Windows
Analysis Report
1.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1.exe (PID: 2584 cmdline:
"C:\Users\ user\Deskt op\1.exe" MD5: D0598443FA9984227105811E5D89B70F) - ._cache_1.exe (PID: 6176 cmdline:
"C:\Users\ user\Deskt op\._cache _1.exe" MD5: 8F02CCF024090E3BD52574174749C778) - Synaptics.exe (PID: 2260 cmdline:
"C:\Progra mData\Syna ptics\Syna ptics.exe" InjUpdate MD5: 065BECDE24188ED65E53BECB09A5A039) - WerFault.exe (PID: 5508 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 2 260 -s 281 6 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- EXCEL.EXE (PID: 4540 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" /aut omation -E mbedding MD5: 4A871771235598812032C822E6F68F19)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Lumma Stealer, LummaC2 Stealer | Lumma Stealer (aka LummaC2 Stealer) is an information stealer written in C language that has been available through a Malware-as-a-Service (MaaS) model on Russian-speaking forums since at least August 2022. It is believed to have been developed by the threat actor "Shamel", who goes by the alias "Lumma". Lumma Stealer primarily targets cryptocurrency wallets and two-factor authentication (2FA) browser extensions, before ultimately stealing sensitive information from the victim's machine. Once the targeted data is obtained, it is exfiltrated to a C2 server via HTTP POST requests using the user agent "TeslaBrowser/5.5"." The stealer also features a non-resident loader that is capable of delivering additional payloads via EXE, DLL, and PowerShell. | No Attribution |
{"C2 url": ["noisycuttej.shop", "tirepublicerj.shop", "framekgirus.shop", "nearycrepso.shop", "cloudewahsj.shop", "wholersorie.shop", "abruptyopsn.shop", "twistforcepo.cfd", "rabidcowse.shop"], "Build id": "sadvnqw3nerasdf--"}
{"C2 url": "xred.mooo.com", "Email": "xredline1@gmail.com", "Payload urls": ["http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978", "https://docs.google.com/uc?id=0BxsMXGfPIZfSVlVsOGlEVGxuZVk&export=download", "https://www.dropbox.com/s/n1w4p8gc6jzo0sg/SUpdate.ini?dl=1", "http://xred.site50.net/syn/SUpdate.ini", "https://docs.google.com/uc?id=0BxsMXGfPIZfSVzUyaHFYVkQxeFk&export=download", "https://www.dropbox.com/s/zhp1b06imehwylq/Synaptics.rar?dl=1", "http://xred.site50.net/syn/Synaptics.rar", "https://docs.google.com/uc?id=0BxsMXGfPIZfSTmlVYkxhSDg5TzQ&export=download", "https://www.dropbox.com/s/fzj752whr3ontsm/SSLLibrary.dll?dl=1", "http://xred.site50.net/syn/SSLLibrary.dll"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XRed | Yara detected XRed | Joe Security | ||
JoeSecurity_DelphiSystemParamCount | Detected Delphi use of System.ParamCount() | Joe Security |
System Summary |
---|
Source: | Author: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-07T13:18:28.735724+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49744 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:28.773157+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49745 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:29.796536+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49754 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:29.799804+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49757 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:30.904201+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49768 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:30.922727+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49769 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:31.948079+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49780 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:31.951596+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49781 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:33.998523+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49806 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:34.040266+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49807 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:35.057851+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49818 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:35.116762+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49820 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:36.130544+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49828 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:36.170403+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49829 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:37.195532+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49840 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:37.222448+0100 | 2044887 | 1 | A Network Trojan was detected | 192.168.2.11 | 49841 | 142.250.185.110 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-07T13:18:29.318163+0100 | 2832617 | 1 | Malware Command and Control Activity Detected | 192.168.2.11 | 49753 | 69.42.215.252 | 80 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: | ||
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: | ||
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 2_2_00521816 | |
Source: | Code function: | 2_2_004F7054 | |
Source: | Code function: | 2_2_004FB021 | |
Source: | Code function: | 2_2_004FB021 | |
Source: | Code function: | 2_2_0051D0D0 | |
Source: | Code function: | 2_2_0051D0D0 | |
Source: | Code function: | 2_2_005238E0 | |
Source: | Code function: | 2_2_004EC080 | |
Source: | Code function: | 2_2_00502880 | |
Source: | Code function: | 2_2_00507885 | |
Source: | Code function: | 2_2_004FF170 | |
Source: | Code function: | 2_2_005221E9 | |
Source: | Code function: | 2_2_005221E9 | |
Source: | Code function: | 2_2_004F618C | |
Source: | Code function: | 2_2_004FBA52 | |
Source: | Code function: | 2_2_004FBA52 | |
Source: | Code function: | 2_2_004FBA52 | |
Source: | Code function: | 2_2_004E2210 | |
Source: | Code function: | 2_2_0051A230 | |
Source: | Code function: | 2_2_00511AF5 | |
Source: | Code function: | 2_2_005242E0 | |
Source: | Code function: | 2_2_00520A90 | |
Source: | Code function: | 2_2_004EB280 | |
Source: | Code function: | 2_2_00521B50 | |
Source: | Code function: | 2_2_00502370 | |
Source: | Code function: | 2_2_0050FB7D | |
Source: | Code function: | 2_2_004E9360 | |
Source: | Code function: | 2_2_004E8320 | |
Source: | Code function: | 2_2_004F9B30 | |
Source: | Code function: | 2_2_004FF3E0 | |
Source: | Code function: | 2_2_004FB3F2 | |
Source: | Code function: | 2_2_004FAB90 | |
Source: | Code function: | 2_2_004F8BA2 | |
Source: | Code function: | 2_2_00508C62 | |
Source: | Code function: | 2_2_00507C10 | |
Source: | Code function: | 2_2_00524C20 | |
Source: | Code function: | 2_2_004F4C30 | |
Source: | Code function: | 2_2_004F8492 | |
Source: | Code function: | 2_2_0051CD40 | |
Source: | Code function: | 2_2_0050C5E0 | |
Source: | Code function: | 2_2_004FB58F | |
Source: | Code function: | 2_2_004F95B6 | |
Source: | Code function: | 2_2_004F95B6 | |
Source: | Code function: | 2_2_0051E6E0 | |
Source: | Code function: | 2_2_0051E6E0 | |
Source: | Code function: | 2_2_00510F54 | |
Source: | Code function: | 2_2_00510F4E | |
Source: | Code function: | 2_2_004FA770 | |
Source: | Code function: | 2_2_0050F716 | |
Source: | Code function: | 2_2_00510F03 | |
Source: | Code function: | 2_2_004E7730 | |
Source: | Code function: | 2_2_004E7730 | |
Source: | Code function: | 2_2_005237D0 | |
Source: | Code function: | 2_2_00507FC0 | |
Source: | Code function: | 2_2_00507FC0 | |
Source: | Code function: | 2_2_0050A7F0 | |
Source: | Code function: | 2_2_0050A7F0 | |
Source: | Code function: | 2_2_00507FFD | |
Source: | Code function: | 2_2_0050AF92 | |
Source: | Code function: | 2_2_0050AF92 | |
Source: | Code function: | 2_2_0050AFB0 |
Source: | Memory has grown: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | DNS query: |
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 2_2_00517A60 |
Source: | Code function: | 2_2_00517A60 |
Source: | Code function: | 2_2_00517C10 |
System Summary |
---|
Source: | Code function: | 2_2_004E8A60 | |
Source: | Code function: | 2_2_00517850 | |
Source: | Code function: | 2_2_004F906A | |
Source: | Code function: | 2_2_00506010 | |
Source: | Code function: | 2_2_0051D0D0 | |
Source: | Code function: | 2_2_005238E0 | |
Source: | Code function: | 2_2_004F80F0 | |
Source: | Code function: | 2_2_00507885 | |
Source: | Code function: | 2_2_004FD8B0 | |
Source: | Code function: | 2_2_00524950 | |
Source: | Code function: | 2_2_004E6950 | |
Source: | Code function: | 2_2_004EE16E | |
Source: | Code function: | 2_2_004ED172 | |
Source: | Code function: | 2_2_00509917 | |
Source: | Code function: | 2_2_0051210B | |
Source: | Code function: | 2_2_004E3910 | |
Source: | Code function: | 2_2_004EB92C | |
Source: | Code function: | 2_2_004E6120 | |
Source: | Code function: | 2_2_0050F1C1 | |
Source: | Code function: | 2_2_005039EB | |
Source: | Code function: | 2_2_004F618C | |
Source: | Code function: | 2_2_0051099F | |
Source: | Code function: | 2_2_00501180 | |
Source: | Code function: | 2_2_0050E9B0 | |
Source: | Code function: | 2_2_004FF9A0 | |
Source: | Code function: | 2_2_004FD1B0 | |
Source: | Code function: | 2_2_0051025E | |
Source: | Code function: | 2_2_004FBA52 | |
Source: | Code function: | 2_2_0050621B | |
Source: | Code function: | 2_2_00523A30 | |
Source: | Code function: | 2_2_004F7222 | |
Source: | Code function: | 2_2_0050BA20 | |
Source: | Code function: | 2_2_004E42C0 | |
Source: | Code function: | 2_2_00523AC0 | |
Source: | Code function: | 2_2_005102CD | |
Source: | Code function: | 2_2_004EF2D0 | |
Source: | Code function: | 2_2_005242E0 | |
Source: | Code function: | 2_2_004EB280 | |
Source: | Code function: | 2_2_005152B0 | |
Source: | Code function: | 2_2_004E2B40 | |
Source: | Code function: | 2_2_00502370 | |
Source: | Code function: | 2_2_00509B7B | |
Source: | Code function: | 2_2_0050FB7D | |
Source: | Code function: | 2_2_00523B60 | |
Source: | Code function: | 2_2_004E9B70 | |
Source: | Code function: | 2_2_00508B10 | |
Source: | Code function: | 2_2_004E5B00 | |
Source: | Code function: | 2_2_00520B00 | |
Source: | Code function: | 2_2_00501B30 | |
Source: | Code function: | 2_2_004F9B30 | |
Source: | Code function: | 2_2_004F1BDE | |
Source: | Code function: | 2_2_004F23EC | |
Source: | Code function: | 2_2_004F8BA2 | |
Source: | Code function: | 2_2_0051C460 | |
Source: | Code function: | 2_2_00508C62 | |
Source: | Code function: | 2_2_0051B410 | |
Source: | Code function: | 2_2_00524C20 | |
Source: | Code function: | 2_2_00521C26 | |
Source: | Code function: | 2_2_004E64C0 | |
Source: | Code function: | 2_2_0050F4E1 | |
Source: | Code function: | 2_2_005124EE | |
Source: | Code function: | 2_2_004FD4A0 | |
Source: | Code function: | 2_2_004E8D10 | |
Source: | Code function: | 2_2_0051E520 | |
Source: | Code function: | 2_2_004F5DD8 | |
Source: | Code function: | 2_2_00522DCA | |
Source: | Code function: | 2_2_00505DA0 | |
Source: | Code function: | 2_2_004E85B0 | |
Source: | Code function: | 2_2_004E9660 | |
Source: | Code function: | 2_2_004E4E20 | |
Source: | Code function: | 2_2_0051C6C0 | |
Source: | Code function: | 2_2_004F86E5 | |
Source: | Code function: | 2_2_0051E6E0 | |
Source: | Code function: | 2_2_0051CE90 | |
Source: | Code function: | 2_2_00524680 | |
Source: | Code function: | 2_2_004FDE90 | |
Source: | Code function: | 2_2_00508750 | |
Source: | Code function: | 2_2_00509F7C | |
Source: | Code function: | 2_2_0051DF60 | |
Source: | Code function: | 2_2_00505713 | |
Source: | Code function: | 2_2_0050F716 | |
Source: | Code function: | 2_2_00513707 | |
Source: | Code function: | 2_2_004E2F10 | |
Source: | Code function: | 2_2_004E7730 | |
Source: | Code function: | 2_2_005237D0 | |
Source: | Code function: | 2_2_00513FDF | |
Source: | Code function: | 2_2_00507FC0 | |
Source: | Code function: | 2_2_0050A7F0 | |
Source: | Code function: | 2_2_00514FF0 | |
Source: | Code function: | 2_2_004F27E0 | |
Source: | Code function: | 2_2_0050AF92 |
Source: | Process created: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 2_2_0051D0D0 |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | File opened: | Jump to behavior |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Registry key monitored for changes: | Jump to behavior | ||
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 2_2_00522080 |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 41 Scripting | 1 Replication Through Removable Media | 1 PowerShell | 41 Scripting | 11 Process Injection | 12 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | 1 Screen Capture | 11 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 11 Virtualization/Sandbox Evasion | LSASS Memory | 111 Security Software Discovery | Remote Desktop Protocol | 1 Archive Collected Data | 3 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 1 DLL Side-Loading | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | 2 Clipboard Data | 3 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 Extra Window Memory Injection | 11 Deobfuscate/Decode Files or Information | NTDS | 11 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 34 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Peripheral Device Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 3 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 Extra Window Memory Injection | DCSync | 12 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
85% | Virustotal | Browse | ||
87% | ReversingLabs | Win32.Trojan.Synaptics | ||
100% | Avira | TR/Dldr.Agent.SH | ||
100% | Avira | W2000M/Dldr.Agent.17651006 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Dldr.Agent.SH | ||
100% | Avira | W2000M/Dldr.Agent.17651006 | ||
100% | Avira | TR/Dldr.Agent.SH | ||
100% | Avira | W2000M/Dldr.Agent.17651006 | ||
100% | Avira | TR/Dldr.Agent.SH | ||
100% | Avira | W2000M/Dldr.Agent.17651006 | ||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
100% | Joe Sandbox ML | |||
87% | ReversingLabs | Win32.Trojan.Synaptics |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
freedns.afraid.org | 69.42.215.252 | true | false | high | |
docs.google.com | 142.250.185.110 | true | false | high | |
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high | |
drive.usercontent.google.com | 142.250.186.161 | true | false | high | |
xred.mooo.com | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
142.250.186.161 | drive.usercontent.google.com | United States | 15169 | GOOGLEUS | false | |
142.250.185.110 | docs.google.com | United States | 15169 | GOOGLEUS | false | |
69.42.215.252 | freedns.afraid.org | United States | 17048 | AWKNET-LLCUS | false |
Joe Sandbox version: | 41.0.0 Charoite |
Analysis ID: | 1585287 |
Start date and time: | 2025-01-07 13:17:18 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 19s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Sample name: | 1.exe |
Detection: | MAL |
Classification: | mal100.troj.expl.evad.winEXE@7/28@6/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WerFault.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 52.109.32.97, 184.28.90.27, 52.113.194.132, 23.56.254.164, 20.189.173.8, 20.42.65.92, 13.107.246.45, 40.126.32.76, 20.12.23.50
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, otelrules.afd.azureedge.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, ecs-office.s-0005.s-msedge.net, onedscolprdwus07.westus.cloudapp.azure.com, login.live.com, e16604.g.akamaiedge.net, officeclient.microsoft.com, ukw-azsc-config.officeapps.live.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, self-events-data.trafficmanager.net, fs.microsoft.com, otelrules.azureedge.net, prod.configsvc1.live.com.akadns.net, self.events.data.microsoft.com, ctldl.windowsupdate.com, s-0005-office.config.skype.com, fe3cr.delivery.mp.microsoft.com, onedsblobprdeus17.eastus.cloudapp.azure.com, s-0005.s-msedge.net, config.officeapps.live.com, blobcollector.events.data.trafficmanager.net, azureedge-t-prod.trafficmanager.net, umwatson.events.data.microsoft.com, ecs.office.trafficmanager.net, europe.configsvc1.live.com.akadns.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Report size getting too big, too many NtSetInformationFile calls found.
