Windows
Analysis Report
http://42.231.79.7:51810/bin.sh
Overview
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- chrome.exe (PID: 3720 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "about :blank" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 5676 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2136 --fi eld-trial- handle=199 2,i,365147 6395786432 483,686983 0452980313 092,262144 --disable -features= Optimizati onGuideMod elDownload ing,Optimi zationHint s,Optimiza tionHintsF etching,Op timization TargetPred iction /pr efetch:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- chrome.exe (PID: 5636 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" "htt p://42.231 .79.7:5181 0/bin.sh" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- OpenWith.exe (PID: 3944 cmdline:
C:\Windows \system32\ OpenWith.e xe -Embedd ing MD5: E4A834784FA08C17D47A1E72429C5109)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Linux_Packer_Patched_UPX_62e11c64 | unknown | unknown |
| |
Linux_Packer_Patched_UPX_62e11c64 | unknown | unknown |
| |
Linux_Packer_Patched_UPX_62e11c64 | unknown | unknown |
|
Click to jump to signature section
AV Detection |
---|
Source: | Avira: | ||
Source: | Avira: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Phishing |
---|
Source: | Joe Sandbox AI: |
Networking |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | TCP traffic: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File deleted: | Jump to behavior |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: | ||
Source: | LNK file: |
Source: | Window detected: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 Browser Extensions | 1 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 2 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 1 Process Injection | LSASS Memory | 1 File and Directory Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 DLL Side-Loading | Security Account Manager | 11 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 File Deletion | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | Internet Connection Discovery | SSH | Keylogging | 3 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | EXP/ELF.Agent.L.26 | ||
100% | Avira | EXP/ELF.Agent.L.26 | ||
74% | ReversingLabs | Linux.Trojan.Dakkatoni | ||
74% | ReversingLabs | Linux.Trojan.Dakkatoni | ||
74% | ReversingLabs | Linux.Trojan.Dakkatoni |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
www.google.com | 142.250.186.100 | true | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
42.231.79.7 | unknown | China | 4837 | CHINA169-BACKBONECHINAUNICOMChina169BackboneCN | true | |
142.250.186.100 | www.google.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.5 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587285 |
Start date and time: | 2025-01-10 04:01:36 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 3m 14s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | browseurl.jbs |
Sample URL: | http://42.231.79.7:51810/bin.sh |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal72.troj.win@19/16@2/4 |
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 142.250.186.67, 142.250.186.110, 64.233.184.84, 172.217.16.206, 142.250.186.78, 142.250.181.238, 199.232.214.172, 192.229.221.95, 142.250.185.206, 216.58.206.78, 142.250.184.206, 142.250.186.99, 172.217.18.14, 34.104.35.123, 2.23.242.162, 172.202.163.200, 13.107.246.45
- Excluded domains from analysis (whitelisted): fs.microsoft.com, accounts.google.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, clientservices.googleapis.com, fe3cr.delivery.mp.microsoft.com, clients2.google.com, ocsp.digicert.com, edgedl.me.gvt1.com, redirector.gvt1.com, update.googleapis.com, clients.l.google.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: http://42.231.79.7:51810/bin.sh
Time | Type | Description |
---|---|---|
22:03:44 | API Interceptor |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Docs.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2677 |
Entropy (8bit): | 3.9799000738313945 |
Encrypted: | false |
SSDEEP: | 48:8RWwdoTM8s1HxidAKZdA19ehwiZUklqehDy+3:8mvuoy |
MD5: | 3425DED89515BE7EBA4832443E353AE2 |
SHA1: | 9DE34E7C76A9427969BCF3F7B04C0B8D5D49D15B |
SHA-256: | B28B4B37B02B86DA6D2574D4A12C03856929CCF3EEA4B47636670F4E491D1897 |
SHA-512: | 2C35F71E93C3CED1C42463EC4B89660B16D4867CE671FDA33EA12B9F8698A18D1D92329259370CE51E3168EA26DEEACF09FE670FC18E44E503C044A2C595217D |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Gmail.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2679 |
Entropy (8bit): | 3.9960264772574705 |
Encrypted: | false |
SSDEEP: | 48:8owdoTM8s1HxidAKZdA1weh/iZUkAQkqehYy+2:82vs9Qxy |
MD5: | B6EC7919659D71A210A1AEBF478D4ABA |
SHA1: | D40D5A6EF569C7236EEB2AD4420C430494AC4E84 |
SHA-256: | E40915764A2D38D03A473BED9F570E18886771352BB494109419764028E4F250 |
SHA-512: | 071E7614E5B971109A3D17347B719810058C37C05BDC292DBCADF6B4D92D77AD3CBAE669A5697786A0C904C9C258AA91FDC3BC8C3DA30D37CE671883ADCC1C48 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Google Drive.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2693 |
Entropy (8bit): | 4.009736386298069 |
Encrypted: | false |
SSDEEP: | 48:8xqwdoTM8sHxidAKZdA14tseh7sFiZUkmgqeh7sOy+BX:8xIvgnEy |
MD5: | B19C29B139167B24EA4FE360F7E8E78A |
SHA1: | D1C853A9CF2F1B7BA5939A5AD99F72C6E34CD259 |
SHA-256: | 49BCBC100E49DAF1DDBFB21B3DADEA03C820B3D61AD85D9E80277867B5C5AF7C |
SHA-512: | 2C6FD3A9A61D05541237D8BF37B3526123B807515407880D1415FD84BEC87479BEB97E120C28756FB69E6CE15FA8F179C725B79E00C8E7B4F804F667A08C41DB |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Sheets.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9961339160408906 |
Encrypted: | false |
SSDEEP: | 48:8awdoTM8s1HxidAKZdA1vehDiZUkwqehsy+R:8YvX2y |
