Windows
Analysis Report
1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe
Overview
General Information
Sample name: | 1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
Analysis ID: | 1587332 |
MD5: | 91d66cb0c8827d4910ccfcbc47c47341 |
SHA1: | bddc6177a0b1e74766aad733e3bf2a9d4a8d2fa8 |
SHA256: | 9535dad2b91fa8471968970c7cd34dff2123511f5b451f200a7d7acef8c738f9 |
Tags: | base64-decodedexeuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe (PID: 6220 cmdline:
"C:\Users\ user\Deskt op\1736491 685cd440ba 0222448613 9c45779065 ac91a3edb4 22c48d3d3c 6920c4d30f c9d2bfc582 .dat-decod ed.exe" MD5: 91D66CB0C8827D4910CCFCBC47C47341) - cmd.exe (PID: 5676 cmdline:
C:\Windows \system32\ cmd.exe /c ""C:\User s\user\App Data\Local \Temp\tmp9 468.tmp.ba t"" MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1824 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - timeout.exe (PID: 5656 cmdline:
timeout 3 MD5: 100065E21CFBBDE57CBA2838921F84D6)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
AsyncRAT | AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victims computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques. | No Attribution |
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
DCRat | DCRat is a typical RAT that has been around since at least June 2019. | No Attribution |
{"Server": "drlas.duckdns.org,", "Ports": "5999", "Version": "1.0.7", "Autorun": "false", "Install_Folder": "%AppData%", "AES_key": "ONIEYu5TdgzF27FrSbiruzYVeQWKFfpu", "Mutex": "DcRatMutex_qwqdanchun", "Certificate": "MIICMDCCAZmgAwIBAgIVAIhNlmebb6nSe6ECHjMpYKJ1i7gvMA0GCSqGSIb3DQEBDQUAMGQxFTATBgNVBAMMDERjUmF0IFNlcnZlcjETMBEGA1UECwwKcXdxZGFuY2h1bjEcMBoGA1UECgwTRGNSYXQgQnkgcXdxZGFuY2h1bjELMAkGA1UEBwwCU0gxCzAJBgNVBAYTAkNOMB4XDTIxMDEyODA1MzU1N1oXDTMxMTEwNzA1MzU1N1owEDEOMAwGA1UEAwwFRGNSYXQwgZ8wDQYJKoZIhvcNAQEBBQADgY0AMIGJAoGBALz18kcXxyYRNtzNciIOitqVEEKYOOJZOGjSaWOLKz3M/Df8QpKzt86Y+GK3639BYF/OzJ6i8PyJcI4jCe+L56ytnlJDfAYTzg7df+pvpE6bSgYYgBSEMcKBPrpx6bV5z/V8FOCVqlt9xfM47rHzIs6kOkc0Xu0TqFGxVfi3Koj/AgMBAAGjMjAwMB0GA1UdDgQWBBQOZShjgdZ92lUVGT5AalbF4rcBrDAPBgNVHRMBAf8EBTADAQH/MA0GCSqGSIb3DQEBDQUAA4GBABuRWEmIgb/BjPElBrcq4LuUTHLBWgnJN3yXXtFA+Nl/+mYto5FZMUmzz3mbjKRHuzo79jdei4h1vSO9+2gTFWw1mY8HoeEoyL0YExBQMCoUPjpLJEuAydiWBMXXBmv0zPzE3W7zhG6DRe8pXQkZ2yu8c9G4KxXS1ITmSrlJqBQ6", "ServerSignature": "LUl+TSA5OfYpNCFirGnKVY2PgFqE//sbmddNOLSMH0n+guFtXitTu57o5KL9UVY6AdSPshxtsmNPz+jIc58b7tVHubUfTMuLPeeSRtO9g5rhtyHIRJ1ccmoF6gMeFImBPGtA6RfONX4v4ooFNlds2HDgTXxKLMqme2ugxPVuS3s=", "BDOS": "null", "External_config_on_Pastebin": "false"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
rat_win_dcrat_qwqdanchun | Find DcRAT samples (qwqdanchun) based on specific strings | Sekoia.io |
| |
INDICATOR_SUSPICIOUS_EXE_B64_Artifacts | Detects executables embedding bas64-encoded APIs, command lines, registry keys, etc. | ditekSHen |
| |
INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice | Detects executables attemping to enumerate video devices using WMI | ditekSHen |
| |
Click to see the 1 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
Click to see the 10 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
Windows_Trojan_DCRat_1aeea1ac | unknown | unknown |
| |
rat_win_dcrat_qwqdanchun | Find DcRAT samples (qwqdanchun) based on specific strings | Sekoia.io |
| |
INDICATOR_SUSPICIOUS_EXE_B64_Artifacts | Detects executables embedding bas64-encoded APIs, command lines, registry keys, etc. | ditekSHen |
| |
INDICATOR_SUSPICIOUS_EXE_WMI_EnumerateVideoDevice | Detects executables attemping to enumerate video devices using WMI | ditekSHen |
| |
Click to see the 5 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-10T07:50:29.002132+0100 | 2034847 | 1 | Domain Observed Used for C2 Detected | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-10T07:50:29.002132+0100 | 2842478 | 1 | Malware Command and Control Activity Detected | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
2025-01-10T07:50:44.670989+0100 | 2842478 | 1 | Malware Command and Control Activity Detected | 45.135.232.38 | 5999 | 192.168.2.6 | 49919 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-10T07:50:29.002132+0100 | 2848048 | 1 | Domain Observed Used for C2 Detected | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: | ||
Source: | URLs: |
Source: | DNS query: |
Source: | TCP traffic: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FFD348ADD50 | |
Source: | Code function: | 0_2_00007FFD3489F7E8 | |
Source: | Code function: | 0_2_00007FFD348A0030 | |
Source: | Code function: | 0_2_00007FFD348930E5 | |
Source: | Code function: | 0_2_00007FFD34899132 | |
Source: | Code function: | 0_2_00007FFD3489C07F | |
Source: | Code function: | 0_2_00007FFD3489FBED | |
Source: | Code function: | 0_2_00007FFD34898386 | |
Source: | Code function: | 0_2_00007FFD3489DBCD | |
Source: | Code function: | 0_2_00007FFD3489FCFA | |
Source: | Code function: | 0_2_00007FFD3489773D | |
Source: | Code function: | 0_2_00007FFD34897E89 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FFD3489083E | |
Source: | Code function: | 0_2_00007FFD348900C1 | |
Source: | Code function: | 0_2_00007FFD348B6D27 |
Boot Survival |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Key value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior |
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 1 Scripting | Valid Accounts | 1 Windows Management Instrumentation | 1 Scheduled Task/Job | 12 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Query Registry | Remote Services | 1 Archive Collected Data | 12 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 Scripting | 1 Scheduled Task/Job | 1 Modify Registry | LSASS Memory | 121 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Disable or Modify Tools | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 31 Virtualization/Sandbox Evasion | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 22 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 12 Process Injection | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 11 Obfuscated Files or Information | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
82% | ReversingLabs | ByteCode-MSIL.Backdoor.AsyncRAT | ||
100% | Avira | HEUR/AGEN.1307404 | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | high | |
drlas.duckdns.org | 45.135.232.38 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true | unknown | ||
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
45.135.232.38 | drlas.duckdns.org | Russian Federation | 49392 | ASBAXETNRU | true |
IP |
---|
192.168.2.6 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587332 |
Start date and time: | 2025-01-10 07:49:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@7/5@1/2 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 192.229.221.95, 199.232.210.172, 13.107.246.45, 20.12.23.50
- Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
01:50:29 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
45.135.232.38 | Get hash | malicious | AsyncRAT, DcRat | Browse | ||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | Remcos | Browse | |||
