Windows
Analysis Report
12.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 12.exe (PID: 7324 cmdline:
"C:\Users\ user\Deskt op\12.exe" MD5: C8C40C038A4A8541E0924520599D8C28)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Cobalt Strike, CobaltStrike | Cobalt Strike is a paid penetration testing product that allows an attacker to deploy an agent named 'Beacon' on the victim machine. Beacon includes a wealth of functionality to the attacker, including, but not limited to command execution, key logging, file transfer, SOCKS proxying, privilege escalation, mimikatz, port scanning and lateral movement. Beacon is in-memory/file-less, in that it consists of stageless or multi-stage shellcode that once loaded by exploiting a vulnerability or executing a shellcode loader, will reflectively load itself into the memory of a process without touching the disk. It supports C2 and staging over HTTP, HTTPS, DNS, SMB named pipes as well as forward and reverse TCP; Beacons can be daisy-chained. Cobalt Strike comes with a toolkit for developing shellcode loaders, called Artifact Kit.The Beacon implant has become popular amongst targeted attackers and criminal users as it is well written, stable, and highly customizable. |
{"BeaconType": ["HTTP"], "Port": 59060, "SleepTime": 60000, "MaxGetSize": 1048576, "Jitter": 0, "C2Server": "152.42.226.16,/cx", "HttpPostUri": "/submit.php", "Malleable_C2_Instructions": [], "HttpGet_Verb": "GET", "HttpPost_Verb": "POST", "HttpPostChunk": 0, "Spawnto_x86": "%windir%\\syswow64\\rundll32.exe", "Spawnto_x64": "%windir%\\sysnative\\rundll32.exe", "CryptoScheme": 0, "Proxy_Behavior": "Use IE settings", "Watermark": 987654321, "bStageCleanup": "False", "bCFGCaution": "False", "KillDate": 0, "bProcInject_StartRWX": "True", "bProcInject_UseRWX": "True", "bProcInject_MinAllocSize": 0, "ProcInject_PrependAppend_x86": "Empty", "ProcInject_PrependAppend_x64": "Empty", "ProcInject_Execute": ["CreateThread", "SetThreadContext", "CreateRemoteThread", "RtlCreateUserThread"], "ProcInject_AllocationMethod": "VirtualAllocEx", "bUsesCookies": "True", "HostHeader": ""}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CobaltStrike_4 | Yara detected CobaltStrike | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Metasploit_7bc0f998 | Identifies the API address lookup function leverage by metasploit shellcode | unknown |
| |
Windows_Trojan_Metasploit_c9773203 | Identifies the 64 bit API hashing function used by Metasploit. This has been re-used by many other malware families. | unknown |
| |
JoeSecurity_ReflectiveLoader | Yara detected ReflectiveLoader | Joe Security | ||
JoeSecurity_CobaltStrike | Yara detected CobaltStrike | Joe Security | ||
JoeSecurity_CobaltStrike_3 | Yara detected CobaltStrike | Joe Security | ||
Click to see the 33 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CobaltStrike_4 | Yara detected CobaltStrike | Joe Security | ||
JoeSecurity_CobaltStrike_4 | Yara detected CobaltStrike | Joe Security | ||
JoeSecurity_ReflectiveLoader | Yara detected ReflectiveLoader | Joe Security | ||
JoeSecurity_CobaltStrike | Yara detected CobaltStrike | Joe Security | ||
JoeSecurity_CobaltStrike_3 | Yara detected CobaltStrike | Joe Security | ||
Click to see the 53 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-26T19:28:01.174082+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49730 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:04.065607+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49731 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:07.008994+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49732 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:09.938290+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49733 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:13.024487+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49734 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:15.921977+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49735 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:18.852713+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49737 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:21.863365+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49741 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:24.767420+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49743 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:27.658629+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49745 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:30.587201+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49746 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:33.469999+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49747 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:36.381095+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49748 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:39.298766+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49749 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:42.220886+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49750 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:45.126842+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49751 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:48.127398+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49752 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:51.077524+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49753 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:53.995484+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49754 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:56.948292+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49755 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:59.893821+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49758 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:02.785028+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49764 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:05.752619+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49770 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:08.643492+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49776 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:11.534105+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49782 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:14.424353+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49788 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:17.315337+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49794 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:20.206541+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49805 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:23.112154+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49811 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:26.230193+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49817 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:29.189460+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49823 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:32.105461+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49829 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:35.046126+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49839 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:37.940700+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49846 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:40.833437+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49852 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:43.731451+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49858 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:46.671469+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49869 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:49.566010+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49875 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:52.473411+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49881 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:55.539263+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49887 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:58.426729+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49896 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:01.355750+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49904 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:04.261831+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49910 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:07.144332+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49916 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:10.036173+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49925 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:12.925060+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49933 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:16.035600+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49939 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:18.931747+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49945 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:21.832539+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49954 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:24.725469+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49962 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:27.613095+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49968 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:30.503531+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49973 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:33.410620+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49978 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:36.319540+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49987 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:39.298482+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 49994 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:42.223934+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50000 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:45.113944+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50009 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:48.020191+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50016 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:50.913584+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50022 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:53.801887+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50029 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:56.737650+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50036 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:59.629939+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50045 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:02.519995+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50050 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:05.411871+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50056 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:08.305535+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50063 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:11.209608+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50067 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:14.098124+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50068 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:16.988917+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50069 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:19.896222+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50070 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:22.845151+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50071 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:25.755345+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50072 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:28.660857+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50073 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:31.559825+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50074 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:34.521650+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50075 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:37.583462+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50076 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:40.475090+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50077 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:43.731887+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50078 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:46.633605+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50079 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:49.520544+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50080 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:52.413722+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50081 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:55.302479+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50082 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:58.236196+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50083 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:32:01.240049+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50084 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:32:04.130504+0100 | 2033713 | 1 | Targeted Malicious Activity was Detected | 192.168.2.4 | 50085 | 152.42.226.16 | 59060 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Code function: | 0_2_00DBEF82 | |
Source: | Code function: | 0_2_00DBEF82 |
Source: | Static PE information: |
Source: | Code function: | 0_2_00DBA70E | |
Source: | Code function: | 0_2_00DB5225 | |
Source: | Code function: | 0_2_00DBA70E |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | Code function: | 0_2_00DB2C3F |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00DB4763 |
Source: | Code function: | 0_2_00D940FD | |
Source: | Code function: | 0_2_00D8A1DB | |
Source: | Code function: | 0_2_00DD8190 | |
Source: | Code function: | 0_2_00DD7320 | |
Source: | Code function: | 0_2_00D944D1 | |
Source: | Code function: | 0_2_00D97590 | |
Source: | Code function: | 0_2_00D96720 | |
Source: | Code function: | 0_2_00D948DD | |
Source: | Code function: | 0_2_00DD4828 | |
Source: | Code function: | 0_2_00D8282F | |
Source: | Code function: | 0_2_00DC59E9 | |
Source: | Code function: | 0_2_00DD7BC0 | |
Source: | Code function: | 0_2_00D94CFD | |
Source: | Code function: | 0_2_00D93C28 | |
Source: | Code function: | 0_2_00DCADDB | |
Source: | Code function: | 0_2_00D84DE9 | |
Source: | Code function: | 0_2_00D96D45 | |
Source: | Code function: | 0_2_00D96FC0 | |
Source: | Code function: | 0_2_00DD50D1 | |
Source: | Code function: | 0_2_00DD58FD | |
Source: | Code function: | 0_2_00DD4828 | |
Source: | Code function: | 0_2_00DC59E9 | |
Source: | Code function: | 0_2_00DD8190 | |
Source: | Code function: | 0_2_00DD7945 | |
Source: | Code function: | 0_2_00DD7BC0 | |
Source: | Code function: | 0_2_00DD7320 | |
Source: | Code function: | 0_2_00DD54DD | |
Source: | Code function: | 0_2_00DD4CFD | |
Source: | Code function: | 0_2_00DCADDB |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 0_2_00DB41CB | |