MD5: | CB8774B70EB7B566EC5EC81612B51277 |
SHA1: | C8BC39F99A78DBE3CB4E736D225B12C604DC0EC3 |
SHA-256: | A66B352B2A8BDDFA80919DF0F16739FA4027BE4E8E3E0F57F1857BD22BB69FBC |
SHA-512: | B95A821F2BFD67E87DA785529EFBD2E04725F4FB6B5C66EDD6E7FD10677EC04E55A1DD2B04A65D8D0751FA21154523B5284AA4413C910F30D652E3465EE4000B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\Slides.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2681 |
Entropy (8bit): | 3.9858150592756294 |
Encrypted: | false |
SSDEEP: | 48:8GwdoTM8s1HxidAKZdA1hehBiZUk1W1qehay+C:8Uvn96y |
MD5: | 6BFC9E2C38E147FDF44BE209BB158C0A |
SHA1: | B8A55F1B206EBE38B16FEB012CB66389FDF947F0 |
SHA-256: | 4B1FF7B502DBC88D25AEC89B94806FC30F22CDDB5CD7830AEF3F9B241770962D |
SHA-512: | 531C0A2EADC64DDA6197D52CC31BD1ADFA906555DAD9B7C6F2C8A366609796FD3321A73159F6DF565E0A426D24E7AE526A16A6F96E9B7E7084B3581C0007CA4C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps\YouTube.lnk
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2683 |
Entropy (8bit): | 3.9971457677396836 |
Encrypted: | false |
SSDEEP: | 48:8twdoTM8s1HxidAKZdA1duT+ehOuTbbiZUk5OjqehOuTbEy+yT+:8NvvT/TbxWOvTbEy7T |
MD5: | 7D197413D0DA495CEB5BD631C51E6188 |
SHA1: | B6463E6972F51DD46ACBE76970784FBE4E4FD8C0 |
SHA-256: | C5C8497A4EF4DB46F7E95B4AE760BE120B41EACD0C371CC2CB081D020A02C450 |
SHA-512: | 03E6FD3A7226EBB968827C66906AA1D3B338B01E3C4FA16892EB95877F916F9A37C074CA7373D9442161E9E62A1494CCCFF92580E76C4259CF8C7CABD4FD35CA |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8132 |
Entropy (8bit): | 7.704654889473878 |
Encrypted: | false |
SSDEEP: | 192:fTu2PzRurki7SLDLVpVovt9SbVySN6TQ3JuGpymy/qD1t:flzEBkDOvTCZuQEkymy/Gt |
MD5: | 0FC8FF39AAF015028EEDCBFFF5F8FC88 |
SHA1: | 0F6413CF9BF630231BAD3D327CC4006AD7C22744 |
SHA-256: | 59AE7309B87C1578CC5920515EBE5B151D059C3794F50ABD8ED1D48ABF53180D |
SHA-512: | 2E24853A41D5AAB0D05BA0A440C1299310B15772B19AB0CA0C13535019CC699857D98E46EEE6F02686C6879C049A9DE4DFCE95D21A3C422768B575300193B5E8 |
Malicious: | true |
Yara Hits: |
|
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 135784 |
Entropy (8bit): | 7.814832789965999 |
Encrypted: | false |
SSDEEP: | 3072:phNlHuBafLeBtfCzpta8xlBIOdVo3/4sxLJ10xioP:p3lOYoaja8xzx/0wsxzSi2 |
MD5: | 59CE0BABA11893F90527FC951AC69912 |
SHA1: | 5857A7DD621C4C3EBB0B5A3BEC915D409F70D39F |
SHA-256: | 4293C1D8574DC87C58360D6BAC3DAA182F64F7785C9D41DA5E0741D2B1817FC7 |
SHA-512: | C5B12797B477E5E5964A78766BB40B1C0D9FDFB8EEF1F9AEE3DF451E3441A40C61D325BF400BA51048811B68E1C70A95F15E4166B7A65A4ECA0C624864328647 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 135784 |
Entropy (8bit): | 7.814832789965999 |
Encrypted: | false |
SSDEEP: | 3072:phNlHuBafLeBtfCzpta8xlBIOdVo3/4sxLJ10xioP:p3lOYoaja8xzx/0wsxzSi2 |
MD5: | 59CE0BABA11893F90527FC951AC69912 |
SHA1: | 5857A7DD621C4C3EBB0B5A3BEC915D409F70D39F |
SHA-256: | 4293C1D8574DC87C58360D6BAC3DAA182F64F7785C9D41DA5E0741D2B1817FC7 |
SHA-512: | C5B12797B477E5E5964A78766BB40B1C0D9FDFB8EEF1F9AEE3DF451E3441A40C61D325BF400BA51048811B68E1C70A95F15E4166B7A65A4ECA0C624864328647 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3720_82846416\LICENSE
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1558 |
Entropy (8bit): | 5.11458514637545 |
Encrypted: | false |
SSDEEP: | 48:OBOCrYJ4rYJVwUCLHDy43HV713XEyMmZ3teTHn:LCrYJ4rYJVwUCHZ3Z13XtdUTH |
MD5: | EE002CB9E51BB8DFA89640A406A1090A |
SHA1: | 49EE3AD535947D8821FFDEB67FFC9BC37D1EBBB2 |
SHA-256: | 3DBD2C90050B652D63656481C3E5871C52261575292DB77D4EA63419F187A55B |
SHA-512: | D1FDCC436B8CA8C68D4DC7077F84F803A535BF2CE31D9EB5D0C466B62D6567B2C59974995060403ED757E92245DB07E70C6BDDBF1C3519FED300CC5B9BF9177C |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3720_82846416\_metadata\verified_contents.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1864 |
Entropy (8bit): | 6.018989605004616 |
Encrypted: | false |
SSDEEP: | 48:p/hUI1OwEU3AdIq7ak68O40E2szOxxUJ8BPFkf31U4PrHfqY3J5D:RnOwtQIq7aZ40E2sYUJAYRr/qYZ5D |
MD5: | C4709C1D483C9233A3A66A7E157624EA |
SHA1: | 99A000EB5FE5CC1E94E3155EE075CD6E43DC7582 |
SHA-256: | 225243DC75352D63B0B9B2F48C8AAA09D55F3FB9E385741B12A1956A941880D9 |
SHA-512: | B45E1FD999D1340CC5EB5A49A4CD967DC736EA3F4EC8B02227577CC3D1E903341BE3217FBB0B74765C72085AC51C63EEF6DCB169D137BBAF3CC49E21EA6468D7 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3720_82846416\manifest.fingerprint
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66 |
Entropy (8bit): | 3.820000180714897 |
Encrypted: | false |
SSDEEP: | 3:SVzHL3phUmWRDNKydvgHVz:SBHLLUmWRbCp |
MD5: | BBEC7670A2519FEB0627F17D0C0B5276 |
SHA1: | 9C30B996F1B069F86EF7C0136DFAF7E614674DEA |
SHA-256: | 670A6F6BBADAB2C2BE63898525FCAF72E7454739E77C04D120BC1A46B6694CAC |
SHA-512: | 1ED4ED6AE2A2CBE86F9E8C6C7A2672EBB2F37DBE83D2BF09D875DB435ED63BF5F5CF60CA846865166F9A498095F6D61BD51B0A092E097430439E8A5A3A14CB15 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3720_82846416\manifest.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 85 |
Entropy (8bit): | 4.462192586591686 |
Encrypted: | false |
SSDEEP: | 3:rR6TAulhFphifFCmMARWHJqS1kULJVPY:F6VlM8aRWpqS1kSJVg |
MD5: | 084E339C0C9FE898102815EAC9A7CDEA |
SHA1: | 6ABF7EAAA407D2EAB8706361E5A2E5F776D6C644 |
SHA-256: | 52CD62F4AC1F9E7D7C4944EE111F84A42337D16D5DE7BE296E945146D6D7DC15 |
SHA-512: | 0B67A89F3EBFF6FEC3796F481EC2AFBAC233CF64FDC618EC6BA1C12AE125F28B27EE09E8CD0FADB8F6C8785C83929EA6F751E0DDF592DD072AB2CF439BD28534 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Windows\SystemTemp\chrome_PuffinComponentUnpacker_BeginUnzipping3720_82846416\sets.json
Download File
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9817 |
Entropy (8bit): | 4.629347296880043 |
Encrypted: | false |
SSDEEP: | 96:Mon4mvC4qX19s1blbw/BNKLcxbdmf56MFJtRTGXvcxN43uP+8qJl:v5C4ql7BkIVmtRTGXvcxBsl |
MD5: | 8C702C686B703020BC0290BAFC90D7A0 |
