Windows
Analysis Report
4NG0guPiKA.exe
Overview
General Information
Sample name: | 4NG0guPiKA.exerenamed because original name is a hash value |
Original sample name: | ec0c8d7a3312e95aa25f0ce8dd738ed1660246374f6a6d1a268b97ae4d3c4d47.exe |
Analysis ID: | 1588607 |
MD5: | 8f02b3e31021d64ed25a599e58bc8f2f |
SHA1: | 7bec44b33d33f11de7f626097b70758f60f655f5 |
SHA256: | ec0c8d7a3312e95aa25f0ce8dd738ed1660246374f6a6d1a268b97ae4d3c4d47 |
Tags: | exeuser-adrian__luca |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 4NG0guPiKA.exe (PID: 7912 cmdline:
"C:\Users\ user\Deskt op\4NG0guP iKA.exe" MD5: 8F02B3E31021D64ED25A599E58BC8F2F) - 4NG0guPiKA.exe (PID: 8156 cmdline:
"C:\Users\ user\Deskt op\4NG0guP iKA.exe" MD5: 8F02B3E31021D64ED25A599E58BC8F2F)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
CloudEyE, GuLoader | CloudEyE (initially named GuLoader) is a small VB5/6 downloader. It typically downloads RATs/Stealers, such as Agent Tesla, Arkei/Vidar, Formbook, Lokibot, Netwire and Remcos, often but not always from Google Drive. The downloaded payload is xored. | No Attribution |
{"C2 url": "https://api.telegram.org/bot7766574905:AAHqEKY-434lRHaHTq5dzX-5SzIzpyCwC4s/sendMessage"}
{"EXfil Mode": "Telegram", "Telegram Token": "7766574905:AAHqEKY-434lRHaHTq5dzX-5SzIzpyCwC4s", "Telegram Chatid": "2065242915"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_MassLogger | Yara detected MassLogger RAT | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_TelegramRAT | Yara detected Telegram RAT | Joe Security | ||
JoeSecurity_GuLoader_2 | Yara detected GuLoader | Joe Security | ||
JoeSecurity_MassLogger | Yara detected MassLogger RAT | Joe Security | ||
Click to see the 2 entries |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T03:05:37.704410+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49712 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:41.624698+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49714 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:45.406336+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49716 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:52.013161+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49720 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:54.865177+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49722 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:02.377370+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49725 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:12.529577+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49728 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:15.965935+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49730 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:17.832210+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49732 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:19.535991+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49734 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:21.431724+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49736 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:23.238549+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49738 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:24.909136+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49740 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:26.624961+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49742 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:28.276828+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49744 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:29.999996+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49746 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:31.750830+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49748 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:33.431948+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49750 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:35.151286+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49752 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:36.876519+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49754 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:39.032361+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49756 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:40.757522+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49758 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:42.413636+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49760 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:44.177514+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49762 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:46.849067+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49764 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:48.866226+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49766 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:50.701288+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49768 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:52.402052+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49770 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:54.047819+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49772 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:55.991776+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49774 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:57.713812+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49776 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:59.524787+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49778 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:01.457769+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49780 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:03.214933+0100 | 2057744 | 1 | Malware Command and Control Activity Detected | 192.168.2.10 | 49782 | 149.154.167.220 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T03:05:28.438391+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.10 | 49710 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:05:35.297783+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.10 | 49710 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:05:40.844817+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.10 | 49713 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:06:11.751087+0100 | 2803274 | 2 | Potentially Bad Traffic | 192.168.2.10 | 49727 | 132.226.8.169 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T03:05:23.278926+0100 | 2803270 | 2 | Potentially Bad Traffic | 192.168.2.10 | 49708 | 142.250.181.238 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T03:05:35.915509+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49712 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:41.443058+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49714 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:45.159302+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49716 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:51.763518+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49720 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:54.618271+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49722 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:02.200710+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49725 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:12.354997+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49728 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:15.719575+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49730 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:17.658282+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49732 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:19.289507+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49734 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:21.119452+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49736 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:22.988605+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49738 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:24.736208+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49740 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:26.374032+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49742 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:28.100460+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49744 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:29.820597+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49746 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:31.576717+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49748 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:33.254475+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49750 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:34.901388+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49752 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:36.703013+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49754 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:38.859785+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49756 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:40.493302+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49758 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:42.236480+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49760 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:43.906128+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49762 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:46.671836+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49764 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:48.612707+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49766 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:50.439435+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49768 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:52.156184+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49770 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:53.871628+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49772 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:55.817470+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49774 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:57.463427+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49776 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:59.268236+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49778 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:01.199872+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49780 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:02.957766+0100 | 1810008 | 1 | Potentially Bad Traffic | 192.168.2.10 | 49782 | 149.154.167.220 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: | ||
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Location Tracking |
---|
Source: | DNS query: |
Source: | Code function: | 3_2_331ED1EC | |
Source: | Code function: | 3_2_331ED9D9 |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_00405772 | |
Source: | Code function: | 0_2_0040622D | |
Source: | Code function: | 0_2_00402770 | |
Source: | Code function: | 3_2_00402770 | |
Source: | Code function: | 3_2_00405772 | |
Source: | Code function: | 3_2_0040622D |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 3_2_331E03AF | |
Source: | Code function: | 3_2_331EC638 | |
Source: | Code function: | 3_2_331E0C28 | |
Source: | Code function: | 3_2_331EE339 | |
Source: | Code function: | 3_2_331EEBF7 | |
Source: | Code function: | 3_2_331EDA89 | |
Source: | Code function: | 3_2_331EB944 | |
Source: | Code function: | 3_2_331EC1F2 | |
Source: | Code function: | 3_2_331EF042 | |
Source: | Code function: | 3_2_331EB07F | |
Source: | Code function: | 3_2_331E0F6F | |
Source: | Code function: | 3_2_331EE790 | |
Source: | Code function: | 3_2_331EDEE1 | |
Source: | Code function: | 3_2_331EBD88 | |
Source: | Code function: | 3_2_331E0C1A | |
Source: | Code function: | 3_2_331EB4EC | |
Source: | Code function: | 3_2_35F2BDF0 | |
Source: | Code function: | 3_2_35F28650 | |
Source: | Code function: | 3_2_35F28650 | |
Source: | Code function: | 3_2_35F24DB0 | |
Source: | Code function: | 3_2_35F22560 | |
Source: | Code function: | 3_2_35F274C8 | |
Source: | Code function: | 3_2_35F21CB0 | |
Source: | Code function: | 3_2_35F26C18 | |
Source: | Code function: | 3_2_35F21400 | |
Source: | Code function: | 3_2_35F267C0 | |
Source: | Code function: | 3_2_35F20FA8 | |
Source: | Code function: | 3_2_35F23F70 | |
Source: | Code function: | 3_2_35F25F10 | |
Source: | Code function: | 3_2_35F236C0 | |
Source: | Code function: | 3_2_35F25660 | |
Source: | Code function: | 3_2_35F22E10 | |
Source: | Code function: | 3_2_35F229B8 | |
Source: | Code function: | 3_2_35F22108 | |
Source: | Code function: | 3_2_35F27070 | |
Source: | Code function: | 3_2_35F21858 | |
Source: | Code function: | 3_2_35F24820 | |
Source: | Code function: | 3_2_35F243C8 | |
Source: | Code function: | 3_2_35F26368 | |
Source: | Code function: | 3_2_35F27B4F | |
Source: | Code function: | 3_2_35F23B18 | |
Source: | Code function: | 3_2_35F25AB8 | |
Source: | Code function: | 3_2_35F23268 | |
Source: | Code function: | 3_2_35F25208 | |
Source: | Code function: | 3_2_3645E8A8 |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTPS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | Code function: | 0_2_004052D3 |
Source: | Code function: | 0_2_0040335A | |
Source: | Code function: | 3_2_0040335A |
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00404B10 | |
Source: | Code function: | 0_2_0040653F | |
Source: | Code function: | 3_2_00404B10 | |
Source: | Code function: | 3_2_0040653F | |
Source: | Code function: | 3_2_000D4328 | |
Source: | Code function: | 3_2_000D66B8 | |
Source: | Code function: | 3_2_000D9048 | |
Source: | Code function: | 3_2_000D19B8 | |
Source: | Code function: | 3_2_000D5F90 | |
Source: | Code function: | 3_2_000D89D0 | |
Source: | Code function: | 3_2_000D2DD1 | |
Source: | Code function: | 3_2_331E331A | |
Source: | Code function: | 3_2_331E5392 | |
Source: | Code function: | 3_2_331E03AF | |
Source: | Code function: | 3_2_331EC638 | |
Source: | Code function: | 3_2_331E7628 | |
Source: | Code function: | 3_2_331EF648 | |
Source: | Code function: | 3_2_331ECCA0 | |
Source: | Code function: | 3_2_331EE339 | |
Source: | Code function: | 3_2_331EEBF7 | |
Source: | Code function: | 3_2_331E6A43 | |
Source: | Code function: | 3_2_331EDA89 | |
Source: | Code function: | 3_2_331EAAEA | |
Source: | Code function: | 3_2_331EB944 | |
Source: | Code function: | 3_2_331E69CB | |
Source: | Code function: | 3_2_331EC1F2 | |
Source: | Code function: | 3_2_331E69E9 | |
Source: | Code function: | 3_2_331E7848 | |
Source: | Code function: | 3_2_331EF042 | |
Source: | Code function: | 3_2_331EB07F | |
Source: | Code function: | 3_2_331EE790 | |
Source: | Code function: | 3_2_331E7E1E | |
Source: | Code function: | 3_2_331E7E3C | |
Source: | Code function: | 3_2_331E7E9A | |
Source: | Code function: | 3_2_331E6E91 | |
Source: | Code function: | 3_2_331E6EA0 | |
Source: | Code function: | 3_2_331EDEE1 | |
Source: | Code function: | 3_2_331E7510 | |
Source: | Code function: | 3_2_331EBD88 | |
Source: | Code function: | 3_2_331ECC8E | |
Source: | Code function: | 3_2_331E748C | |
Source: | Code function: | 3_2_331E74B1 | |
Source: | Code function: | 3_2_331EB4EC | |
Source: | Code function: | 3_2_35F2BDF0 | |
Source: | Code function: | 3_2_35F29D10 | |
Source: | Code function: | 3_2_35F296C8 | |
Source: | Code function: | 3_2_35F28650 | |
Source: | Code function: | 3_2_35F2A9B0 | |
Source: | Code function: | 3_2_35F2A360 | |
Source: | Code function: | 3_2_35F2BA97 | |
Source: | Code function: | 3_2_35F2BDE1 | |
Source: | Code function: | 3_2_35F24DB0 | |
Source: | Code function: | 3_2_35F24DA0 | |
Source: | Code function: | 3_2_35F22560 | |
Source: | Code function: | 3_2_35F22550 | |
Source: | Code function: | 3_2_35F29D00 | |
Source: | Code function: | 3_2_35F274C8 | |
Source: | Code function: | 3_2_35F21CB0 | |
Source: | Code function: | 3_2_35F274B8 | |
Source: | Code function: | 3_2_35F21CA0 | |
Source: | Code function: | 3_2_35F26C18 | |
Source: | Code function: | 3_2_35F21400 | |
Source: | Code function: | 3_2_35F2AFF7 | |
Source: | Code function: | 3_2_35F2AFF8 | |
Source: | Code function: | 3_2_35F2AFE8 | |
Source: | Code function: | 3_2_35F267C0 | |
Source: | Code function: | 3_2_35F267B0 | |
Source: | Code function: | 3_2_35F20FA8 | |
Source: | Code function: | 3_2_35F23F70 | |
Source: | Code function: | 3_2_35F23F60 | |
Source: | Code function: | 3_2_35F25F10 | |
Source: | Code function: | 3_2_35F236C0 | |
Source: | Code function: | 3_2_35F236B0 | |
Source: | Code function: | 3_2_35F296B8 | |
Source: | Code function: | 3_2_35F25660 | |
Source: | Code function: | 3_2_35F25650 | |
Source: | Code function: | 3_2_35F28640 | |
Source: | Code function: | 3_2_35F22E10 | |
Source: | Code function: | 3_2_35F229B8 | |
Source: | Code function: | 3_2_35F2A9A0 | |
Source: | Code function: | 3_2_35F229A8 | |
Source: | Code function: | 3_2_35F2F138 | |
Source: | Code function: | 3_2_35F2F12A | |
Source: | Code function: | 3_2_35F22108 | |
Source: | Code function: | 3_2_35F220FA | |
Source: | Code function: | 3_2_35F27070 | |
Source: | Code function: | 3_2_35F27061 | |
Source: | Code function: | 3_2_35F21858 | |
Source: | Code function: | 3_2_35F20040 | |
Source: | Code function: | 3_2_35F20037 | |
Source: | Code function: | 3_2_35F24820 | |
Source: | Code function: | 3_2_35F24810 | |
Source: | Code function: | 3_2_35F213F0 | |
Source: | Code function: | 3_2_35F243C8 | |
Source: | Code function: | 3_2_35F243B9 | |
Source: | Code function: | 3_2_35F26368 | |
Source: | Code function: | 3_2_35F2A352 | |
Source: | Code function: | 3_2_35F26358 | |
Source: | Code function: | 3_2_35F27B4F | |
Source: | Code function: | 3_2_35F23B18 | |
Source: | Code function: | 3_2_35F23B08 | |
Source: | Code function: | 3_2_35F25AB8 | |
Source: | Code function: | 3_2_35F25AA8 | |
Source: | Code function: | 3_2_35F23268 | |
Source: | Code function: | 3_2_35F25207 | |
Source: | Code function: | 3_2_35F25208 | |
Source: | Code function: | 3_2_3645D6E8 | |
Source: | Code function: | 3_2_3645E8A8 | |
Source: | Code function: | 3_2_364575E8 | |
Source: | Code function: | 3_2_3645E89A |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_004045CA |
Source: | Code function: | 0_2_0040206A |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | File source: |