Source: | Code function: | 0_2_00DB41CB | |
Source: | Code function: | 0_2_00DB41CB | |
Source: | Code function: | 0_2_00DB41CB |
Source: | Code function: | 0_2_00DBA4E3 |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00DB21D8 |
Source: | Code function: | 0_2_00DCB3FC | |
Source: | Code function: | 0_2_00DC85D7 | |
Source: | Code function: | 0_2_00D8A7FC | |
Source: | Code function: | 0_2_00D88728 | |
Source: | Code function: | 0_2_00D879D7 | |
Source: | Code function: | 0_2_00DCB3FC | |
Source: | Code function: | 0_2_00DDCBE5 | |
Source: | Code function: | 0_2_00DC9328 | |
Source: | Code function: | 0_2_00DC85D7 | |
Source: | Code function: | 0_2_00DE5E79 |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Malware Analysis System Evasion |
---|
Source: | Code function: | 0_2_00DB3685 | |
Source: | Code function: | 0_2_00DB7E57 | |
Source: | Code function: | 0_2_00DB3685 | |
Source: | Code function: | 0_2_00DB7E57 |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Evasive API call chain: | graph_0-40462 | ||
Source: | Evasive API call chain: | graph_0-40142 |
Source: | API coverage: |
Source: | Code function: | 0_2_00DB7E57 |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 0_2_00DBA70E | |
Source: | Code function: | 0_2_00DB5225 | |
Source: | Code function: | 0_2_00DBA70E |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-40316 |
Anti Debugging |
---|
Source: | Process Stats: |
Source: | Code function: | 0_2_00DD9375 |
Source: | Code function: | 0_2_00DB21D8 |
Source: | Code function: | 0_2_00DBB870 | |
Source: | Code function: | 0_2_00DBABA0 | |
Source: | Code function: | 0_2_00D7AC70 | |
Source: | Code function: | 0_2_00D79FA0 | |
Source: | Code function: | 0_2_00DBB870 | |
Source: | Code function: | 0_2_00DBABA0 |
Source: | Code function: | 0_2_00DB91C2 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_0040116C | |
Source: | Code function: | 0_2_00401A5C | |
Source: | Code function: | 0_2_00401A60 | |
Source: | Code function: | 0_2_00401160 | |
Source: | Code function: | 0_2_004013C1 | |
Source: | Code function: | 0_2_004011A3 | |
Source: | Code function: | 0_2_00DD0331 | |
Source: | Code function: | 0_2_00DCC4B2 | |
Source: | Code function: | 0_2_00DD2950 | |
Source: | Code function: | 0_2_00DD2950 | |
Source: | Code function: | 0_2_00DD0331 | |
Source: | Code function: | 0_2_00DCC4B2 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | File source: |
Source: | Code function: | 0_2_00DBE272 |
Source: | Code function: | 0_2_00DBE442 |
Source: | Code function: | 0_2_00DD5EF0 | |
Source: | Code function: | 0_2_00DD5EF0 |
Source: | Code function: | 0_2_0040161C |
Source: | Code function: | 0_2_004019A0 |
Source: | Code function: | 0_2_00DB7F09 |
Source: | Code function: | 0_2_00DB7F09 |
Source: | Key value queried: | Jump to behavior |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 0_2_00DB85B7 | |
Source: | Code function: | 0_2_00DB8699 | |
Source: | Code function: | 0_2_00DBEDB3 | |
Source: | Code function: | 0_2_00DBEDB3 | |
Source: | Code function: | 0_2_00DB85B7 | |
Source: | Code function: | 0_2_00DB8699 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 2 Valid Accounts | 2 Native API | 2 Valid Accounts | 2 Valid Accounts | 2 Valid Accounts | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 21 Access Token Manipulation | 112 Virtualization/Sandbox Evasion | LSASS Memory | 231 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 11 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 Process Injection | 21 Access Token Manipulation | Security Account Manager | 112 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Process Injection | NTDS | 1 Process Discovery | Distributed Component Object Model | Input Capture | 1 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | 111 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Obfuscated Files or Information | Cached Domain Credentials | 1 Account Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | 1 System Owner/User Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 1 File and Directory Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
Network Topology | Malvertising | Exploit Public-Facing Application | Command and Scripting Interpreter | At | At | HTML Smuggling | /etc/passwd and /etc/shadow | 14 System Information Discovery | Direct Cloud VM Connections | Data Staged | Web Protocols | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Internal Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
95% | ReversingLabs | Win32.Trojan.CobaltStrike | ||
100% | Avira | HEUR/AGEN.1344233 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
152.42.226.16 | unknown | United States | 81 | NCRENUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1581039 |
Start date and time: | 2024-12-26 19:27:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 15s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 12.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@1/0@0/1 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.246.63
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- VT rate limit hit for: 12.exe
Time | Type | Description |
---|---|---|
13:27:57 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
152.42.226.16 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
NCRENUS | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 6.737889780496197 |
TrID: |
|
File name: | 12.exe |
File size: | 324'096 bytes |
MD5: | c8c40c038a4a8541e0924520599d8c28 |
SHA1: | 295bb62eaf5f53f55d60f2f339a45cd7cd7aa82c |
SHA256: | cbc52ae56076b1e28cff760b662145425620ae4b6d400cc9446deec21d1aae4a |
SHA512: | 76a4daccd65b67304942575cd47e8b63a658ba76d3be9a1a8977189538fb69bd22c9faa8b441fe1a5b355802afa0613c1c74b5e219360bfce5b447677e46e51c |
SSDEEP: | 6144:niCnYE+pwcF84FHvr3JeYF+u5KyckoVuB31c1:iCnj+Y4FPUM+u57sG31c1 |
TLSH: | E464CEB0D852E6E3C3885CB13D92FA57B7939B14013627EB892F948097F57A0CD4A74E |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......................".....................0....@..........................@......l......... ............................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x4014a0 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED |
DLL Characteristics: | |
Time Stamp: | 0x0 [Thu Jan 1 00:00:00 1970 UTC] |
TLS Callbacks: | 0x401b40, 0x401af0 |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f6243a15fa8eee8ee96b5e1144d461f6 |
Instruction |
---|
sub esp, 0Ch |
mov dword ptr [00450394h], 00000001h |
call 00007F4AB506DA43h |
add esp, 0Ch |
jmp 00007F4AB506D1FBh |
lea esi, dword ptr [esi+00000000h] |
sub esp, 0Ch |
mov dword ptr [00450394h], 00000000h |
call 00007F4AB506DA23h |
add esp, 0Ch |
jmp 00007F4AB506D1DBh |
lea esi, dword ptr [esi+00000000h] |
sub esp, 1Ch |
mov eax, dword ptr [esp+20h] |
mov dword ptr [esp], eax |
call 00007F4AB506E9CAh |
test eax, eax |
sete al |
add esp, 1Ch |
movzx eax, al |
neg eax |
ret |
nop |
nop |
nop |
push ebp |
mov ebp, esp |
sub esp, 18h |
mov dword ptr [esp], 00401520h |
call 00007F4AB506D523h |
leave |
ret |
lea esi, dword ptr [esi+00000000h] |
lea esi, dword ptr [esi+00h] |
nop |
ret |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
nop |
push ebp |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
pop ebp |
jmp eax |
push ebp |
mov edx, dword ptr [0040302Ch] |
mov ebp, esp |
mov eax, dword ptr [ebp+08h] |
test edx, edx |
jle 00007F4AB506D573h |
cmp dword ptr [00403030h], 00000000h |
jle 00007F4AB506D56Ah |
mov ecx, dword ptr [00451148h] |
mov dword ptr [eax+edx], ecx |
mov ecx, dword ptr [0045114Ch] |
mov edx, dword ptr [00403030h] |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x51000 | 0x644 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x4f030 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x5111c | 0xe0 | .idata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1a44 | 0x1c00 | 78084e5ca85835392a463f62abd5746c | False | 0.5334821428571429 | data | 5.700340700341032 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.data | 0x3000 | 0x4bc6c | 0x4be00 | 15647f750fd4bb141b4734a68d6d66f5 | False | 0.564453125 | dBase III DBT, version number 0, next free block index 10, 1st item "\206\270\324\021\242\273\324\021\242\273\324\021\242\273\324\021\242\273\324\021\242\273\324\021\242\273\324\021\214\317\261i\326\273\324\021w*\326\021\242\253\324\021\242)\326\021\242\277\324\021\242\273\324\021\242\273\324\021\242\273\324\021\202\273\324q\214\311\260p\326\332\324\021\203'\324\021\242\013\326\021\242%\324\021\242-\326\021\242\273\324\021\242\273\324\021\242\273\324\021\342\273\324Q\214\337\265e\303\273\324\021\342I\324\021\242\353\327\021\242\311\324" | 6.758593457994394 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0x4f000 | 0x634 | 0x800 | 667441c840a2c3ea7e1291acd47bf4c5 | False | 0.2275390625 | data | 4.495993508967327 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ |
.bss | 0x50000 | 0x428 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_8BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_2048BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0x51000 | 0x644 | 0x800 | 7d72908e4c68f22d444c4e664d88dda3 | False | 0.3544921875 | data | 4.2935353496828945 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.CRT | 0x52000 | 0x34 | 0x200 | a09a5f5fb4593e99cd0076e5f2fcec2e | False | 0.072265625 | Matlab v4 mat-file (little endian) \200\031@, numeric, rows 4198688, columns 0 | 0.2711142780062829 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0x53000 | 0x8 | 0x200 | bf619eac0cdf3f68d496ea9344137e8b | False | 0.02734375 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
DLL | Import |
---|---|
KERNEL32.dll | CloseHandle, ConnectNamedPipe, CreateFileA, CreateNamedPipeA, CreateThread, DeleteCriticalSection, EnterCriticalSection, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, GetLastError, GetModuleHandleA, GetProcAddress, GetStartupInfoA, GetSystemTimeAsFileTime, GetTickCount, InitializeCriticalSection, LeaveCriticalSection, QueryPerformanceCounter, ReadFile, SetUnhandledExceptionFilter, Sleep, TerminateProcess, TlsGetValue, UnhandledExceptionFilter, VirtualAlloc, VirtualProtect, VirtualQuery, WriteFile |
msvcrt.dll | __getmainargs, __initenv, __lconv_init, __p__acmdln, __p__fmode, __set_app_type, __setusermatherr, _amsg_exit, _cexit, _initterm, _iob, _onexit, abort, calloc, exit, fprintf, free, fwrite, malloc, memcpy, signal, sprintf, strlen, strncmp, vfprintf |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-26T19:28:01.174082+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49730 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:04.065607+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49731 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:07.008994+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49732 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:09.938290+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49733 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:13.024487+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49734 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:15.921977+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49735 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:18.852713+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49737 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:21.863365+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49741 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:24.767420+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49743 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:27.658629+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49745 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:30.587201+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49746 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:33.469999+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49747 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:36.381095+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49748 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:39.298766+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49749 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:42.220886+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49750 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:45.126842+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49751 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:48.127398+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49752 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:51.077524+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49753 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:53.995484+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49754 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:56.948292+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49755 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:28:59.893821+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49758 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:02.785028+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49764 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:05.752619+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49770 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:08.643492+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49776 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:11.534105+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49782 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:14.424353+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49788 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:17.315337+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49794 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:20.206541+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49805 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:23.112154+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49811 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:26.230193+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49817 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:29.189460+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49823 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:32.105461+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49829 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:35.046126+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49839 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:37.940700+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49846 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:40.833437+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49852 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:43.731451+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49858 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:46.671469+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49869 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:49.566010+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49875 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:52.473411+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49881 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:55.539263+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49887 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:29:58.426729+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49896 