SHA1: | EB08FF7885B4C1DE3EF3D61E40697C0C71903E27 |
SHA-256: | 97D9E39021512305820F27B9662F0351E45639124F5BD29F0466E9072A9D0C62 |
SHA-512: | 6137D0ED10E6A27924ED3AB6A0C5F9B21EB0E16A876447DADABD88338198F31BB9D89EF8F0630F4573EA34A24FB3FD3365D7EA78A97BA10028A0758E0A550739 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 135784 |
Entropy (8bit): | 7.814832789965999 |
Encrypted: | false |
SSDEEP: | 3072:phNlHuBafLeBtfCzpta8xlBIOdVo3/4sxLJ10xioP:p3lOYoaja8xzx/0wsxzSi2 |
MD5: | 59CE0BABA11893F90527FC951AC69912 |
SHA1: | 5857A7DD621C4C3EBB0B5A3BEC915D409F70D39F |
SHA-256: | 4293C1D8574DC87C58360D6BAC3DAA182F64F7785C9D41DA5E0741D2B1817FC7 |
SHA-512: | C5B12797B477E5E5964A78766BB40B1C0D9FDFB8EEF1F9AEE3DF451E3441A40C61D325BF400BA51048811B68E1C70A95F15E4166B7A65A4ECA0C624864328647 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
URL: | http://42.231.79.7:51810/bin.sh |
Preview: |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 10, 2025 04:02:21.093709946 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:21.093713045 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:21.171883106 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:30.701411963 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:30.701412916 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:30.779536963 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:31.819282055 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:31.819338083 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:31.819421053 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:31.819657087 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:31.819683075 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.414586067 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 10, 2025 04:02:32.414800882 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 10, 2025 04:02:32.457524061 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.457940102 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:32.458007097 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.459695101 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.459768057 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:32.461333990 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:32.461432934 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.513541937 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:32.513571978 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:32.560591936 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:32.930692911 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:32.930927038 CET | 49715 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:32.935581923 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:32.935652018 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:32.936336994 CET | 51810 | 49715 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:32.936397076 CET | 49715 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:32.963551998 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:32.968571901 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.097925901 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098540068 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098550081 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098558903 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098568916 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098577976 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098645926 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.098647118 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.098918915 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098927975 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098942041 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.098948002 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.100039005 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.103455067 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.103466034 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.103475094 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.103631020 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.157557011 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.189660072 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.189672947 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.190340042 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.448100090 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.448112965 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.448163986 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.448910952 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.448971033 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.448983908 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449002028 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449011087 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449017048 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.449040890 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.449340105 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449383020 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.449471951 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449482918 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449491978 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.449522018 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.450098991 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.450109005 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.450162888 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.450190067 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.450233936 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.450236082 