Windows
Analysis Report
XClient.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- XClient.exe (PID: 6884 cmdline:
"C:\Users\ user\Deskt op\XClient .exe" MD5: 2E525CCEBF9EDE7492931251EB66571A) - schtasks.exe (PID: 5968 cmdline:
"C:\Window s\System32 \schtasks. exe" /crea te /f /RL HIGHEST /s c minute / mo 1 /tn " XClient" / tr "C:\Use rs\user\Ap pData\Roam ing\XClien t.exe" MD5: 76CD6626DD8834BD4A42E6A565104DC2) - conhost.exe (PID: 5800 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- XClient.exe (PID: 2132 cmdline:
C:\Users\u ser\AppDat a\Roaming\ XClient.ex e MD5: 2E525CCEBF9EDE7492931251EB66571A)
- XClient.exe (PID: 5180 cmdline:
C:\Users\u ser\AppDat a\Roaming\ XClient.ex e MD5: 2E525CCEBF9EDE7492931251EB66571A)
- XClient.exe (PID: 3592 cmdline:
C:\Users\u ser\AppDat a\Roaming\ XClient.ex e MD5: 2E525CCEBF9EDE7492931251EB66571A)
- XClient.exe (PID: 6496 cmdline:
C:\Users\u ser\AppDat a\Roaming\ XClient.ex e MD5: 2E525CCEBF9EDE7492931251EB66571A)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
{"C2 url": ["https://pastebin.com/raw/c8qJf1m5"], "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Version": "XWorm V5.6"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
JoeSecurity_XWorm | Yara detected XWorm | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
System Summary |
---|
Source: | Author: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): |
Source: | Author: Florian Roth (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-03T14:07:19.356985+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:26.053811+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:32.199336+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:45.057721+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:55.943481+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:57.899617+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:07.931512+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:08.429735+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:18.960693+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.225076+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.225960+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.312128+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.358606+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.477694+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:25.839737+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:25.963366+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.322721+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.409395+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.503593+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.597019+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.622947+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.716125+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.809161+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.894946+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.989565+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:35.084120+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:47.867467+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:48.601585+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:49.289059+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.461112+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.551238+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.644750+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.723432+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:53.336467+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:54.930018+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:55.851922+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:55.981477+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:58.211406+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:01.136759+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:06.476691+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:11.325602+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:13.336525+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:13.436101+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:20.229781+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:21.476571+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:21.576018+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:25.399402+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:25.944410+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:27.337864+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:27.338032+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:37.382583+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:37.699959+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:38.299166+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:47.195629+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:47.555250+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:52.648936+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:52.944630+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:55.941742+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:02.589170+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:03.048695+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:03.141843+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.195539+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.322235+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.415532+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:22.664732+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:24.610608+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:25.942800+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.711534+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.809849+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.903054+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.995921+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:35.088920+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.120046+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.213398+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.310161+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.403174+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:50.826218+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:50.920411+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:51.013312+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:51.106485+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:55.246273+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:55.942781+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:56.325098+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:59.308022+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:11:00.870752+0100 | 2852870 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-03T14:07:19.383879+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:32.200994+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:45.119776+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:57.900946+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:07.937369+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:08.431252+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:18.962533+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.314165+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.361315+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.479640+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:25.847864+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.328176+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.411984+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.505485+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.603256+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.624385+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.717433+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.810988+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.896488+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.991018+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.085619+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.178907+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.184981+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:47.869276+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:48.602944+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:49.297369+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.464486+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.552997+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.646220+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.725396+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.802939+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.897646+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.902763+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.995663+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.007122+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.088767+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.093644+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:53.342240+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:54.931644+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:55.858233+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:58.258236+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.138062+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.225686+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.322255+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:06.478780+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:11.330253+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:13.344413+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:13.440256+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:20.233278+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:21.484371+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:21.580271+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:25.403642+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:27.339604+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:27.344416+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:37.388404+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:37.704422+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