Source: | Code function: | 0_2_00406254 |
Source: | Code function: | 0_2_10002DCE |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | API/Special instruction interceptor: | ||
Source: | API/Special instruction interceptor: |
Source: | RDTSC instruction interceptor: | ||
Source: | RDTSC instruction interceptor: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | API coverage: |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Code function: | 0_2_00405772 | |
Source: | Code function: | 0_2_0040622D | |
Source: | Code function: | 0_2_00402770 | |
Source: | Code function: | 3_2_00402770 | |
Source: | Code function: | 3_2_00405772 | |
Source: | Code function: | 3_2_0040622D |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-4703 | ||
Source: | API call chain: | graph_0-4705 |
Source: | Code function: | 0_2_00406254 |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_00405F0C |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Registry value created: | Jump to behavior |
Source: | Registry value created: | Jump to behavior |
Source: | Registry key created or modified: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: |
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Native API | 1 DLL Side-Loading | 11 Process Injection | 11 Masquerading | 1 OS Credential Dumping | 21 Security Software Discovery | Remote Services | 1 Email Collection | 1 Web Service | Exfiltration Over Other Network Medium | 1 System Shutdown/Reboot |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 31 Disable or Modify Tools | LSASS Memory | 31 Virtualization/Sandbox Evasion | Remote Desktop Protocol | 1 Archive Collected Data | 21 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 31 Virtualization/Sandbox Evasion | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | 1 Data from Local System | 1 Ingress Tool Transfer | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 11 Process Injection | NTDS | 1 System Network Configuration Discovery | Distributed Component Object Model | 1 Clipboard Data | 3 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Deobfuscate/Decode Files or Information | LSA Secrets | 3 File and Directory Discovery | SSH | Keylogging | 14 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 3 Obfuscated Files or Information | Cached Domain Credentials | 215 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
76% | Virustotal | Browse | ||
63% | ReversingLabs | Win32.Trojan.GuLoader | ||
100% | Avira | HEUR/AGEN.1337946 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
drive.google.com | 142.250.181.238 | true | false | high | |
drive.usercontent.google.com | 142.250.186.33 | true | false | high | |
reallyfreegeoip.org | 104.21.80.1 | true | false | high | |
api.telegram.org | 149.154.167.220 | true | false | high | |
checkip.dyndns.com | 132.226.8.169 | true | false | high | |
checkip.dyndns.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
132.226.8.169 | checkip.dyndns.com | United States | 16989 | UTMEMUS | false | |
142.250.181.238 | drive.google.com | United States | 15169 | GOOGLEUS | false | |
149.154.167.220 | api.telegram.org | United Kingdom | 62041 | TELEGRAMRU | false | |
142.250.186.33 | drive.usercontent.google.com | United States | 15169 | GOOGLEUS | false | |
104.21.80.1 | reallyfreegeoip.org | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588607 |
Start date and time: | 2025-01-11 03:03:54 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 7m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 8 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 4NG0guPiKA.exerenamed because original name is a hash value |
Original Sample Name: | ec0c8d7a3312e95aa25f0ce8dd738ed1660246374f6a6d1a268b97ae4d3c4d47.exe |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@3/8@5/5 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 4.245.163.56, 20.12.23.50
- Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
21:05:34 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
132.226.8.169 | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
149.154.167.220 | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse | ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | AsyncRAT, StormKitty, WorldWind Stealer | Browse | |||
Get hash | malicious | Snake Keylogger | Browse | |||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
reallyfreegeoip.org | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
api.telegram.org | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | AsyncRAT, StormKitty, WorldWind Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
checkip.dyndns.com | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TELEGRAMRU | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | AsyncRAT, StormKitty, WorldWind Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
UTMEMUS | Get hash | malicious | Snake Keylogger | Browse |
| |
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
54328bd36c14bd82ddaa0c04b25ed9ad | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | PureLog Stealer, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AsyncRAT, StormKitty, WorldWind Stealer | Browse |
| ||
37f463bf4616ecd445d4a1937da06e19 | Get hash | malicious | GuLoader, Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | Snake Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
| ||
Get hash | malicious | GuLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\nso68A0.tmp\System.dll | Get hash | malicious | GuLoader, MassLogger RAT | Browse | ||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | GuLoader, MassLogger RAT | Browse | |||
Get hash | malicious | Azorult, GuLoader | Browse | |||
Get hash | malicious | GuLoader, Snake Keylogger | Browse | |||
Get hash | malicious | GuLoader | Browse |
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11264 |
Entropy (8bit): | 5.801108840712148 |
Encrypted: | false |
SSDEEP: | 192:e/b2HS5ih/7i00eWz9T7PH6yeFcQMI5+Vw+EXWZ77dslFZk:ewSUmWw9T7MmnI5+/F7Kdk |
MD5: | FC90DFB694D0E17B013D6F818BCE41B0 |
SHA1: | 3243969886D640AF3BFA442728B9F0DFF9D5F5B0 |
SHA-256: | 7FE77CA13121A113C59630A3DBA0C8AAA6372E8082393274DA8F8608C4CE4528 |
SHA-512: | 324F13AA7A33C6408E2A57C3484D1691ECEE7C3C1366DE2BB8978C8DC66B18425D8CAB5A32D1702C13C43703E36148A022263DE7166AFDCE141DA2B01169F1C6 |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1315865 |
Entropy (8bit): | 3.5949686472855396 |
Encrypted: | false |
SSDEEP: | 12288:j8rRd69L0r8yMuaf+MP9jeCmo5gw7mS2J8OD0ZCPHb5g5YTmVBbTvR4/uWv871W8:Yf6Pgg1U0CT5Tm3vvDypK |
MD5: | 5A6642E8988A81F18B4290B6822BB259 |
SHA1: | 42D4DF7B97EED5A2840A7E678708CA32EB535E41 |
SHA-256: | 8FA1E9AE96D55A6AE8F0D7AD408782A09B14CD83AF3E43CCAFC0675307D4C445 |
SHA-512: | 71E804077ACB1B60BE07996337400F4B07A37A02CDD39A48E06229D8AF156628AFB9229B43EB4882E26CE274F4550482AB4F7DAF07476E37C3E5385009FE3D54 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\Emalje.kap
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 161977 |
Entropy (8bit): | 1.2465706431701635 |
Encrypted: | false |
SSDEEP: | 768:j91kr2E4uLB4rAvVSJUxZOKLuPYUIlh6njQqVK+P7T6r6hI4W7lD1jBCgUpo:94irAZug+TLg1cpo |
MD5: | 818D9B577C6A2CCB8C8D753C89B0AEED |
SHA1: | 1912E60E75B47E0AC0B0ACDB2B320F0B36D3CE22 |
SHA-256: | B53DFB245A8D5A0F0FAEEC7E8B4AE273522AC29FD29B33608F9BA7F9ADB90279 |
SHA-512: | 91993AA2E3E2666A3945886101B2B670CD3B0D76CF3CFFF3684DCB310FE324A1C650FAB5D5D00B8CFA49B5A7713FE2DBBA6DC2D8BB8DAC7A169495E6694CE4C6 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\Jaskendes.Tin19
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 288630 |
Entropy (8bit): | 7.7491676192107075 |
Encrypted: | false |
SSDEEP: | 6144:juzLxL0r8yMuaf+MP9jeCmo5gj0D/A/DlsX5YJVCOD0ZCPzzb5wp03sB5aT1pTmP:S9L0r8yMuaf+MP9jeCmo5gw7mS2J8ODW |
MD5: | 03D02A84B85376B663A29D160AD89822 |
SHA1: | BED64291853193091B6867F3D890D1F64F210637 |
SHA-256: | 72EC51CE52A19D8DCBA9176D1C3C40E15FE5637AD5721DB27DC4AD0314EB4CF9 |
SHA-512: | 3C7F4EF9C1CFA9B004CA0F4CA6FBD3947C77CD9D1CAF9C18D863FA7C038E4EBB84B8025D4083C0F4F4EAF74684481EEF47CE04FBCDEC175A526D3D0249144E53 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\Skankeben.Pri
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 149030 |
Entropy (8bit): | 4.598765709098575 |
Encrypted: | false |
SSDEEP: | 1536:qAtbIHGVtkzD0DCax4/D7tw1DGdZuFPx/8xFGHM1iaLu/xuuPqhYiieeAK2:qARIHG7s0DD4/lwUcFeGHME5FqCiifAD |
MD5: | CC1D8E3E4DC2D1AE30EA61C63E82FFE0 |
SHA1: | CB85577C8192221AB0B1A85B22786791C7430862 |
SHA-256: | 5244EFBEF13598381119C2942340E9F3CC5AAF2B4D636ED0C32CB4CE5936A3F4 |
SHA-512: | AAF38BD184E0BC7B4101387E82F31C457481BE5584E94AA004C6E40CE91C919A8D4B1FB795AC3C37963751A093BD6FE840929215046D06F0C0693CAA98D08314 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\img2.jpg
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2929 |
Entropy (8bit): | 7.418910042244289 |
Encrypted: | false |
SSDEEP: | 48:j2XBhBOaFxHfEaq1kk1YunCRbvwxhjAxnyHIvR4SnHP7oNLpLR8Fqhr:j2XBv9Fx2kkO7RihjlovpnHPCpaQ1 |
MD5: | 49DAF4E74443D8502F3229468615185F |
SHA1: | 9BB41BF5F382EE315893366F559FA26D57A4CD5F |
SHA-256: | E5EE495A89E55467DB6A396F012EDB6A71D2E762CFC7FC6846FE7259528BF168 |
SHA-512: | EE9ABC6A19215FED64584BA24736ECBA24139CD03A75530FF351C99A25628410472A28F4EE08E87CE1F75DC79396A2A9C1AC79C399720C320437BC18993B561A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\pinrail.whe
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 461378 |
Entropy (8bit): | 1.252059381950645 |
Encrypted: | false |
SSDEEP: | 1536:s3tr+hilKd11tUzcxZg7SBobbR5FF7b7IvSog:sRVmQc3u9F7b76 |
MD5: | 3AD2FE4EA13486258EADDD1E5940A6D7 |
SHA1: | 06D0468A125D754D4534C182D79444DFB7A1CF61 |
SHA-256: | E4C5F20595C446D20C978CF7B486579BA2FFC17E64B940733B40C89DF4331319 |
SHA-512: | 82328E01492BDB8B23555CB369279A5352B35E0B51A4A4AC88D9F9285BBDABA627FE01139B4F9669847252D5A59FC512B2463A364EFD5C33B83309D6A8985D59 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Templates\Kopieringsprogrammet\unyouthfully.ske
Download File
Process: | C:\Users\user\Desktop\4NG0guPiKA.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 225641 |
Entropy (8bit): | 1.2362366155163755 |
Encrypted: | false |
SSDEEP: | 768:HcPiBl7QD/ad4B+etLBBF64vscOIBiMFYnfBc1TS/HVtHlY4bDzZkmNQyFY670Fn:QaxOPt/G9V4yf7P/zZkX00b/h |
MD5: | 94C4B93474D07658FCBD411A20E68532 |
SHA1: | 66421117EB902B48D39A1514C88C868394085FCF |
SHA-256: | 50B1D7356F0CC22F2A9AE93A7CC9738C6BC0907724ACDB85F68F594333B706DC |
SHA-512: | BC1C40FF5B9FD71590E9B3E71D7B58A46E8AFBE56DFBD22C39F5DC0952ACEDC96F2BC4D8428EA0BCD75D67BD32F2B095585925CD8141063801FB128EA46F7471 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.141789881872813 |
TrID: |
|
File name: | 4NG0guPiKA.exe |
File size: | 778'465 bytes |
MD5: | 8f02b3e31021d64ed25a599e58bc8f2f |
SHA1: | 7bec44b33d33f11de7f626097b70758f60f655f5 |
SHA256: | ec0c8d7a3312e95aa25f0ce8dd738ed1660246374f6a6d1a268b97ae4d3c4d47 |
SHA512: | d16554484647d2875b0bcf4b84c7726b14cd96725ba562be2f06714d80468367ecbdfd251c20eee5cd0220fba15becc9c53ccd42fe1110699fe2eb43813fb142 |
SSDEEP: | 12288:xlYZmcRHOg1BFC+gpurATKGOCDUYRpRlUcRzhPnxd2ckxkYJLY:UmcdOOBRg00W4YYJlUcR1vxdgxk2LY |
TLSH: | 98F4D06F1B068446EE9415F2B8A3DE47A1F5BE7C206873452D66FE1790B3F70398E488 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......1.D9u.*ju.*ju.*j..ujw.*ju.+j..*j..wjd.*j!..j..*j..,jt.*jRichu.*j........PE..L.....oS.................`...*......Z3.......p....@ |
Icon Hash: | 058cc0e474936126 |
Entrypoint: | 0x40335a |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | TERMINAL_SERVER_AWARE |
Time Stamp: | 0x536FD79B [Sun May 11 20:03:39 2014 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | e221f4f7d36469d53810a4b5f9fc8966 |
Instruction |
---|
sub esp, 000002D4h |
push ebx |
push ebp |
push esi |
push edi |
push 00000020h |
xor ebp, ebp |
pop esi |
mov dword ptr [esp+14h], ebp |
mov dword ptr [esp+10h], 00409230h |
mov dword ptr [esp+1Ch], ebp |
call dword ptr [00407034h] |
push 00008001h |
call dword ptr [004070BCh] |
push ebp |
call dword ptr [004072ACh] |
push 00000008h |
mov dword ptr [00429298h], eax |
call 00007F962CF1ECECh |
mov dword ptr [004291E4h], eax |
push ebp |
lea eax, dword ptr [esp+34h] |
push 000002B4h |
push eax |
push ebp |
push 00420690h |
call dword ptr [0040717Ch] |
push 0040937Ch |
push 004281E0h |
call 00007F962CF1E957h |
call dword ptr [00407134h] |
mov ebx, 00434000h |
push eax |
push ebx |
call 00007F962CF1E945h |
push ebp |
call dword ptr [0040710Ch] |
cmp word ptr [00434000h], 0022h |
mov dword ptr [004291E0h], eax |
mov eax, ebx |
jne 00007F962CF1BE3Ah |
push 00000022h |
mov eax, 00434002h |
pop esi |
push esi |
push eax |
call 00007F962CF1E396h |
push eax |
call dword ptr [00407240h] |
mov dword ptr [esp+18h], eax |
jmp 00007F962CF1BEFEh |
push 00000020h |
pop edx |
cmp cx, dx |
jne 00007F962CF1BE39h |
inc eax |
inc eax |
cmp word ptr [eax], dx |
je 00007F962CF1BE2Bh |
add word ptr [eax], 0000h |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x7494 | 0xb4 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x5f000 | 0x43188 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x7000 | 0x2b8 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x5e68 | 0x6000 | 2f6554958e1a5093777de617d6e0bffc | False | 0.6566162109375 | data | 6.419811957742583 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x7000 | 0x1354 | 0x1400 | 2222fe44ebbadbc32af32dfc9c88e48e | False | 0.4306640625 | data | 5.037511188789184 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x9000 | 0x202d8 | 0x600 | 9587277f9a9b39e2caf86eae07909d87 | False | 0.4733072916666667 | data | 3.757932017065988 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.ndata | 0x2a000 | 0x35000 | 0x0 | d41d8cd98f00b204e9800998ecf8427e | False | 0 | empty | 0.0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x5f000 | 0x43188 | 0x43200 | ad79ab7bc0418c21ba04b90eb50d4a0c | False | 0.18500494646182494 | data | 4.605797713668011 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_BITMAP | 0x5f2b0 | 0x368 | Device independent bitmap graphic, 96 x 16 x 4, image size 768 | English | United States | 0.23623853211009174 |
RT_ICON | 0x5f618 | 0x42028 | Device independent bitmap graphic, 256 x 512 x 32, image size 270336 | English | United States | 0.1810552711779152 |
RT_DIALOG | 0xa1640 | 0x144 | data | English | United States | 0.5216049382716049 |
RT_DIALOG | 0xa1788 | 0x13c | data | English | United States | 0.5506329113924051 |
RT_DIALOG | 0xa18c8 | 0x100 | data | English | United States | 0.5234375 |
RT_DIALOG | 0xa19c8 | 0x11c | data | English | United States | 0.6091549295774648 |
RT_DIALOG | 0xa1ae8 | 0xc4 | data | English | United States | 0.5918367346938775 |
RT_DIALOG | 0xa1bb0 | 0x60 | data | English | United States | 0.7291666666666666 |
RT_GROUP_ICON | 0xa1c10 | 0x14 | data | English | United States | 1.1 |
RT_VERSION | 0xa1c28 | 0x258 | data | English | United States | 0.5216666666666666 |
RT_MANIFEST | 0xa1e80 | 0x305 | XML 1.0 document, ASCII text, with very long lines (773), with no line terminators | English | United States | 0.5614489003880984 |
DLL | Import |
---|---|
KERNEL32.dll | CompareFileTime, SearchPathW, SetFileTime, CloseHandle, GetShortPathNameW, MoveFileW, SetCurrentDirectoryW, GetFileAttributesW, GetLastError, GetFullPathNameW, CreateDirectoryW, Sleep, GetTickCount, CreateFileW, GetFileSize, GetModuleFileNameW, GetCurrentProcess, CopyFileW, ExitProcess, SetEnvironmentVariableW, GetWindowsDirectoryW, SetFileAttributesW, ExpandEnvironmentStringsW, SetErrorMode, LoadLibraryW, lstrlenW, lstrcpynW, GetDiskFreeSpaceW, GlobalUnlock, GlobalLock, CreateThread, CreateProcessW, RemoveDirectoryW, lstrcmpiA, GetTempFileNameW, lstrcpyA, lstrcpyW, lstrcatW, GetSystemDirectoryW, GetVersion, GetProcAddress, LoadLibraryA, GetModuleHandleA, GetModuleHandleW, lstrcmpiW, lstrcmpW, WaitForSingleObject, GlobalFree, GlobalAlloc, LoadLibraryExW, GetExitCodeProcess, FreeLibrary, WritePrivateProfileStringW, GetCommandLineW, GetTempPathW, GetPrivateProfileStringW, FindFirstFileW, FindNextFileW, DeleteFileW, SetFilePointer, ReadFile, FindClose, MulDiv, MultiByteToWideChar, WriteFile, lstrlenA, WideCharToMultiByte |
USER32.dll | EndDialog, ScreenToClient, GetWindowRect, RegisterClassW, EnableMenuItem, GetSystemMenu, SetClassLongW, IsWindowEnabled, SetWindowPos, GetSysColor, GetWindowLongW, SetCursor, LoadCursorW, CheckDlgButton, GetMessagePos, LoadBitmapW, CallWindowProcW, IsWindowVisible, CloseClipboard, SetClipboardData, wsprintfW, CreateWindowExW, SystemParametersInfoW, AppendMenuW, CreatePopupMenu, GetSystemMetrics, SetDlgItemTextW, GetDlgItemTextW, MessageBoxIndirectW, CharPrevW, CharNextA, wsprintfA, DispatchMessageW, PeekMessageW, ReleaseDC, EnableWindow, InvalidateRect, SendMessageW, DefWindowProcW, BeginPaint, GetClientRect, FillRect, DrawTextW, GetClassInfoW, DialogBoxParamW, CharNextW, ExitWindowsEx, DestroyWindow, CreateDialogParamW, SetTimer, SetWindowTextW, PostQuitMessage, GetDC, SetWindowLongW, LoadImageW, SendMessageTimeoutW, FindWindowExW, EmptyClipboard, OpenClipboard, TrackPopupMenu, EndPaint, ShowWindow, GetDlgItem, IsWindow, SetForegroundWindow |
GDI32.dll | SelectObject, SetBkMode, CreateFontIndirectW, SetTextColor, DeleteObject, GetDeviceCaps, CreateBrushIndirect, SetBkColor |
SHELL32.dll | SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHBrowseForFolderW, SHGetFileInfoW, ShellExecuteW, SHFileOperationW |
ADVAPI32.dll | RegCloseKey, RegOpenKeyExW, RegDeleteKeyW, RegDeleteValueW, RegEnumValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegEnumKeyW |
COMCTL32.dll | ImageList_Create, ImageList_AddMasked, ImageList_Destroy |
ole32.dll | CoCreateInstance, CoTaskMemFree, OleInitialize, OleUninitialize |
VERSION.dll | GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-11T03:05:23.278926+0100 | 2803270 | ETPRO MALWARE Common Downloader Header Pattern UHCa | 2 | 192.168.2.10 | 49708 | 142.250.181.238 | 443 | TCP |