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.451121092 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451133013 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451143026 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451152086 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451173067 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.451210976 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.451879978 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451890945 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451895952 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.451940060 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.452327967 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.452337980 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.452383995 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.452455997 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.453020096 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.453030109 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.453038931 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.453075886 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.453107119 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.538940907 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.538963079 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.539019108 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.799068928 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799092054 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799120903 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799149990 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799154043 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.799173117 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799194098 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.799504042 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799519062 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799527884 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799595118 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.799895048 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799957991 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799973011 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799988985 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.799998045 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.800031900 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.800209045 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800224066 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800249100 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800271034 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.800563097 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800587893 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800602913 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800606012 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.800652027 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.800965071 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800980091 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.800993919 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.801026106 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.803307056 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803369999 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803386927 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803389072 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.803402901 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803421974 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803426027 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.803436995 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.803529978 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.803989887 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804003954 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804018021 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804033995 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804034948 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.804055929 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804063082 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.804094076 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.804835081 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804847956 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804872990 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804884911 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.804908991 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.804936886 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.805249929 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.805275917 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.805290937 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.805316925 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.806041956 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806077003 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806086063 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.806092024 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806128979 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.806508064 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806521893 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806545019 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806556940 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.806560040 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.806598902 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.807096958 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807112932 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807133913 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807167053 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.807514906 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807540894 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807560921 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.807564020 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807576895 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.807602882 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.808028936 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808083057 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808084011 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.808095932 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808104038 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808137894 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.808545113 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808559895 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808574915 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.808597088 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.808608055 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.809073925 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.809088945 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.809103012 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.809128046 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.858906031 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:34.892987013 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.893002033 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:34.893068075 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.149082899 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149099112 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149161100 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.149514914 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149539948 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149554014 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149569988 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149589062 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.149593115 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.149609089 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150028944 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150049925 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150075912 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150080919 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150094986 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150130033 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150463104 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150479078 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150496960 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150511026 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150546074 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150645018 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150669098 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150681973 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150695086 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.150707960 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.150741100 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.151119947 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151135921 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151149988 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151185036 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.151627064 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151642084 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151655912 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.151676893 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.151701927 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.152192116 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.152209044 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.152226925 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.152252913 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.153599024 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.153636932 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.153650045 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.153659105 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.153666019 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.153692007 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.155709982 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.155735970 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.155751944 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.155774117 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.155791044 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.157151937 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.157166004 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.157187939 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.157201052 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.157217026 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.157243967 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.158235073 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.158250093 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.158263922 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.158302069 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.159387112 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159401894 