:38.304303+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:47.197312+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:47.558589+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:52.650949+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:52.946369+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.039248+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.044482+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.263432+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:02.591056+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:03.050258+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:03.143437+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.203880+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.323976+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.417056+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:22.666304+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:24.612694+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.713528+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.811492+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.904303+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.997326+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:35.091153+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.121619+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.218478+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.311654+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.405751+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:50.828802+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:50.921759+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:51.015010+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:51.107738+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:55.248291+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:59.337165+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:11:00.871460+0100 | 2852923 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-03T14:07:26.053811+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:55.943481+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:25.963366+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:55.981477+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:25.944410+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:55.941742+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:25.942800+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:55.942781+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:56.325098+0100 | 2852874 | 1 | Malware Command and Control Activity Detected | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-03T14:08:19.131552+0100 | 2853193 | 1 | Malware Command and Control Activity Detected | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | DNS query: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Window created: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Code function: | 0_2_00007FFD9B88A312 | |
Source: | Code function: | 0_2_00007FFD9B88CDF4 | |
Source: | Code function: | 0_2_00007FFD9B889566 | |
Source: | Code function: | 0_2_00007FFD9B8805B8 | |
Source: | Code function: | 3_2_00007FFD9B8B0C5E | |
Source: | Code function: | 7_2_00007FFD9B890C5E | |
Source: | Code function: | 9_2_00007FFD9B8B0C5E | |
Source: | Code function: | 10_2_00007FFD9B8A0C5E |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Base64 encoded string: | ||
Source: | Base64 encoded string: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Code function: | 0_2_00007FFD9B8806EA | |
Source: | Code function: | 0_2_00007FFD9B88060A | |
Source: | Code function: | 0_2_00007FFD9B88060A | |
Source: | Code function: | 3_2_00007FFD9B8B060A | |
Source: | Code function: | 3_2_00007FFD9B8B06EA | |
Source: | Code function: | 7_2_00007FFD9B89060A | |
Source: | Code function: | 7_2_00007FFD9B8906EA | |
Source: | Code function: | 9_2_00007FFD9B8B060A | |
Source: | Code function: | 9_2_00007FFD9B8B06EA | |
Source: | Code function: | 10_2_00007FFD9B8A060A | |
Source: | Code function: | 10_2_00007FFD9B8A06EA |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | Process created: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | 1 Input Capture | 1 File and Directory Discovery | Remote Services | 11 Archive Collected Data | 1 Web Service | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 11 Process Injection | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 13 System Information Discovery | Remote Desktop Protocol | 1 Input Capture | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 2 Registry Run Keys / Startup Folder | 1 Scheduled Task/Job | 11 Obfuscated Files or Information | Security Account Manager | 1 Query Registry | SMB/Windows Admin Shares | 1 Clipboard Data | 11 Encrypted Channel | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 2 Registry Run Keys / Startup Folder | 2 Software Packing | NTDS | 211 Security Software Discovery | Distributed Component Object Model | Input Capture | 1 Non-Standard Port | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Process Discovery | SSH | Keylogging | 2 Non-Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Masquerading | Cached Domain Credentials | 131 Virtualization/Sandbox Evasion | VNC | GUI Input Capture | 13 Application Layer Protocol | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 131 Virtualization/Sandbox Evasion | DCSync | 1 Application Window Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | 11 Process Injection | Proc Filesystem | System Owner/User Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
74% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT | ||
68% | Virustotal | Browse | ||
100% | Avira | TR/Spy.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Spy.Gen | ||
100% | Joe Sandbox ML | |||
74% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT | ||
68% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
pastebin.com | 172.67.19.24 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
172.67.19.24 | pastebin.com | United States | 13335 | CLOUDFLARENETUS | false | |
87.120.125.47 | unknown | Bulgaria | 25206 | UNACS-AS-BG8000BurgasBG | true |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1583745 |
Start date and time: | 2025-01-03 14:06:04 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 42s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | XClient.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@8/3@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 52.149.20.212, 13.107.253.45
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target XClient.exe, PID 2132 because it is empty
- Execution Graph export aborted for target XClient.exe, PID 3592 because it is empty
- Execution Graph export aborted for target XClient.exe, PID 5180 because it is empty
- Execution Graph export aborted for target XClient.exe, PID 6496 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
08:07:05 | API Interceptor | |
13:06:59 | Task Scheduler | |
13:06:59 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
172.67.19.24 | Get hash | malicious | AsyncRAT | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AsyncRAT, XWorm | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
pastebin.com | Get hash | malicious | DCRat | Browse |
| |
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UNACS-AS-BG8000BurgasBG | Get hash | malicious | DcRat, JasonRAT | Browse |
| |
Get hash | malicious | DarkVision Rat | Browse |
| ||
Get hash | malicious | SmokeLoader | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | CobaltStrike | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Quasar | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Users\user\AppData\Roaming\XClient.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 654 |
Entropy (8bit): | 5.380476433908377 |
Encrypted: | false |
SSDEEP: | 12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6Khap+92n4MNQp3/VXM5gXu9tv:ML9E4KQwKDE4KGKZI6Kh6+84xp3/VclT |
MD5: | 30E4BDFC34907D0E4D11152CAEBE27FA |
SHA1: | 825402D6B151041BA01C5117387228EC9B7168BF |
SHA-256: | A7B8F7FFB4822570DB1423D61ED74D7F4B538CE73521CC8745BC6B131C18BE63 |
SHA-512: | 89FBCBCDB0BE5AD7A95685CF9AA4330D5B0250440E67DC40C6642260E024F52A402E9381F534A9824D2541B98B02094178A15BF2320148432EDB0D09B5F972BA |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\XClient.lnk
Download File
Process: | C:\Users\user\Desktop\XClient.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 764 |
Entropy (8bit): | 5.053190431527314 |
Encrypted: | false |
SSDEEP: | 12:8j324I9hTWC78dY//ILp0La/djAsKrHkfpqHrHoBmV:8jDI9ws8+kU0ZAsKYfpqHrHoBm |
MD5: | A7EF7354D416D3A12E1F1B289197CA04 |
SHA1: | 565B54A914DA690B7D1D2BDEF652004B6CA773A1 |
SHA-256: | E50C9E500CCC767E5D501C28AED1636301C62D8597A48F41B4B560AFFAC4679E |
SHA-512: | 2B557608928B2A77FD4F23736E3A22BC5C6ECCEC9EAD981CF8691B5E713429E76A4C40424E488E20F41CE0E270A3FEA63777E11DD62BA97B413975A29D21FBA7 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\XClient.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 41984 |
Entropy (8bit): | 5.594602217818213 |
Encrypted: | false |
SSDEEP: | 768:hJn0mOvGjMI5r2NpaNFu9vsOChR6RklT:ht0raCNaFu9vsOCLYmT |
MD5: | 2E525CCEBF9EDE7492931251EB66571A |
SHA1: | A0598BFFA349759FB3DCF130CF93ED41A3C3D8F4 |
SHA-256: | FDEFEDD8F02446DD47723F4B1829F685F64E76B9D29002545DD4C5D5257EAE29 |
SHA-512: | 2E459CA08A91FE27F0C3BE7BC73E5EC9E3B10B17CE99F11372DA0E0176E8647419E8C1B0478F0D3CE763246E92B84293AB42CE9769BB8BBF3F9B3D7DDA9FEA01 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.594602217818213 |
TrID: |
|
File name: | XClient.exe |
File size: | 41'984 bytes |
MD5: | 2e525ccebf9ede7492931251eb66571a |
SHA1: | a0598bffa349759fb3dcf130cf93ed41a3c3d8f4 |
SHA256: | fdefedd8f02446dd47723f4b1829f685f64e76b9d29002545dd4c5d5257eae29 |
SHA512: | 2e459ca08a91fe27f0c3be7bc73e5ec9e3b10b17ce99f11372da0e0176e8647419e8c1b0478f0d3ce763246e92b84293ab42ce9769bb8bbf3f9b3d7dda9fea01 |
SSDEEP: | 768:hJn0mOvGjMI5r2NpaNFu9vsOChR6RklT:ht0raCNaFu9vsOCLYmT |