2025-01-11T03:05:28.438391+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.10 | 49710 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:05:35.297783+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.10 | 49710 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:05:35.915509+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49712 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:37.704410+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49712 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:40.844817+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.10 | 49713 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:05:41.443058+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49714 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:41.624698+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49714 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:45.159302+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49716 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:45.406336+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49716 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:51.763518+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49720 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:52.013161+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49720 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:54.618271+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49722 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:05:54.865177+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49722 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:02.200710+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49725 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:02.377370+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49725 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:11.751087+0100 | 2803274 | ETPRO MALWARE Common Downloader Header Pattern UH | 2 | 192.168.2.10 | 49727 | 132.226.8.169 | 80 | TCP |
2025-01-11T03:06:12.354997+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49728 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:12.529577+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49728 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:15.719575+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49730 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:15.965935+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49730 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:17.658282+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49732 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:17.832210+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49732 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:19.289507+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49734 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:19.535991+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49734 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:21.119452+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49736 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:21.431724+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49736 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:22.988605+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49738 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:23.238549+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49738 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:24.736208+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49740 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:24.909136+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49740 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:26.374032+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49742 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:26.624961+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49742 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:28.100460+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49744 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:28.276828+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49744 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:29.820597+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49746 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:29.999996+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49746 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:31.576717+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49748 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:31.750830+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49748 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:33.254475+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49750 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:33.431948+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49750 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:34.901388+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49752 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:35.151286+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49752 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:36.703013+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49754 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:36.876519+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49754 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:38.859785+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49756 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:39.032361+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49756 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:40.493302+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49758 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:40.757522+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49758 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:42.236480+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49760 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:42.413636+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49760 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:43.906128+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49762 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:44.177514+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49762 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:46.671836+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49764 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:46.849067+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49764 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:48.612707+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49766 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:48.866226+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49766 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:50.439435+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49768 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:50.701288+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49768 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:52.156184+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49770 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:52.402052+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49770 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:53.871628+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49772 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:54.047819+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49772 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:55.817470+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49774 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:55.991776+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49774 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:57.463427+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49776 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:57.713812+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49776 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:59.268236+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49778 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:06:59.524787+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49778 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:01.199872+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49780 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:01.457769+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49780 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:02.957766+0100 | 1810008 | Joe Security ANOMALY Telegram Send File | 1 | 192.168.2.10 | 49782 | 149.154.167.220 | 443 | TCP |
2025-01-11T03:07:03.214933+0100 | 2057744 | ET MALWARE Snake/Best Private Keylogger CnC Exfil Via Telegram | 1 | 192.168.2.10 | 49782 | 149.154.167.220 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 03:05:21.914495945 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:21.914539099 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:21.914678097 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:21.937899113 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:21.937925100 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:22.592200994 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:22.592303991 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:22.592988968 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:22.593034983 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:22.983067036 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:22.983093977 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:22.984098911 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:22.987194061 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:22.989475012 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:23.031328917 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:23.278932095 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:23.279117107 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:23.279133081 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:23.279220104 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:23.279264927 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:23.279299974 CET | 443 | 49708 | 142.250.181.238 | 192.168.2.10 |
Jan 11, 2025 03:05:23.279350042 CET | 49708 | 443 | 192.168.2.10 | 142.250.181.238 |
Jan 11, 2025 03:05:23.309701920 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.309729099 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:23.309799910 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.310409069 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.310424089 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:23.953073978 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:23.953198910 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.957209110 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.957217932 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:23.957528114 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:23.957597971 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.957986116 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:23.999335051 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.667594910 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.667813063 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.673283100 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.673810005 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.685863018 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.685924053 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.685941935 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.685997963 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.691878080 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.691986084 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.755505085 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.755595922 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.755615950 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.755678892 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.755685091 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.755827904 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.756572008 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.756663084 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.756666899 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.756833076 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.763134956 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.763204098 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.763252974 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.763329983 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.769287109 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.769364119 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.769373894 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.769519091 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.775374889 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.775445938 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.775471926 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.775532007 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.781696081 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.781831026 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.781845093 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.781976938 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.788100958 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.788212061 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.788218975 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.788302898 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.794363022 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.794487000 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.794493914 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.794620037 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.800440073 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.800518036 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.800548077 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.800646067 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.805854082 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.806034088 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.806041956 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.806215048 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.811790943 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.811944008 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.811959982 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.812021971 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.817754030 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.817807913 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.820635080 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.820804119 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.825330973 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.825577974 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.843986988 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844156981 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844167948 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844213009 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844218016 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844263077 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844268084 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844353914 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844358921 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844432116 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844436884 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844530106 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.844881058 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.844983101 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.848786116 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.848925114 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.848939896 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.848946095 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.848997116 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.848997116 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.853950024 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.854088068 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.854094028 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.854294062 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.859443903 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.859580994 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.859590054 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.859635115 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.864417076 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.864552021 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.864557981 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.864613056 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.869707108 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.869858027 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.869863987 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.869956970 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.874161959 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.874227047 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.874244928 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.874334097 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.878710985 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.878772020 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.878818989 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.878869057 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.883380890 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.883467913 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.883486986 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.883544922 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.888586044 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.888700008 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.888711929 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.888806105 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.892617941 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.892684937 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.892731905 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.892791033 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.897344112 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.897445917 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.897455931 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.897500992 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.901678085 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.901736975 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.901791096 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.901865005 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.905829906 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.906111956 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.906163931 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.906163931 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.906176090 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.906263113 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.906263113 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.906270027 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.906316996 CET | 443 | 49709 | 142.250.186.33 | 192.168.2.10 |