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:01.355750+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49904 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:04.261831+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49910 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:07.144332+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49916 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:10.036173+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49925 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:12.925060+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49933 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:16.035600+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49939 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:18.931747+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49945 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:21.832539+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49954 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:24.725469+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49962 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:27.613095+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49968 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:30.503531+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49973 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:33.410620+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49978 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:36.319540+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49987 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:39.298482+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 49994 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:42.223934+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50000 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:45.113944+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50009 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:48.020191+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50016 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:50.913584+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50022 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:53.801887+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50029 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:56.737650+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50036 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:30:59.629939+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50045 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:02.519995+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50050 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:05.411871+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50056 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:08.305535+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50063 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:11.209608+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50067 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:14.098124+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50068 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:16.988917+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50069 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:19.896222+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50070 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:22.845151+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50071 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:25.755345+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50072 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:28.660857+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50073 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:31.559825+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50074 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:34.521650+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50075 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:37.583462+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50076 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:40.475090+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50077 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:43.731887+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50078 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:46.633605+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50079 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:49.520544+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50080 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:52.413722+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50081 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:55.302479+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50082 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:31:58.236196+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50083 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:32:01.240049+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50084 | 152.42.226.16 | 59060 | TCP |
2024-12-26T19:32:04.130504+0100 | 2033713 | ET MALWARE Cobalt Strike Beacon Observed | 1 | 192.168.2.4 | 50085 | 152.42.226.16 | 59060 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 26, 2024 19:27:58.381906033 CET | 49730 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:27:58.501657009 CET | 59060 | 49730 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:27:58.501773119 CET | 49730 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:27:58.501960039 CET | 49730 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:27:58.621462107 CET | 59060 | 49730 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:01.173985004 CET | 59060 | 49730 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:01.174082041 CET | 49730 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:01.174201012 CET | 49730 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:01.284480095 CET | 49731 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:01.293832064 CET | 59060 | 49730 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:01.404340029 CET | 59060 | 49731 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:01.404429913 CET | 49731 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:01.404603958 CET | 49731 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:01.525646925 CET | 59060 | 49731 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:04.065500975 CET | 59060 | 49731 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:04.065607071 CET | 49731 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:04.065776110 CET | 49731 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:04.188317060 CET | 59060 | 49731 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:04.205208063 CET | 49732 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:04.324865103 CET | 59060 | 49732 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:04.324954987 CET | 49732 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:04.326299906 CET | 49732 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:04.445831060 CET | 59060 | 49732 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:07.008816957 CET | 59060 | 49732 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:07.008994102 CET | 49732 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:07.008994102 CET | 49732 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:07.125379086 CET | 49733 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:07.129863977 CET | 59060 | 49732 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:07.245503902 CET | 59060 | 49733 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:07.245574951 CET | 49733 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:07.245825052 CET | 49733 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:07.365350008 CET | 59060 | 49733 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:09.938190937 CET | 59060 | 49733 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:09.938290119 CET | 49733 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:09.938359022 CET | 49733 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:10.051434040 CET | 49734 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:10.057986975 CET | 59060 | 49733 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:10.171535015 CET | 59060 | 49734 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:10.171627045 CET | 49734 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:10.171814919 CET | 49734 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:10.292514086 CET | 59060 | 49734 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:13.024419069 CET | 59060 | 49734 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:13.024487019 CET | 49734 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:13.024561882 CET | 49734 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:13.128958941 CET | 49735 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:13.144754887 CET | 59060 | 49734 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:13.248680115 CET | 59060 | 49735 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:13.248749018 CET | 49735 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:13.248894930 CET | 49735 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:13.368614912 CET | 59060 | 49735 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:15.921891928 CET | 59060 | 49735 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:15.921977043 CET | 49735 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:15.922068119 CET | 49735 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:16.036178112 CET | 49737 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:16.042495966 CET | 59060 | 49735 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:16.155747890 CET | 59060 | 49737 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:16.155836105 CET | 49737 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:16.155977964 CET | 49737 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:16.275733948 CET | 59060 | 49737 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:18.852616072 CET | 59060 | 49737 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:18.852713108 CET | 49737 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:18.878941059 CET | 49737 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:18.990123987 CET | 49741 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:18.998482943 CET | 59060 | 49737 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:19.110018969 CET | 59060 | 49741 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:19.110097885 CET | 49741 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:19.110304117 CET | 49741 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:19.229834080 CET | 59060 | 49741 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:21.863044977 CET | 59060 | 49741 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:21.863364935 CET | 49741 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:21.863465071 CET | 49741 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:21.972388983 CET | 49743 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:21.982944965 CET | 59060 | 49741 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:22.092065096 CET | 59060 | 49743 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:22.092134953 CET | 49743 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:22.092303991 CET | 49743 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:22.211987019 CET | 59060 | 49743 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:24.767355919 CET | 59060 | 49743 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:24.767420053 CET | 49743 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:24.767528057 CET | 49743 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:24.880848885 CET | 49745 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:24.887006998 CET | 59060 | 49743 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:25.001029968 CET | 59060 | 49745 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:25.001147032 CET | 49745 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:25.001307964 CET | 49745 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:25.120786905 CET | 59060 | 49745 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:27.658510923 CET | 59060 | 49745 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:27.658628941 CET | 49745 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:27.658691883 CET | 49745 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:27.769164085 CET | 49746 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:27.778188944 CET | 59060 | 49745 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:27.888797998 CET | 59060 | 49746 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:27.888875961 CET | 49746 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:27.889086008 CET | 49746 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:28.009470940 CET | 59060 | 49746 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:30.587101936 CET | 59060 | 49746 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:30.587201118 CET | 49746 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:30.587260008 CET | 49746 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:30.690825939 CET | 49747 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:30.706803083 CET | 59060 | 49746 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:30.810405970 CET | 59060 | 49747 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:30.810489893 CET | 49747 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:30.810631990 CET | 49747 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:30.931967974 CET | 59060 | 49747 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:33.469933987 CET | 59060 | 49747 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:33.469999075 CET | 49747 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:33.470076084 CET | 49747 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:33.591033936 CET | 59060 | 49747 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:33.607059002 CET | 49748 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:33.726680994 CET | 59060 | 49748 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:33.726816893 CET | 49748 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:33.727039099 CET | 49748 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:33.846566916 CET | 59060 | 49748 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:36.380842924 CET | 59060 | 49748 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:36.381094933 CET | 49748 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:36.381165981 CET | 49748 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:36.489202976 CET | 49749 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:36.500874043 CET | 59060 | 49748 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:36.608969927 CET | 59060 | 49749 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:36.609054089 CET | 49749 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:36.613922119 CET | 49749 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:36.733736992 CET | 59060 | 49749 