TLSH: | 0A135C0837E04626D9FF6FF959F362030B31E5035913D7AE0CE5899B1B67B84CA4179A |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....!mg................................. ........@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x40b8de |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x676D21E8 [Thu Dec 26 09:29:12 2024 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xb888 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xc000 | 0x4d8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xe000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x98e4 | 0x9a00 | 671f9584bf24256d711c81f614358341 | False | 0.4957132711038961 | data | 5.713572049892492 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xc000 | 0x4d8 | 0x600 | 2472af5ddbb53779b7381f16b8b9407b | False | 0.3756510416666667 | data | 3.7216503306685733 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0xe000 | 0xc | 0x200 | 24f7d304061bf2d9404c5ca731b0cde8 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xc0a0 | 0x244 | data | 0.4724137931034483 | ||
RT_MANIFEST | 0xc2e8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-03T14:07:19.183005+0100 | 2855924 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:19.356985+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:19.383879+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:26.053811+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:26.053811+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:32.199336+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:32.200994+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:45.057721+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:45.119776+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:07:55.943481+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:55.943481+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:57.899617+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:07:57.900946+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:07.931512+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:07.937369+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:08.429735+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:08.431252+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:18.960693+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:18.962533+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.131552+0100 | 2853193 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.225076+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.225960+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.312128+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.314165+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.358606+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.361315+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:19.477694+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:19.479640+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:25.839737+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:25.847864+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:25.963366+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:25.963366+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.322721+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.328176+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.409395+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.411984+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.503593+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.505485+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:29.597019+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:29.603256+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.622947+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.624385+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.716125+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.717433+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.809161+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.810988+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.894946+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.896488+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:34.989565+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:34.991018+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.084120+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:35.085619+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.178907+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:35.184981+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:47.867467+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:47.869276+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:48.601585+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:48.602944+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:49.289059+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:49.297369+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.461112+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.464486+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.551238+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.552997+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.644750+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.646220+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.723432+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:50.725396+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.802939+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.897646+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.902763+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:50.995663+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.007122+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.088767+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:51.093644+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:53.336467+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:53.342240+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:54.930018+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:54.931644+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:55.851922+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:55.858233+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:08:55.981477+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:55.981477+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:58.211406+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:08:58.258236+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.136759+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:01.138062+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.225686+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:01.322255+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:06.476691+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:06.478780+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:11.325602+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:11.330253+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:13.336525+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:13.344413+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:13.436101+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:13.440256+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:20.229781+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:20.233278+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:21.476571+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:21.484371+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:21.576018+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:21.580271+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:25.399402+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:25.403642+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:25.944410+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:25.944410+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:27.337864+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:27.338032+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:27.339604+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:27.344416+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:37.382583+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:37.388404+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:37.699959+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:37.704422+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:38.299166+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:38.304303+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:47.195629+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:47.197312+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:47.555250+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:47.558589+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:52.648936+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:52.650949+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:52.944630+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:52.946369+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.039248+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.044482+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:53.263432+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:09:55.941742+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:09:55.941742+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:02.589170+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:02.591056+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:03.048695+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:03.050258+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:03.141843+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:03.143437+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.195539+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.203880+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.322235+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.323976+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:13.415532+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:13.417056+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:22.664732+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:22.666304+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:24.610608+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:24.612694+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:25.942800+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:25.942800+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.711534+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.713528+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.809849+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.811492+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.903054+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.904303+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:34.995921+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:34.997326+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:35.088920+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:35.091153+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.120046+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.121619+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.213398+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.218478+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.310161+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.311654+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:45.403174+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:45.405751+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:50.826218+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:50.828802+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:50.920411+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:50.921759+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:51.013312+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:51.015010+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:51.106485+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:51.107738+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:55.246273+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:55.248291+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:10:55.942781+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:55.942781+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:56.325098+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:56.325098+0100 | 2852874 | ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:59.308022+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:10:59.337165+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
2025-01-03T14:11:00.870752+0100 | 2852870 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes | 1 | 87.120.125.47 | 7000 | 192.168.2.4 | 49731 | TCP |
2025-01-03T14:11:00.871460+0100 | 2852923 | ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) | 1 | 192.168.2.4 | 49731 | 87.120.125.47 | 7000 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2025 14:07:00.570508957 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:00.570538998 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:00.570601940 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:00.591351032 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:00.591362953 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.072931051 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.073010921 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:01.077982903 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:01.077991009 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.078263044 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.131035089 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:01.141375065 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:01.187341928 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.633932114 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.633997917 CET | 443 | 49730 | 172.67.19.24 | 192.168.2.4 |
Jan 3, 2025 14:07:01.634056091 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:01.650686026 CET | 49730 | 443 | 192.168.2.4 | 172.67.19.24 |
Jan 3, 2025 14:07:05.869640112 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:05.874458075 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:05.874562979 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:06.324534893 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:06.329504967 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:19.183005095 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:19.187800884 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:19.356985092 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:19.383878946 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:19.388684034 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:26.053811073 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:26.099967003 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:32.022135973 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:32.027098894 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:32.199336052 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:32.200994015 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:32.205818892 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:44.884918928 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:44.889780045 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:45.057720900 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:45.099874020 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:45.119776011 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:45.124532938 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:55.943480968 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:55.990519047 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:57.725306034 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:57.730151892 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:57.899616957 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:07:57.900945902 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:07:57.905721903 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:07.756355047 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:07.762268066 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:07.931512117 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:07.937369108 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:07.942197084 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:08.256393909 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:08.261279106 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:08.429734945 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:08.431252003 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:08.436053991 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.787636995 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:18.792474031 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.834656000 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:18.839473009 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.881438971 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:18.886223078 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.960692883 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.962532997 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:18.967334986 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:18.990848064 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:18.995594025 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.006355047 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.011183977 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.131551981 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.225075960 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.225960016 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.226166964 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.266690969 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.266872883 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.271687031 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.312128067 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.314165115 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.318886995 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.358606100 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.361315012 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.406749010 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.477694035 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:19.479640007 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:19.484831095 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:25.664558887 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:25.669495106 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:25.839736938 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:25.847863913 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:25.852660894 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:25.963366032 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:26.008635998 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.147136927 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.151952982 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.209532976 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.214330912 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.225193024 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.229939938 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.242178917 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.246936083 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.322721004 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.328176022 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.333012104 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.409394979 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.411983967 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.416729927 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.503592968 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.505485058 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.510258913 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.597018957 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:29.603255987 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:29.608057022 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.444206953 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.449059010 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.459568977 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.464490891 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.521974087 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.526839972 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.584481955 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.589437962 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.622946978 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.624385118 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.670773029 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.716125011 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.717432976 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.722318888 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.740725040 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.745539904 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.803270102 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.808172941 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.809160948 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.810987949 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.862684965 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.862751007 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.867630959 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.894946098 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.896487951 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.946677923 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.989564896 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:34.991018057 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:34.995874882 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:35.084120035 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:35.085618973 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:35.091948986 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:35.177324057 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:35.178906918 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:35.184926033 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:35.184981108 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:35.192368031 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:47.694211960 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:47.699204922 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:47.867466927 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:47.869276047 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:47.874152899 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:48.428359032 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:48.433171034 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:48.601584911 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:48.602943897 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:48.607712030 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:49.100320101 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:49.105288982 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:49.289058924 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:49.297369003 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:49.302191973 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.287803888 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.294152975 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.303428888 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.308176994 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.397253990 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.402205944 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.412857056 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.417670965 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.459589958 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.461112022 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.464441061 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.464485884 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.469297886 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.491030931 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.495872021 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.522097111 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.526844025 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.551238060 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.552997112 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.602659941 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.602701902 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.607474089 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.615828037 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.620634079 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.631659985 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.636467934 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.644750118 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.646219969 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.694943905 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.694988012 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.699897051 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.709585905 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.714519978 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.723432064 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.725395918 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.771015882 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.772102118 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.777127981 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.801326036 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.802938938 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.850686073 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.850730896 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.858294964 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.896190882 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.897645950 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.902718067 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.902762890 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:50.908036947 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.989243031 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:50.995662928 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:51.000813961 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:51.007122040 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:51.011960030 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:51.087438107 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:51.088767052 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:51.093604088 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:51.093643904 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:51.098505974 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:53.162769079 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:53.167727947 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:53.336467028 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:53.342240095 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:53.347342968 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:54.757023096 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:54.761883020 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:54.930017948 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:54.931643963 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:54.936472893 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:55.678410053 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:55.683208942 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:55.851922035 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:55.858232975 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:55.862997055 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:55.981477022 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:56.021889925 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:58.038238049 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:58.043104887 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:58.211405993 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:08:58.258235931 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:08:58.263151884 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.881724119 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.886604071 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.897136927 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.901989937 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.912827015 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.917604923 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.928392887 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.933173895 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.944117069 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.949037075 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:00.991055965 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:00.995862961 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.006478071 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.011265039 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.022125959 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.026892900 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.037713051 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.042470932 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.136759043 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.138062000 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.142874002 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.223908901 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.225686073 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.230519056 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.230571985 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.235321999 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.317476988 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.322254896 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.327035904 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:01.327249050 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:01.332053900 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:06.303385973 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:06.308279037 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:06.476691008 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:06.478780031 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:06.483604908 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:11.147185087 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:11.152177095 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:11.325602055 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:11.330252886 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:11.336361885 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.162929058 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:13.167831898 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.240856886 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:13.245601892 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.336524963 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.344413042 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:13.349169016 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.436100960 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:13.440256119 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:13.445099115 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:20.054263115 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:20.059138060 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:20.229780912 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:20.233278036 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:20.238120079 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.303472042 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:21.308506012 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.336880922 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:21.341886044 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.476571083 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.484370947 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:21.489181042 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.576018095 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:21.580271006 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:21.585058928 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:25.225289106 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:25.230216026 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:25.399401903 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:25.403641939 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:25.408500910 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:25.944410086 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:25.992320061 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.069315910 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.074270010 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:27.100428104 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.105164051 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:27.337863922 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:27.338032007 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:27.338072062 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.339603901 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.344372988 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:27.344415903 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:27.349155903 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.209697962 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:37.214675903 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.382582903 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.388403893 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:37.393177986 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.522829056 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:37.527776957 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.699959040 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:37.704421997 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:37.709183931 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:38.100297928 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:38.105164051 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:38.299165964 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:38.304302931 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:38.309079885 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.022329092 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:47.027363062 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.195628881 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.197312117 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:47.202105045 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.381680965 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:47.386449099 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.555249929 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:47.558588982 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:47.563453913 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.475389957 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.480324984 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.648936033 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.650949001 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.655719042 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.662841082 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.667644024 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.694119930 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.698978901 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.709759951 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.714529991 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.772186995 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.777007103 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.787825108 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.792607069 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.803464890 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.808294058 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.944629908 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:52.946368933 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:52.951124907 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.037945986 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.039247990 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:53.044435978 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.044481993 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:53.049662113 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.262099028 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.263432026 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:53.268213987 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:53.268265009 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:09:53.273133039 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:55.941741943 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:09:55.992388964 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:02.412970066 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:02.417853117 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:02.589169979 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:02.591056108 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:02.595844984 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:02.866190910 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:02.871062994 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:02.881937027 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:02.886919022 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:03.048695087 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:03.050257921 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:03.057060957 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:03.141843081 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:03.143436909 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:03.148576021 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.022377014 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.027226925 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.131850004 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.136750937 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.178540945 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.183330059 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.195538998 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.203880072 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.250699043 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.322235107 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.323976040 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.328727961 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.415532112 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:13.417056084 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:13.421822071 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:22.491461992 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:22.496253014 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:22.664731979 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:22.666304111 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:22.671164036 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:24.428664923 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:24.435165882 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:24.610608101 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:24.612694025 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:24.617470980 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:25.942800045 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:25.992396116 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.538135052 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.543016911 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.631721973 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.636612892 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.647265911 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.652137041 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.662950993 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.667853117 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.711534023 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.713527918 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.718365908 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.788079977 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.793051958 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.809849024 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.811491966 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.858639002 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.903053999 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.904303074 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:34.909064054 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.995920897 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:34.997325897 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:35.002484083 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:35.088920116 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:35.091152906 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:35.095947981 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:44.929065943 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:44.933969021 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.022392035 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.027885914 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.053906918 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.059375048 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.069839001 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.075206995 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.120045900 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.121618986 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.126370907 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.213397980 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.218477964 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.223381996 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.310161114 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.311654091 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.316414118 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.403173923 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:45.405750990 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:45.410511971 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.648050070 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.652829885 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.662919044 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.667722940 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.725528955 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.730371952 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.741065979 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.745810032 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.826217890 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.828802109 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.833642960 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.920411110 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:50.921758890 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:50.926549911 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:51.013312101 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:51.015010118 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:51.019756079 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:51.106484890 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:51.107738018 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:51.112509012 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:55.069255114 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:55.074157000 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:55.246273041 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:55.248291016 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:55.253109932 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:55.942780972 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:56.147120953 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:56.325098038 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:56.325205088 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:59.116274118 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:59.121182919 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:59.308022022 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:10:59.337165117 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:10:59.342147112 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:11:00.694281101 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:11:00.699126005 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:11:00.870752096 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Jan 3, 2025 14:11:00.871459961 CET | 49731 | 7000 | 192.168.2.4 | 87.120.125.47 |
Jan 3, 2025 14:11:00.877003908 CET | 7000 | 49731 | 87.120.125.47 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 3, 2025 14:07:00.551600933 CET | 55325 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 3, 2025 14:07:00.562392950 CET | 53 | 55325 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 3, 2025 14:07:00.551600933 CET | 192.168.2.4 | 1.1.1.1 | 0xd56d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 3, 2025 14:07:00.562392950 CET | 1.1.1.1 | 192.168.2.4 | 0xd56d | No error (0) | 172.67.19.24 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2025 14:07:00.562392950 CET | 1.1.1.1 | 192.168.2.4 | 0xd56d | No error (0) | 104.20.3.235 | A (IP address) | IN (0x0001) | false | ||
Jan 3, 2025 14:07:00.562392950 CET | 1.1.1.1 | 192.168.2.4 | 0xd56d | No error (0) | 104.20.4.235 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49730 | 172.67.19.24 | 443 | 6884 | C:\Users\user\Desktop\XClient.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-03 13:07:01 UTC | 74 | OUT | |
2025-01-03 13:07:01 UTC | 388 | IN | |
2025-01-03 13:07:01 UTC | 24 | IN | |
2025-01-03 13:07:01 UTC | 5 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 08:06:54 |
Start date: | 03/01/2025 |
Path: | C:\Users\user\Desktop\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x210000 |
File size: | 41'984 bytes |
MD5 hash: | 2E525CCEBF9EDE7492931251EB66571A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 08:06:58 |
Start date: | 03/01/2025 |
Path: | C:\Windows\System32\schtasks.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76f990000 |
File size: | 235'008 bytes |
MD5 hash: | 76CD6626DD8834BD4A42E6A565104DC2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 08:06:58 |
Start date: | 03/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 08:06:59 |
Start date: | 03/01/2025 |
Path: | C:\Users\user\AppData\Roaming\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xaa0000 |
File size: | 41'984 bytes |
MD5 hash: | 2E525CCEBF9EDE7492931251EB66571A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 08:08:00 |
Start date: | 03/01/2025 |
Path: | C:\Users\user\AppData\Roaming\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x20000 |
File size: | 41'984 bytes |
MD5 hash: | 2E525CCEBF9EDE7492931251EB66571A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 08:09:00 |
Start date: | 03/01/2025 |
Path: | C:\Users\user\AppData\Roaming\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf90000 |
File size: | 41'984 bytes |
MD5 hash: | 2E525CCEBF9EDE7492931251EB66571A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 08:10:00 |
Start date: | 03/01/2025 |
Path: | C:\Users\user\AppData\Roaming\XClient.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x4d0000 |
File size: | 41'984 bytes |
MD5 hash: | 2E525CCEBF9EDE7492931251EB66571A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 15.8% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8805B8 Relevance: 1.0, Instructions: 1000COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B889566 Relevance: .5, Instructions: 472COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B88A312 Relevance: .5, Instructions: 458COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0C5E Relevance: 1.0, Instructions: 1021COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0730 Relevance: .2, Instructions: 241COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B17E1 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B07A8 Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B04E0 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B09A9 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0B48 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B1981 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B890C5E Relevance: 1.0, Instructions: 1022COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B890730 Relevance: .2, Instructions: 241COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8917E1 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8907A8 Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8904E0 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8909A9 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B890B48 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B891981 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0C5E Relevance: 1.0, Instructions: 1021COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0730 Relevance: .2, Instructions: 241COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B17E1 Relevance: .2, Instructions: 187COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B07A8 Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B04E0 Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B09A9 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B0B48 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8B1981 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A0C5E Relevance: 1.0, Instructions: 1022COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A0730 Relevance: .3, Instructions: 297COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A07A8 Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A17E1 Relevance: .2, Instructions: 184COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A04E0 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A09A9 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A0B48 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD9B8A1981 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|