29.514007092 CET | 804 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
76 | 192.168.2.4 | 49884 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:29.770255089 CET | 307 | OUT | |
Dec 26, 2024 17:18:30.115520954 CET | 2548 | OUT | |
Dec 26, 2024 17:18:30.952878952 CET | 25 | IN | |
Dec 26, 2024 17:18:31.205693960 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
77 | 192.168.2.4 | 49885 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:30.533382893 CET | 307 | OUT | |
Dec 26, 2024 17:18:30.880510092 CET | 2128 | OUT | |
Dec 26, 2024 17:18:31.710469961 CET | 25 | IN | |
Dec 26, 2024 17:18:31.961982012 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
78 | 192.168.2.4 | 49889 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:31.452398062 CET | 307 | OUT | |
Dec 26, 2024 17:18:31.803553104 CET | 2548 | OUT | |
Dec 26, 2024 17:18:32.628463030 CET | 25 | IN | |
Dec 26, 2024 17:18:32.881541014 CET | 797 | IN | |
Dec 26, 2024 17:18:33.131807089 CET | 307 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
79 | 192.168.2.4 | 49892 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:33.445492983 CET | 307 | OUT | |
Dec 26, 2024 17:18:33.802706003 CET | 2548 | OUT | |
Dec 26, 2024 17:18:34.624866009 CET | 25 | IN | |
Dec 26, 2024 17:18:34.870090008 CET | 807 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
80 | 192.168.2.4 | 49898 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:34.442589045 CET | 307 | OUT | |
Dec 26, 2024 17:18:34.786797047 CET | 2128 | OUT | |
Dec 26, 2024 17:18:35.623749971 CET | 25 | IN | |
Dec 26, 2024 17:18:35.869573116 CET | 946 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
81 | 192.168.2.4 | 49899 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:35.144561052 CET | 307 | OUT | |
Dec 26, 2024 17:18:35.489938974 CET | 2548 | OUT | |
Dec 26, 2024 17:18:36.322590113 CET | 25 | IN | |
Dec 26, 2024 17:18:36.573695898 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
82 | 192.168.2.4 | 49905 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:36.830749035 CET | 307 | OUT | |
Dec 26, 2024 17:18:37.177422047 CET | 2548 | OUT | |
Dec 26, 2024 17:18:38.008965969 CET | 25 | IN | |
Dec 26, 2024 17:18:38.262115955 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
83 | 192.168.2.4 | 49906 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:36.970320940 CET | 307 | OUT | |
Dec 26, 2024 17:18:37.318070889 CET | 2128 | OUT | |
Dec 26, 2024 17:18:38.149158955 CET | 25 | IN | |
Dec 26, 2024 17:18:38.579509974 CET | 953 | IN | |
Dec 26, 2024 17:18:38.579664946 CET | 953 | IN | |
Dec 26, 2024 17:18:38.728271961 CET | 307 | OUT | |
Dec 26, 2024 17:18:39.061249018 CET | 25 | IN | |
Dec 26, 2024 17:18:39.061434984 CET | 2548 | OUT | |
Dec 26, 2024 17:18:39.579225063 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
84 | 192.168.2.4 | 49912 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:39.720262051 CET | 307 | OUT | |
Dec 26, 2024 17:18:40.068140984 CET | 2128 | OUT | |
Dec 26, 2024 17:18:40.897283077 CET | 25 | IN | |
Dec 26, 2024 17:18:41.149702072 CET | 948 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
85 | 192.168.2.4 | 49913 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:39.825892925 CET | 307 | OUT | |
Dec 26, 2024 17:18:40.177405119 CET | 2548 | OUT | |
Dec 26, 2024 17:18:41.001554012 CET | 25 | IN | |
Dec 26, 2024 17:18:41.253739119 CET | 803 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
86 | 192.168.2.4 | 49919 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:41.618165016 CET | 307 | OUT | |
Dec 26, 2024 17:18:41.974330902 CET | 2548 | OUT | |
Dec 26, 2024 17:18:42.795603991 CET | 25 | IN | |
Dec 26, 2024 17:18:43.285592079 CET | 794 | IN | |
Dec 26, 2024 17:18:43.435101986 CET | 794 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
87 | 192.168.2.4 | 49920 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:42.195533037 CET | 307 | OUT | |
Dec 26, 2024 17:18:42.552436113 CET | 2128 | OUT | |
Dec 26, 2024 17:18:43.374866962 CET | 25 | IN | |
Dec 26, 2024 17:18:43.625386000 CET | 948 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
88 | 192.168.2.4 | 49922 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:43.717396975 CET | 307 | OUT | |
Dec 26, 2024 17:18:44.068008900 CET | 2548 | OUT | |
Dec 26, 2024 17:18:44.891454935 CET | 25 | IN | |
Dec 26, 2024 17:18:45.149710894 CET | 803 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
89 | 192.168.2.4 | 49927 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:44.845799923 CET | 307 | OUT | |
Dec 26, 2024 17:18:45.193017960 CET | 2128 | OUT | |
Dec 26, 2024 17:18:46.024354935 CET | 25 | IN | |
Dec 26, 2024 17:18:46.286910057 CET | 953 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
90 | 192.168.2.4 | 49928 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:45.387126923 CET | 307 | OUT | |
Dec 26, 2024 17:18:45.740107059 CET | 2548 | OUT | |
Dec 26, 2024 17:18:46.565474987 CET | 25 | IN | |
Dec 26, 2024 17:18:46.835933924 CET | 796 | IN | |
Dec 26, 2024 17:18:47.046119928 CET | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
91 | 192.168.2.4 | 49934 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:47.269145012 CET | 307 | OUT | |
Dec 26, 2024 17:18:47.614980936 CET | 2128 | OUT | |
Dec 26, 2024 17:18:48.452908993 CET | 25 | IN | |
Dec 26, 2024 17:18:48.705521107 CET | 943 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
92 | 192.168.2.4 | 49935 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:47.299079895 CET | 307 | OUT | |
Dec 26, 2024 17:18:47.646269083 CET | 2548 | OUT | |
Dec 26, 2024 17:18:48.516638994 CET | 25 | IN | |
Dec 26, 2024 17:18:48.773500919 CET | 795 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
93 | 192.168.2.4 | 49940 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:49.014398098 CET | 307 | OUT | |
Dec 26, 2024 17:18:49.364878893 CET | 2536 | OUT | |
Dec 26, 2024 17:18:50.192792892 CET | 25 | IN | |
Dec 26, 2024 17:18:50.446396112 CET | 801 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
94 | 192.168.2.4 | 49941 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:49.658101082 CET | 307 | OUT | |
Dec 26, 2024 17:18:50.005574942 CET | 2100 | OUT | |
Dec 26, 2024 17:18:50.839406967 CET | 25 | IN | |
Dec 26, 2024 17:18:51.093485117 CET | 948 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