Get hash | malicious | AsyncRAT, DcRat | Browse | |||
Get hash | malicious | Remcos | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | DCRat | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | StormKitty | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ASBAXETNRU | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Meduza Stealer | Browse |
| ||
Get hash | malicious | CredGrabber, Meduza Stealer | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Cryptbot | Browse |
| ||
Get hash | malicious | Clipboard Hijacker, Cryptbot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | KnowBe4 | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Users\user\Desktop\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Users\user\Desktop\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2429904267830576 |
Encrypted: | false |
SSDEEP: | 6:kKwVGDL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:YVGDiDImsLNkPlE99SNxAhUe/3 |
MD5: | 170841B51CFB6DB18036C8AC2B4C58F1 |
SHA1: | 13BD85FB77D71363D011DFED10092E36152C2634 |
SHA-256: | 92734317C95EF193A37EC1F89567360224965C09A13734702D1C672EFC52E66C |
SHA-512: | E90CD32E30C05E0C793FF246DF3352912905938EDC04BFB1B2F04122658D54ACE25820FEB2C825DCA4565864B004A0DD76FD6CDAA9E860BCC993DF4CD268E152 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe.log
Download File
Process: | C:\Users\user\Desktop\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1907 |
Entropy (8bit): | 5.375380268342155 |
Encrypted: | false |
SSDEEP: | 48:MxHKQwYHKGSI6oPtHTHhAHKKkl+vxp3/ell1qHGIs0HKJHNptLHqHj:iqbYqGSI6oPtzHeqKksZp/ellwmj0qJi |
MD5: | 4CEAC8E156C9A1D90AB03AF9133D7A38 |
SHA1: | 39ACAE4267BF940B8995DD12CC797DE497B4D73E |
SHA-256: | 7BB4ADB915FC1C1076B35CC3D69402A22EB89878D6269FAF5826FF06958ED0D6 |
SHA-512: | 597A202013C9E046449D71BF4C816E98BC7203EDBEB17F3D181400590C36E9E545B6FD7449635719EEF595B8730C066313912B1DA1A7F87AC818082B2C330A7B |
Malicious: | true |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 236 |
Entropy (8bit): | 5.295808172690044 |
Encrypted: | false |
SSDEEP: | 6:hWKqTtLN2KO9L0Ek8xK197XGw0rDNeN723fTXCk:wdtR2KO9w+xKW/rDN+aLXh |
MD5: | 3D05AAC2E39D259030F55B271D9A6989 |
SHA1: | F4DAD1F4E2432E5CA6462B2169974D7C8961B4F8 |
SHA-256: | 82CC4FC6B35F59F1D6372A757511C16B82D46F8977465FD8BF8BC97EADDAC88F |
SHA-512: | 181191F787FC6F8D565375D2A8B01DF175C621CE43E41005A95A6A276363716726B15A62CABD61CE81501E494CA19F994EDB6F2DCD11422A7E441209FFA0EB06 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\timeout.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.41440934524794 |
Encrypted: | false |
SSDEEP: | 3:hYFqdLGAR+mQRKVxLZXt0sn:hYFqGaNZKsn |
MD5: | 3DD7DD37C304E70A7316FE43B69F421F |
SHA1: | A3754CFC33E9CA729444A95E95BCB53384CB51E4 |
SHA-256: | 4FA27CE1D904EA973430ADC99062DCF4BAB386A19AB0F8D9A4185FA99067F3AA |
SHA-512: | 713533E973CF0FD359AC7DB22B1399392C86D9FD1E715248F5724AAFBBF0EEB5EAC0289A0E892167EB559BE976C2AD0A0A0D8EFC407FFAF5B3C3A32AA9A0AAA4 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 5.61761828164522 |
TrID: |
|
File name: | 1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
File size: | 48'640 bytes |
MD5: | 91d66cb0c8827d4910ccfcbc47c47341 |
SHA1: | bddc6177a0b1e74766aad733e3bf2a9d4a8d2fa8 |
SHA256: | 9535dad2b91fa8471968970c7cd34dff2123511f5b451f200a7d7acef8c738f9 |
SHA512: | 5c9ac570df36d4822889fa57ff16acf88fb0e55ed88e040443d5f385abae43fad7df5710a07393837edc6995e13fca5cd142c650430e5017a99c3e1acf176627 |
SSDEEP: | 768:xGq+s3pUtDILNCCa+Di+0jd3gLqRp8A0PiBMYb5geHuFNxGNKvEgK/JLZVc6KN:8q+AGtQO+GaPAPDbWiyNsknkJLZVclN |
TLSH: | F2236C0037D8C13AE2FD4BB5A9F2A1458279E6576903CB596CC811EA2F13BC597036FE |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`................................. ........@.. ....................... ............@................................ |
Icon Hash: | 00928e8e8686b000 |
Entrypoint: | 0x40cbbe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x60930A0B [Wed May 5 21:11:39 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xcb68 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0xe000 | 0xdf7 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x10000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xabc4 | 0xac00 | c45e84d071d614c5ee46942222967e66 | False | 0.5022256540697675 | data | 5.6433375334755755 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0xe000 | 0xdf7 | 0xe00 | 2083376922615c09cdda9acfd9305376 | False | 0.4017857142857143 | data | 5.110607648061562 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x10000 | 0xc | 0x200 | 82148d01c3935cf90ef81a3dd1fad607 | False | 0.044921875 | data | 0.07763316234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0xe0a0 | 0x2d4 | data | 0.4350828729281768 | ||
RT_MANIFEST | 0xe374 | 0xa83 | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.40245261984392416 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-10T07:50:29.002132+0100 | 2842478 | ETPRO JA3 Hash - Suspected ASYNCRAT Server Cert (ja3s) | 1 | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
2025-01-10T07:50:29.002132+0100 | 2034847 | ET MALWARE Observed Malicious SSL Cert (AsyncRAT) | 1 | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
2025-01-10T07:50:29.002132+0100 | 2848048 | ETPRO MALWARE Observed Malicious SSL Cert (AsyncRAT) | 1 | 45.135.232.38 | 5999 | 192.168.2.6 | 49826 | TCP |
2025-01-10T07:50:44.670989+0100 | 2842478 | ETPRO JA3 Hash - Suspected ASYNCRAT Server Cert (ja3s) | 1 | 45.135.232.38 | 5999 | 192.168.2.6 | 49919 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 10, 2025 07:50:06.132013083 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:06.132019997 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:06.261193037 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:06.261229992 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:06.261428118 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:06.261869907 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:06.261883974 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:06.444556952 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:07.070242882 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.070452929 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.075671911 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.075691938 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.076077938 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.088617086 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.088645935 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.088653088 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.088787079 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.131324053 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.263334990 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.263423920 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:07.263500929 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.263667107 CET | 49709 | 443 | 192.168.2.6 | 40.113.110.67 |
Jan 10, 2025 07:50:07.263689995 CET | 443 | 49709 | 40.113.110.67 | 192.168.2.6 |
Jan 10, 2025 07:50:14.178601980 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.178612947 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.178675890 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.179434061 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.179445028 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.979967117 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.980057955 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.982486963 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.982500076 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.982780933 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.984657049 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.984708071 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:14.984718084 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:14.984834909 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:15.027331114 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:15.159013033 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:15.159106970 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:15.159671068 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:15.160243988 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:15.160264015 CET | 443 | 49736 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:15.160284042 CET | 49736 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:15.741614103 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:15.741709948 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:16.053922892 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:17.753611088 CET | 443 | 49704 | 173.222.162.64 | 192.168.2.6 |
Jan 10, 2025 07:50:17.753699064 CET | 49704 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 10, 2025 07:50:26.311728954 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:26.311770916 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:26.311855078 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:26.312566996 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:26.312581062 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.118375063 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.118663073 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.120063066 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.120078087 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.120291948 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.121932983 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.121932983 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.121954918 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.122195005 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.163338900 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.301204920 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.301446915 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:27.301565886 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.301743031 CET | 49808 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:27.301760912 CET | 443 | 49808 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:28.285481930 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:28.290518999 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:28.290604115 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:28.318129063 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:28.322922945 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:28.991379023 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:28.996828079 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:29.002131939 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:29.228600025 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:29.272576094 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:30.405498981 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:30.410283089 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:30.410341978 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:30.415164948 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.082490921 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.132076979 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.278964043 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.294898987 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.299710035 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.299777985 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.304645061 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754081964 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754190922 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754247904 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754256964 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754297972 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.754333973 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754343033 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754378080 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.754483938 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754493952 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754503965 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754514933 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754537106 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.754554033 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.754889965 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754937887 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754946947 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.754987001 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.755271912 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.755326033 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.759169102 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.759218931 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.759229898 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.759274960 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.884433031 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885081053 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885132074 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885157108 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885170937 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885186911 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885194063 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885200977 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885212898 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885230064 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885287046 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885371923 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885412931 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885509014 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885523081 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885536909 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885593891 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885593891 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885672092 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885684013 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885698080 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.885737896 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.885747910 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.886276007 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886291027 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886303902 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886344910 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.886384964 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.886415958 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886435986 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886449099 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886462927 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.886475086 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.886502981 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.887139082 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.887166023 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.887182951 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.887219906 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.887243032 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:42.887294054 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.889205933 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.890016079 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:42.928868055 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.015384912 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015433073 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015444994 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015494108 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.015502930 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015583038 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.015611887 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015625000 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015666962 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.015789032 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015801907 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015815020 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015827894 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.015851974 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.015875101 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.016062021 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016067982 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016105890 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.016438961 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016541004 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016583920 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.016592979 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016654015 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016668081 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016695023 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.016791105 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016803026 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016815901 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016827106 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.016833067 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.016861916 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017015934 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017028093 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017060041 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017560005 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017580032 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017592907 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017601013 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017626047 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017795086 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017807007 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017818928 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017831087 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017838001 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017877102 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.017986059 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.017997980 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018034935 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.018503904 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018547058 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018558025 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018589020 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.018691063 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018703938 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018732071 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.018868923 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018881083 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018892050 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018903017 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.018909931 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.018927097 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.019475937 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.019486904 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.019514084 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.020302057 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.020313025 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.020340919 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.069504023 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330516100 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330537081 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330555916 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330568075 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330578089 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330589056 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330600023 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330610991 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330624104 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330629110 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330640078 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330651999 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330657005 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330677986 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330822945 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330833912 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330845118 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330857038 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330864906 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330869913 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.330881119 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.330904961 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331095934 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331106901 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331119061 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331129074 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331140995 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331140995 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331176043 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331196070 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331207991 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331218958 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331231117 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331232071 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331240892 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331252098 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331257105 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331263065 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331276894 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.331283092 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.331300020 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332065105 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332078934 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332088947 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332099915 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332109928 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332112074 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332118034 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332122087 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332133055 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332144022 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332150936 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332154989 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332165956 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332170963 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332175970 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332184076 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332187891 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332200050 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332211018 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.332225084 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.332247972 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.333029985 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333043098 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333053112 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333064079 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333072901 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.333072901 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333085060 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.333098888 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.333126068 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.338272095 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338325024 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338335991 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338360071 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.338454962 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338466883 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338493109 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.338570118 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.338609934 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.360733986 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.365525007 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.370356083 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.370417118 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.375286102 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.884471893 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.885837078 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.889458895 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.889544964 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.890759945 CET | 5999 | 49919 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.890841007 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.891186953 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:43.894557953 CET | 5999 | 49826 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:43.896001101 CET | 5999 | 49919 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:44.665642023 CET | 5999 | 49919 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:44.666248083 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:44.670989037 CET | 5999 | 49919 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:44.701884031 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:44.706958055 CET | 5999 | 49919 | 45.135.232.38 | 192.168.2.6 |
Jan 10, 2025 07:50:44.707055092 CET | 49919 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:44.712488890 CET | 49826 | 5999 | 192.168.2.6 | 45.135.232.38 |
Jan 10, 2025 07:50:44.890357018 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:44.890403986 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:44.890485048 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:44.891087055 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:44.891103983 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.778808117 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.778889894 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.782510042 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.782519102 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.782753944 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.784409046 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.784468889 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.784476042 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.784745932 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.827325106 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.963174105 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.963248968 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:50:45.963300943 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.963458061 CET | 49925 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:50:45.963473082 CET | 443 | 49925 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:08.623238087 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:08.623270988 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:08.623373032 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:08.623918056 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:08.623931885 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.423871994 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.423971891 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.425896883 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.425909042 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.426153898 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.427611113 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.427681923 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.427687883 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.427824974 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.475330114 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.606277943 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.606373072 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:09.606436968 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.607748985 CET | 49988 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:09.607770920 CET | 443 | 49988 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:40.984044075 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:40.984144926 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:40.984241009 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:40.984827995 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:40.984868050 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.760119915 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.760231018 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.762192011 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.762227058 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.762495995 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.764266014 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.764309883 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.764323950 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.764439106 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.807323933 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.934061050 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.934143066 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:41.934277058 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.934519053 CET | 49989 | 443 | 192.168.2.6 | 40.113.103.199 |
Jan 10, 2025 07:51:41.934561014 CET | 443 | 49989 | 40.113.103.199 | 192.168.2.6 |
Jan 10, 2025 07:51:47.078392029 CET | 49703 | 443 | 192.168.2.6 | 20.190.159.4 |
Jan 10, 2025 07:51:47.085212946 CET | 443 | 49703 | 20.190.159.4 | 192.168.2.6 |
Jan 10, 2025 07:51:47.085268021 CET | 49703 | 443 | 192.168.2.6 | 20.190.159.4 |
Jan 10, 2025 07:51:49.648036957 CET | 49707 | 443 | 192.168.2.6 | 20.190.159.4 |
Jan 10, 2025 07:51:49.655132055 CET | 443 | 49707 | 20.190.159.4 | 192.168.2.6 |
Jan 10, 2025 07:51:49.655224085 CET | 49707 | 443 | 192.168.2.6 | 20.190.159.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 10, 2025 07:50:28.179986954 CET | 59101 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 10, 2025 07:50:28.284655094 CET | 53 | 59101 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 10, 2025 07:50:28.179986954 CET | 192.168.2.6 | 1.1.1.1 | 0x7ac | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 10, 2025 07:50:28.284655094 CET | 1.1.1.1 | 192.168.2.6 | 0x7ac | No error (0) | 45.135.232.38 | A (IP address) | IN (0x0001) | false | ||
Jan 10, 2025 07:50:29.043571949 CET | 1.1.1.1 | 192.168.2.6 | 0x5dc8 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 10, 2025 07:50:29.043571949 CET | 1.1.1.1 | 192.168.2.6 | 0x5dc8 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.6 | 49709 | 40.113.110.67 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:50:07 UTC | 70 | OUT | |
2025-01-10 06:50:07 UTC | 249 | OUT | |
2025-01-10 06:50:07 UTC | 1083 | OUT | |
2025-01-10 06:50:07 UTC | 217 | OUT | |
2025-01-10 06:50:07 UTC | 14 | IN | |
2025-01-10 06:50:07 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.6 | 49736 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:50:14 UTC | 71 | OUT | |
2025-01-10 06:50:14 UTC | 249 | OUT | |
2025-01-10 06:50:14 UTC | 1084 | OUT | |
2025-01-10 06:50:14 UTC | 218 | OUT | |
2025-01-10 06:50:15 UTC | 14 | IN | |
2025-01-10 06:50:15 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
2 | 192.168.2.6 | 49808 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:50:27 UTC | 71 | OUT | |
2025-01-10 06:50:27 UTC | 249 | OUT | |
2025-01-10 06:50:27 UTC | 1084 | OUT | |
2025-01-10 06:50:27 UTC | 218 | OUT | |
2025-01-10 06:50:27 UTC | 14 | IN | |
2025-01-10 06:50:27 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
3 | 192.168.2.6 | 49925 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:50:45 UTC | 70 | OUT | |
2025-01-10 06:50:45 UTC | 249 | OUT | |
2025-01-10 06:50:45 UTC | 1083 | OUT | |
2025-01-10 06:50:45 UTC | 217 | OUT | |
2025-01-10 06:50:45 UTC | 14 | IN | |
2025-01-10 06:50:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
4 | 192.168.2.6 | 49988 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:51:09 UTC | 70 | OUT | |
2025-01-10 06:51:09 UTC | 249 | OUT | |
2025-01-10 06:51:09 UTC | 1083 | OUT | |
2025-01-10 06:51:09 UTC | 217 | OUT | |
2025-01-10 06:51:09 UTC | 14 | IN | |
2025-01-10 06:51:09 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
5 | 192.168.2.6 | 49989 | 40.113.103.199 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-10 06:51:41 UTC | 71 | OUT | |
2025-01-10 06:51:41 UTC | 249 | OUT | |
2025-01-10 06:51:41 UTC | 1084 | OUT | |
2025-01-10 06:51:41 UTC | 218 | OUT | |
2025-01-10 06:51:41 UTC | 14 | IN | |
2025-01-10 06:51:41 UTC | 58 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 01:50:10 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\Desktop\1736491685cd440ba02224486139c45779065ac91a3edb422c48d3d3c6920c4d30fc9d2bfc582.dat-decoded.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xc60000 |
File size: | 48'640 bytes |
MD5 hash: | 91D66CB0C8827D4910CCFCBC47C47341 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 4 |
Start time: | 01:50:43 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7538d0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 01:50:43 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 01:50:43 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\timeout.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e1d60000 |
File size: | 32'768 bytes |
MD5 hash: | 100065E21CFBBDE57CBA2838921F84D6 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Execution Graph
Execution Coverage: | 19.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 6 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34898386 Relevance: .5, Instructions: 471COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34899132 Relevance: .5, Instructions: 456COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD34897E89 Relevance: .4, Instructions: 411COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FFD3489773D Relevance: .4, Instructions: 390COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|