Time | Type | Description |
---|---|---|
07:18:26 | API Interceptor | |
07:18:45 | API Interceptor | |
13:18:22 | Autostart |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
69.42.215.252 | Get hash | malicious | XRed | Browse |
| |
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | LummaC | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Branchlock Obfuscator | Browse |
| ||
Get hash | malicious | Branchlock Obfuscator | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Bdaejec | Browse |
| ||
freedns.afraid.org | Get hash | malicious | XRed | Browse |
| |
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AWKNET-LLCUS | Get hash | malicious | XRed | Browse |
| |
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
| ||
Get hash | malicious | XRed | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | Lokibot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Nitol | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Nitol | Browse |
|
C:\Program Files (x86)\Microsoft Office\root\vfs\Common AppData\Microsoft\OFFICE\Heartbeat\HeartbeatCache.xml
Download File
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 118 |
Entropy (8bit): | 3.5700810731231707 |
Encrypted: | false |
SSDEEP: | 3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq |
MD5: | 573220372DA4ED487441611079B623CD |
SHA1: | 8F9D967AC6EF34640F1F0845214FBC6994C0CB80 |
SHA-256: | BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D |
SHA-512: | F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Synaptics.exe_348ac1a0e27e10257094c0b0d8fb7ab45be575f_455b7b6e_cc67f19a-ef6b-45cb-8e05-6f572bf8087e\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 1.133326375425338 |
Encrypted: | false |
SSDEEP: | 192:fmBVps3Imo0WMn4DzJDzqjLOA/FczxwzuiFc/Z24IO8EKDzy:My35WMn4JqjkKzuiFc/Y4IO8zy |
MD5: | FB203EC6304224ED55D9CF99C716CB2C |
SHA1: | F0DA6B7AAA5476951D92441FC6B33790013BA9BA |
SHA-256: | 9840CCC5462DB65AB0CF41ED3A89B00958D3AF04000518ECDD0CD109E47749DC |
SHA-512: | 69B4B0536201FFB0670EFA66EF98E62B6F7BE2CAE1C0314655C88A27D42CD38882B8A6DF1BD6B1F5EEA50386E1D4EDD99DDF0A5B23786BDC4821CA7924E2A970 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2139536 |
Entropy (8bit): | 1.8205505237118613 |
Encrypted: | false |
SSDEEP: | 3072:qWQzOICwegAKSLywJRjmx9mYFvi6wpqYKLPFqwL5Me4DfLRPWf0BuAQpQQh:qWQrCvbDRjd4kqYcpABw0BmLh |
MD5: | EDDAEF1468D1980FE079705DAC29D66F |
SHA1: | 8CC0E10F102B5B0E82281F3049C4054006AC35FB |
SHA-256: | 073797EF1786BA6FD13BCDA9C2C1C5C15E4D47A772A022CD1EFB6835B2E8DE62 |
SHA-512: | 06E4B731019575D04080D7BC5D6D038C6A1A12A88EEF91960C64CBC833D01ED53D920197F2CE9956AF6DF52EE51D7486C86C5095AAA78B37DEB348A444E06470 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6302 |
Entropy (8bit): | 3.7145337268819967 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJ5xy6CYiSW5XpDA89bPcjsfStam:R6lXJa6CYu5PkIfY |
MD5: | DCD3C9442CD7122AB5355DF492894E18 |
SHA1: | D1CB7CAAE2DDEAF496FD08A5FC6062F0946B64A1 |
SHA-256: | A11E5E29290736FBF36FEE9901F45AFA866F20E1726B1BA4043B28EE38040218 |
SHA-512: | 23491B191B186A3E360277A3B0F4BC16CDD23FEA5AF0B5A7D8B1B0205FA7E9468F5146B148D0BB4D0EBFCDE695E8AA19A952369529028412F0AED6BE7FE4655B |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4572 |
Entropy (8bit): | 4.442504612095313 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsPQJg77aI9k3WpW8VYFYm8M4JFetFOE+q84ihUlsZ9d:uIjfPWI7aG7VhJPEMUlsZ9d |
MD5: | 6C1B52DF00F1600A731E245E705D611B |
SHA1: | E0E9A3999E6127783331DAC4E8654828A831F266 |
SHA-256: | 13AA1276889A55CA8D966C16661CE806A2CD0B957EC02DBE19B9918F3FED51D0 |
SHA-512: | D4328B0B98693ED818A11148DC9B4D1528BDDC56A927B1139E648CA93A40B82FB6AF5BF0EB1DBBFBF347FF6A539D857F7BA97628F331570B206290F18B9226D0 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\1.exe |
File Type: | |
Category: | modified |
Size (bytes): | 772096 |
Entropy (8bit): | 6.636956363807124 |
Encrypted: | false |
SSDEEP: | 12288:aMSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9F6+:ansJ39LyjbJkQFMhmC+6GD9B |
MD5: | 065BECDE24188ED65E53BECB09A5A039 |
SHA1: | 1B93E985BC3000BAC77112697F6702B2EB52CC37 |
SHA-256: | 641147AE6E518E7930EFE2A90B61DD0A22F23BBA6D77F7FAE48380A6F7842E6C |
SHA-512: | 879D047CF07153B113D39A20BFDEC4B3429D5B431641D026AE38FBBD198C40BD28179CC03B9A208C3214B4E604E568E5813B20E720F150E9A06EE7C54D667A08 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\1.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1101824 |
Entropy (8bit): | 6.7652852257842975 |
Encrypted: | false |
SSDEEP: | 24576:FnsJ39LyjbJkQFMhmC+6GD9nkKh5OYceEMQ+h0W:FnsHyjtk2MYC5GDT58M7hH |
MD5: | D0598443FA9984227105811E5D89B70F |
SHA1: | 3932D4696F4130658FBF2A16E7F771FC756A63CC |
SHA-256: | FC1595C71B570027B6712C70CAFCC075686E14B5702A5A0910F642EB739AC01F |
SHA-512: | 142EBD6E1BF24D82533355E76BB9433DEEFDD4EE918BA04CC12419CC17CB564F86AF386BF949617E386BFFA1E0036EC5DB912BC8B985A1DE94330B3B14E3FD29 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\1.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | true |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.269673333085929 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0JSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+C+pAZewRDK4mW |
MD5: | FE2DC39B57A684C3BE12F81E9BB5C598 |
SHA1: | EE4D488252D35907BC5B92BE9D8ED3233127B07E |
SHA-256: | 03D716C13F3A18F32987D02BD096CD55F3A89B5A732A8893B1D5D91D16B02675 |
SHA-512: | 9958C4E3BF47CF36E20DAF2256CF5E988D44DF3C1DBB279BC108B95B870897CA986A7B70017A46E24E4FF9383A9429C18789B468FE29956BE481989DC3911042 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.25997657714486 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0yR6SU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+c+pAZewRDK4mW |
MD5: | 2CFEE4A7A22D87B7F93BA3088DD2CEF7 |
SHA1: | DC036BC940E99C461F8ED8B3DA1CA742773A64A0 |
SHA-256: | ED5E71887481B8FFC9796A5C0205D4FCB4324277F484570683F5735212E6AD5B |
SHA-512: | CB0E738BE07CC3ABC306C28AD143BF077DD136F1B6BA86267DA88AECFB0CFE8607621C51C90B97030D0BF7EA8805E6C737FDDF5164D3BE913D4EE100E623BB9B |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.257417802448201 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0BSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+e+pAZewRDK4mW |
MD5: | 05616047A97587562E81F06BD789BE4B |
SHA1: | 0B9ACC06383DAB60643E5DD4F66DFAB8C43E1827 |
SHA-256: | F93221E4A9412828B57EE281AD1651EE0A55BBE61DCCE6E434A04874C45E3188 |
SHA-512: | 838ECB7D58493443F6F7FCC18790E7571226B56DAEDE879D4ED4378FB374B7B982F1674E4816F65AF598EA48BC30B381A3792E17A34D5387EB0AB858F9E6651A |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.2539822571349255 |
Encrypted: | false |
SSDEEP: | 24:GgsF+052SU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+g2+pAZewRDK4mW |
MD5: | 210DCAC51CAC2B03EF546E86397ACA1C |
SHA1: | F0A26611AC655D5426674815F225B3E9BC8BD71C |
SHA-256: | CAF5722EA5B563AF4F3DEF61C33E5EE486DC53D0F0997461268E039244CF9AF7 |
SHA-512: | F94634C67219F7986F26884941C85717A0CF2D1C304FCEC3F3E62B8F82BB561D6C50FC9543A326EC37611002286260A2E4194062D3CAF45A57C3B7EA87F21B09 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.258755459992018 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0HSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+o+pAZewRDK4mW |
MD5: | CE2D5D2907126FD4EC6F80EF0B4B74EB |
SHA1: | 751398C80FF92B2F9BAE2CBF286F0DBCD8BB1BBD |
SHA-256: | E89FF12E7B972AA3F6AF1A57B1C10CD20FF0E74EA329BD5FCE30E4AB1227A25F |
SHA-512: | 028D91886C79947ADC824B78C30FE65A199EB38D9503F2B08FCE3561437F44D61CC7F6CEF37097F915B6D8FB94AAEB45FB9610805C8B9194961DAE1DB97607D7 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.258640999418921 |
Encrypted: | false |
SSDEEP: | 24:GgsF+09iamSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+4M+pAZewRDK4mW |
MD5: | BEE5BC6D0D255C51FBF03A61DE57BD26 |
SHA1: | 951D38E5433BC13568C99ABBEF2797076A099E2A |
SHA-256: | 2F21CD0B4188D49EE6FD52880E41D4E6EB0A316BE075B247C79872744F01A176 |
SHA-512: | 40C9AB2BAA8EBF4FA1136552D2AE7DB07F33605BB76022E092DF5886E75A50BDA1E5FD613642486330D6800888CF13149009C671D73AFCD450D0974E6815E755 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18387 |
Entropy (8bit): | 7.523057953697544 |
Encrypted: | false |
SSDEEP: | 384:oUaZLPzMfVSa1VvYXmrsdPkLmDAx7r/l0:oUatwNSSvY2IdsHr/y |
MD5: | E566FC53051035E1E6FD0ED1823DE0F9 |
SHA1: | 00BC96C48B98676ECD67E81A6F1D7754E4156044 |
SHA-256: | 8E574B4AE6502230C0829E2319A6C146AEBD51B7008BF5BBFB731424D7952C15 |
SHA-512: | A12F56FF30EA35381C2B8F8AF2446CF1DAA21EE872E98CAD4B863DB060ACD4C33C5760918C277DADB7A490CB4CA2F925D59C70DC5171E16601A11BC4A6542B04 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.278627987755061 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0DSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+w+pAZewRDK4mW |
MD5: | 8213DD2C7D5A5C9662D2938BE703849C |
SHA1: | A1C3795DA43A0164B169EE6238AD9EFDC2929A67 |
SHA-256: | 4E42F0EE8ED720938F841D29E4C01CF79700CA53FD02C29C8DFF4EEB83B9CB65 |
SHA-512: | B2F3C1FCF191102C97711FD10BEEE2A2E710A276C8D2C45CF3C06F4108C24B2086EA8F1E47AA6C22903422D57FB2265184FC08BDDEC172752A4DB739CD56E1C4 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.264787141711439 |
Encrypted: | false |
SSDEEP: | 24:GgsF+04SU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+j+pAZewRDK4mW |
MD5: | A0EF0A7B90AC7D26B0E14F7D15AE3193 |
SHA1: | 6F7A3983DE186383585A5485C880232B3C062C5B |
SHA-256: | BD6A506143F23B956F6467362123D30584E947AD56B2E8D7852949109E9DF06A |
SHA-512: | 83E83D903A154943CBAE783DDDE50DF1C967E0B93B4DC380CF1DFCCCB4013876E2ABB546F593D6A5B0D871755242A5DC51AE689E78E117E2F73DFA0753F5815E |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.2708240056155535 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0vrSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+s+pAZewRDK4mW |
MD5: | BD4373CDB50BA315597B70DCB149044A |
SHA1: | 059A0C744FCBB538482FFB5A115249F85364A76B |
SHA-256: | 13E1016A0C33BE4ADA41A72484D9FE3F85EED0A1FCFB0ACA4D8D1F1DDD3E057A |
SHA-512: | 830B74B54C628A70FFB1E7D0FC49A2689E24084EE323387050F7966C9EC1F8C312994A7EF8E9E5283EE51602512BEA65DF6B31B49A472DDD1ADEDF3F2BA488CD |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.263299926755047 |
Encrypted: | false |
SSDEEP: | 24:GgsF+01TbSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+O+pAZewRDK4mW |
MD5: | B694F18937B923C719341DAC11244FA9 |
SHA1: | 9CB124ABD09C1E3BA403591B488EB83682A24083 |
SHA-256: | C5C70B1C7FEC151B0D8A062A9AAB7578A246CD618933A3D3AE71B062FBEDDC39 |
SHA-512: | 119DA815E7EA2376215B9BC05323156ECE7E5A92C6BA568EDABF00A15D8F4DB82E2C6BC716FE0964CC8E6CB79AB8978CE550428C6AF0A028B25CC482F68CFF27 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.268602448567942 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0wuCbSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+5+pAZewRDK4mW |
MD5: | 1884CA0598AB0088FC091979E2E2E191 |
SHA1: | 17549906DE9EFFD54399AB61D78D948394B984D2 |
SHA-256: | 15505D6F32AAAF223287F86D60068DA77B0445E528AC7BC743662A8492638D3B |
SHA-512: | 17BC5ACFF2EA2868BB73035F2048D4664A416D6145D521CCA0D9141F20570F1DE471A90DE6F813FABE932684A2DA087B930F2C9095BAD3A7E2F0318074C56966 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.241269109409595 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0eyRSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+O+pAZewRDK4mW |
MD5: | A2478FF1AC238686FA25F571F8673F6C |
SHA1: | D9CB224262B8D57F822710C72FC26EBE5364DDBA |
SHA-256: | 20A1CACC10C7C73512140DDC2CF5FD591BFD020385B1C4756AF23AA38B5D75E8 |
SHA-512: | B471A7495551C0E83235A31C82BF69FE52C29C819572C5FB105645FA5FA96B0DBB986C9A1E87F6C3C4600CA26EA8834D11C45E50DB901FE49EB245F19B3C6634 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.258415197370358 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0cSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+3+pAZewRDK4mW |
MD5: | 4BFFF3D51B141C2E387AD88068BB69C3 |
SHA1: | 891FB77214FC1D6DE305098990ABC330C7B07ACB |
SHA-256: | 9B44E533F921BF04C5F24E2A73046A521CED5F529F458579A34D80B446253580 |
SHA-512: | E0062E4728DBFDC769A946139C529FD500FF3D45582EC204E9060EFF5666F79BAC247A11CA0FADB32C9CF51A584407E288E282169A1188E80DB67BA2B1BAD8A1 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1652 |
Entropy (8bit): | 5.253327595725399 |
Encrypted: | false |
SSDEEP: | 24:GgsF+0BqdoSU6pepPQfkZbc6cn1BZdAe1nCr1LTHm6D9viLRIxv+5A:GgK+y+pAZewRDK4mW |
MD5: | C93DEB775D5E6E0DCB3DA954E249DF3D |
SHA1: | 6397A7DE487879FE738E6F5251C2DE846354B41D |
SHA-256: | 2F75AFFD1F8364DB8C41BD0DF46BF460BD075E8055F9A3E2AE11DCBCE627F0AF |
SHA-512: | F03CECC94F9687371E8F531B0E47B69CE62888BF81B76F5A9E775608DEE4BB7448DDC0CB2E582FC7805FD0C853ED2A988DE2B4A5F33907DEFB71E9BB2F85A690 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\1.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 329728 |
Entropy (8bit): | 6.754399552154763 |
Encrypted: | false |
SSDEEP: | 6144:aA6xKh6ckttv2vzCYaF82Dx6AU/AbMQTKhCVnXtn43J7:XkKh6c5bCYaF824EMQ+hCZXq |
MD5: | 8F02CCF024090E3BD52574174749C778 |
SHA1: | 73CE3AFED686E7157CA919118B62F29F5A423196 |
SHA-256: | F7E32CCE4D55BF0DC2F688466983F6F6AA69F1BDACAB7522297125AD04D9ECFC |
SHA-512: | 97D68507DB1CACF116E19BAE4F01C99D9466AAF3A88F29AD52C4A9168E668AB8262F091ED4C0515D560774A013D53FFD8945CE5347198D6E65C4A7ACFC540E9C |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18387 |
Entropy (8bit): | 7.523057953697544 |
Encrypted: | false |
SSDEEP: | 384:oUaZLPzMfVSa1VvYXmrsdPkLmDAx7r/l0:oUatwNSSvY2IdsHr/y |
MD5: | E566FC53051035E1E6FD0ED1823DE0F9 |
SHA1: | 00BC96C48B98676ECD67E81A6F1D7754E4156044 |
SHA-256: | 8E574B4AE6502230C0829E2319A6C146AEBD51B7008BF5BBFB731424D7952C15 |
SHA-512: | A12F56FF30EA35381C2B8F8AF2446CF1DAA21EE872E98CAD4B863DB060ACD4C33C5760918C277DADB7A490CB4CA2F925D59C70DC5171E16601A11BC4A6542B04 |
Malicious: | false |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.3801032810853697 |
Encrypted: | false |
SSDEEP: | 3:UvNFiKVMNv:UvNsKVkv |
MD5: | 9AA76EF018A0F672FA8DF9799D834C34 |
SHA1: | 75B4E1ADC263E4F966CAD3ECA3A2C84638CA525E |
SHA-256: | ED0F89EA4BAE07B1876B61240D06D56CDDB5CE83EF10E41F68142378CB750B77 |
SHA-512: | 6A8AF40C8225E60E652BCCB7D7E7FF03A8A014A7AC782D620AA6120B134213D4A4E279EF0005FCCBA513E85785E7CF6EA42422A6E936F4F690E47D0AAD11AA77 |
Malicious: | false |
Preview: |
Process: | C:\ProgramData\Synaptics\Synaptics.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 772096 |
Entropy (8bit): | 6.636956363807124 |
Encrypted: | false |
SSDEEP: | 12288:aMSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9F6+:ansJ39LyjbJkQFMhmC+6GD9B |
MD5: | 065BECDE24188ED65E53BECB09A5A039 |
SHA1: | 1B93E985BC3000BAC77112697F6702B2EB52CC37 |
SHA-256: | 641147AE6E518E7930EFE2A90B61DD0A22F23BBA6D77F7FAE48380A6F7842E6C |
SHA-512: | 879D047CF07153B113D39A20BFDEC4B3429D5B431641D026AE38FBBD198C40BD28179CC03B9A208C3214B4E604E568E5813B20E720F150E9A06EE7C54D667A08 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.2988451233561795 |
Encrypted: | false |
SSDEEP: | 6144:LECqOEmWfd+WQFHy/9026ZTyaRsCDusBqD5dooi8lfSD6VJSRhL:wCsL6seqD5SWSWVARh |
MD5: | 8A8CB1BB8BB23FA49FA6C7240CA64FEC |
SHA1: | 08EE29FF162066E444FA2279578302453671FCB7 |
SHA-256: | 017C495D36FD742C72E94C7BFB789B0EAE10B3329EFECF7090DAF8D04C60F46E |
SHA-512: | 029A87BCBA78D4FBC7B3B792DDE63F4F192B970E1EB64D1E0D1CBA866F3A8F24C4342B3CCBFA79AEBB86029B37F504B7F91B7626CC3B72B507DAAEEC6ADFA3F6 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 6.7652852257842975 |
TrID: |
|
File name: | 1.exe |
File size: | 1'101'824 bytes |
MD5: | d0598443fa9984227105811e5d89b70f |
SHA1: | 3932d4696f4130658fbf2a16e7f771fc756a63cc |
SHA256: | fc1595c71b570027b6712c70cafcc075686e14b5702a5a0910f642eb739ac01f |
SHA512: | 142ebd6e1bf24d82533355e76bb9433deefdd4ee918ba04cc12419cc17cb564f86af386bf949617e386bffa1e0036ec5db912bc8b985a1de94330b3b14e3fd29 |
SSDEEP: | 24576:FnsJ39LyjbJkQFMhmC+6GD9nkKh5OYceEMQ+h0W:FnsHyjtk2MYC5GDT58M7hH |
TLSH: | 2D359F22F3929077C5630A385CABA37958397F512F346D4B7BE4DE4C5E3A6C22835293 |
File Content Preview: | MZP.....................@...............................................!..L.!..This program must be run under Win32..$7....................................................................................................................................... |
Icon Hash: | 1fc8cfce5e391d0d |
Entrypoint: | 0x49ab80 |
Entrypoint Section: | CODE |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
DLL Characteristics: | |
Time Stamp: | 0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 332f7ce65ead0adfb3d35147033aabe9 |
Instruction |
---|
push ebp |
mov ebp, esp |
add esp, FFFFFFF0h |
mov eax, 0049A778h |
call 00007F58DD073DBDh |
mov eax, dword ptr [0049DBCCh] |
mov eax, dword ptr [eax] |
call 00007F58DD0C7705h |
mov eax, dword ptr [0049DBCCh] |
mov eax, dword ptr [eax] |
mov edx, 0049ABE0h |
call 00007F58DD0C7304h |
mov ecx, dword ptr [0049DBDCh] |
mov eax, dword ptr [0049DBCCh] |
mov eax, dword ptr [eax] |
mov edx, dword ptr [00496590h] |
call 00007F58DD0C76F4h |
mov eax, dword ptr [0049DBCCh] |
mov eax, dword ptr [eax] |
call 00007F58DD0C7768h |
call 00007F58DD07189Bh |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xa0000 | 0x2a42 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xb0000 | 0x627a0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xa5000 | 0xa980 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0xa4018 | 0x21 | .rdata |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0xa4000 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
CODE | 0x1000 | 0x99bec | 0x99c00 | 33fbe30e8a64654287edd1bf05ae7c8c | False | 0.5141641260162602 | data | 6.572957870355296 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
DATA | 0x9b000 | 0x2e54 | 0x3000 | 1f5e19e7d20c1d128443d738ac7bc610 | False | 0.453125 | data | 4.854620797809023 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
BSS | 0x9e000 | 0x11e5 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.idata | 0xa0000 | 0x2a42 | 0x2c00 | 21ff53180b390dc06e3a1adf0e57a073 | False | 0.3537819602272727 | data | 4.919333216027082 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.tls | 0xa3000 | 0x10 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rdata | 0xa4000 | 0x39 | 0x200 | a92cf494c617731a527994013429ad97 | False | 0.119140625 | MacBinary, Mon Feb 6 07:28:16 2040 INVALID date, modified Mon Feb 6 07:28:16 2040 "J" | 0.7846201577093705 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ |
.reloc | 0xa5000 | 0xa980 | 0xaa00 | dcd1b1c3f3d28d444920211170d1e8e6 | False | 0.5899816176470588 | data | 6.674124985579511 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ |
.rsrc | 0xb0000 | 0x627a0 | 0x62800 | 3f4bf534b7e82a87e254331294b5d609 | False | 0.546731242068528 | data | 6.6892158308280525 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_SHARED, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_CURSOR | 0xb0de0 | 0x134 | Targa image data - Map 64 x 65536 x 1 +32 "\001" | 0.38636363636363635 | ||
RT_CURSOR | 0xb0f14 | 0x134 | data | 0.4642857142857143 | ||
RT_CURSOR | 0xb1048 | 0x134 | data | 0.4805194805194805 | ||
RT_CURSOR | 0xb117c | 0x134 | data | 0.38311688311688313 | ||
RT_CURSOR | 0xb12b0 | 0x134 | data | 0.36038961038961037 | ||
RT_CURSOR | 0xb13e4 | 0x134 | data | 0.4090909090909091 | ||
RT_CURSOR | 0xb1518 | 0x134 | Targa image data - RGB 64 x 65536 x 1 +32 "\001" | 0.4967532467532468 | ||
RT_BITMAP | 0xb164c | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.43103448275862066 | ||
RT_BITMAP | 0xb181c | 0x1e4 | Device independent bitmap graphic, 36 x 19 x 4, image size 380 | 0.46487603305785125 | ||
RT_BITMAP | 0xb1a00 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.43103448275862066 | ||
RT_BITMAP | 0xb1bd0 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.39870689655172414 | ||
RT_BITMAP | 0xb1da0 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.4245689655172414 | ||
RT_BITMAP | 0xb1f70 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.5021551724137931 | ||
RT_BITMAP | 0xb2140 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.5064655172413793 | ||
RT_BITMAP | 0xb2310 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.39655172413793105 | ||
RT_BITMAP | 0xb24e0 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.5344827586206896 | ||
RT_BITMAP | 0xb26b0 | 0x1d0 | Device independent bitmap graphic, 36 x 18 x 4, image size 360 | 0.39655172413793105 | ||
RT_BITMAP | 0xb2880 | 0xe8 | Device independent bitmap graphic, 16 x 16 x 4, image size 128 | 0.4870689655172414 | ||
RT_ICON | 0xb2968 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4096 | 0.4589587242026266 | ||
RT_ICON | 0xb3a10 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 8192 | Turkish | Turkey | 0.2101313320825516 |
RT_DIALOG | 0xb4ab8 | 0x52 | data | 0.7682926829268293 | ||
RT_STRING | 0xb4b0c | 0x358 | data | 0.3796728971962617 | ||
RT_STRING | 0xb4e64 | 0x428 | data | 0.37406015037593987 | ||
RT_STRING | 0xb528c | 0x3a4 | data | 0.40879828326180256 | ||
RT_STRING | 0xb5630 | 0x3bc | data | 0.33472803347280333 | ||
RT_STRING | 0xb59ec | 0x2d4 | data | 0.4654696132596685 | ||
RT_STRING | 0xb5cc0 | 0x334 | data | 0.42804878048780487 | ||
RT_STRING | 0xb5ff4 | 0x42c | data | 0.42602996254681647 | ||
RT_STRING | 0xb6420 | 0x1f0 | data | 0.4213709677419355 | ||
RT_STRING | 0xb6610 | 0x1c0 | data | 0.44419642857142855 | ||
RT_STRING | 0xb67d0 | 0xdc | data | 0.6 | ||
RT_STRING | 0xb68ac | 0x320 | data | 0.45125 | ||
RT_STRING | 0xb6bcc | 0xd8 | data | 0.5879629629629629 | ||
RT_STRING | 0xb6ca4 | 0x118 | data | 0.5678571428571428 | ||
RT_STRING | 0xb6dbc | 0x268 | data | 0.4707792207792208 | ||
RT_STRING | 0xb7024 | 0x3f8 | data | 0.37598425196850394 | ||
RT_STRING | 0xb741c | 0x378 | data | 0.41103603603603606 | ||
RT_STRING | 0xb7794 | 0x380 | data | 0.35379464285714285 | ||
RT_STRING | 0xb7b14 | 0x374 | data | 0.4061085972850679 | ||
RT_STRING | 0xb7e88 | 0xe0 | data | 0.5535714285714286 | ||
RT_STRING | 0xb7f68 | 0xbc | data | 0.526595744680851 | ||
RT_STRING | 0xb8024 | 0x368 | data | 0.40940366972477066 | ||
RT_STRING | 0xb838c | 0x3fc | data | 0.34901960784313724 | ||
RT_STRING | 0xb8788 | 0x2fc | data | 0.36649214659685864 | ||
RT_STRING | 0xb8a84 | 0x354 | data | 0.31572769953051644 | ||
RT_RCDATA | 0xb8dd8 | 0x44 | data | 0.8676470588235294 | ||
RT_RCDATA | 0xb8e1c | 0x10 | data | 1.5 | ||
RT_RCDATA | 0xb8e2c | 0x50800 | PE32 executable (GUI) Intel 80386, for MS Windows | 0.5530528192934783 | ||
RT_RCDATA | 0x10962c | 0x3 | ASCII text, with no line terminators | Turkish | Turkey | 3.6666666666666665 |
RT_RCDATA | 0x109630 | 0x3c00 | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows | Turkish | Turkey | 0.54296875 |
RT_RCDATA | 0x10d230 | 0x64c | data | 0.5998759305210918 | ||
RT_RCDATA | 0x10d87c | 0x153 | Delphi compiled form 'TFormVir' | 0.7522123893805309 | ||
RT_RCDATA | 0x10d9d0 | 0x47d3 | Microsoft Excel 2007+ | Turkish | Turkey | 0.8675150921846957 |
RT_GROUP_CURSOR | 0x1121a4 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.25 | ||
RT_GROUP_CURSOR | 0x1121b8 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.25 | ||
RT_GROUP_CURSOR | 0x1121cc | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.3 | ||
RT_GROUP_CURSOR | 0x1121e0 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.3 | ||
RT_GROUP_CURSOR | 0x1121f4 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.3 | ||
RT_GROUP_CURSOR | 0x112208 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.3 | ||
RT_GROUP_CURSOR | 0x11221c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | 1.3 | ||
RT_GROUP_ICON | 0x112230 | 0x14 | data | Turkish | Turkey | 1.1 |
RT_VERSION | 0x112244 | 0x304 | data | Turkish | Turkey | 0.42875647668393785 |
RT_VERSION | 0x112548 | 0x258 | data | Chinese | China | 0.525 |
DLL | Import |
---|---|
kernel32.dll | DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, VirtualFree, VirtualAlloc, LocalFree, LocalAlloc, GetTickCount, QueryPerformanceCounter, GetVersion, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, SetCurrentDirectoryA, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCurrentDirectoryA, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle |
user32.dll | GetKeyboardType, LoadStringA, MessageBoxA, CharNextA |
advapi32.dll | RegQueryValueExA, RegOpenKeyExA, RegCloseKey |
oleaut32.dll | SysFreeString, SysReAllocStringLen, SysAllocStringLen |
kernel32.dll | TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA |
advapi32.dll | RegSetValueExA, RegQueryValueExA, RegOpenKeyExA, RegNotifyChangeKeyValue, RegFlushKey, RegDeleteValueA, RegCreateKeyExA, RegCloseKey, OpenProcessToken, LookupPrivilegeValueA, GetUserNameA, AdjustTokenPrivileges |
kernel32.dll | lstrcpyA, WritePrivateProfileStringA, WriteFile, WaitForSingleObject, WaitForMultipleObjects, VirtualQuery, VirtualAlloc, UpdateResourceA, UnmapViewOfFile, TerminateProcess, Sleep, SizeofResource, SetThreadLocale, SetFilePointer, SetFileAttributesA, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, RemoveDirectoryA, ReadFile, OpenProcess, OpenMutexA, MultiByteToWideChar, MulDiv, MoveFileA, MapViewOfFile, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalReAlloc, GlobalHandle, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetVersionExA, GetVersion, GetTimeZoneInformation, GetTickCount, GetThreadLocale, GetTempPathA, GetTempFileNameA, GetSystemInfo, GetSystemDirectoryA, GetStringTypeExA, GetStdHandle, GetProcAddress, GetPrivateProfileStringA, GetModuleHandleA, GetModuleFileNameA, GetLogicalDrives, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetFileSize, GetFileAttributesA, GetExitCodeThread, GetDriveTypeA, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess, GetComputerNameA, GetCPInfo, GetACP, FreeResource, InterlockedIncrement, InterlockedExchange, InterlockedDecrement, FreeLibrary, FormatMessageA, FindResourceA, FindNextFileA, FindFirstFileA, FindClose, FileTimeToLocalFileTime, FileTimeToDosDateTime, EnumCalendarInfoA, EnterCriticalSection, EndUpdateResourceA, DeleteFileA, DeleteCriticalSection, CreateThread, CreateProcessA, CreatePipe, CreateMutexA, CreateFileMappingA, CreateFileA, CreateEventA, CreateDirectoryA, CopyFileA, CompareStringA, CloseHandle, BeginUpdateResourceA |
version.dll | VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA |
gdi32.dll | UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, GdiFlush, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, BitBlt |
user32.dll | CreateWindowExA, WindowFromPoint, WinHelpA, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, ToAsciiEx, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, ShowCursor, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageA, OffsetRect, OemToCharA, MsgWaitForMultipleObjects, MessageBoxA, MapWindowPoints, MapVirtualKeyExA, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextLengthA, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassNameA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawEdge, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharUpperBuffA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout |
ole32.dll | CLSIDFromString |
kernel32.dll | Sleep |
oleaut32.dll | SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopyInd, VariantCopy, VariantClear, VariantInit |
ole32.dll | CLSIDFromProgID, CoCreateInstance, CoUninitialize, CoInitialize |
oleaut32.dll | GetErrorInfo, SysFreeString |
comctl32.dll | ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_GetDragImage, ImageList_DragShowNolock, ImageList_SetDragCursorImage, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_ReplaceIcon, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create |
shell32.dll | ShellExecuteExA, ExtractIconExW |
wininet.dll | InternetGetConnectedState, InternetReadFile, InternetOpenUrlA, InternetOpenA, InternetCloseHandle |
shell32.dll | SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc, SHGetDesktopFolder |
advapi32.dll | OpenSCManagerA, CloseServiceHandle |
wsock32.dll | WSACleanup, WSAStartup, gethostname, gethostbyname, inet_ntoa |
netapi32.dll | Netbios |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Turkish | Turkey | |
Chinese | China |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-07T13:18:28.735724+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49744 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:28.773157+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49745 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:29.318163+0100 | 2832617 | ETPRO MALWARE W32.Bloat-A Checkin | 1 | 192.168.2.11 | 49753 | 69.42.215.252 | 80 | TCP |
2025-01-07T13:18:29.796536+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49754 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:29.799804+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49757 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:30.904201+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49768 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:30.922727+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49769 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:31.948079+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49780 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:31.951596+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49781 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:33.998523+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49806 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:34.040266+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49807 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:35.057851+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49818 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:35.116762+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49820 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:36.130544+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49828 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:36.170403+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49829 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:37.195532+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49840 | 142.250.185.110 | 443 | TCP |
2025-01-07T13:18:37.222448+0100 | 2044887 | ET MALWARE Snake Keylogger Payload Request (GET) | 1 | 192.168.2.11 | 49841 | 142.250.185.110 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 13:18:27.683043957 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.683077097 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:27.683197975 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.693763018 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.693775892 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:27.732606888 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.732667923 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:27.732778072 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.733462095 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:27.733481884 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.343372107 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.343471050 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.344367027 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.344424009 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.368834972 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.368901968 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.369590044 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.369642019 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.416276932 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.416302919 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.416351080 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.416384935 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.416663885 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.416673899 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.416727066 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.416740894 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.419173956 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.419195890 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.459331989 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.463330984 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.688366890 CET | 49753 | 80 | 192.168.2.11 | 69.42.215.252 |
Jan 7, 2025 13:18:28.693231106 CET | 80 | 49753 | 69.42.215.252 | 192.168.2.11 |
Jan 7, 2025 13:18:28.693334103 CET | 49753 | 80 | 192.168.2.11 | 69.42.215.252 |
Jan 7, 2025 13:18:28.693512917 CET | 49753 | 80 | 192.168.2.11 | 69.42.215.252 |
Jan 7, 2025 13:18:28.698283911 CET | 80 | 49753 | 69.42.215.252 | 192.168.2.11 |
Jan 7, 2025 13:18:28.735745907 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.735800028 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.736887932 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.736924887 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.736929893 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.736964941 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.737271070 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.737277031 CET | 443 | 49744 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.737289906 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.737325907 CET | 49744 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.739222050 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.739240885 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.739308119 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.740328074 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.740339041 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.751915932 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.751965046 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:28.752047062 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.752537012 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.752556086 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:28.773169041 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.773219109 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.773329973 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.773385048 CET | 443 | 49745 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.773433924 CET | 49745 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.774221897 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.774260998 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:28.774333954 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.774918079 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.774955034 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:28.775010109 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.775871992 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:28.775887012 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:28.776422024 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:28.776434898 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.317869902 CET | 80 | 49753 | 69.42.215.252 | 192.168.2.11 |
Jan 7, 2025 13:18:29.318162918 CET | 49753 | 80 | 192.168.2.11 | 69.42.215.252 |
Jan 7, 2025 13:18:29.378194094 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.378509045 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.379080057 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.379198074 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.382046938 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.382236004 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.383297920 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.383307934 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.383650064 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.384561062 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.387257099 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.387269020 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.387500048 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.387541056 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.387670994 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.388237000 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.407299995 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.407403946 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.408159018 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.410142899 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.412219048 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.412333965 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.415690899 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.415704012 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.415946960 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.417825937 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.417840004 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.417872906 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.418081999 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.418276072 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.418420076 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.418426037 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.431329012 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.431330919 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.459332943 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.463341951 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.796554089 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.797900915 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.799817085 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.799945116 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.799961090 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.801106930 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.801146030 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.804724932 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.818173885 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.818207979 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.818301916 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.818301916 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.818325996 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.819145918 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:29.824212074 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.845875025 CET | 49754 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.845890045 CET | 443 | 49754 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.846446037 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.846463919 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.846615076 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.847104073 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.847107887 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.847117901 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.847121954 CET | 443 | 49757 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.847383976 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.847759962 CET | 49757 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.847968102 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.848010063 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.848148108 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.852165937 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:29.852186918 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:29.983551979 CET | 49755 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:29.983573914 CET | 443 | 49755 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.005094051 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.005126953 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.005312920 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.016103983 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.016119957 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.032166958 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.032217979 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.032345057 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.032816887 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.050380945 CET | 49756 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.050416946 CET | 443 | 49756 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.059272051 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.059298992 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.059509039 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.060652018 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.060678005 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.508974075 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.509033918 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.509633064 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.509639025 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.512547970 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.512553930 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.524086952 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.524180889 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.524606943 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.524617910 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.527062893 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.527077913 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.662370920 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.662437916 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.662856102 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.662862062 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.663120985 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.663132906 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.697844028 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.697906971 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.698491096 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.698512077 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.698678017 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:30.698684931 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:30.904220104 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.904285908 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.904294968 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.904339075 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.904548883 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.904582977 CET | 443 | 49768 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.904630899 CET | 49768 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.905184984 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.905209064 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.905275106 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.905448914 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.905459881 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.922741890 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.922811031 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.922826052 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.922863007 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.923060894 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.923111916 CET | 443 | 49769 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.923197031 CET | 49769 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.923643112 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.923671961 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:30.923737049 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.923998117 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:30.924021006 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.207685947 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.207726955 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.207760096 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.207771063 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.207830906 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.207885027 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.208117008 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.209347010 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.209374905 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.209388971 CET | 49772 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.209400892 CET | 443 | 49772 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.209697962 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.210129976 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.210140944 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.212759018 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.212795019 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.212910891 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.212913990 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.213057041 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.213632107 CET | 49771 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.213646889 CET | 443 | 49771 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.214258909 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.214288950 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.214652061 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.214652061 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.214682102 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.554946899 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.555433035 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.555784941 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.556176901 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.557493925 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.558398008 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.558470964 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.558505058 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.559566975 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.559577942 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.559597015 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.559864044 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.560487986 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.560487986 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.561708927 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.561717987 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.561995983 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.562612057 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.562612057 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.607336998 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.607342005 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.838161945 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.838958979 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.838958979 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.838985920 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.840670109 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.840678930 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.842889071 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.843348026 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.843348026 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.843364954 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.843616009 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:31.843622923 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948096991 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948182106 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948201895 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948303938 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948375940 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948497057 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948636055 CET | 443 | 49780 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948662043 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948750019 CET | 49780 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948862076 CET | 49792 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.948888063 CET | 443 | 49792 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.948966026 CET | 49792 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.949193954 CET | 49792 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.949204922 CET | 443 | 49792 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.951637030 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.951776028 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.951792955 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.951900959 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.951900959 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.951956034 CET | 443 | 49781 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.952161074 CET | 49781 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.952275038 CET | 49793 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.952301979 CET | 443 | 49793 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:31.952531099 CET | 49793 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.952531099 CET | 49793 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:31.952564001 CET | 443 | 49793 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:32.400347948 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.400389910 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.400455952 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.400485039 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.400537014 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.400588036 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.404544115 CET | 49782 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.404572964 CET | 443 | 49782 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.405456066 CET | 49801 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.405494928 CET | 443 | 49801 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.405560017 CET | 49801 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.405962944 CET | 49801 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.405977011 CET | 443 | 49801 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407404900 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407454967 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.407461882 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407478094 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407505989 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.407537937 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.407547951 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407591105 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.407599926 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407620907 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.407643080 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.407665014 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.408756971 CET | 49784 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.408773899 CET | 443 | 49784 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.409528971 CET | 49802 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.409560919 CET | 443 | 49802 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.409641981 CET | 49802 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.409960985 CET | 49802 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.409975052 CET | 443 | 49802 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:32.459796906 CET | 49792 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.459857941 CET | 49793 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.459888935 CET | 49801 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.459912062 CET | 49802 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:32.956984997 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.957026005 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:32.957123995 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.958517075 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.958529949 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:32.961069107 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.961102962 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:32.961225986 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.962647915 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:32.962668896 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.601870060 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.601943970 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.603022099 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.603081942 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.609689951 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.609785080 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.610470057 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.610528946 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.612890005 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.612905025 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.613255024 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.613317013 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.613663912 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.614300013 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.614310980 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.614586115 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.614809036 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.615091085 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.655327082 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.655338049 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.998523951 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.998596907 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.998625994 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.998667002 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.998775959 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.998819113 CET | 443 | 49806 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.998861074 CET | 49806 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.999403954 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.999444962 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:33.999527931 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:33.999536037 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:33.999576092 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:33.999634981 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.000098944 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.000102997 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.000113964 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.000122070 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.040278912 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.040337086 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.040349960 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.040388107 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.040534019 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.040570974 CET | 443 | 49807 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.040621042 CET | 49807 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.041268110 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.041301012 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.041316032 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.041364908 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.041373014 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.041663885 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.041680098 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.041707993 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.041919947 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.041934013 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.646856070 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.646930933 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.650774002 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.650779963 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.651093006 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.651149988 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.651556015 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.657499075 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.657577038 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.658273935 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.658339024 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.659898996 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.659907103 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.660151958 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.660214901 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.660531044 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.681148052 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.681222916 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.683640003 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.683645010 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.683872938 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.684005022 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.684320927 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:34.699337006 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.700006962 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.700068951 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.700862885 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.700932026 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.702756882 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.702769995 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.703011036 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.703059912 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.703460932 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:34.707331896 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:34.731323004 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:34.747333050 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.057858944 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.057945013 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.057971954 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.058105946 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.058351994 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.058396101 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.058402061 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.058480978 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.081825018 CET | 49818 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.081835032 CET | 443 | 49818 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.082700968 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.082740068 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.082798004 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.089560986 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.089579105 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.116790056 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.116843939 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.116852999 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.116904020 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.120588064 CET | 49820 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.120599031 CET | 443 | 49820 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.123995066 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.124027967 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.124268055 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.128737926 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.128752947 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142724991 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142771006 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142781973 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.142793894 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142813921 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.142853975 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.142858982 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142868042 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.142935038 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.143980026 CET | 49821 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.143987894 CET | 443 | 49821 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.144694090 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.144728899 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.144903898 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.145339966 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.145354986 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.150571108 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.150621891 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.150631905 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.150644064 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.150672913 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.150705099 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.150712013 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.150764942 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.150765896 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.154181957 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.169692039 CET | 49819 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.169711113 CET | 443 | 49819 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.170326948 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.170368910 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.170433044 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.170928955 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.170942068 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.718436003 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.718549967 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.719274998 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.719283104 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.721276999 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.721285105 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.765273094 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.765330076 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.765644073 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.765650034 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.765836000 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:35.765840054 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:35.793395042 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.793482065 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.796544075 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.796561956 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.796776056 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.796781063 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.814271927 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.814546108 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.815170050 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.815177917 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:35.815344095 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:35.815347910 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.130290985 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.130357981 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.130382061 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.130889893 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.130970955 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.131017923 CET | 443 | 49828 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.131117105 CET | 49828 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.131572008 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.131613970 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.131668091 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.131998062 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.132013083 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.170404911 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.170466900 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.170478106 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.170681000 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.170759916 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.170794010 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.170924902 CET | 443 | 49829 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.170974016 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.170993090 CET | 49829 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.171365976 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.171401978 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.171493053 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.171696901 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.171708107 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.304730892 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.304801941 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.304841995 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.304860115 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.304878950 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.304943085 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.304971933 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.304981947 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.305882931 CET | 49831 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.305893898 CET | 443 | 49831 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.307121992 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.307161093 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.307218075 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.307493925 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.307507992 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.313656092 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.313698053 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.313771009 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.313782930 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.313795090 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.313796997 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.313879013 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.316792965 CET | 49830 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.316827059 CET | 443 | 49830 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.317295074 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.317315102 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.317404985 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.317826986 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.317837000 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.789386034 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.789468050 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.790139914 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.790189028 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.792453051 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.792462111 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.792692900 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.792735100 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.793091059 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.809273958 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.809345961 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.810055971 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.810106039 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.826960087 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.826975107 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.827255011 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.827302933 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.827714920 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:36.839329004 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.875324011 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:36.934679031 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.934758902 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.935344934 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.935352087 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.937886000 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.937891960 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.945928097 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.945983887 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.946607113 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.946613073 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:36.946788073 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:36.946791887 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.195538044 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.195599079 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.195755005 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.195785999 CET | 443 | 49840 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.195880890 CET | 49840 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.196418047 CET | 49852 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.196453094 CET | 443 | 49852 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.196525097 CET | 49852 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.196717978 CET | 49852 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.196733952 CET | 443 | 49852 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.222454071 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.222521067 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.222680092 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.222709894 CET | 443 | 49841 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.222820997 CET | 49841 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.223261118 CET | 49853 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.223304987 CET | 443 | 49853 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.223382950 CET | 49853 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.223670959 CET | 49853 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.223684072 CET | 443 | 49853 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.386413097 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.386464119 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.386476994 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.386518955 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.386535883 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.386589050 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.386634111 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.387454987 CET | 49842 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.387474060 CET | 443 | 49842 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.388037920 CET | 49854 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.388092041 CET | 443 | 49854 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.388164043 CET | 49854 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.388406038 CET | 49854 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.388421059 CET | 443 | 49854 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.562308073 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.562340975 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.562422037 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.562429905 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.562485933 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.563596964 CET | 49843 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.563616991 CET | 443 | 49843 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.564402103 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.564448118 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.564605951 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.564824104 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.564837933 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:37.602612972 CET | 49852 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.602777958 CET | 49853 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.602792978 CET | 49854 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:37.603158951 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.603182077 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.603451014 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.604252100 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.604285002 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.604346991 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.604984045 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.605000019 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:37.605604887 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:37.605616093 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.191543102 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.191625118 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.192127943 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.192137003 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.192322016 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.192328930 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.258644104 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.258802891 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.259493113 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.259552002 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.259938002 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.260003090 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.261194944 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.261241913 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.263617039 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.263626099 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.263906002 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.263987064 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.264308929 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.267725945 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.267734051 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.268110037 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.268171072 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.268524885 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.311325073 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.315320015 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.651856899 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.651922941 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.651936054 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.651976109 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.652026892 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.652050972 CET | 443 | 49857 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.652101994 CET | 49857 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.652276039 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.652380943 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.652663946 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.652678013 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.652725935 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.652904034 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.652945042 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653065920 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653069019 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653136015 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653172016 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653223991 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653232098 CET | 443 | 49858 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653264999 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653439999 CET | 49858 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653537035 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.653547049 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653727055 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653772116 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653815985 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.653815985 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.653830051 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653847933 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653853893 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.653855085 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.653917074 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.654040098 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.654082060 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.654136896 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.654334068 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:38.654345989 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:38.654509068 CET | 49856 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.654517889 CET | 443 | 49856 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.655200005 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.655229092 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:38.655297041 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.655491114 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:38.655499935 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.284399986 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.284480095 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.287900925 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.287905931 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.288145065 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.288192987 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.288625002 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.292557001 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.292614937 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.292895079 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.292902946 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.293050051 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.293056011 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.295700073 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.295766115 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.296046972 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.296056986 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.296222925 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.296228886 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.304455996 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.304522991 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.309231043 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.309237003 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.309487104 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.309556961 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.309922934 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.331331015 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.351339102 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.692838907 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.692917109 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.692933083 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.693063974 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.693114996 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.693166018 CET | 443 | 49863 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.693212986 CET | 49863 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.694092989 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.694130898 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.694192886 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.694580078 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.694592953 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.700954914 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.701009035 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701019049 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.701064110 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701134920 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701170921 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.701294899 CET | 443 | 49864 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.701314926 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701348066 CET | 49864 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701751947 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.701800108 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.701889038 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.702068090 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:39.702083111 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723197937 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723261118 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723275900 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.723305941 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723335981 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.723407030 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.723411083 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723453045 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.723498106 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.724065065 CET | 49862 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.724080086 CET | 443 | 49862 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.724587917 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.724652052 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.724706888 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.724956036 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.724972963 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.877137899 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.877183914 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.877235889 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.877263069 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.877363920 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.878189087 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.878233910 CET | 443 | 49865 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:39.878242970 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:39.878273010 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:40.343178034 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:40.343271017 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:40.343975067 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:40.344023943 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:40.352684021 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:40.352802992 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:40.358230114 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:40.358314991 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:40.359006882 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:40.359055996 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.746095896 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:46.746123075 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:46.749432087 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.749444962 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:46.749728918 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:46.749816895 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.749882936 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:46.749892950 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:46.750322104 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.750339031 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.750349998 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:46.750720978 CET | 443 | 49876 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:46.750765085 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:46.791338921 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:47.067473888 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:47.067687035 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:47.068718910 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:47.068758965 CET | 443 | 49877 | 142.250.185.110 | 192.168.2.11 |
Jan 7, 2025 13:18:47.068766117 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:47.068798065 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:47.087347031 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:47.087399006 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:47.087408066 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:47.087423086 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:47.087443113 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:47.087480068 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:47.087486982 CET | 443 | 49878 | 142.250.186.161 | 192.168.2.11 |
Jan 7, 2025 13:18:47.087729931 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:47.918863058 CET | 49753 | 80 | 192.168.2.11 | 69.42.215.252 |
Jan 7, 2025 13:18:47.918939114 CET | 49877 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:47.919449091 CET | 49876 | 443 | 192.168.2.11 | 142.250.185.110 |
Jan 7, 2025 13:18:47.919483900 CET | 49865 | 443 | 192.168.2.11 | 142.250.186.161 |
Jan 7, 2025 13:18:47.919539928 CET | 49878 | 443 | 192.168.2.11 | 142.250.186.161 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 7, 2025 13:18:27.670217991 CET | 55541 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:27.676908016 CET | 53 | 55541 | 1.1.1.1 | 192.168.2.11 |
Jan 7, 2025 13:18:28.531847000 CET | 52541 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:28.539412022 CET | 53 | 52541 | 1.1.1.1 | 192.168.2.11 |
Jan 7, 2025 13:18:28.542031050 CET | 64025 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:28.687283993 CET | 53 | 64025 | 1.1.1.1 | 192.168.2.11 |
Jan 7, 2025 13:18:28.744261980 CET | 62784 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:28.751075029 CET | 53 | 62784 | 1.1.1.1 | 192.168.2.11 |
Jan 7, 2025 13:18:32.960489988 CET | 60871 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:32.969486952 CET | 53 | 60871 | 1.1.1.1 | 192.168.2.11 |
Jan 7, 2025 13:18:38.932378054 CET | 56046 | 53 | 192.168.2.11 | 1.1.1.1 |
Jan 7, 2025 13:18:38.941159010 CET | 53 | 56046 | 1.1.1.1 | 192.168.2.11 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 7, 2025 13:18:27.670217991 CET | 192.168.2.11 | 1.1.1.1 | 0x8d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:28.531847000 CET | 192.168.2.11 | 1.1.1.1 | 0x94a6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:28.542031050 CET | 192.168.2.11 | 1.1.1.1 | 0xe81c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:28.744261980 CET | 192.168.2.11 | 1.1.1.1 | 0x2461 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:32.960489988 CET | 192.168.2.11 | 1.1.1.1 | 0x8428 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:38.932378054 CET | 192.168.2.11 | 1.1.1.1 | 0x4a51 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 7, 2025 13:18:20.515013933 CET | 1.1.1.1 | 192.168.2.11 | 0x70c9 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 7, 2025 13:18:20.515013933 CET | 1.1.1.1 | 192.168.2.11 | 0x70c9 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 13:18:27.676908016 CET | 1.1.1.1 | 192.168.2.11 | 0x8d | No error (0) | 142.250.185.110 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 13:18:28.539412022 CET | 1.1.1.1 | 192.168.2.11 | 0x94a6 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:28.687283993 CET | 1.1.1.1 | 192.168.2.11 | 0xe81c | No error (0) | 69.42.215.252 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 13:18:28.751075029 CET | 1.1.1.1 | 192.168.2.11 | 0x2461 | No error (0) | 142.250.186.161 | A (IP address) | IN (0x0001) | false | ||
Jan 7, 2025 13:18:32.969486952 CET | 1.1.1.1 | 192.168.2.11 | 0x8428 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:18:38.941159010 CET | 1.1.1.1 | 192.168.2.11 | 0x4a51 | Name error (3) | none | none | A (IP address) | IN (0x0001) | false | |
Jan 7, 2025 13:19:30.852786064 CET | 1.1.1.1 | 192.168.2.11 | 0xdf70 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 7, 2025 13:19:30.852786064 CET | 1.1.1.1 | 192.168.2.11 | 0xdf70 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.11 | 49753 | 69.42.215.252 | 80 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 7, 2025 13:18:28.693512917 CET | 154 | OUT | |
Jan 7, 2025 13:18:29.317869902 CET | 243 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.11 | 49744 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:28 UTC | 143 | OUT | |
2025-01-07 12:18:28 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.11 | 49745 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:28 UTC | 143 | OUT | |
2025-01-07 12:18:28 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.11 | 49754 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:29 UTC | 143 | OUT | |
2025-01-07 12:18:29 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.11 | 49755 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:29 UTC | 186 | OUT | |
2025-01-07 12:18:29 UTC | 1595 | IN | |
2025-01-07 12:18:29 UTC | 1595 | IN | |
2025-01-07 12:18:29 UTC | 57 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.11 | 49757 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:29 UTC | 143 | OUT | |
2025-01-07 12:18:29 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.11 | 49756 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:29 UTC | 186 | OUT | |
2025-01-07 12:18:30 UTC | 1595 | IN | |
2025-01-07 12:18:30 UTC | 1595 | IN | |
2025-01-07 12:18:30 UTC | 57 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.11 | 49768 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:30 UTC | 143 | OUT | |
2025-01-07 12:18:30 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.11 | 49769 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:30 UTC | 143 | OUT | |
2025-01-07 12:18:30 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.11 | 49771 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:30 UTC | 186 | OUT | |
2025-01-07 12:18:31 UTC | 1594 | IN | |
2025-01-07 12:18:31 UTC | 1594 | IN | |
2025-01-07 12:18:31 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.11 | 49772 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:30 UTC | 186 | OUT | |
2025-01-07 12:18:31 UTC | 1595 | IN | |
2025-01-07 12:18:31 UTC | 1595 | IN | |
2025-01-07 12:18:31 UTC | 57 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.11 | 49780 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:31 UTC | 143 | OUT | |
2025-01-07 12:18:31 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.11 | 49781 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:31 UTC | 143 | OUT | |
2025-01-07 12:18:31 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.11 | 49782 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:31 UTC | 388 | OUT | |
2025-01-07 12:18:32 UTC | 1243 | IN | |
2025-01-07 12:18:32 UTC | 147 | IN | |
2025-01-07 12:18:32 UTC | 1390 | IN | |
2025-01-07 12:18:32 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.11 | 49784 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:31 UTC | 388 | OUT | |
2025-01-07 12:18:32 UTC | 1243 | IN | |
2025-01-07 12:18:32 UTC | 147 | IN | |
2025-01-07 12:18:32 UTC | 1390 | IN | |
2025-01-07 12:18:32 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.11 | 49806 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:33 UTC | 143 | OUT | |
2025-01-07 12:18:33 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.11 | 49807 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:33 UTC | 143 | OUT | |
2025-01-07 12:18:34 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.11 | 49819 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:34 UTC | 387 | OUT | |
2025-01-07 12:18:35 UTC | 1250 | IN | |
2025-01-07 12:18:35 UTC | 140 | IN | |
2025-01-07 12:18:35 UTC | 1390 | IN | |
2025-01-07 12:18:35 UTC | 122 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.11 | 49818 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:34 UTC | 143 | OUT | |
2025-01-07 12:18:35 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.11 | 49821 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:34 UTC | 387 | OUT | |
2025-01-07 12:18:35 UTC | 1243 | IN | |
2025-01-07 12:18:35 UTC | 147 | IN | |
2025-01-07 12:18:35 UTC | 1390 | IN | |
2025-01-07 12:18:35 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.11 | 49820 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:34 UTC | 143 | OUT | |
2025-01-07 12:18:35 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.11 | 49828 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:35 UTC | 143 | OUT | |
2025-01-07 12:18:36 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.11 | 49829 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:35 UTC | 143 | OUT | |
2025-01-07 12:18:36 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.11 | 49830 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:35 UTC | 387 | OUT | |
2025-01-07 12:18:36 UTC | 1243 | IN | |
2025-01-07 12:18:36 UTC | 147 | IN | |
2025-01-07 12:18:36 UTC | 1390 | IN | |
2025-01-07 12:18:36 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.11 | 49831 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:35 UTC | 387 | OUT | |
2025-01-07 12:18:36 UTC | 1243 | IN | |
2025-01-07 12:18:36 UTC | 147 | IN | |
2025-01-07 12:18:36 UTC | 1390 | IN | |
2025-01-07 12:18:36 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.11 | 49840 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:36 UTC | 143 | OUT | |
2025-01-07 12:18:37 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.11 | 49841 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:36 UTC | 143 | OUT | |
2025-01-07 12:18:37 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.11 | 49842 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:36 UTC | 387 | OUT | |
2025-01-07 12:18:37 UTC | 1250 | IN | |
2025-01-07 12:18:37 UTC | 140 | IN | |
2025-01-07 12:18:37 UTC | 1390 | IN | |
2025-01-07 12:18:37 UTC | 122 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.11 | 49843 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:36 UTC | 387 | OUT | |
2025-01-07 12:18:37 UTC | 1243 | IN | |
2025-01-07 12:18:37 UTC | 147 | IN | |
2025-01-07 12:18:37 UTC | 1390 | IN | |
2025-01-07 12:18:37 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.11 | 49856 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:38 UTC | 387 | OUT | |
2025-01-07 12:18:38 UTC | 1243 | IN | |
2025-01-07 12:18:38 UTC | 147 | IN | |
2025-01-07 12:18:38 UTC | 1390 | IN | |
2025-01-07 12:18:38 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.11 | 49858 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:38 UTC | 345 | OUT | |
2025-01-07 12:18:38 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.11 | 49857 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:38 UTC | 345 | OUT | |
2025-01-07 12:18:38 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.11 | 49862 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:39 UTC | 387 | OUT | |
2025-01-07 12:18:39 UTC | 1243 | IN | |
2025-01-07 12:18:39 UTC | 147 | IN | |
2025-01-07 12:18:39 UTC | 1390 | IN | |
2025-01-07 12:18:39 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.11 | 49864 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:39 UTC | 345 | OUT | |
2025-01-07 12:18:39 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.11 | 49863 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:39 UTC | 345 | OUT | |
2025-01-07 12:18:39 UTC | 1314 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.11 | 49865 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:39 UTC | 387 | OUT | |
2025-01-07 12:18:39 UTC | 1243 | IN | |
2025-01-07 12:18:39 UTC | 147 | IN | |
2025-01-07 12:18:39 UTC | 1390 | IN | |
2025-01-07 12:18:39 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.11 | 49878 | 142.250.186.161 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:46 UTC | 387 | OUT | |
2025-01-07 12:18:47 UTC | 1243 | IN | |
2025-01-07 12:18:47 UTC | 147 | IN | |
2025-01-07 12:18:47 UTC | 1390 | IN | |
2025-01-07 12:18:47 UTC | 115 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.11 | 49877 | 142.250.185.110 | 443 | 2260 | C:\ProgramData\Synaptics\Synaptics.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-07 12:18:46 UTC | 345 | OUT | |
2025-01-07 12:18:47 UTC | 1314 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 07:18:18 |
Start date: | 07/01/2025 |
Path: | C:\Users\user\Desktop\1.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1'101'824 bytes |
MD5 hash: | D0598443FA9984227105811E5D89B70F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Borland Delphi |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 2 |
Start time: | 07:18:19 |
Start date: | 07/01/2025 |
Path: | C:\Users\user\Desktop\._cache_1.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x4e0000 |
File size: | 329'728 bytes |
MD5 hash: | 8F02CCF024090E3BD52574174749C778 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 07:18:20 |
Start date: | 07/01/2025 |
Path: | C:\ProgramData\Synaptics\Synaptics.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 772'096 bytes |
MD5 hash: | 065BECDE24188ED65E53BECB09A5A039 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Borland Delphi |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 07:18:21 |
Start date: | 07/01/2025 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc70000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 14 |
Start time: | 07:18:39 |
Start date: | 07/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xd20000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Execution Graph
Execution Coverage: | 1.1% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 34.1% |
Total number of Nodes: | 41 |
Total number of Limit Nodes: | 3 |
Graph
Function 004E8A60 Relevance: 7.7, APIs: 5, Instructions: 216threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00522080 Relevance: 1.5, APIs: 1, Instructions: 14libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00521B50 Relevance: .1, Instructions: 110COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00521816 Relevance: .1, Instructions: 58COMMON
Control-flow Graph
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005223C5 Relevance: 3.0, APIs: 2, Instructions: 26COMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005204B0 Relevance: 1.5, APIs: 1, Instructions: 9memoryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00522000 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F27E0 Relevance: 183.9, APIs: 3, Strings: 101, Instructions: 1937COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050621B Relevance: 33.7, Strings: 26, Instructions: 1202COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051D0D0 Relevance: 30.7, APIs: 10, Strings: 7, Instructions: 957memorycomCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F618C Relevance: 13.5, Strings: 10, Instructions: 1044COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EB280 Relevance: 10.4, Strings: 8, Instructions: 384COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E9360 Relevance: 10.3, Strings: 8, Instructions: 272COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00501B30 Relevance: 9.3, Strings: 7, Instructions: 527COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E9660 Relevance: 9.2, Strings: 7, Instructions: 448COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E9B70 Relevance: 9.2, Strings: 7, Instructions: 418COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051C6C0 Relevance: 9.1, Strings: 7, Instructions: 361COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508B10 Relevance: 8.0, Strings: 6, Instructions: 513COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E42C0 Relevance: 6.7, Strings: 5, Instructions: 465COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EC080 Relevance: 6.4, Strings: 5, Instructions: 104COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507FC0 Relevance: 5.4, Strings: 4, Instructions: 431COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F8BA2 Relevance: 5.4, Strings: 4, Instructions: 367COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F906A Relevance: 5.3, Strings: 4, Instructions: 328COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005237D0 Relevance: 4.4, Strings: 3, Instructions: 647COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005238E0 Relevance: 4.3, Strings: 3, Instructions: 577COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00520B00 Relevance: 4.3, Strings: 3, Instructions: 555COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00523A30 Relevance: 4.2, Strings: 3, Instructions: 488COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502370 Relevance: 4.2, Strings: 3, Instructions: 457COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00523AC0 Relevance: 4.2, Strings: 3, Instructions: 453COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00501180 Relevance: 4.2, Strings: 3, Instructions: 428COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050F716 Relevance: 4.1, Strings: 3, Instructions: 366COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508750 Relevance: 4.1, Strings: 3, Instructions: 328COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050FB7D Relevance: 4.1, Strings: 3, Instructions: 327COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EF2D0 Relevance: 3.9, Strings: 3, Instructions: 168COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E4E20 Relevance: 3.3, Strings: 2, Instructions: 792COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050BA20 Relevance: 3.1, APIs: 2, Instructions: 146COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00502880 Relevance: 3.0, Strings: 2, Instructions: 455COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00523B60 Relevance: 2.9, Strings: 2, Instructions: 441COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00509F7C Relevance: 2.9, Strings: 2, Instructions: 421COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F95B6 Relevance: 2.9, Strings: 2, Instructions: 363COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050F1C1 Relevance: 2.8, Strings: 2, Instructions: 284COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051025E Relevance: 2.8, Strings: 2, Instructions: 282COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005102CD Relevance: 2.8, Strings: 2, Instructions: 281COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F23EC Relevance: 2.8, Strings: 2, Instructions: 271COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051099F Relevance: 2.8, Strings: 2, Instructions: 251COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F5DD8 Relevance: 2.7, Strings: 2, Instructions: 215COMMON
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051E6E0 Relevance: 2.0, Strings: 1, Instructions: 749COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050AF92 Relevance: 2.0, Strings: 1, Instructions: 719COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005124EE Relevance: 1.8, Strings: 1, Instructions: 514COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005039EB Relevance: 1.7, Strings: 1, Instructions: 458COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00506010 Relevance: 1.7, APIs: 1, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051DF60 Relevance: 1.6, Strings: 1, Instructions: 391COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F4C30 Relevance: 1.6, Strings: 1, Instructions: 384COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00510F54 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00510F4E Relevance: 1.6, APIs: 1, Instructions: 81COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E85B0 Relevance: 1.6, Strings: 1, Instructions: 314COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00524C20 Relevance: 1.6, Strings: 1, Instructions: 312COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051B410 Relevance: 1.5, Strings: 1, Instructions: 299COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FBA52 Relevance: 1.5, Strings: 1, Instructions: 293COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E6120 Relevance: 1.5, Strings: 1, Instructions: 265COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00524950 Relevance: 1.5, Strings: 1, Instructions: 257COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F80F0 Relevance: 1.5, Strings: 1, Instructions: 255COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050AFB0 Relevance: 1.5, Strings: 1, Instructions: 222COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FD8B0 Relevance: 1.5, Strings: 1, Instructions: 202COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F8492 Relevance: 1.4, Strings: 1, Instructions: 158COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004ED172 Relevance: 1.4, Strings: 1, Instructions: 132COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00522DCA Relevance: 1.4, Strings: 1, Instructions: 130COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005221E9 Relevance: 1.3, Strings: 1, Instructions: 96COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FB58F Relevance: 1.3, Strings: 1, Instructions: 79COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507FFD Relevance: 1.3, Strings: 1, Instructions: 67COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FF9A0 Relevance: .8, Instructions: 771COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E6950 Relevance: .7, Instructions: 665COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E2F10 Relevance: .7, Instructions: 657COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005152B0 Relevance: .6, Instructions: 627COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E7730 Relevance: .6, Instructions: 613COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E3910 Relevance: .6, Instructions: 600COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E5B00 Relevance: .5, Instructions: 539COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00508C62 Relevance: .4, Instructions: 434COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00513FDF Relevance: .4, Instructions: 423COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004EB92C Relevance: .4, Instructions: 383COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F86E5 Relevance: .4, Instructions: 379COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00513707 Relevance: .3, Instructions: 348COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FD4A0 Relevance: .3, Instructions: 337COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 005242E0 Relevance: .3, Instructions: 321COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E64C0 Relevance: .3, Instructions: 303COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00521C26 Relevance: .3, Instructions: 289COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507C10 Relevance: .3, Instructions: 277COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FD1B0 Relevance: .3, Instructions: 274COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051210B Relevance: .2, Instructions: 246COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00524680 Relevance: .2, Instructions: 244COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00514FF0 Relevance: .2, Instructions: 240COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00507885 Relevance: .2, Instructions: 211COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FF170 Relevance: .2, Instructions: 204COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050F4E1 Relevance: .2, Instructions: 198COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FAB90 Relevance: .2, Instructions: 196COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051C460 Relevance: .2, Instructions: 189COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00517850 Relevance: .2, Instructions: 188COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FA770 Relevance: .2, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E2210 Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051CE90 Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004F7054 Relevance: .1, Instructions: 146COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051CD40 Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E8D10 Relevance: .1, Instructions: 123COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051E520 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FB021 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050E9B0 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00511AF5 Relevance: .1, Instructions: 109COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E8320 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004E2B40 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FB3F2 Relevance: .1, Instructions: 96COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00510F03 Relevance: .1, Instructions: 79COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0051A230 Relevance: .1, Instructions: 64COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0050C5E0 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00520A90 Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004FF3E0 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|