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:39.298552036 CET | 59060 | 49749 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:39.298765898 CET | 49749 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:39.298765898 CET | 49749 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:39.409729004 CET | 49750 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:39.419059992 CET | 59060 | 49749 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:39.532253981 CET | 59060 | 49750 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:39.532438040 CET | 49750 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:39.532476902 CET | 49750 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:39.652034044 CET | 59060 | 49750 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:42.220810890 CET | 59060 | 49750 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:42.220885992 CET | 49750 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:42.220958948 CET | 49750 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:42.333338976 CET | 49751 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:42.340542078 CET | 59060 | 49750 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:42.453094959 CET | 59060 | 49751 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:42.453190088 CET | 49751 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:42.453362942 CET | 49751 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:42.573633909 CET | 59060 | 49751 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:45.126789093 CET | 59060 | 49751 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:45.126842022 CET | 49751 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:45.126919031 CET | 49751 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:45.246484995 CET | 59060 | 49751 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:45.311599970 CET | 49752 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:45.431130886 CET | 59060 | 49752 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:45.431241035 CET | 49752 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:45.440135956 CET | 49752 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:45.561371088 CET | 59060 | 49752 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:48.127335072 CET | 59060 | 49752 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:48.127398014 CET | 49752 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:48.158183098 CET | 49752 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:48.273011923 CET | 49753 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:48.277904987 CET | 59060 | 49752 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:48.396697998 CET | 59060 | 49753 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:48.396774054 CET | 49753 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:48.397075891 CET | 49753 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:48.518801928 CET | 59060 | 49753 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:51.077346087 CET | 59060 | 49753 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:51.077523947 CET | 49753 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:51.077616930 CET | 49753 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:51.195455074 CET | 49754 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:51.197217941 CET | 59060 | 49753 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:51.315269947 CET | 59060 | 49754 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:51.315527916 CET | 49754 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:51.315757036 CET | 49754 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:51.435231924 CET | 59060 | 49754 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:53.995269060 CET | 59060 | 49754 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:53.995484114 CET | 49754 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:53.995588064 CET | 49754 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:54.097229004 CET | 49755 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:54.115704060 CET | 59060 | 49754 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:54.217515945 CET | 59060 | 49755 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:54.217698097 CET | 49755 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:54.218161106 CET | 49755 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:54.337990999 CET | 59060 | 49755 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:56.948162079 CET | 59060 | 49755 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:56.948292017 CET | 49755 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:56.979860067 CET | 49755 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:57.084100962 CET | 49758 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:57.099351883 CET | 59060 | 49755 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:57.203691959 CET | 59060 | 49758 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:57.203768015 CET | 49758 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:57.203973055 CET | 49758 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:57.323568106 CET | 59060 | 49758 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:59.893759012 CET | 59060 | 49758 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:28:59.893821001 CET | 49758 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:28:59.893956900 CET | 49758 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:00.004810095 CET | 49764 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:00.018047094 CET | 59060 | 49758 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:00.131144047 CET | 59060 | 49764 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:00.131216049 CET | 49764 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:00.131360054 CET | 49764 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:00.250821114 CET | 59060 | 49764 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:02.784812927 CET | 59060 | 49764 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:02.785027981 CET | 49764 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:02.785027981 CET | 49764 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:02.894084930 CET | 49770 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:02.906250954 CET | 59060 | 49764 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:03.033308983 CET | 59060 | 49770 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:03.033422947 CET | 49770 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:03.033688068 CET | 49770 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:03.214739084 CET | 59060 | 49770 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:05.752500057 CET | 59060 | 49770 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:05.752619028 CET | 49770 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:05.752715111 CET | 49770 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:05.864645958 CET | 49776 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:05.872536898 CET | 59060 | 49770 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:05.984224081 CET | 59060 | 49776 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:05.984334946 CET | 49776 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:05.984513998 CET | 49776 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:06.106645107 CET | 59060 | 49776 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:08.643415928 CET | 59060 | 49776 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:08.643491983 CET | 49776 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:08.646202087 CET | 49776 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:08.755592108 CET | 49782 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:08.769798994 CET | 59060 | 49776 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:08.875336885 CET | 59060 | 49782 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:08.875538111 CET | 49782 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:08.875693083 CET | 49782 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:08.995280981 CET | 59060 | 49782 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:11.533996105 CET | 59060 | 49782 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:11.534105062 CET | 49782 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:11.535875082 CET | 49782 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:11.646469116 CET | 49788 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:11.657885075 CET | 59060 | 49782 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:11.766161919 CET | 59060 | 49788 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:11.766273975 CET | 49788 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:11.766458035 CET | 49788 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:11.886267900 CET | 59060 | 49788 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:14.424277067 CET | 59060 | 49788 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:14.424352884 CET | 49788 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:14.424458027 CET | 49788 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:14.534986019 CET | 49794 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:14.544081926 CET | 59060 | 49788 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:14.654622078 CET | 59060 | 49794 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:14.654738903 CET | 49794 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:14.654863119 CET | 49794 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:14.774420977 CET | 59060 | 49794 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:17.315108061 CET | 59060 | 49794 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:17.315336943 CET | 49794 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:17.315431118 CET | 49794 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:17.427928925 CET | 49805 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:17.435002089 CET | 59060 | 49794 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:17.547877073 CET | 59060 | 49805 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:17.547954082 CET | 49805 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:17.548139095 CET | 49805 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:17.667715073 CET | 59060 | 49805 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:20.206419945 CET | 59060 | 49805 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:20.206541061 CET | 49805 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:20.206563950 CET | 49805 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:20.325421095 CET | 49811 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:20.326260090 CET | 59060 | 49805 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:20.445081949 CET | 59060 | 49811 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:20.445197105 CET | 49811 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:20.445466042 CET | 49811 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:20.571774960 CET | 59060 | 49811 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:23.112092972 CET | 59060 | 49811 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:23.112154007 CET | 49811 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:23.112220049 CET | 49811 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:23.225373030 CET | 49817 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:23.231843948 CET | 59060 | 49811 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:23.509383917 CET | 59060 | 49817 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:23.509493113 CET | 49817 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:23.509773970 CET | 49817 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:23.629334927 CET | 59060 | 49817 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:26.230084896 CET | 59060 | 49817 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:26.230192900 CET | 49817 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:26.230300903 CET | 49817 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:26.333434105 CET | 49823 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:26.349837065 CET | 59060 | 49817 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:26.454288006 CET | 59060 | 49823 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:26.454466105 CET | 49823 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:26.454684973 CET | 49823 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:26.574361086 CET | 59060 | 49823 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:29.189400911 CET | 59060 | 49823 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:29.189460039 CET | 49823 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:29.189522982 CET | 49823 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:29.302544117 CET | 49829 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:29.309094906 CET | 59060 | 49823 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:29.422203064 CET | 59060 | 49829 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:29.422276020 CET | 49829 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:29.422482967 CET | 49829 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:29.545082092 CET | 59060 | 49829 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:32.103863001 CET | 59060 | 49829 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:32.105460882 CET | 49829 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:32.105462074 CET | 49829 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:32.209331036 CET | 49839 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:32.225203037 CET | 59060 | 49829 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:32.328928947 CET | 59060 | 49839 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:32.329576015 CET | 49839 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:32.329576015 CET | 49839 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:32.450042009 CET | 59060 | 49839 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:35.046013117 CET | 59060 | 49839 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:35.046125889 CET | 49839 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:35.046247959 CET | 49839 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:35.162214994 CET | 49846 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:35.165822983 CET | 59060 | 49839 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:35.281780958 CET | 59060 | 49846 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:35.281923056 CET | 49846 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:35.282052994 CET | 49846 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:35.401596069 CET | 59060 | 49846 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:37.940637112 CET | 59060 | 49846 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:37.940700054 CET | 49846 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:37.940817118 CET | 49846 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:38.053219080 CET | 49852 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:38.062377930 CET | 59060 | 49846 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:38.172900915 CET | 59060 | 49852 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:38.173069000 CET | 49852 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:38.175260067 CET | 49852 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:38.295310974 CET | 59060 | 49852 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:40.831753969 CET | 59060 | 49852 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:40.833436966 CET | 49852 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:40.833533049 CET | 49852 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:40.949373960 CET | 49858 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:40.953280926 CET | 59060 | 49852 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:41.070861101 CET | 59060 | 49858 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:41.073452950 CET | 49858 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:41.077363968 CET | 49858 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:41.197103977 CET | 59060 | 49858 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:43.731386900 CET | 59060 | 49858 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:43.731451035 CET | 49858 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:43.731550932 CET | 49858 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:43.850842953 CET | 49869 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:43.854172945 CET | 59060 | 49858 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:43.975255013 CET | 59060 | 49869 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:43.975339890 CET | 49869 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:43.975519896 CET | 49869 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:44.095278025 CET | 59060 | 49869 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:46.671401978 CET | 59060 | 49869 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:46.671468973 CET | 49869 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:46.671612978 CET | 49869 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:46.789351940 CET | 49875 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:46.791106939 CET | 59060 | 49869 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:46.910106897 CET | 59060 | 49875 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:46.910197973 CET | 49875 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:46.910454988 CET | 49875 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:47.030015945 CET | 59060 | 49875 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:49.565959930 CET | 59060 | 49875 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:49.566009998 CET | 49875 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:49.566128016 CET | 49875 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:49.678575993 CET | 49881 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:49.689160109 CET | 59060 | 49875 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:49.798221111 CET | 59060 | 49881 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:49.798290968 CET | 49881 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:49.798528910 CET | 49881 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:49.923557043 CET | 59060 | 49881 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:52.473210096 CET | 59060 | 49881 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:52.473411083 CET | 49881 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:52.473582029 CET | 49881 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:52.585360050 CET | 49887 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:52.593095064 CET | 59060 | 49881 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:52.705117941 CET | 59060 | 49887 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:52.705255032 CET | 49887 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:52.706290007 CET | 49887 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:52.825978041 CET | 59060 | 49887 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:55.539190054 CET | 59060 | 49887 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:55.539263010 CET | 49887 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:55.540455103 CET | 49887 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:55.646775961 CET | 49896 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:55.661164045 CET | 59060 | 49887 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:55.766330004 CET | 59060 | 49896 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:55.766413927 CET | 49896 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:55.766638041 CET | 49896 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:55.888631105 CET | 59060 | 49896 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:58.426526070 CET | 59060 | 49896 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:58.426728964 CET | 49896 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:58.426814079 CET | 49896 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:58.536645889 CET | 49904 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:58.546593904 CET | 59060 | 49896 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:58.656606913 CET | 59060 | 49904 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:29:58.656872988 CET | 49904 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:58.656970024 CET | 49904 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:29:58.776513100 CET | 59060 | 49904 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:01.355679989 CET | 59060 | 49904 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:01.355750084 CET | 49904 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:01.355839968 CET | 49904 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:01.458798885 CET | 49910 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:01.475378990 CET | 59060 | 49904 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:01.580722094 CET | 59060 | 49910 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:01.580812931 CET | 49910 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:01.581043959 CET | 49910 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:01.700673103 CET | 59060 | 49910 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:04.261286020 CET | 59060 | 49910 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:04.261831045 CET | 49910 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:04.261929035 CET | 49910 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:04.365428925 CET | 49916 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:04.381567955 CET | 59060 | 49910 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:04.485116959 CET | 59060 | 49916 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:04.487509966 CET | 49916 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:04.487708092 CET | 49916 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:04.607249975 CET | 59060 | 49916 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:07.143734932 CET | 59060 | 49916 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:07.144331932 CET | 49916 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:07.144526958 CET | 49916 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:07.255527020 CET | 49925 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:07.263931036 CET | 59060 | 49916 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:07.375387907 CET | 59060 | 49925 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:07.375474930 CET | 49925 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:07.375737906 CET | 49925 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:07.495448112 CET | 59060 | 49925 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:10.036117077 CET | 59060 | 49925 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:10.036173105 CET | 49925 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:10.036263943 CET | 49925 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:10.146622896 CET | 49933 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:10.159163952 CET | 59060 | 49925 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:10.267723083 CET | 59060 | 49933 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:10.268042088 CET | 49933 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:10.273402929 CET | 49933 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:10.395725965 CET | 59060 | 49933 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:12.924824953 CET | 59060 | 49933 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:12.925060034 CET | 49933 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:12.925060034 CET | 49933 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:13.037429094 CET | 49939 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:13.044684887 CET | 59060 | 49933 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:13.159260035 CET | 59060 | 49939 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:13.159411907 CET | 49939 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:13.159877062 CET | 49939 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:13.486232996 CET | 59060 | 49939 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:16.035536051 CET | 59060 | 49939 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:16.035599947 CET | 49939 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:16.035732985 CET | 49939 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:16.147144079 CET | 49945 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:16.155189991 CET | 59060 | 49939 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:16.266839981 CET | 59060 | 49945 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:16.268884897 CET | 49945 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:16.272543907 CET | 49945 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:16.392177105 CET | 59060 | 49945 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:18.925544024 CET | 59060 | 49945 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:18.931746960 CET | 49945 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:18.932109118 CET | 49945 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:19.037403107 CET | 49954 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:19.051522970 CET | 59060 | 49945 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:19.157145977 CET | 59060 | 49954 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:19.157583952 CET | 49954 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:19.157583952 CET | 49954 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:19.277087927 CET | 59060 | 49954 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:21.832463980 CET | 59060 | 49954 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:21.832539082 CET | 49954 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:21.832581997 CET | 49954 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:21.944772959 CET | 49962 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:21.952322960 CET | 59060 | 49954 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:22.064637899 CET | 59060 | 49962 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:22.064740896 CET | 49962 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:22.064928055 CET | 49962 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:22.185148001 CET | 59060 | 49962 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:24.723762035 CET | 59060 | 49962 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:24.725469112 CET | 49962 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:24.725579023 CET | 49962 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:24.833586931 CET | 49968 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:24.845232964 CET | 59060 | 49962 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:24.953109980 CET | 59060 | 49968 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:24.955570936 CET | 49968 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:24.961429119 CET | 49968 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:25.081486940 CET | 59060 | 49968 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:27.613040924 CET | 59060 | 49968 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:27.613095045 CET | 49968 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:27.613149881 CET | 49968 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:27.725446939 CET | 49973 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:27.732889891 CET | 59060 | 49968 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:27.845037937 CET | 59060 | 49973 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:27.845117092 CET | 49973 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:27.845325947 CET | 49973 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:27.966254950 CET | 59060 | 49973 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:30.503401995 CET | 59060 | 49973 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:30.503530979 CET | 49973 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:30.503642082 CET | 49973 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:30.623066902 CET | 59060 | 49973 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:30.624186039 CET | 49978 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:30.743916988 CET | 59060 | 49978 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:30.744081974 CET | 49978 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:30.744345903 CET | 49978 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:30.864121914 CET | 59060 | 49978 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:33.410553932 CET | 59060 | 49978 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:33.410619974 CET | 49978 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:33.410713911 CET | 49978 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:33.522068977 CET | 49987 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:33.530293941 CET | 59060 | 49978 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:33.641638041 CET | 59060 | 49987 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:33.641710043 CET | 49987 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:33.642071962 CET | 49987 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:33.761821032 CET | 59060 | 49987 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:36.316817999 CET | 59060 | 49987 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:36.319540024 CET | 49987 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:36.319622040 CET | 49987 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:36.430314064 CET | 49994 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:36.461288929 CET | 59060 | 49987 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:36.581005096 CET | 59060 | 49994 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:36.583951950 CET | 49994 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:36.584374905 CET | 49994 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:36.704761982 CET | 59060 | 49994 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:39.298399925 CET | 59060 | 49994 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:39.298481941 CET | 49994 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:39.298763990 CET | 49994 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:39.413134098 CET | 50000 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:39.418293953 CET | 59060 | 49994 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:39.532872915 CET | 59060 | 50000 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:39.532941103 CET | 50000 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:39.533180952 CET | 50000 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:39.652695894 CET | 59060 | 50000 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:42.223833084 CET | 59060 | 50000 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:42.223933935 CET | 50000 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:42.223985910 CET | 50000 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:42.337469101 CET | 50009 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:42.343713045 CET | 59060 | 50000 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:42.457485914 CET | 59060 | 50009 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:42.461509943 CET | 50009 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:42.461770058 CET | 50009 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:42.581305027 CET | 59060 | 50009 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:45.113858938 CET | 59060 | 50009 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:45.113944054 CET | 50009 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:45.122766018 CET | 50009 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:45.241350889 CET | 50016 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:45.243107080 CET | 59060 | 50009 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:45.363455057 CET | 59060 | 50016 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:45.363562107 CET | 50016 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:45.363850117 CET | 50016 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:45.483381987 CET | 59060 | 50016 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:48.020108938 CET | 59060 | 50016 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:48.020190954 CET | 50016 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:48.020288944 CET | 50016 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:48.131387949 CET | 50022 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:48.186465979 CET | 59060 | 50016 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:48.251367092 CET | 59060 | 50022 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:48.253293991 CET | 50022 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:48.253293991 CET | 50022 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:48.372956038 CET | 59060 | 50022 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:50.909996986 CET | 59060 | 50022 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:50.913583994 CET | 50022 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:50.917469978 CET | 50022 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:51.022778988 CET | 50029 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:51.036978006 CET | 59060 | 50022 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:51.142822981 CET | 59060 | 50029 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:51.145656109 CET | 50029 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:51.145812988 CET | 50029 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:51.268532038 CET | 59060 | 50029 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:53.801824093 CET | 59060 | 50029 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:53.801887035 CET | 50029 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:53.801969051 CET | 50029 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:53.912539005 CET | 50036 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:53.921555042 CET | 59060 | 50029 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:54.033088923 CET | 59060 | 50036 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:54.033155918 CET | 50036 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:54.033323050 CET | 50036 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:54.152776003 CET | 59060 | 50036 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:56.735111952 CET | 59060 | 50036 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:56.737649918 CET | 50036 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:56.738687992 CET | 50036 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:56.849514961 CET | 50045 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:56.858298063 CET | 59060 | 50036 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:56.971518993 CET | 59060 | 50045 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:56.973634958 CET | 50045 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:56.974014044 CET | 50045 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:57.095529079 CET | 59060 | 50045 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:59.629878998 CET | 59060 | 50045 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:59.629939079 CET | 50045 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:59.630018950 CET | 50045 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:59.741372108 CET | 50050 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:59.749857903 CET | 59060 | 50045 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:59.861047029 CET | 59060 | 50050 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:30:59.861116886 CET | 50050 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:59.861352921 CET | 50050 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:30:59.980786085 CET | 59060 | 50050 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:02.519850969 CET | 59060 | 50050 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:02.519994974 CET | 50050 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:02.519994974 CET | 50050 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:02.630422115 CET | 50056 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:02.659183025 CET | 59060 | 50050 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:02.750138044 CET | 59060 | 50056 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:02.750293970 CET | 50056 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:02.750802040 CET | 50056 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:02.871299982 CET | 59060 | 50056 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:05.411786079 CET | 59060 | 50056 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:05.411870956 CET | 50056 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:05.412240982 CET | 50056 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:05.521898031 CET | 50063 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:05.532038927 CET | 59060 | 50056 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:05.641504049 CET | 59060 | 50063 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:05.641573906 CET | 50063 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:05.641815901 CET | 50063 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:05.761378050 CET | 59060 | 50063 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:08.301745892 CET | 59060 | 50063 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:08.305535078 CET | 50063 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:08.305648088 CET | 50063 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:08.413490057 CET | 50067 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:08.425344944 CET | 59060 | 50063 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:08.538296938 CET | 59060 | 50067 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:08.541639090 CET | 50067 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:08.545495987 CET | 50067 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:08.670759916 CET | 59060 | 50067 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:11.207623959 CET | 59060 | 50067 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:11.209608078 CET | 50067 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:11.209608078 CET | 50067 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:11.319192886 CET | 50068 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:11.330179930 CET | 59060 | 50067 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:11.439435005 CET | 59060 | 50068 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:11.439524889 CET | 50068 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:11.439768076 CET | 50068 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:11.559969902 CET | 59060 | 50068 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:14.098051071 CET | 59060 | 50068 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:14.098124027 CET | 50068 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:14.099030018 CET | 50068 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:14.210242987 CET | 50069 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:14.218589067 CET | 59060 | 50068 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:14.331023932 CET | 59060 | 50069 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:14.335798025 CET | 50069 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:14.336307049 CET | 50069 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:14.455863953 CET | 59060 | 50069 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:16.988807917 CET | 59060 | 50069 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:16.988917112 CET | 50069 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:16.989059925 CET | 50069 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:17.101635933 CET | 50070 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:17.109639883 CET | 59060 | 50069 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:17.221447945 CET | 59060 | 50070 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:17.221600056 CET | 50070 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:17.221771002 CET | 50070 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:17.341250896 CET | 59060 | 50070 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:19.896161079 CET | 59060 | 50070 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:19.896222115 CET | 50070 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:19.896342039 CET | 50070 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:20.006856918 CET | 50071 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:20.015815973 CET | 59060 | 50070 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:20.126341105 CET | 59060 | 50071 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:20.126410007 CET | 50071 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:20.126601934 CET | 50071 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:20.246169090 CET | 59060 | 50071 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:22.845076084 CET | 59060 | 50071 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:22.845150948 CET | 50071 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:22.845253944 CET | 50071 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:22.958726883 CET | 50072 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:22.964870930 CET | 59060 | 50071 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:23.078520060 CET | 59060 | 50072 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:23.079722881 CET | 50072 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:23.079849958 CET | 50072 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:23.200109959 CET | 59060 | 50072 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:25.755268097 CET | 59060 | 50072 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:25.755345106 CET | 50072 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:25.772150040 CET | 50072 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:25.882299900 CET | 50073 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:25.891699076 CET | 59060 | 50072 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:26.001961946 CET | 59060 | 50073 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:26.002033949 CET | 50073 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:26.002208948 CET | 50073 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:26.122737885 CET | 59060 | 50073 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:28.660767078 CET | 59060 | 50073 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:28.660856962 CET | 50073 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:28.660974979 CET | 50073 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:28.772547960 CET | 50074 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:28.780559063 CET | 59060 | 50073 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:28.893815041 CET | 59060 | 50074 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:28.897706032 CET | 50074 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:28.897826910 CET | 50074 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:29.017288923 CET | 59060 | 50074 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:31.559768915 CET | 59060 | 50074 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:31.559824944 CET | 50074 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:31.559921980 CET | 50074 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:31.678514004 CET | 50075 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:31.681379080 CET | 59060 | 50074 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:31.800256968 CET | 59060 | 50075 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:31.800335884 CET | 50075 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:31.800551891 CET | 50075 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:31.921432018 CET | 59060 | 50075 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:34.517851114 CET | 59060 | 50075 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:34.521650076 CET | 50075 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:34.521650076 CET | 50075 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:34.633538961 CET | 50076 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:34.641894102 CET | 59060 | 50075 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:34.753243923 CET | 59060 | 50076 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:34.753393888 CET | 50076 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:34.753815889 CET | 50076 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:35.015242100 CET | 59060 | 50076 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:37.583408117 CET | 59060 | 50076 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:37.583462000 CET | 50076 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:37.583528042 CET | 50076 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:37.693984032 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:37.703119040 CET | 59060 | 50076 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:37.813515902 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:37.813596010 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:37.813818932 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:37.935028076 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:40.474548101 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:40.475090027 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:40.475234985 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:40.585547924 CET | 50078 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:40.785557032 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:41.055795908 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:41.056081057 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:41.056137085 CET | 59060 | 50078 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:41.056149960 CET | 59060 | 50077 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:41.056243896 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:41.056267023 CET | 50078 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:41.056358099 CET | 50077 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:41.056504965 CET | 50078 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:41.176073074 CET | 59060 | 50078 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:43.731837988 CET | 59060 | 50078 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:43.731887102 CET | 50078 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:43.731971025 CET | 50078 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:43.850303888 CET | 50079 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:43.851541996 CET | 59060 | 50078 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:43.969991922 CET | 59060 | 50079 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:43.970068932 CET | 50079 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:43.970377922 CET | 50079 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:44.089889050 CET | 59060 | 50079 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:46.631531954 CET | 59060 | 50079 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:46.633605003 CET | 50079 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:46.633671045 CET | 50079 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:46.740775108 CET | 50080 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:46.753174067 CET | 59060 | 50079 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:46.860582113 CET | 59060 | 50080 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:46.860682011 CET | 50080 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:46.860937119 CET | 50080 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:46.980849981 CET | 59060 | 50080 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:49.520464897 CET | 59060 | 50080 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:49.520544052 CET | 50080 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:49.520590067 CET | 50080 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:49.631028891 CET | 50081 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:49.640225887 CET | 59060 | 50080 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:49.750746965 CET | 59060 | 50081 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:49.750819921 CET | 50081 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:49.751136065 CET | 50081 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:49.870963097 CET | 59060 | 50081 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:52.411937952 CET | 59060 | 50081 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:52.413722038 CET | 50081 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:52.413722038 CET | 50081 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:52.521015882 CET | 50082 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:52.533343077 CET | 59060 | 50081 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:52.640676975 CET | 59060 | 50082 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:52.640818119 CET | 50082 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:52.641571045 CET | 50082 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:52.762439966 CET | 59060 | 50082 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:55.302402973 CET | 59060 | 50082 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:55.302479029 CET | 50082 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:55.302933931 CET | 50082 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:55.413165092 CET | 50083 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:55.422420979 CET | 59060 | 50082 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:55.534677982 CET | 59060 | 50083 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:55.534775972 CET | 50083 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:55.534957886 CET | 50083 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:55.654504061 CET | 59060 | 50083 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:58.236124039 CET | 59060 | 50083 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:58.236196041 CET | 50083 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:58.236236095 CET | 50083 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:58.349260092 CET | 50084 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:58.356400013 CET | 59060 | 50083 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:58.469794989 CET | 59060 | 50084 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:31:58.469934940 CET | 50084 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:58.470114946 CET | 50084 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:31:58.589824915 CET | 59060 | 50084 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:01.239901066 CET | 59060 | 50084 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:01.240048885 CET | 50084 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:32:01.240165949 CET | 50084 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:32:01.349574089 CET | 50085 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:32:01.359796047 CET | 59060 | 50084 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:01.470118999 CET | 59060 | 50085 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:01.470205069 CET | 50085 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:32:01.470427990 CET | 50085 | 59060 | 192.168.2.4 | 152.42.226.16 |
Dec 26, 2024 19:32:01.591388941 CET | 59060 | 50085 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:04.130444050 CET | 59060 | 50085 | 152.42.226.16 | 192.168.2.4 |
Dec 26, 2024 19:32:04.130503893 CET | 50085 | 59060 | 192.168.2.4 | 152.42.226.16 |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:27:58.501960039 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49731 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:01.404603958 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49732 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:04.326299906 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49733 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:07.245825052 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49734 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:10.171814919 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49735 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:13.248894930 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49737 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:16.155977964 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.4 | 49741 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:19.110304117 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.4 | 49743 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:22.092303991 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.4 | 49745 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:25.001307964 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.4 | 49746 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:27.889086008 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.4 | 49747 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:30.810631990 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.4 | 49748 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:33.727039099 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.4 | 49749 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:36.613922119 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.4 | 49750 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:39.532476902 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.4 | 49751 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:42.453362942 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.4 | 49752 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:45.440135956 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.4 | 49753 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:48.397075891 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.4 | 49754 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:51.315757036 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.4 | 49755 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:54.218161106 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.4 | 49758 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:28:57.203973055 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.4 | 49764 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:00.131360054 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.4 | 49770 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:03.033688068 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.4 | 49776 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:05.984513998 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.4 | 49782 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:08.875693083 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.4 | 49788 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:11.766458035 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.4 | 49794 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:14.654863119 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.4 | 49805 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:17.548139095 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.4 | 49811 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:20.445466042 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.4 | 49817 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:23.509773970 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.4 | 49823 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:26.454684973 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.4 | 49829 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:29.422482967 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.4 | 49839 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:32.329576015 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.4 | 49846 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:35.282052994 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.4 | 49852 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:38.175260067 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.4 | 49858 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:41.077363968 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.4 | 49869 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:43.975519896 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.4 | 49875 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:46.910454988 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.4 | 49881 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:49.798528910 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.4 | 49887 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:52.706290007 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.4 | 49896 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:55.766638041 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.4 | 49904 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:29:58.656970024 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.4 | 49910 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:01.581043959 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.4 | 49916 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:04.487708092 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
44 | 192.168.2.4 | 49925 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:07.375737906 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
45 | 192.168.2.4 | 49933 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:10.273402929 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
46 | 192.168.2.4 | 49939 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:13.159877062 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
47 | 192.168.2.4 | 49945 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:16.272543907 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
48 | 192.168.2.4 | 49954 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:19.157583952 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
49 | 192.168.2.4 | 49962 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:22.064928055 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
50 | 192.168.2.4 | 49968 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:24.961429119 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
51 | 192.168.2.4 | 49973 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:27.845325947 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
52 | 192.168.2.4 | 49978 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:30.744345903 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
53 | 192.168.2.4 | 49987 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:33.642071962 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
54 | 192.168.2.4 | 49994 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:36.584374905 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
55 | 192.168.2.4 | 50000 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:39.533180952 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
56 | 192.168.2.4 | 50009 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:42.461770058 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
57 | 192.168.2.4 | 50016 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:45.363850117 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
58 | 192.168.2.4 | 50022 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:48.253293991 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
59 | 192.168.2.4 | 50029 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:51.145812988 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
60 | 192.168.2.4 | 50036 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:54.033323050 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
61 | 192.168.2.4 | 50045 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:56.974014044 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
62 | 192.168.2.4 | 50050 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:30:59.861352921 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
63 | 192.168.2.4 | 50056 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:02.750802040 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
64 | 192.168.2.4 | 50063 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:05.641815901 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
65 | 192.168.2.4 | 50067 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:08.545495987 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
66 | 192.168.2.4 | 50068 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:11.439768076 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
67 | 192.168.2.4 | 50069 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:14.336307049 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
68 | 192.168.2.4 | 50070 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:17.221771002 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
69 | 192.168.2.4 | 50071 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:20.126601934 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
70 | 192.168.2.4 | 50072 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:23.079849958 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
71 | 192.168.2.4 | 50073 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:26.002208948 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
72 | 192.168.2.4 | 50074 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:28.897826910 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
73 | 192.168.2.4 | 50075 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:31.800551891 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
74 | 192.168.2.4 | 50076 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:34.753815889 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
75 | 192.168.2.4 | 50077 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:37.813818932 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
76 | 192.168.2.4 | 50078 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:41.056504965 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
77 | 192.168.2.4 | 50079 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:43.970377922 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
78 | 192.168.2.4 | 50080 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:46.860937119 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
79 | 192.168.2.4 | 50081 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:49.751136065 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
80 | 192.168.2.4 | 50082 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:52.641571045 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
81 | 192.168.2.4 | 50083 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:55.534957886 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
82 | 192.168.2.4 | 50084 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:31:58.470114946 CET | 380 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
83 | 192.168.2.4 | 50085 | 152.42.226.16 | 59060 | 7324 | C:\Users\user\Desktop\12.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Dec 26, 2024 19:32:01.470427990 CET | 380 | OUT |
Target ID: | 0 |
Start time: | 13:27:56 |
Start date: | 26/12/2024 |
Path: | C:\Users\user\Desktop\12.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 324'096 bytes |
MD5 hash: | C8C40C038A4A8541E0924520599D8C28 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 2.4% |
Dynamic/Decrypted Code Coverage: | 89.5% |
Signature Coverage: | 18.1% |
Total number of Nodes: | 591 |
Total number of Limit Nodes: | 17 |
Graph
Function 00DB2C3F Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 186networkfileCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2C3F Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 186networkfileCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB7F09 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 123COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DBEF82 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 44encryptionCOMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401805 Relevance: 21.0, APIs: 3, Strings: 9, Instructions: 31threadCOMMON
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB131C Relevance: 7.8, APIs: 5, Instructions: 308COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 0040156C Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 47memorythreadCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401296 Relevance: 5.1, APIs: 4, Instructions: 79stringCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004013B3 Relevance: 5.1, APIs: 4, Instructions: 65stringCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DB2F1B Relevance: 4.6, APIs: 3, Instructions: 68networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2F1B Relevance: 4.6, APIs: 3, Instructions: 68networkCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401700 Relevance: 4.5, APIs: 3, Instructions: 49fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004017AC Relevance: 4.5, APIs: 2, Strings: 1, Instructions: 26sleepCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DB273C Relevance: 3.1, APIs: 2, Instructions: 115networkCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2E6E Relevance: 3.0, APIs: 2, Instructions: 50networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2E6E Relevance: 3.0, APIs: 2, Instructions: 50networkCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBA802 Relevance: 1.6, APIs: 1, Instructions: 70memoryCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DC3EF7 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DCA68A Relevance: 1.5, APIs: 1, Instructions: 20memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7A860 Relevance: 1.3, APIs: 1, Instructions: 93memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB54A0 Relevance: 1.3, APIs: 1, Instructions: 31sleepCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004029E0 Relevance: 1.3, APIs: 1, Instructions: 14sleepCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DB5225 Relevance: 24.7, APIs: 10, Strings: 4, Instructions: 172filetimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBA4E3 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 157processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBA70E Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 84fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4763 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 98processCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4763 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 98processCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB8699 Relevance: 9.1, APIs: 6, Instructions: 68networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB85B7 Relevance: 9.1, APIs: 6, Instructions: 54networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401A60 Relevance: 7.6, APIs: 5, Instructions: 55COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401A5C Relevance: 7.5, APIs: 5, Instructions: 47COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00DBEDB3 Relevance: 7.5, APIs: 5, Instructions: 45networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB21D8 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 131libraryloaderCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB21D8 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 131libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB3685 Relevance: 4.6, APIs: 3, Instructions: 68sleepCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBE442 Relevance: 4.5, APIs: 3, Instructions: 42memoryCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD8190 Relevance: .4, Instructions: 435COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D97590 Relevance: .4, Instructions: 435COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD7BC0 Relevance: .4, Instructions: 406COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D96FC0 Relevance: .4, Instructions: 406COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD58FD Relevance: .4, Instructions: 384COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D94CFD Relevance: .4, Instructions: 384COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD54DD Relevance: .4, Instructions: 378COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D948DD Relevance: .4, Instructions: 378COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD50D1 Relevance: .4, Instructions: 361COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D944D1 Relevance: .4, Instructions: 361COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD4CFD Relevance: .4, Instructions: 351COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D940FD Relevance: .4, Instructions: 351COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBB870 Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBABA0 Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7AC70 Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D79FA0 Relevance: .2, Instructions: 182COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D8282F Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DC59E9 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D84DE9 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DD7945 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D96D45 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB8B1A Relevance: 30.0, APIs: 16, Strings: 1, Instructions: 210networkCOMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2962 Relevance: 26.4, APIs: 13, Strings: 2, Instructions: 196networksleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB2962 Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 196networksleepCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4870 Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 184processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB8919 Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 69networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBE114 Relevance: 16.6, APIs: 11, Instructions: 122COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D8CD61 Relevance: 16.6, APIs: 11, Instructions: 105COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB8853 Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 59networksleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB66BF Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 111threadsleepprocessCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB5EEC Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 73COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4B7A Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 130processCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00401C80 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 124filememoryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00402110 Relevance: 12.1, APIs: 8, Instructions: 90COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB6072 Relevance: 10.7, APIs: 7, Instructions: 184COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4870 Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 184processCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBE65A Relevance: 10.6, APIs: 7, Instructions: 81COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB5FB6 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 72COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB7C49 Relevance: 10.6, APIs: 7, Instructions: 59COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB8E51 Relevance: 9.1, APIs: 6, Instructions: 113networkCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB94FD Relevance: 9.1, APIs: 6, Instructions: 91threadCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4B7A Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 130processCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB3927 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 96COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB690F Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 79libraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB18D3 Relevance: 7.6, APIs: 5, Instructions: 75COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB18D3 Relevance: 7.6, APIs: 5, Instructions: 75COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4A7E Relevance: 7.6, APIs: 5, Instructions: 65processCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB71C8 Relevance: 7.6, APIs: 5, Instructions: 62pipeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB3615 Relevance: 7.5, APIs: 5, Instructions: 45networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7E06F Relevance: 7.5, APIs: 5, Instructions: 45COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DC8722 Relevance: 7.5, APIs: 5, Instructions: 44memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBC0FD Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 140COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB6BCF Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 35libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB6BCF Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 35libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB67F1 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 29libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4354 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 22libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4354 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 22libraryloaderCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB5450 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 13libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB5475 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 13libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB1DEA Relevance: 6.4, APIs: 4, Instructions: 389COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4CCD Relevance: 6.1, APIs: 4, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB4CCD Relevance: 6.1, APIs: 4, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB3F99 Relevance: 6.1, APIs: 4, Instructions: 138COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB3F99 Relevance: 6.1, APIs: 4, Instructions: 138COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB7303 Relevance: 6.1, APIs: 4, Instructions: 106sleepCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB7303 Relevance: 6.1, APIs: 4, Instructions: 106sleepCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB6C20 Relevance: 6.1, APIs: 4, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB6C20 Relevance: 6.1, APIs: 4, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB7017 Relevance: 6.1, APIs: 4, Instructions: 81synchronizationCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB32EC Relevance: 6.1, APIs: 4, Instructions: 76synchronizationpipeCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB32EC Relevance: 6.1, APIs: 4, Instructions: 76synchronizationpipeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D70CD3 Relevance: 6.1, APIs: 4, Instructions: 75COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB113A Relevance: 6.1, APIs: 4, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DB113A Relevance: 6.1, APIs: 4, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7053A Relevance: 6.1, APIs: 4, Instructions: 71COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBC8C3 Relevance: 6.1, APIs: 4, Instructions: 63COMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7BCC3 Relevance: 6.1, APIs: 4, Instructions: 63COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBDE47 Relevance: 6.0, APIs: 4, Instructions: 46sleepsynchronizationthreadCOMMONLIBRARYCODE
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBE0A1 Relevance: 6.0, APIs: 4, Instructions: 42threadCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBED4F Relevance: 6.0, APIs: 4, Instructions: 40networkCOMMON
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBCF6B Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 141COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00D7C36B Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 141COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00DBC072 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 37COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 004022C0 Relevance: 5.0, APIs: 4, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|