Jan 11, 2025 03:05:26.906435013 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:26.906436920 CET | 49709 | 443 | 192.168.2.10 | 142.250.186.33 |
Jan 11, 2025 03:05:27.258977890 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:27.263905048 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:27.264095068 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:27.264302015 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:27.269085884 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:28.078248024 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:28.083086014 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:28.087841034 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:28.387295961 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:28.438390970 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:28.908267021 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:28.908319950 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:28.908376932 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:28.910851002 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:28.910870075 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.404174089 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.404330969 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:29.408622026 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:29.408636093 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.408963919 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.413389921 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:29.455337048 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.553085089 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.553162098 CET | 443 | 49711 | 104.21.80.1 | 192.168.2.10 |
Jan 11, 2025 03:05:29.553430080 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:29.559806108 CET | 49711 | 443 | 192.168.2.10 | 104.21.80.1 |
Jan 11, 2025 03:05:34.965766907 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:34.970676899 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:35.246803045 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:35.258548975 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.258595943 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.258662939 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.259061098 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.259073019 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.297782898 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:35.867887974 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.867986917 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.869910002 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.869916916 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.870157957 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.871572971 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.915330887 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:35.915402889 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:35.915414095 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:37.704612970 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:37.704835892 CET | 443 | 49712 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:37.704921007 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:37.709410906 CET | 49712 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:37.860893965 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:37.862047911 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:37.866116047 CET | 80 | 49710 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:37.866211891 CET | 49710 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:37.866890907 CET | 80 | 49713 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:37.867011070 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:37.867239952 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:37.872071981 CET | 80 | 49713 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:40.796513081 CET | 80 | 49713 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:40.798062086 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:40.798106909 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:40.798193932 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:40.798868895 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:40.798877954 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:40.844816923 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:41.440977097 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:41.442725897 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:41.442759037 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:41.442830086 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:41.442838907 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:41.624736071 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:41.624820948 CET | 443 | 49714 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:41.624917984 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:41.625416994 CET | 49714 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:41.629764080 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:41.637403011 CET | 80 | 49715 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:41.637586117 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:41.637671947 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:41.645570993 CET | 80 | 49715 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:44.534039021 CET | 80 | 49715 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:44.538414955 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:44.538444996 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:44.538527012 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:44.539038897 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:44.539053917 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:44.579097986 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.157274961 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:45.159075975 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:45.159100056 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:45.159166098 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:45.159172058 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:45.406491995 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:45.406683922 CET | 443 | 49716 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:45.406769991 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:45.407267094 CET | 49716 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:45.410738945 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.411714077 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.418411970 CET | 80 | 49717 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:45.418557882 CET | 80 | 49715 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:45.418565989 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.418610096 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.418649912 CET | 49715 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:45.425384998 CET | 80 | 49717 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:49.278007984 CET | 80 | 49717 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:49.282824039 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:49.287709951 CET | 80 | 49718 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:49.287935972 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:49.287935972 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:49.292795897 CET | 80 | 49718 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:49.329150915 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:51.116115093 CET | 80 | 49718 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:51.120868921 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:51.120873928 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:51.120886087 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:51.120968103 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:51.121288061 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:51.121299028 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:51.125911951 CET | 80 | 49717 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:51.126009941 CET | 49717 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:51.157334089 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:51.761284113 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:51.763134003 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:51.763173103 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:51.763334990 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:51.763344049 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:52.013350010 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:52.013588905 CET | 443 | 49720 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:52.013875008 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:52.014148951 CET | 49720 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:52.018933058 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:52.020225048 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:52.023885965 CET | 80 | 49718 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:52.023971081 CET | 49718 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:52.025000095 CET | 80 | 49721 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:52.025065899 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:52.025201082 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:52.029936075 CET | 80 | 49721 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:53.969919920 CET | 80 | 49721 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:53.982810020 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:53.982846022 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:53.982911110 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:53.983161926 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:53.983171940 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.016613007 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.616087914 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.618097067 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:54.618127108 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.618194103 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:54.618204117 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.865231037 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.865317106 CET | 443 | 49722 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:05:54.865362883 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:54.865802050 CET | 49722 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:05:54.869997025 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.870618105 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.875073910 CET | 80 | 49721 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:54.875128984 CET | 49721 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.878192902 CET | 80 | 49723 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:54.878269911 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.878374100 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:54.883585930 CET | 80 | 49723 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:58.729590893 CET | 80 | 49723 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:58.734325886 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:58.739298105 CET | 80 | 49724 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:58.739403009 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:58.739515066 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:05:58.744371891 CET | 80 | 49724 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:05:58.782286882 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:01.571975946 CET | 80 | 49724 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:01.572571993 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:01.573314905 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:01.573367119 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:01.573441029 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:01.573731899 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:01.573745966 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:01.577717066 CET | 80 | 49723 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:01.577785015 CET | 49723 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:01.626039028 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.198704958 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:02.200525999 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:02.200546980 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:02.200609922 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:02.200617075 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:02.377540112 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:02.377753019 CET | 443 | 49725 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:02.377827883 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:02.378633022 CET | 49725 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:02.382761002 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.384021997 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.387847900 CET | 80 | 49724 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:02.388873100 CET | 80 | 49726 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:02.388962030 CET | 49724 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.389014959 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.389221907 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:02.394085884 CET | 80 | 49726 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:06.283741951 CET | 80 | 49726 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:06.288949966 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:06.295562029 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:06.295701027 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:06.295854092 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:06.302355051 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:06.329173088 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:10.363274097 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:10.371022940 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:10.371051073 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:10.375895977 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:10.375993967 CET | 80 | 49726 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:10.376116991 CET | 49726 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:11.709779024 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:11.711246967 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:11.711288929 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:11.711373091 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:11.711766958 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:11.711779118 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:11.751086950 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.350435019 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:12.354758978 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:12.354774952 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:12.354842901 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:12.354851007 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:12.529570103 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:12.529649973 CET | 443 | 49728 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:12.529802084 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:12.540561914 CET | 49728 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:12.594397068 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.596302032 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.599466085 CET | 80 | 49727 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:12.599541903 CET | 49727 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.601182938 CET | 80 | 49729 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:12.601268053 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.603893995 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:12.608745098 CET | 80 | 49729 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:15.106184959 CET | 80 | 49729 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:15.107527018 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.107568026 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.107631922 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.107985973 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.107995987 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.157468081 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.717087030 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.719176054 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.719202995 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.719258070 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.719268084 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.965970039 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.966042995 CET | 443 | 49730 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:15.966088057 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.966665983 CET | 49730 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:15.970834017 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.971857071 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.975868940 CET | 80 | 49729 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:15.975919008 CET | 49729 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.976639986 CET | 80 | 49731 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:15.976701021 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.976789951 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:15.983371019 CET | 80 | 49731 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:17.024198055 CET | 80 | 49731 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:17.025583029 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.025634050 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.025707006 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.026043892 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.026061058 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.079257011 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.655940056 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.658091068 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.658123970 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.658186913 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.658195972 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.832246065 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.832334042 CET | 443 | 49732 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:17.832417965 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.833045959 CET | 49732 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:17.836489916 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.837490082 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.843343973 CET | 80 | 49731 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:17.843419075 CET | 49731 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.844383001 CET | 80 | 49733 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:17.844455957 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.844587088 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:17.850604057 CET | 80 | 49733 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:18.657212019 CET | 80 | 49733 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:18.679003954 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:18.679052114 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:18.679126978 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:18.679460049 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:18.679476023 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:18.704250097 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.287355900 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:19.289294004 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:19.289310932 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:19.289366007 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:19.289371014 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:19.536190987 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:19.536402941 CET | 443 | 49734 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:19.536617994 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:19.537235022 CET | 49734 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:19.540798903 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.542032957 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.546653032 CET | 80 | 49733 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:19.546812057 CET | 80 | 49735 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:19.546901941 CET | 49733 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.546928883 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.547066927 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:19.552006006 CET | 80 | 49735 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:20.372675896 CET | 80 | 49735 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:20.377449036 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:20.377496958 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:20.377577066 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:20.378005981 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:20.378017902 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:20.423012972 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.003385067 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:21.058465958 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:21.118901014 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:21.118921995 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:21.119416952 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:21.119421005 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:21.431798935 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:21.431890011 CET | 443 | 49736 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:21.431986094 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:21.488697052 CET | 49736 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:21.538351059 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.540194035 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.543556929 CET | 80 | 49735 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:21.543634892 CET | 49735 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.545015097 CET | 80 | 49737 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:21.545113087 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.545291901 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:21.550044060 CET | 80 | 49737 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:22.353651047 CET | 80 | 49737 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:22.355402946 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:22.355464935 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:22.355549097 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:22.356440067 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:22.356456995 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:22.407450914 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:22.986562967 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:22.988437891 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:22.988475084 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:22.988550901 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:22.988559008 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:23.238718033 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:23.238951921 CET | 443 | 49738 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:23.239041090 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:23.239438057 CET | 49738 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:23.242959023 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:23.244069099 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:23.248019934 CET | 80 | 49737 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:23.248090982 CET | 49737 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:23.248956919 CET | 80 | 49739 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:23.249022007 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:23.249130964 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:23.254728079 CET | 80 | 49739 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:24.109461069 CET | 80 | 49739 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:24.117516041 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.117548943 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.117620945 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.121532917 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.121545076 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.163769960 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.733524084 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.735987902 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.736000061 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.736093044 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.736100912 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.909185886 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.909288883 CET | 443 | 49740 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:24.909343004 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.910161018 CET | 49740 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:24.915324926 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.916851997 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.920311928 CET | 80 | 49739 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:24.920380116 CET | 49739 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.921693087 CET | 80 | 49741 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:24.921756983 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.921981096 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:24.926914930 CET | 80 | 49741 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:25.734456062 CET | 80 | 49741 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:25.736242056 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:25.736301899 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:25.736367941 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:25.736660957 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:25.736680031 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:25.782392025 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.371185064 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:26.373863935 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:26.373899937 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:26.373961926 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:26.373969078 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:26.624994993 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:26.625082970 CET | 443 | 49742 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:26.625253916 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:26.625860929 CET | 49742 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:26.636612892 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.637686968 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.641639948 CET | 80 | 49741 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:26.642544985 CET | 80 | 49743 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:26.642551899 CET | 49741 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.642617941 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.642739058 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:26.647514105 CET | 80 | 49743 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:27.470195055 CET | 80 | 49743 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:27.472301960 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:27.472352982 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:27.472421885 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:27.472875118 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:27.472888947 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:27.516712904 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.098107100 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:28.100256920 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:28.100285053 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:28.100346088 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:28.100353003 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:28.276896000 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:28.276994944 CET | 443 | 49744 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:28.277093887 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:28.277844906 CET | 49744 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:28.281810045 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.283229113 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.286788940 CET | 80 | 49743 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:28.286859035 CET | 49743 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.288021088 CET | 80 | 49745 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:28.288093090 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.288182974 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:28.293054104 CET | 80 | 49745 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:29.113658905 CET | 80 | 49745 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:29.115684032 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:29.115732908 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:29.115817070 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:29.116163969 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:29.116178036 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:29.157373905 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:29.784471989 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:29.820245981 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:29.820281982 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:29.820358038 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:29.820368052 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:30.000014067 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:30.000181913 CET | 443 | 49746 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:30.000266075 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:30.017786026 CET | 49746 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:30.106791019 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:30.108705997 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:30.112055063 CET | 80 | 49745 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:30.112107992 CET | 49745 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:30.113502026 CET | 80 | 49747 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:30.113563061 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:30.117631912 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:30.122525930 CET | 80 | 49747 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:30.949954987 CET | 80 | 49747 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:30.951831102 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:30.951854944 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:30.951926947 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:30.952272892 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:30.952281952 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.001132965 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.574525118 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.576539993 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:31.576554060 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.576616049 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:31.576622009 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.750873089 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.750951052 CET | 443 | 49748 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:31.751127005 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:31.751898050 CET | 49748 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:31.755283117 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.756380081 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.760209084 CET | 80 | 49747 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:31.760317087 CET | 49747 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.761243105 CET | 80 | 49749 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:31.761308908 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.761440039 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:31.766181946 CET | 80 | 49749 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:32.586575031 CET | 80 | 49749 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:32.587882042 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:32.587915897 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:32.587995052 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:32.588299036 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:32.588309050 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:32.641757011 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.252440929 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:33.254329920 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:33.254342079 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:33.254374027 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:33.254381895 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:33.432002068 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:33.432092905 CET | 443 | 49750 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:33.432244062 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:33.434962034 CET | 49750 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:33.438252926 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.439500093 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.443429947 CET | 80 | 49749 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:33.444309950 CET | 80 | 49751 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:33.444360018 CET | 49749 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.444401026 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.444525957 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:33.449300051 CET | 80 | 49751 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:34.289345026 CET | 80 | 49751 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:34.290945053 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:34.290983915 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:34.291054964 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:34.291399956 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:34.291408062 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:34.329281092 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:34.899238110 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:34.901139021 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:34.901154041 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:34.901216984 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:34.901225090 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:35.151307106 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:35.151396990 CET | 443 | 49752 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:35.151500940 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:35.152101994 CET | 49752 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:35.156002045 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:35.156989098 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:35.161525965 CET | 80 | 49751 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:35.161598921 CET | 49751 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:35.162395000 CET | 80 | 49753 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:35.162482023 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:35.162589073 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:35.167536974 CET | 80 | 49753 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:36.037976027 CET | 80 | 49753 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:36.054119110 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.054166079 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.054266930 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.054867029 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.054877043 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.085654020 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.700932980 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.702847004 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.702878952 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.702960968 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.702967882 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.876534939 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.876611948 CET | 443 | 49754 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:36.876729012 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.877341986 CET | 49754 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:36.881035089 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.886425018 CET | 80 | 49753 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:36.886539936 CET | 49753 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.887881994 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.892733097 CET | 80 | 49755 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:36.892935038 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.893040895 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:36.897811890 CET | 80 | 49755 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:38.221594095 CET | 80 | 49755 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:38.235255003 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:38.235323906 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:38.235410929 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:38.235807896 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:38.235821962 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:38.282565117 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:38.856278896 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:38.859540939 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:38.859570026 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:38.859626055 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:38.859637022 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:39.032404900 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:39.032480955 CET | 443 | 49756 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:39.032535076 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:39.033122063 CET | 49756 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:39.037395954 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:39.038582087 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:39.042437077 CET | 80 | 49755 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:39.042491913 CET | 49755 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:39.043471098 CET | 80 | 49757 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:39.043533087 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:39.043637991 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:39.048419952 CET | 80 | 49757 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:39.882061958 CET | 80 | 49757 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:39.883789062 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:39.883838892 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:39.883913040 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:39.884222031 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:39.884241104 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:39.923259974 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.490006924 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:40.493100882 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:40.493123055 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:40.493192911 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:40.493202925 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:40.757575035 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:40.757679939 CET | 443 | 49758 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:40.757900000 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:40.758404016 CET | 49758 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:40.761779070 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.762761116 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.766812086 CET | 80 | 49757 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:40.767072916 CET | 49757 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.767581940 CET | 80 | 49759 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:40.771358013 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.771517038 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:40.776334047 CET | 80 | 49759 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:41.594609976 CET | 80 | 49759 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:41.626024961 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:41.626079082 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:41.626173973 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:41.626686096 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:41.626698017 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:41.641782999 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.234013081 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:42.236330032 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:42.236358881 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:42.236422062 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:42.236428022 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:42.413688898 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:42.413774967 CET | 443 | 49760 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:42.413826942 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:42.419596910 CET | 49760 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:42.424115896 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.424750090 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.433779001 CET | 80 | 49759 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:42.433831930 CET | 49759 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.434163094 CET | 80 | 49761 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:42.434223890 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.434350014 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:42.440171957 CET | 80 | 49761 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:43.279299021 CET | 80 | 49761 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:43.280735016 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:43.280785084 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:43.280996084 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:43.281339884 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:43.281358957 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:43.329308033 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:43.904056072 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:43.905780077 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:43.905813932 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:43.905873060 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:43.905895948 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:44.177551031 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:44.177645922 CET | 443 | 49762 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:44.177707911 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:44.199424028 CET | 49762 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:44.520904064 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:44.521575928 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:44.526139021 CET | 80 | 49761 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:44.526237011 CET | 49761 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:44.526477098 CET | 80 | 49763 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:44.526546955 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:44.526838064 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:44.531626940 CET | 80 | 49763 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:45.796715021 CET | 80 | 49713 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:45.798158884 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:45.845668077 CET | 80 | 49763 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:45.846973896 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:45.847012997 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:45.847075939 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:45.847382069 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:45.847393990 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:45.891799927 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.669894934 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:46.671683073 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:46.671696901 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:46.671751976 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:46.671758890 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:46.849107027 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:46.849194050 CET | 443 | 49764 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:46.849271059 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:46.849790096 CET | 49764 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:46.856251001 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.857055902 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.861269951 CET | 80 | 49763 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:46.861341953 CET | 49763 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.861845970 CET | 80 | 49765 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:46.861910105 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.862025976 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:46.866744995 CET | 80 | 49765 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:47.889677048 CET | 80 | 49765 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:47.890942097 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:47.890976906 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:47.891208887 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:47.891514063 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:47.891525984 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:47.938683033 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.608517885 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:48.612454891 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:48.612484932 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:48.612555027 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:48.612566948 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:48.866168976 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:48.866250038 CET | 443 | 49766 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:48.866617918 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:48.866942883 CET | 49766 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:48.870392084 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.871546030 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.876193047 CET | 80 | 49765 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:48.876250982 CET | 49765 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.876351118 CET | 80 | 49767 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:48.876408100 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.876497984 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:48.881208897 CET | 80 | 49767 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:49.825568914 CET | 80 | 49767 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:49.828707933 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:49.828751087 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:49.828851938 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:49.829143047 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:49.829154015 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:49.876211882 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.434844971 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:50.437148094 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:50.437175035 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:50.439366102 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:50.439385891 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:50.701338053 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:50.701406002 CET | 443 | 49768 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:50.701551914 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:50.702119112 CET | 49768 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:50.706160069 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.707484961 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.711170912 CET | 80 | 49767 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:50.711297989 CET | 49767 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.712297916 CET | 80 | 49769 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:50.712393999 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.712588072 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:50.717365980 CET | 80 | 49769 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:51.544471025 CET | 80 | 49769 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:51.546312094 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:51.546365976 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:51.546444893 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:51.546823978 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:51.546834946 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:51.594932079 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.154125929 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:52.155997038 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:52.156017065 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:52.156086922 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:52.156095982 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:52.402120113 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:52.402192116 CET | 443 | 49770 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:52.402504921 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:52.402822971 CET | 49770 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:52.405715942 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.406831980 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.413146019 CET | 80 | 49769 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:52.413958073 CET | 80 | 49771 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:52.414024115 CET | 49769 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.414062977 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.414118052 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:52.419513941 CET | 80 | 49771 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:53.242187977 CET | 80 | 49771 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:53.247042894 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:53.247092009 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:53.247344971 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:53.247724056 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:53.247740984 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:53.298109055 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:53.869505882 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:53.871368885 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:53.871388912 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:53.871592045 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:53.871597052 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:54.047749043 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:54.047827005 CET | 443 | 49772 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:54.047894001 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:54.157478094 CET | 49772 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:54.169150114 CET | 49713 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.367850065 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.368998051 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.373718023 CET | 80 | 49771 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:54.373760939 CET | 49771 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.373785019 CET | 80 | 49773 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:54.373835087 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.373991966 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:54.378750086 CET | 80 | 49773 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:55.204922915 CET | 80 | 49773 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:55.206379890 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.206428051 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.206506014 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.206788063 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.206800938 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.251223087 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:55.810712099 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.817109108 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.817131996 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.817435026 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.817441940 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.991808891 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.991894007 CET | 443 | 49774 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:55.992105007 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.992496014 CET | 49774 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:55.995874882 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:55.997162104 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:56.000894070 CET | 80 | 49773 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:56.002480984 CET | 49773 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:56.002903938 CET | 80 | 49775 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:56.002989054 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:56.003343105 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:56.008112907 CET | 80 | 49775 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:56.822174072 CET | 80 | 49775 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:56.853013039 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:56.853065014 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:56.853164911 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:56.853475094 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:56.853487015 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:56.876249075 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.455017090 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:57.461680889 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:57.461704969 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:57.463378906 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:57.463383913 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:57.713885069 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:57.713965893 CET | 443 | 49776 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:57.715384007 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:57.715701103 CET | 49776 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:57.719216108 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.720515966 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.725790977 CET | 80 | 49775 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:57.726780891 CET | 80 | 49777 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:57.726880074 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.726906061 CET | 49775 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.727060080 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:57.734066963 CET | 80 | 49777 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:58.555742025 CET | 80 | 49777 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:58.558331013 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:58.558382034 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:58.558433056 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:58.559058905 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:58.559078932 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:58.610596895 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.266021967 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:59.268043041 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:59.268078089 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:59.268141031 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:59.268150091 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:59.524807930 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:59.525217056 CET | 443 | 49778 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:06:59.527481079 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:59.528059006 CET | 49778 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:06:59.531565905 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.532356024 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.538640022 CET | 80 | 49777 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:59.538983107 CET | 80 | 49779 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:06:59.539397001 CET | 49777 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.539432049 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.554446936 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:06:59.563211918 CET | 80 | 49779 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:00.358151913 CET | 80 | 49779 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:00.407509089 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:00.563529015 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:00.563610077 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:00.563690901 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:00.564527988 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:00.564539909 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.197789907 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.199637890 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:01.199666023 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.199836016 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:01.199842930 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.457820892 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.457914114 CET | 443 | 49780 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:01.457978964 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:01.458550930 CET | 49780 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:01.463217020 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:01.464626074 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:01.468206882 CET | 80 | 49779 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:01.468266010 CET | 49779 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:01.469504118 CET | 80 | 49781 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:01.469593048 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:01.469693899 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:01.474426985 CET | 80 | 49781 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:02.299186945 CET | 80 | 49781 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:02.305006981 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:02.305046082 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:02.305140972 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:02.305527925 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:02.305537939 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:02.345037937 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:02.955689907 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:02.957612991 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:02.957640886 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:02.957714081 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:02.957720995 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:03.214999914 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:03.215080023 CET | 443 | 49782 | 149.154.167.220 | 192.168.2.10 |
Jan 11, 2025 03:07:03.215156078 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:05.860783100 CET | 49782 | 443 | 192.168.2.10 | 149.154.167.220 |
Jan 11, 2025 03:07:05.863830090 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:05.864190102 CET | 49783 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:05.868999958 CET | 80 | 49781 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:05.869044065 CET | 80 | 49783 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:05.869090080 CET | 49781 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:05.869141102 CET | 49783 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:05.869218111 CET | 49783 | 80 | 192.168.2.10 | 132.226.8.169 |
Jan 11, 2025 03:07:05.873950005 CET | 80 | 49783 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:06.698160887 CET | 80 | 49783 | 132.226.8.169 | 192.168.2.10 |
Jan 11, 2025 03:07:06.751249075 CET | 49783 | 80 | 192.168.2.10 | 132.226.8.169 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 11, 2025 03:05:21.900881052 CET | 65153 | 53 | 192.168.2.10 | 1.1.1.1 |
Jan 11, 2025 03:05:21.907567978 CET | 53 | 65153 | 1.1.1.1 | 192.168.2.10 |
Jan 11, 2025 03:05:23.301553011 CET | 61052 | 53 | 192.168.2.10 | 1.1.1.1 |
Jan 11, 2025 03:05:23.308876038 CET | 53 | 61052 | 1.1.1.1 | 192.168.2.10 |
Jan 11, 2025 03:05:27.245166063 CET | 49196 | 53 | 192.168.2.10 | 1.1.1.1 |
Jan 11, 2025 03:05:27.252181053 CET | 53 | 49196 | 1.1.1.1 | 192.168.2.10 |
Jan 11, 2025 03:05:28.897032976 CET | 61121 | 53 | 192.168.2.10 | 1.1.1.1 |
Jan 11, 2025 03:05:28.907454014 CET | 53 | 61121 | 1.1.1.1 | 192.168.2.10 |
Jan 11, 2025 03:05:35.251332045 CET | 59793 | 53 | 192.168.2.10 | 1.1.1.1 |
Jan 11, 2025 03:05:35.257931948 CET | 53 | 59793 | 1.1.1.1 | 192.168.2.10 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 11, 2025 03:05:21.900881052 CET | 192.168.2.10 | 1.1.1.1 | 0x8ef5 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 03:05:23.301553011 CET | 192.168.2.10 | 1.1.1.1 | 0xc454 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 03:05:27.245166063 CET | 192.168.2.10 | 1.1.1.1 | 0x613d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 03:05:28.897032976 CET | 192.168.2.10 | 1.1.1.1 | 0xa935 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 11, 2025 03:05:35.251332045 CET | 192.168.2.10 | 1.1.1.1 | 0x284f | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 11, 2025 03:05:21.907567978 CET | 1.1.1.1 | 192.168.2.10 | 0x8ef5 | No error (0) | 142.250.181.238 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:23.308876038 CET | 1.1.1.1 | 192.168.2.10 | 0xc454 | No error (0) | 142.250.186.33 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | checkip.dyndns.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | 132.226.8.169 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | 158.101.44.242 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | 132.226.247.73 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | 193.122.130.0 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:27.252181053 CET | 1.1.1.1 | 192.168.2.10 | 0x613d | No error (0) | 193.122.6.168 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.80.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.112.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.16.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.48.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.96.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.32.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:28.907454014 CET | 1.1.1.1 | 192.168.2.10 | 0xa935 | No error (0) | 104.21.64.1 | A (IP address) | IN (0x0001) | false | ||
Jan 11, 2025 03:05:35.257931948 CET | 1.1.1.1 | 192.168.2.10 | 0x284f | No error (0) | 149.154.167.220 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49710 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:27.264302015 CET | 151 | OUT | |
Jan 11, 2025 03:05:28.078248024 CET | 273 | IN | |
Jan 11, 2025 03:05:28.083086014 CET | 127 | OUT | |
Jan 11, 2025 03:05:28.387295961 CET | 273 | IN | |
Jan 11, 2025 03:05:34.965766907 CET | 127 | OUT | |
Jan 11, 2025 03:05:35.246803045 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.10 | 49713 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:37.867239952 CET | 127 | OUT | |
Jan 11, 2025 03:05:40.796513081 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.10 | 49715 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:41.637671947 CET | 151 | OUT | |
Jan 11, 2025 03:05:44.534039021 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.10 | 49717 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:45.418610096 CET | 151 | OUT | |
Jan 11, 2025 03:05:49.278007984 CET | 697 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.10 | 49718 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:49.287935972 CET | 151 | OUT | |
Jan 11, 2025 03:05:51.116115093 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.10 | 49721 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:52.025201082 CET | 151 | OUT | |
Jan 11, 2025 03:05:53.969919920 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.10 | 49723 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:54.878374100 CET | 151 | OUT | |
Jan 11, 2025 03:05:58.729590893 CET | 697 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.10 | 49724 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:05:58.739515066 CET | 151 | OUT | |
Jan 11, 2025 03:06:01.571975946 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.10 | 49726 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:02.389221907 CET | 151 | OUT | |
Jan 11, 2025 03:06:06.283741951 CET | 697 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.10 | 49727 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:06.295854092 CET | 151 | OUT | |
Jan 11, 2025 03:06:10.363274097 CET | 697 | IN | |
Jan 11, 2025 03:06:10.371051073 CET | 127 | OUT | |
Jan 11, 2025 03:06:11.709779024 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.10 | 49729 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:12.603893995 CET | 151 | OUT | |
Jan 11, 2025 03:06:15.106184959 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.10 | 49731 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:15.976789951 CET | 151 | OUT | |
Jan 11, 2025 03:06:17.024198055 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.10 | 49733 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:17.844587088 CET | 151 | OUT | |
Jan 11, 2025 03:06:18.657212019 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.10 | 49735 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:19.547066927 CET | 151 | OUT | |
Jan 11, 2025 03:06:20.372675896 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.10 | 49737 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:21.545291901 CET | 151 | OUT | |
Jan 11, 2025 03:06:22.353651047 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.10 | 49739 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:23.249130964 CET | 151 | OUT | |
Jan 11, 2025 03:06:24.109461069 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.10 | 49741 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:24.921981096 CET | 151 | OUT | |
Jan 11, 2025 03:06:25.734456062 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.10 | 49743 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:26.642739058 CET | 151 | OUT | |
Jan 11, 2025 03:06:27.470195055 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.10 | 49745 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:28.288182974 CET | 151 | OUT | |
Jan 11, 2025 03:06:29.113658905 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.10 | 49747 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:30.117631912 CET | 151 | OUT | |
Jan 11, 2025 03:06:30.949954987 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.10 | 49749 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:31.761440039 CET | 151 | OUT | |
Jan 11, 2025 03:06:32.586575031 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.10 | 49751 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:33.444525957 CET | 151 | OUT | |
Jan 11, 2025 03:06:34.289345026 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.10 | 49753 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:35.162589073 CET | 151 | OUT | |
Jan 11, 2025 03:06:36.037976027 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.10 | 49755 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:36.893040895 CET | 151 | OUT | |
Jan 11, 2025 03:06:38.221594095 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.10 | 49757 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:39.043637991 CET | 151 | OUT | |
Jan 11, 2025 03:06:39.882061958 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.10 | 49759 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:40.771517038 CET | 151 | OUT | |
Jan 11, 2025 03:06:41.594609976 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.10 | 49761 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:42.434350014 CET | 151 | OUT | |
Jan 11, 2025 03:06:43.279299021 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.10 | 49763 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:44.526838064 CET | 151 | OUT | |
Jan 11, 2025 03:06:45.845668077 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.10 | 49765 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:46.862025976 CET | 151 | OUT | |
Jan 11, 2025 03:06:47.889677048 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.10 | 49767 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:48.876497984 CET | 151 | OUT | |
Jan 11, 2025 03:06:49.825568914 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.10 | 49769 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:50.712588072 CET | 151 | OUT | |
Jan 11, 2025 03:06:51.544471025 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.10 | 49771 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:52.414118052 CET | 151 | OUT | |
Jan 11, 2025 03:06:53.242187977 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.10 | 49773 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:54.373991966 CET | 151 | OUT | |
Jan 11, 2025 03:06:55.204922915 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.10 | 49775 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:56.003343105 CET | 151 | OUT | |
Jan 11, 2025 03:06:56.822174072 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.10 | 49777 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:57.727060080 CET | 151 | OUT | |
Jan 11, 2025 03:06:58.555742025 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.10 | 49779 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:06:59.554446936 CET | 151 | OUT | |
Jan 11, 2025 03:07:00.358151913 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.10 | 49781 | 132.226.8.169 | 80 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:07:01.469693899 CET | 151 | OUT | |
Jan 11, 2025 03:07:02.299186945 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
37 | 192.168.2.10 | 49783 | 132.226.8.169 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 11, 2025 03:07:05.869218111 CET | 151 | OUT | |
Jan 11, 2025 03:07:06.698160887 CET | 273 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.10 | 49708 | 142.250.181.238 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:22 UTC | 216 | OUT | |
2025-01-11 02:05:23 UTC | 1920 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.10 | 49709 | 142.250.186.33 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:23 UTC | 258 | OUT | |
2025-01-11 02:05:26 UTC | 4933 | IN | |
2025-01-11 02:05:26 UTC | 4933 | IN | |
2025-01-11 02:05:26 UTC | 4832 | IN | |
2025-01-11 02:05:26 UTC | 1323 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN | |
2025-01-11 02:05:26 UTC | 1390 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.10 | 49711 | 104.21.80.1 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:29 UTC | 85 | OUT | |
2025-01-11 02:05:29 UTC | 853 | IN | |
2025-01-11 02:05:29 UTC | 362 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.10 | 49712 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:35 UTC | 294 | OUT | |
2025-01-11 02:05:35 UTC | 1090 | OUT | |
2025-01-11 02:05:37 UTC | 347 | IN | |
2025-01-11 02:05:37 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.10 | 49714 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:41 UTC | 294 | OUT | |
2025-01-11 02:05:41 UTC | 1090 | OUT | |
2025-01-11 02:05:41 UTC | 347 | IN | |