95 | 192.168.2.4 | 49944 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:50.685636997 CET | 307 | OUT | |
Dec 26, 2024 17:18:51.036808968 CET | 2548 | OUT | |
Dec 26, 2024 17:18:51.863084078 CET | 25 | IN | |
Dec 26, 2024 17:18:52.117490053 CET | 803 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
96 | 192.168.2.4 | 49948 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:52.038904905 CET | 307 | OUT | |
Dec 26, 2024 17:18:52.404848099 CET | 2128 | OUT | |
Dec 26, 2024 17:18:53.195504904 CET | 25 | IN | |
Dec 26, 2024 17:18:53.473581076 CET | 947 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
97 | 192.168.2.4 | 49949 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:52.578778982 CET | 307 | OUT | |
Dec 26, 2024 17:18:52.927421093 CET | 2548 | OUT | |
Dec 26, 2024 17:18:53.755889893 CET | 25 | IN | |
Dec 26, 2024 17:18:54.013592005 CET | 797 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
98 | 192.168.2.4 | 49954 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:54.261763096 CET | 307 | OUT | |
Dec 26, 2024 17:18:54.615606070 CET | 2548 | OUT | |
Dec 26, 2024 17:18:55.439224958 CET | 25 | IN | |
Dec 26, 2024 17:18:55.711705923 CET | 797 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
99 | 192.168.2.4 | 49955 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:54.376370907 CET | 307 | OUT | |
Dec 26, 2024 17:18:54.724273920 CET | 2116 | OUT | |
Dec 26, 2024 17:18:55.569037914 CET | 25 | IN | |
Dec 26, 2024 17:18:55.821434021 CET | 942 | IN | |
Dec 26, 2024 17:18:55.830271006 CET | 307 | OUT | |
Dec 26, 2024 17:18:56.163384914 CET | 25 | IN | |
Dec 26, 2024 17:18:56.165584087 CET | 2548 | OUT | |
Dec 26, 2024 17:18:56.649712086 CET | 799 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
100 | 192.168.2.4 | 49960 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:56.690002918 CET | 307 | OUT | |
Dec 26, 2024 17:18:57.036798000 CET | 2128 | OUT | |
Dec 26, 2024 17:18:57.867057085 CET | 25 | IN | |
Dec 26, 2024 17:18:58.146224976 CET | 945 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
101 | 192.168.2.4 | 49961 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:56.887049913 CET | 307 | OUT | |
Dec 26, 2024 17:18:57.240035057 CET | 2544 | OUT | |
Dec 26, 2024 17:18:58.067847013 CET | 25 | IN | |
Dec 26, 2024 17:18:58.325517893 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
102 | 192.168.2.4 | 49966 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:58.563220024 CET | 307 | OUT | |
Dec 26, 2024 17:18:58.911910057 CET | 2548 | OUT | |
Dec 26, 2024 17:18:59.740767002 CET | 25 | IN | |
Dec 26, 2024 17:19:00.235456944 CET | 796 | IN | |
Dec 26, 2024 17:19:00.235574961 CET | 796 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
103 | 192.168.2.4 | 49968 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:18:58.987138987 CET | 307 | OUT | |
Dec 26, 2024 17:18:59.333756924 CET | 2128 | OUT | |
Dec 26, 2024 17:19:00.235542059 CET | 25 | IN | |
Dec 26, 2024 17:19:00.417484045 CET | 949 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
104 | 192.168.2.4 | 49971 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:19:00.483310938 CET | 307 | OUT | |
Dec 26, 2024 17:19:00.833734035 CET | 2548 | OUT | |
Dec 26, 2024 17:19:01.661772966 CET | 25 | IN | |
Dec 26, 2024 17:19:01.913671017 CET | 804 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
105 | 192.168.2.4 | 49974 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:19:01.236841917 CET | 307 | OUT | |
Dec 26, 2024 17:19:01.588527918 CET | 2128 | OUT | |
Dec 26, 2024 17:19:02.417151928 CET | 25 | IN | |
Dec 26, 2024 17:19:02.697639942 CET | 947 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
106 | 192.168.2.4 | 49976 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:19:02.495732069 CET | 307 | OUT | |
Dec 26, 2024 17:19:02.849327087 CET | 2548 | OUT | |
Dec 26, 2024 17:19:03.672945023 CET | 25 | IN | |
Dec 26, 2024 17:19:03.925323009 CET | 795 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
107 | 192.168.2.4 | 49981 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:19:03.486768007 CET | 307 | OUT | |
Dec 26, 2024 17:19:03.833729029 CET | 2128 | OUT | |
Dec 26, 2024 17:19:04.664607048 CET | 25 | IN | |
Dec 26, 2024 17:19:04.917418003 CET | 945 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
108 | 192.168.2.4 | 49983 | 104.21.93.162 | 80 | 2308 | C:\Windows\GameBarPresenceWriter\services.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 17:19:04.199542999 CET | 307 | OUT | |
Dec 26, 2024 17:19:04.552719116 CET | 2544 | OUT | |
Dec 26, 2024 17:19:05.377367973 CET | 25 | IN | |
Dec 26, 2024 17:19:05.673398972 CET | 799 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:16:56 |
Start date: | 26/12/2024 |
Path: | C:\Users\user\Desktop\Z4D3XAZ2jB.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x4a0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 12 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 13 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 14 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 15 |
Start time: | 11:17:00 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 16 |
Start time: | 11:17:01 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x10000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Has exited: | false |
Target ID: | 17 |
Start time: | 11:17:01 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d8370000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 11:17:01 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 11:17:02 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xa30000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 11:17:02 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x9b0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Has exited: | true |
Target ID: | 21 |
Start time: | 11:17:02 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\chcp.com |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71a540000 |
File size: | 14'848 bytes |
MD5 hash: | 33395C4732A49065EA72590B14B64F32 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 22 |
Start time: | 11:17:02 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xc30000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 23 |
Start time: | 11:17:02 |
Start date: | 26/12/2024 |
Path: | C:\Windows\System32\w32tm.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c7dd0000 |
File size: | 108'032 bytes |
MD5 hash: | 81A82132737224D324A3E8DA993E2FB5 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 24 |
Start time: | 11:17:07 |
Start date: | 26/12/2024 |
Path: | C:\Program Files (x86)\Windows Defender\en-GB\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Has exited: | true |
Target ID: | 25 |
Start time: | 11:17:09 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x860000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 28 |
Start time: | 11:17:17 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd50000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 31 |
Start time: | 11:17:25 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xcc0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 32 |
Start time: | 11:17:33 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x9b0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 33 |
Start time: | 11:17:41 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x9d0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 34 |
Start time: | 11:17:49 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x520000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 35 |
Start time: | 11:17:58 |
Start date: | 26/12/2024 |
Path: | C:\Windows\GameBarPresenceWriter\services.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xd30000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 36 |
Start time: | 11:18:06 |
Start date: | 26/12/2024 |
Path: | C:\Windows\BitLockerDiscoveryVolumeContents\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x940000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Has exited: | true |
Target ID: | 37 |
Start time: | 11:18:15 |
Start date: | 26/12/2024 |
Path: | C:\Program Files (x86)\Windows Multimedia Platform\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x60000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Has exited: | true |
Target ID: | 39 |
Start time: | 11:18:23 |
Start date: | 26/12/2024 |
Path: | C:\Program Files (x86)\Windows Defender\en-GB\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x340000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 40 |
Start time: | 11:18:31 |
Start date: | 26/12/2024 |
Path: | C:\Windows\twain_32\ZDtOzYsYYWKWEhNYzFc.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x2f0000 |
File size: | 3'163'910 bytes |
MD5 hash: | 0A5D9CD0A4B6ABDBB272262811774A8D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Execution Graph
Execution Coverage: | 5.6% |
Dynamic/Decrypted Code Coverage: | 75% |
Signature Coverage: | 0% |
Total number of Nodes: | 12 |
Total number of Limit Nodes: | 0 |
Graph
Function 00007FFD9B761AC5 Relevance: .3, Instructions: 275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B91AF5D Relevance: 1.6, APIs: 1, Instructions: 140threadinjectionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE33EA1 Relevance: 1.1, Instructions: 1068COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE37D50 Relevance: .7, Instructions: 694COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE33440 Relevance: .5, Instructions: 519COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE38D69 Relevance: .4, Instructions: 374COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3A04F Relevance: .4, Instructions: 363COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE371DF Relevance: .4, Instructions: 354COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE39902 Relevance: .3, Instructions: 336COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3720D Relevance: .3, Instructions: 334COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3A06F Relevance: .3, Instructions: 332COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE31CB2 Relevance: .3, Instructions: 327COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE30B29 Relevance: .3, Instructions: 304COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE35FC0 Relevance: .3, Instructions: 303COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE323FF Relevance: .3, Instructions: 299COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE372A5 Relevance: .3, Instructions: 285COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B760A19 Relevance: .3, Instructions: 283COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE372F2 Relevance: .3, Instructions: 282COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE372C7 Relevance: .3, Instructions: 277COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE36F79 Relevance: .2, Instructions: 247COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE37B3B Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3B091 Relevance: .2, Instructions: 224COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3245B Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3A3E0 Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE349C2 Relevance: .2, Instructions: 208COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B9B1E5E Relevance: .2, Instructions: 164COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B760870 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3131C Relevance: .1, Instructions: 140COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3278C Relevance: .1, Instructions: 131COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3DEB0 Relevance: .1, Instructions: 130COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3B6B7 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE33A67 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7680CB Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3B761 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE33B11 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3B6FB Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE33AAB Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7612E8 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE392DE Relevance: .1, Instructions: 108COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3881D Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3B4C5 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3A3B0 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE377B2 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B760CB9 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE388F5 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B761575 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B761EBD Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE32790 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3D0F0 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE39460 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE4FF0E Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B761588 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE31810 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE30F3C Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B761590 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE36CA8 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3168E Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE34ABF Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B764AC1 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B761598 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE30C67 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE37A4B Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE37A4A Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE37AC2 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7615A0 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3475A Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B760705 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B760728 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE30118 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE392BB Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE3166B Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE387D3 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE30BA1 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B9194AD Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 6.4% |
Dynamic/Decrypted Code Coverage: | 83.3% |
Signature Coverage: | 0% |
Total number of Nodes: | 18 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AB0DD Relevance: 1.3, Instructions: 1265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC5A8 Relevance: .8, Instructions: 778COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6A04F Relevance: .7, Instructions: 739COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC84E Relevance: .7, Instructions: 721COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC782 Relevance: .7, Instructions: 684COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC926 Relevance: .7, Instructions: 675COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC735 Relevance: .7, Instructions: 663COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC90C Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC87E Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC919 Relevance: .6, Instructions: 644COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC88B Relevance: .6, Instructions: 644COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791AC5 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B94E525 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 133COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B94C8A9 Relevance: 3.1, APIs: 1, Strings: 1, Instructions: 142COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B94AF5D Relevance: 1.6, APIs: 1, Instructions: 139threadinjectionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEB802 Relevance: .7, Instructions: 693COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE49D0 Relevance: .5, Instructions: 461COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D8E7D Relevance: .4, Instructions: 431COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE63440 Relevance: .4, Instructions: 416COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE64829 Relevance: .4, Instructions: 409COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE7CE1 Relevance: .4, Instructions: 408COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6A06F Relevance: .3, Instructions: 335COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE69902 Relevance: .3, Instructions: 330COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE61CB2 Relevance: .3, Instructions: 327COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE9078 Relevance: .3, Instructions: 319COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE67D50 Relevance: .3, Instructions: 310COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE623FF Relevance: .3, Instructions: 296COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE6DB5 Relevance: .3, Instructions: 292COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE672F2 Relevance: .3, Instructions: 291COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790A19 Relevance: .3, Instructions: 281COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE68E36 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE66F79 Relevance: .2, Instructions: 250COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEB0C9 Relevance: .2, Instructions: 250COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE47BB Relevance: .2, Instructions: 243COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE6CBA Relevance: .2, Instructions: 242COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7ADE85 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6B091 Relevance: .2, Instructions: 229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1508 Relevance: .2, Instructions: 228COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6D048 Relevance: .2, Instructions: 227COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6245B Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE8741 Relevance: .2, Instructions: 223COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE782BE Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7ADF03 Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE2322 Relevance: .2, Instructions: 215COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE66AE Relevance: .2, Instructions: 213COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE67B3B Relevance: .2, Instructions: 209COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE64027 Relevance: .2, Instructions: 199COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED7DB Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE5ADB Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6A3E0 Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEAC5A Relevance: .2, Instructions: 179COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1E4D Relevance: .2, Instructions: 171COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B9E1E5E Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790870 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1E88 Relevance: .2, Instructions: 155COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6130C Relevance: .2, Instructions: 154COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEACAA Relevance: .2, Instructions: 151COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE94FC Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE65FC0 Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6B6B7 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE63A67 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE8307 Relevance: .1, Instructions: 127COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE62790 Relevance: .1, Instructions: 125COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7980CB Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1D72 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6B761 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE63B11 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE83B1 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1630 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6DEB0 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6B6FB Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE63AAB Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE834B Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE8B8A Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE34E6 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE692DE Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE5BAD Relevance: .1, Instructions: 111COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6A21 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1F48 Relevance: .1, Instructions: 105COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED23A Relevance: .1, Instructions: 99COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6881D Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE8115 Relevance: .1, Instructions: 97COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6B4C5 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60CA5 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE63875 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE688F8 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE7000 Relevance: .1, Instructions: 91COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE5555 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D8A09 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6A3B0 Relevance: .1, Instructions: 89COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D76C6 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A8F2D Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEC41B Relevance: .1, Instructions: 84COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE677B2 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEC41A Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790CB9 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60C31 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791575 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4449 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED1A8 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE26B4 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEC199 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE8A2D Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791EBD Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE0AF0 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE7030 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE69460 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1A5D Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE61810 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE53FD Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791588 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B1A65 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEADFA Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B1C85 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6168E Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4F77 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEC1C0 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEBE71 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED4D6 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4F13 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE202E Relevance: .1, Instructions: 55COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE9383 Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE64000 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE60AC Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED1F7 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4F1C Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D9739 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60F38 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE66CA8 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791598 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AEF3B Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6D49 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60C67 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B794AC1 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D7149 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE64AC4 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE54F4 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D9750 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE67A4B Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7915A0 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D9EC8 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE67A4A Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEC089 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D94B9 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6E29 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D878A Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE67AC2 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDF45 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4742 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDBD3 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DA1A8 Relevance: .0, Instructions: 37COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D94D0 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A91B0 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6E40 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE687BA Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B0895 Relevance: .0, Instructions: 30COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B0C45 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE1FCF Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6471A Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D71B9 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60B87 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DE45C Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFEB76E Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE3422 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE60118 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE692BB Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BE6166B Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE5F0B Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE4075 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFED12F Relevance: .0, Instructions: 8COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE2011 Relevance: .0, Instructions: 7COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9BFE5451 Relevance: .0, Instructions: 6COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B9414D0 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 4.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 6 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AB0DD Relevance: 1.3, Instructions: 1265COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC5A8 Relevance: .8, Instructions: 778COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC84E Relevance: .7, Instructions: 721COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC782 Relevance: .7, Instructions: 684COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC926 Relevance: .7, Instructions: 675COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC735 Relevance: .7, Instructions: 663COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC90C Relevance: .6, Instructions: 647COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC87E Relevance: .6, Instructions: 647COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC919 Relevance: .6, Instructions: 644COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AC88B Relevance: .6, Instructions: 644COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791AC5 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D8E7D Relevance: .4, Instructions: 431COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790A19 Relevance: .3, Instructions: 281COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7ADE85 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7ADF03 Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790870 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7980CB Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6A21 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D76C6 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7A8F2D Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790CB9 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791575 Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791EBD Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B1A65 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791588 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6D49 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7AEF3B Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791598 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B794AC1 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7915A0 Relevance: .0, Instructions: 44COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D94B9 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6E29 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D878A Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B0894 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7DDBD3 Relevance: .0, Instructions: 38COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D94D0 Relevance: .0, Instructions: 36COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7D6E40 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7B0C45 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 3.3% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 6 |
Total number of Limit Nodes: | 0 |
Graph
Function 00007FFD9B78B0DD Relevance: 1.3, Instructions: 1263COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C5AF Relevance: .8, Instructions: 776COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C84E Relevance: .7, Instructions: 721COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C782 Relevance: .7, Instructions: 684COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C926 Relevance: .7, Instructions: 675COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C735 Relevance: .7, Instructions: 663COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C90C Relevance: .6, Instructions: 647COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78C919 Relevance: .6, Instructions: 644COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B771AC5 Relevance: .3, Instructions: 275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770A19 Relevance: .3, Instructions: 283COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78DE85 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78DF03 Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770870 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B7780CB Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B788F2D Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B770CB9 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B771EBD Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B791A65 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B78EF3B Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B774AC1 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B776FC5 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B790C45 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|