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159416914 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159442902 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.159461975 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.159864902 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159881115 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159894943 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.159926891 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.160222054 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.161128044 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:35.161181927 CET | 49714 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:02:35.164995909 CET | 51810 | 49714 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:02:42.374804020 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:42.374965906 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:02:42.375164986 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:43.802361965 CET | 49712 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:02:43.802433014 CET | 443 | 49712 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:17.951351881 CET | 49715 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:03:17.956171989 CET | 51810 | 49715 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:03:31.877393007 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:31.877443075 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:31.881390095 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:31.881390095 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:31.881434917 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:32.536631107 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:32.536910057 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:32.536925077 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:32.537425041 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:32.537908077 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:32.538012981 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:32.592592001 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:33.797544003 CET | 49715 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:03:33.803158998 CET | 51810 | 49715 | 42.231.79.7 | 192.168.2.5 |
Jan 10, 2025 04:03:33.803276062 CET | 49715 | 51810 | 192.168.2.5 | 42.231.79.7 |
Jan 10, 2025 04:03:36.883874893 CET | 56560 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:03:36.889484882 CET | 53 | 56560 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:36.889568090 CET | 56560 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:03:36.895200968 CET | 53 | 56560 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:37.367089033 CET | 56560 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:03:37.372351885 CET | 53 | 56560 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:37.372435093 CET | 56560 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:03:42.438101053 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:42.438263893 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Jan 10, 2025 04:03:42.438353062 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:43.798037052 CET | 49990 | 443 | 192.168.2.5 | 142.250.186.100 |
Jan 10, 2025 04:03:43.798115015 CET | 443 | 49990 | 142.250.186.100 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 10, 2025 04:02:27.257371902 CET | 53 | 60146 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:02:27.559366941 CET | 53 | 52768 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:02:28.600276947 CET | 53 | 52358 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:02:31.811335087 CET | 64049 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:02:31.811789989 CET | 63493 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 10, 2025 04:02:31.818226099 CET | 53 | 64049 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:02:31.818453074 CET | 53 | 63493 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:02:45.709294081 CET | 53 | 64033 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:04.757165909 CET | 53 | 60901 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:27.149926901 CET | 53 | 64702 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:28.411617994 CET | 53 | 58663 | 1.1.1.1 | 192.168.2.5 |
Jan 10, 2025 04:03:36.883142948 CET | 53 | 65478 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 10, 2025 04:02:31.811335087 CET | 192.168.2.5 | 1.1.1.1 | 0xb942 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 10, 2025 04:02:31.811789989 CET | 192.168.2.5 | 1.1.1.1 | 0x1287 | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 10, 2025 04:02:31.818226099 CET | 1.1.1.1 | 192.168.2.5 | 0xb942 | No error (0) | 142.250.186.100 | A (IP address) | IN (0x0001) | false | ||
Jan 10, 2025 04:02:31.818453074 CET | 1.1.1.1 | 192.168.2.5 | 0x1287 | No error (0) | 65 | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49714 | 42.231.79.7 | 51810 | 5676 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 10, 2025 04:02:32.963551998 CET | 438 | OUT | |
Jan 10, 2025 04:02:34.097925901 CET | 108 | IN |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 22:02:22 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 2 |
Start time: | 22:02:26 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 3 |
Start time: | 22:02:32 |
Start date: | 09/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff715980000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 22:03:44 |
Start date: | 09/01/2025 |
Path: | C:\Windows\System32\OpenWith.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f0350000 |
File size: | 123'984 bytes |
MD5 hash: | E4A834784FA08C17D47A1E72429C5109 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |