Windows
Analysis Report
XClient.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64_ra
- XClient.exe (PID: 6524 cmdline:
"C:\Users\ user\Deskt op\XClient .exe" MD5: CA1B3F03551F41B8C83217C3AF2B0D3C)
- XClient.exe (PID: 4992 cmdline:
"C:\Users\ user\Deskt op\XClient .exe" MD5: CA1B3F03551F41B8C83217C3AF2B0D3C)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
{"C2 url": ["144.48.105.119"], "Port": 7000, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.6"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm_1 | Yara detected XWorm | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T20:13:41.777567+0100 | 2853685 | 1 | A Network Trojan was detected | 192.168.2.16 | 49702 | 149.154.167.220 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T20:14:59.749315+0100 | 2855924 | 1 | Malware Command and Control Activity Detected | 192.168.2.16 | 49733 | 144.48.105.119 | 7000 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T20:13:41.777567+0100 | 1810007 | 1 | Potentially Bad Traffic | 192.168.2.16 | 49702 | 149.154.167.220 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | DNS query: |
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: |
Source: | Window created: | Jump to behavior | ||
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FFEC82A9A4A | |
Source: | Code function: | 0_2_00007FFEC82A2E3A | |
Source: | Code function: | 0_2_00007FFEC82A060A | |
Source: | Code function: | 0_2_00007FFEC82A06EA | |
Source: | Code function: | 12_2_00007FFEC82A06EA | |
Source: | Code function: | 12_2_00007FFEC82A060A |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 1 Disable or Modify Tools | 1 Input Capture | 121 Security Software Discovery | Remote Services | 1 Input Capture | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 131 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | 1 Clipboard Data | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 11 Obfuscated Files or Information | LSA Secrets | 13 System Information Discovery | SSH | Keylogging | 3 Non-Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 2 Software Packing | Cached Domain Credentials | Wi-Fi Discovery | VNC | GUI Input Capture | 14 Application Layer Protocol | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
76% | ReversingLabs | Win32.Exploit.Xworm | ||
100% | Avira | TR/Spy.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
api.telegram.org | 149.154.167.220 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | false | |
144.48.105.119 | unknown | Singapore | 63018 | DEDICATEDUS | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1582524 |
Start date and time: | 2024-12-30 20:13:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | XClient.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@2/0@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 4.175.87.197, 184.28.90.27
- Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target XClient.exe, PID 4992 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- VT rate limit hit for: XClient.exe
Time | Type | Description |
---|---|---|
14:13:41 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
149.154.167.220 | Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | ||
Get hash | malicious | LummaC | Browse | |||
Get hash | malicious | Luca Stealer, Rusty Stealer | Browse | |||
Get hash | malicious | LummaC, Amadey, AsyncRAT, LummaC Stealer, Stealc, StormKitty, Vidar | Browse | |||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | LummaC, Amadey, LummaC Stealer, RedLine | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Babadeda | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
api.telegram.org | Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Luca Stealer, Rusty Stealer | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Babadeda | Browse |
| ||
Get hash | malicious | Babadeda | Browse |
| ||
Get hash | malicious | Babadeda | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | Vidar | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Luca Stealer, Rusty Stealer | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
DEDICATEDUS | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | SmokeLoader | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LodaRAT, XRed | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | LummaC | Browse |
|
File type: | |
Entropy (8bit): | 5.598050581972324 |
TrID: |
|
File name: | XClient.exe |
File size: | 40'960 bytes |
MD5: | ca1b3f03551f41b8c83217c3af2b0d3c |
SHA1: | 7cebd14139aad3b194080a7210c78a6587de1de5 |
SHA256: | e62ef733237ababe82f6b2109c70159744994515bc941b8ed025de10bb8aa624 |
SHA512: | c2044ae1a0b76c02ac8952fd205cbcf3ff1a9dbb491af1e9a18d7b212bdedd7d22fda7e3ba8b081b1279ae7d6e8951c2008eb79c9227a0c5f6a98c209c9ac10b |
SSDEEP: | 768:I7tEWUj10f2kgAWMLxOc2O5Ft9jwO+hdFuk:aKjPIV2wFt9jwO+3Ek |
TLSH: | A0034C04B7E14626DAEE6BF019F366060630E617DD17EB8E1CD499DA1B3BA80CD413E6 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...o.rg................................. ........@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x40b50e |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6772CD6F [Mon Dec 30 16:42:23 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xb4b8 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc000 | 0x4d8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x9514 | 0x9600 | 5764ca3132be3244f35079ef92569dc4 | False | 0.49747395833333335 | data | 5.719926020626053 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc000 | 0x4d8 | 0x600 | 2472af5ddbb53779b7381f16b8b9407b | False | 0.3756510416666667 | data | 3.7216503306685733 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0xc | 0x200 | e4691ef7dae40ff5e0b74653525043d4 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xc0a0 | 0x244 | data | 0.4724137931034483 | ||
RT_MANIFEST | 0xc2e8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2024-12-30T20:13:41.777567+0100 | 1810007 | Joe Security ANOMALY Telegram Send Message | 1 | 192.168.2.16 | 49702 | 149.154.167.220 | 443 | TCP |
2024-12-30T20:13:41.777567+0100 | 2853685 | ETPRO MALWARE Win32/XWorm Checkin via Telegram | 1 | 192.168.2.16 | 49702 | 149.154.167.220 | 443 | TCP |
2024-12-30T20:14:59.749315+0100 | 2855924 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.16 | 49733 | 144.48.105.119 | 7000 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 20:13:40.805891991 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:40.805927992 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:40.806025982 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:40.820647001 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:40.820688963 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.532702923 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.532816887 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:41.537188053 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:41.537219048 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.537647009 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.593182087 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:41.595483065 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:41.643332005 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.777589083 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.777645111 CET | 443 | 49702 | 149.154.167.220 | 192.168.2.16 |
Dec 30, 2024 20:13:41.777767897 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:41.856561899 CET | 49702 | 443 | 192.168.2.16 | 149.154.167.220 |
Dec 30, 2024 20:13:42.002224922 CET | 49703 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:42.007117987 CET | 7000 | 49703 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:42.007282972 CET | 49703 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:42.050957918 CET | 49703 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:42.055802107 CET | 7000 | 49703 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:43.602611065 CET | 7000 | 49703 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:43.602719069 CET | 49703 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:45.549318075 CET | 49703 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:45.551016092 CET | 49706 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:45.554155111 CET | 7000 | 49703 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:45.555876970 CET | 7000 | 49706 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:45.555967093 CET | 49706 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:45.572228909 CET | 49706 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:45.577008963 CET | 7000 | 49706 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:47.104125977 CET | 7000 | 49706 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:47.104212046 CET | 49706 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:49.395411968 CET | 49706 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:49.396564960 CET | 49711 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:49.400299072 CET | 7000 | 49706 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:49.401405096 CET | 7000 | 49711 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:49.401599884 CET | 49711 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:49.417012930 CET | 49711 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:49.421757936 CET | 7000 | 49711 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:51.103070974 CET | 7000 | 49711 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:51.103166103 CET | 49711 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:52.800225973 CET | 49712 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:52.800228119 CET | 49711 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:52.805123091 CET | 7000 | 49711 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:52.805161953 CET | 7000 | 49712 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:52.807154894 CET | 49712 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:52.823163033 CET | 49712 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:52.827982903 CET | 7000 | 49712 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:54.368104935 CET | 7000 | 49712 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:54.368208885 CET | 49712 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:56.956332922 CET | 49712 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:56.957577944 CET | 49713 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:56.961316109 CET | 7000 | 49712 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:56.962450027 CET | 7000 | 49713 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:56.962532043 CET | 49713 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:56.979473114 CET | 49713 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:13:56.984317064 CET | 7000 | 49713 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:58.507014990 CET | 7000 | 49713 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:13:58.507253885 CET | 49713 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:00.807307005 CET | 49713 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:00.808399916 CET | 49714 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:00.812304020 CET | 7000 | 49713 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:00.813250065 CET | 7000 | 49714 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:00.813349009 CET | 49714 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:00.828598976 CET | 49714 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:00.833549976 CET | 7000 | 49714 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:02.352765083 CET | 7000 | 49714 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:02.352843046 CET | 49714 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:03.957310915 CET | 49714 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:03.958199024 CET | 49715 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:03.962292910 CET | 7000 | 49714 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:03.963156939 CET | 7000 | 49715 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:03.963258982 CET | 49715 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:03.977523088 CET | 49715 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:03.982350111 CET | 7000 | 49715 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:05.618236065 CET | 7000 | 49715 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:05.618345022 CET | 49715 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:07.380345106 CET | 49715 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:07.381505966 CET | 49716 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:07.385282993 CET | 7000 | 49715 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:07.386409044 CET | 7000 | 49716 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:07.386504889 CET | 49716 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:07.402076960 CET | 49716 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:07.406990051 CET | 7000 | 49716 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:08.931176901 CET | 7000 | 49716 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:08.931334019 CET | 49716 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:11.215478897 CET | 49716 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:11.216619015 CET | 49717 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:11.220448971 CET | 7000 | 49716 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:11.221532106 CET | 7000 | 49717 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:11.221631050 CET | 49717 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:11.237302065 CET | 49717 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:11.242134094 CET | 7000 | 49717 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:12.856436968 CET | 7000 | 49717 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:12.856658936 CET | 49717 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:16.776381969 CET | 49717 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:16.777482033 CET | 49718 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:16.781394005 CET | 7000 | 49717 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:16.782377005 CET | 7000 | 49718 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:16.782468081 CET | 49718 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:16.799046040 CET | 49718 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:16.803841114 CET | 7000 | 49718 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:18.341010094 CET | 7000 | 49718 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:18.341170073 CET | 49718 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:20.434417009 CET | 49718 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:20.435575962 CET | 49719 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:20.439467907 CET | 7000 | 49718 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:20.440432072 CET | 7000 | 49719 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:20.440524101 CET | 49719 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:20.455895901 CET | 49719 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:20.460700035 CET | 7000 | 49719 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:21.993482113 CET | 7000 | 49719 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:21.993593931 CET | 49719 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:22.847409010 CET | 49719 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:22.848387003 CET | 49720 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:22.852339029 CET | 7000 | 49719 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:22.853358984 CET | 7000 | 49720 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:22.853456974 CET | 49720 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:22.868463993 CET | 49720 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:22.873266935 CET | 7000 | 49720 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:24.417490005 CET | 7000 | 49720 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:24.417706966 CET | 49720 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:26.276384115 CET | 49720 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:26.277167082 CET | 49722 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:26.281523943 CET | 7000 | 49720 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:26.282035112 CET | 7000 | 49722 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:26.282124043 CET | 49722 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:26.296772957 CET | 49722 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:26.301681995 CET | 7000 | 49722 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:27.839638948 CET | 7000 | 49722 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:27.839735031 CET | 49722 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:28.914414883 CET | 49722 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:28.915575027 CET | 49723 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:28.919363976 CET | 7000 | 49722 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:28.920500994 CET | 7000 | 49723 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:28.920594931 CET | 49723 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:28.935609102 CET | 49723 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:28.940433025 CET | 7000 | 49723 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:30.479022980 CET | 7000 | 49723 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:30.479135990 CET | 49723 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:31.135540962 CET | 49723 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:31.136390924 CET | 49724 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:31.141670942 CET | 7000 | 49723 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:31.143775940 CET | 7000 | 49724 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:31.143873930 CET | 49724 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:31.157807112 CET | 49724 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:31.162667990 CET | 7000 | 49724 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:32.696366072 CET | 7000 | 49724 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:32.696432114 CET | 49724 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:32.920411110 CET | 49724 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:32.921252966 CET | 49725 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:32.925323963 CET | 7000 | 49724 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:32.926135063 CET | 7000 | 49725 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:32.926230907 CET | 49725 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:32.940151930 CET | 49725 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:32.945009947 CET | 7000 | 49725 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:34.511468887 CET | 7000 | 49725 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:34.511548042 CET | 49725 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:35.093411922 CET | 49725 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:35.094355106 CET | 49726 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:35.098423958 CET | 7000 | 49725 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:35.099220037 CET | 7000 | 49726 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:35.099297047 CET | 49726 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:35.112306118 CET | 49726 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:35.117207050 CET | 7000 | 49726 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:36.775485039 CET | 7000 | 49726 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:36.775569916 CET | 49726 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:37.301428080 CET | 49726 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:37.302191973 CET | 49727 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:37.306344032 CET | 7000 | 49726 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:37.307105064 CET | 7000 | 49727 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:37.307188034 CET | 49727 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:37.321789980 CET | 49727 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:37.326611042 CET | 7000 | 49727 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:38.858503103 CET | 7000 | 49727 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:38.858580112 CET | 49727 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:39.474515915 CET | 49727 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:39.475229979 CET | 49728 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:39.479537010 CET | 7000 | 49727 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:39.480074883 CET | 7000 | 49728 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:39.480165958 CET | 49728 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:39.495151997 CET | 49728 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:39.500082970 CET | 7000 | 49728 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:41.027615070 CET | 7000 | 49728 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:41.027694941 CET | 49728 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:41.120405912 CET | 49728 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:41.121459007 CET | 49729 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:41.125233889 CET | 7000 | 49728 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:41.126382113 CET | 7000 | 49729 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:41.126462936 CET | 49729 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:41.139780045 CET | 49729 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:41.144637108 CET | 7000 | 49729 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:42.665252924 CET | 7000 | 49729 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:42.665429115 CET | 49729 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:42.686512947 CET | 49729 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:42.687299013 CET | 49730 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:42.691345930 CET | 7000 | 49729 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:42.692167997 CET | 7000 | 49730 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:42.692260027 CET | 49730 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:42.709459066 CET | 49730 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:42.714360952 CET | 7000 | 49730 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:44.242203951 CET | 7000 | 49730 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:44.242296934 CET | 49730 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:48.982522964 CET | 49730 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:48.984756947 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:48.987730980 CET | 7000 | 49730 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:48.989849091 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:48.989923000 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.006444931 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.011411905 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.051316023 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.056278944 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.062597036 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.067517042 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.094571114 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.099431992 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.110528946 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.115351915 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.126528978 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.131373882 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.142543077 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.147351027 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.174532890 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.179307938 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:49.399318933 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:49.608829975 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:50.635099888 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:50.635174036 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.398488998 CET | 49731 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.399661064 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.403538942 CET | 7000 | 49731 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.404541969 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.404633999 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.419476032 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.424274921 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.430996895 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.436326981 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.461621046 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.466521978 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.477705956 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.482537031 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.525624037 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.531038046 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.541559935 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.546438932 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.573584080 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.578408957 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.589576960 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.594436884 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.605561972 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.610388994 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.637753010 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.642868996 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:54.701586962 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:54.706429005 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:55.947626114 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:55.951387882 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.701316118 CET | 49732 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.705549002 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.706357002 CET | 7000 | 49732 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:59.710433006 CET | 7000 | 49733 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:59.717353106 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.729456902 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.734333038 CET | 7000 | 49733 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:14:59.749315023 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:14:59.754249096 CET | 7000 | 49733 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:01.277767897 CET | 7000 | 49733 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:01.283272028 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:04.754534006 CET | 49733 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:04.756056070 CET | 49734 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:04.759376049 CET | 7000 | 49733 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:04.760876894 CET | 7000 | 49734 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:04.760971069 CET | 49734 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:04.775459051 CET | 49734 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:04.780304909 CET | 7000 | 49734 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:06.324250937 CET | 7000 | 49734 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:06.324326992 CET | 49734 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:09.789855003 CET | 49734 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:09.789856911 CET | 49735 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:09.794779062 CET | 7000 | 49734 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:09.794790030 CET | 7000 | 49735 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:09.799309015 CET | 49735 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:09.811309099 CET | 49735 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:09.816163063 CET | 7000 | 49735 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:11.354947090 CET | 7000 | 49735 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:11.361931086 CET | 49735 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:14.821580887 CET | 49735 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:14.823112965 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:14.969042063 CET | 7000 | 49735 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:14.969059944 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:14.969175100 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:14.985213995 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:14.991628885 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:15.029675007 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:15.034519911 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:15.061642885 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:15.066468000 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:15.077652931 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:15.082454920 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:15.955323935 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:15.960150957 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:16.526101112 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:16.526164055 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:20.099337101 CET | 49736 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:20.099363089 CET | 49737 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:20.104255915 CET | 7000 | 49736 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:20.104266882 CET | 7000 | 49737 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:20.111362934 CET | 49737 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:20.123908997 CET | 49737 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:20.128726959 CET | 7000 | 49737 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:21.668632984 CET | 7000 | 49737 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:21.673516989 CET | 49737 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.129623890 CET | 49737 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.131107092 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.134476900 CET | 7000 | 49737 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:25.135905981 CET | 7000 | 49738 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:25.135967970 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.156759977 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.161626101 CET | 7000 | 49738 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:25.177671909 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:25.182472944 CET | 7000 | 49738 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:26.696139097 CET | 7000 | 49738 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:26.696197987 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.211347103 CET | 49738 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.215353966 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.216267109 CET | 7000 | 49738 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.220163107 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.223409891 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.239589930 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.244467020 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.257746935 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.262587070 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.544842005 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.549772978 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.560718060 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.565613985 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.576695919 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.581495047 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:30.591739893 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:30.596493959 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:31.778141975 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:31.778446913 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.611383915 CET | 49739 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.614392042 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.616286039 CET | 7000 | 49739 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:35.619249105 CET | 7000 | 49740 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:35.626384020 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.638386011 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.643232107 CET | 7000 | 49740 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:35.755377054 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:35.760164976 CET | 7000 | 49740 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:37.201652050 CET | 7000 | 49740 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:37.201772928 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.865643978 CET | 49740 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.867216110 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.871107101 CET | 7000 | 49740 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:40.872478008 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:40.872561932 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.887136936 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.891974926 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:40.929980040 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.934825897 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:40.961738110 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:40.966582060 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:41.009751081 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:41.014676094 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:41.025741100 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:41.030533075 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:41.073693037 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:41.078521967 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:43.264991045 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:43.265068054 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:43.265315056 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:43.265357018 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:43.265538931 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:43.265772104 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:48.855631113 CET | 49741 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:48.857700109 CET | 49742 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:48.860548019 CET | 7000 | 49741 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:48.862576962 CET | 7000 | 49742 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:48.865747929 CET | 49742 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:48.877449989 CET | 49742 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:48.882210016 CET | 7000 | 49742 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:50.477534056 CET | 7000 | 49742 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:50.477644920 CET | 49742 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:53.843677998 CET | 49742 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:53.844906092 CET | 49743 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:53.848566055 CET | 7000 | 49742 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:53.849746943 CET | 7000 | 49743 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:53.849843025 CET | 49743 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:53.860455990 CET | 49743 | 7000 | 192.168.2.16 | 144.48.105.119 |
Dec 30, 2024 20:15:53.865273952 CET | 7000 | 49743 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:55.403444052 CET | 7000 | 49743 | 144.48.105.119 | 192.168.2.16 |
Dec 30, 2024 20:15:55.403517962 CET | 49743 | 7000 | 192.168.2.16 | 144.48.105.119 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Dec 30, 2024 20:13:40.791917086 CET | 49895 | 53 | 192.168.2.16 | 1.1.1.1 |
Dec 30, 2024 20:13:40.799556017 CET | 53 | 49895 | 1.1.1.1 | 192.168.2.16 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Dec 30, 2024 20:13:40.791917086 CET | 192.168.2.16 | 1.1.1.1 | 0x5a35 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Dec 30, 2024 20:13:40.799556017 CET | 1.1.1.1 | 192.168.2.16 | 0x5a35 | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.16 | 49702 | 149.154.167.220 | 443 | 6524 | C:\Users\user\Desktop\XClient.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2024-12-30 19:13:41 UTC | 409 | OUT | |
2024-12-30 19:13:41 UTC | 344 | IN | |
2024-12-30 19:13:41 UTC | 55 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 14:13:36 |
Start date: | 30/12/2024 |
Path: | C:\Users\user\Desktop\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x9b0000 |
File size: | 40'960 bytes |
MD5 hash: | CA1B3F03551F41B8C83217C3AF2B0D3C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 12 |
Start time: | 14:15:24 |
Start date: | 30/12/2024 |
Path: | C:\Users\user\Desktop\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x170000 |
File size: | 40'960 bytes |
MD5 hash: | CA1B3F03551F41B8C83217C3AF2B0D3C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 17.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A06ED Relevance: .3, Instructions: 280COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A09BD Relevance: .2, Instructions: 167COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A0EB9 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A0EF8 Relevance: .1, Instructions: 57COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A10E4 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A1058 Relevance: .0, Instructions: 32COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A0E7C Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A12EF Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A10B9 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A0D96 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFEC82A0DB0 Relevance: .0, Instructions: 11COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|