2025-01-11 02:05:41 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.10 | 49716 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:45 UTC | 270 | OUT | |
2025-01-11 02:05:45 UTC | 1090 | OUT | |
2025-01-11 02:05:45 UTC | 347 | IN | |
2025-01-11 02:05:45 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.10 | 49720 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:51 UTC | 294 | OUT | |
2025-01-11 02:05:51 UTC | 1090 | OUT | |
2025-01-11 02:05:52 UTC | 347 | IN | |
2025-01-11 02:05:52 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.10 | 49722 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:05:54 UTC | 270 | OUT | |
2025-01-11 02:05:54 UTC | 1090 | OUT | |
2025-01-11 02:05:54 UTC | 347 | IN | |
2025-01-11 02:05:54 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.10 | 49725 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:02 UTC | 294 | OUT | |
2025-01-11 02:06:02 UTC | 1090 | OUT | |
2025-01-11 02:06:02 UTC | 347 | IN | |
2025-01-11 02:06:02 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.10 | 49728 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:12 UTC | 294 | OUT | |
2025-01-11 02:06:12 UTC | 1090 | OUT | |
2025-01-11 02:06:12 UTC | 347 | IN | |
2025-01-11 02:06:12 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.10 | 49730 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:15 UTC | 294 | OUT | |
2025-01-11 02:06:15 UTC | 1090 | OUT | |
2025-01-11 02:06:15 UTC | 347 | IN | |
2025-01-11 02:06:15 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.10 | 49732 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:17 UTC | 270 | OUT | |
2025-01-11 02:06:17 UTC | 1090 | OUT | |
2025-01-11 02:06:17 UTC | 347 | IN | |
2025-01-11 02:06:17 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.10 | 49734 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:19 UTC | 270 | OUT | |
2025-01-11 02:06:19 UTC | 1090 | OUT | |
2025-01-11 02:06:19 UTC | 347 | IN | |
2025-01-11 02:06:19 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.10 | 49736 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:21 UTC | 270 | OUT | |
2025-01-11 02:06:21 UTC | 1090 | OUT | |
2025-01-11 02:06:21 UTC | 347 | IN | |
2025-01-11 02:06:21 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.10 | 49738 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:22 UTC | 294 | OUT | |
2025-01-11 02:06:22 UTC | 1090 | OUT | |
2025-01-11 02:06:23 UTC | 347 | IN | |
2025-01-11 02:06:23 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.10 | 49740 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:24 UTC | 270 | OUT | |
2025-01-11 02:06:24 UTC | 1090 | OUT | |
2025-01-11 02:06:24 UTC | 347 | IN | |
2025-01-11 02:06:24 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.10 | 49742 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:26 UTC | 270 | OUT | |
2025-01-11 02:06:26 UTC | 1090 | OUT | |
2025-01-11 02:06:26 UTC | 347 | IN | |
2025-01-11 02:06:26 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.10 | 49744 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:28 UTC | 294 | OUT | |
2025-01-11 02:06:28 UTC | 1090 | OUT | |
2025-01-11 02:06:28 UTC | 347 | IN | |
2025-01-11 02:06:28 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.10 | 49746 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:29 UTC | 294 | OUT | |
2025-01-11 02:06:29 UTC | 1090 | OUT | |
2025-01-11 02:06:29 UTC | 347 | IN | |
2025-01-11 02:06:29 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.10 | 49748 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:31 UTC | 294 | OUT | |
2025-01-11 02:06:31 UTC | 1090 | OUT | |
2025-01-11 02:06:31 UTC | 347 | IN | |
2025-01-11 02:06:31 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.10 | 49750 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:33 UTC | 270 | OUT | |
2025-01-11 02:06:33 UTC | 1090 | OUT | |
2025-01-11 02:06:33 UTC | 347 | IN | |
2025-01-11 02:06:33 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.10 | 49752 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:34 UTC | 270 | OUT | |
2025-01-11 02:06:34 UTC | 1090 | OUT | |
2025-01-11 02:06:35 UTC | 347 | IN | |
2025-01-11 02:06:35 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.10 | 49754 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:36 UTC | 270 | OUT | |
2025-01-11 02:06:36 UTC | 1090 | OUT | |
2025-01-11 02:06:36 UTC | 347 | IN | |
2025-01-11 02:06:36 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.10 | 49756 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:38 UTC | 270 | OUT | |
2025-01-11 02:06:38 UTC | 1090 | OUT | |
2025-01-11 02:06:39 UTC | 347 | IN | |
2025-01-11 02:06:39 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.10 | 49758 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:40 UTC | 270 | OUT | |
2025-01-11 02:06:40 UTC | 1090 | OUT | |
2025-01-11 02:06:40 UTC | 347 | IN | |
2025-01-11 02:06:40 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.10 | 49760 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:42 UTC | 270 | OUT | |
2025-01-11 02:06:42 UTC | 1090 | OUT | |
2025-01-11 02:06:42 UTC | 347 | IN | |
2025-01-11 02:06:42 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.10 | 49762 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:43 UTC | 294 | OUT | |
2025-01-11 02:06:43 UTC | 1090 | OUT | |
2025-01-11 02:06:44 UTC | 347 | IN | |
2025-01-11 02:06:44 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.10 | 49764 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:46 UTC | 294 | OUT | |
2025-01-11 02:06:46 UTC | 1090 | OUT | |
2025-01-11 02:06:46 UTC | 347 | IN | |
2025-01-11 02:06:46 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.10 | 49766 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:48 UTC | 270 | OUT | |
2025-01-11 02:06:48 UTC | 1090 | OUT | |
2025-01-11 02:06:48 UTC | 347 | IN | |
2025-01-11 02:06:48 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.10 | 49768 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:50 UTC | 270 | OUT | |
2025-01-11 02:06:50 UTC | 1090 | OUT | |
2025-01-11 02:06:50 UTC | 347 | IN | |
2025-01-11 02:06:50 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.10 | 49770 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:52 UTC | 294 | OUT | |
2025-01-11 02:06:52 UTC | 1090 | OUT | |
2025-01-11 02:06:52 UTC | 347 | IN | |
2025-01-11 02:06:52 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.10 | 49772 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:53 UTC | 270 | OUT | |
2025-01-11 02:06:53 UTC | 1090 | OUT | |
2025-01-11 02:06:54 UTC | 347 | IN | |
2025-01-11 02:06:54 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.10 | 49774 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:55 UTC | 294 | OUT | |
2025-01-11 02:06:55 UTC | 1090 | OUT | |
2025-01-11 02:06:55 UTC | 347 | IN | |
2025-01-11 02:06:55 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.10 | 49776 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:57 UTC | 270 | OUT | |
2025-01-11 02:06:57 UTC | 1090 | OUT | |
2025-01-11 02:06:57 UTC | 347 | IN | |
2025-01-11 02:06:57 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.10 | 49778 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:06:59 UTC | 270 | OUT | |
2025-01-11 02:06:59 UTC | 1090 | OUT | |
2025-01-11 02:06:59 UTC | 347 | IN | |
2025-01-11 02:06:59 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.10 | 49780 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:07:01 UTC | 270 | OUT | |
2025-01-11 02:07:01 UTC | 1090 | OUT | |
2025-01-11 02:07:01 UTC | 347 | IN | |
2025-01-11 02:07:01 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.10 | 49782 | 149.154.167.220 | 443 | 8156 | C:\Users\user\Desktop\4NG0guPiKA.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-11 02:07:02 UTC | 270 | OUT | |
2025-01-11 02:07:02 UTC | 1090 | OUT | |
2025-01-11 02:07:03 UTC | 347 | IN | |
2025-01-11 02:07:03 UTC | 58 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 21:04:55 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\Desktop\4NG0guPiKA.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 778'465 bytes |
MD5 hash: | 8F02B3E31021D64ED25A599E58BC8F2F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 3 |
Start time: | 21:05:16 |
Start date: | 10/01/2025 |
Path: | C:\Users\user\Desktop\4NG0guPiKA.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 778'465 bytes |
MD5 hash: | 8F02B3E31021D64ED25A599E58BC8F2F |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 20.5% |
Dynamic/Decrypted Code Coverage: | 15.8% |
Signature Coverage: | 19.6% |
Total number of Nodes: | 1451 |
Total number of Limit Nodes: | 43 |
Graph
Function 0040335A Relevance: 75.6, APIs: 27, Strings: 16, Instructions: 335stringfilecomCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404B10 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 481windowmemoryCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405F0C Relevance: 19.5, APIs: 8, Strings: 3, Instructions: 207stringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405772 Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 148filestringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040653F Relevance: 5.4, APIs: 4, Instructions: 382COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004038B4 Relevance: 49.2, APIs: 15, Strings: 13, Instructions: 216stringregistrylibraryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402DBC Relevance: 26.5, APIs: 5, Strings: 10, Instructions: 203memoryCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401752 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 145stringtimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402573 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 142fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040317D Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 108fileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402331 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 71registrystringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405108 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405665 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 24processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406974 Relevance: 5.2, APIs: 4, Instructions: 236COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406B75 Relevance: 5.2, APIs: 4, Instructions: 208COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040688B Relevance: 5.2, APIs: 4, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406390 Relevance: 5.2, APIs: 4, Instructions: 198COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004067DE Relevance: 5.2, APIs: 4, Instructions: 180COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004068FC Relevance: 5.2, APIs: 4, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406848 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F98 Relevance: 4.6, APIs: 3, Instructions: 73libraryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401B22 Relevance: 4.6, APIs: 2, Strings: 1, Instructions: 72memoryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10002868 Relevance: 3.2, APIs: 2, Instructions: 156COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401389 Relevance: 3.0, APIs: 2, Instructions: 43windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401DC7 Relevance: 3.0, APIs: 2, Instructions: 21COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B56 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004026F9 Relevance: 1.5, APIs: 1, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402253 Relevance: 1.5, APIs: 1, Instructions: 25COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401718 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405BD9 Relevance: 1.5, APIs: 1, Instructions: 22fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000278D Relevance: 1.5, APIs: 1, Instructions: 21memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404164 Relevance: 1.5, APIs: 1, Instructions: 6windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040330F Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000121B Relevance: 1.3, APIs: 1, Instructions: 6memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004052D3 Relevance: 65.0, APIs: 36, Strings: 1, Instructions: 282windowclipboardmemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004045CA Relevance: 23.0, APIs: 10, Strings: 3, Instructions: 269stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402770 Relevance: 1.5, APIs: 1, Instructions: 30fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C08 Relevance: 29.9, APIs: 12, Strings: 5, Instructions: 136stringmemoryfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100022EB Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 134memorystringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004024EE Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 54filestringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404196 Relevance: 12.1, APIs: 8, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404A5E Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402C7F Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 36timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 1000248D Relevance: 9.1, APIs: 6, Instructions: 108COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100018C1 Relevance: 7.7, APIs: 5, Instructions: 190COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 10001617 Relevance: 7.5, APIs: 5, Instructions: 41memorylibraryloaderCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401CE5 Relevance: 7.5, APIs: 5, Instructions: 39windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D41 Relevance: 7.5, APIs: 5, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404978 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BCA Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 76windowtimeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405DB7 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 45registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405935 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F08 Relevance: 6.1, APIs: 4, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405981 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 16stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 100010E1 Relevance: 5.1, APIs: 4, Instructions: 104memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405ABB Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Execution Graph
Execution Coverage: | 11.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 2% |
Total number of Nodes: | 307 |
Total number of Limit Nodes: | 17 |
Graph
Function 000D66B8 Relevance: 10.5, Strings: 8, Instructions: 475COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D5F90 Relevance: 9.2, Strings: 7, Instructions: 465COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D19B8 Relevance: 8.2, Strings: 6, Instructions: 685COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D9048 Relevance: 3.4, Strings: 2, Instructions: 898COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 3645E8A8 Relevance: 3.3, Strings: 2, Instructions: 764COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2BDF0 Relevance: 3.3, Strings: 2, Instructions: 758COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D4328 Relevance: 2.7, Strings: 2, Instructions: 191COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F28650 Relevance: .7, Instructions: 709COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EC638 Relevance: .3, Instructions: 320COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331E03AF Relevance: .3, Instructions: 284COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331E0C1A Relevance: .2, Instructions: 236COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331E0C28 Relevance: .2, Instructions: 220COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F29D10 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2A360 Relevance: .2, Instructions: 219COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F296C8 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2A9B0 Relevance: .2, Instructions: 218COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331E0F6F Relevance: .2, Instructions: 202COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2BA97 Relevance: .2, Instructions: 191COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F28640 Relevance: .2, Instructions: 169COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2A9A0 Relevance: .2, Instructions: 164COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F296B8 Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F29D00 Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2A352 Relevance: .1, Instructions: 107COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D7458 Relevance: 29.5, Strings: 23, Instructions: 706COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450971 Relevance: 6.1, APIs: 4, Instructions: 133threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450980 Relevance: 6.1, APIs: 4, Instructions: 128threadCOMMON
Control-flow Graph
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D8D90 Relevance: 4.1, Strings: 3, Instructions: 318COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2D548 Relevance: 3.9, Strings: 3, Instructions: 149COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D4F00 Relevance: 2.8, Strings: 2, Instructions: 333COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D5460 Relevance: 2.7, Strings: 2, Instructions: 228COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D0B29 Relevance: 2.7, Strings: 2, Instructions: 203COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D0B30 Relevance: 2.7, Strings: 2, Instructions: 200COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D8BF0 Relevance: 2.7, Strings: 2, Instructions: 152COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450104 Relevance: 1.6, APIs: 1, Instructions: 117COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450110 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36451854 Relevance: 1.6, APIs: 1, Instructions: 97COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450BC1 Relevance: 1.6, APIs: 1, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36450BC8 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36452019 Relevance: 1.5, APIs: 1, Instructions: 47timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 3645C618 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 3645C6C4 Relevance: 1.5, APIs: 1, Instructions: 46windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 3645D4C8 Relevance: 1.5, APIs: 1, Instructions: 46comCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 36452020 Relevance: 1.5, APIs: 1, Instructions: 44timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 3645E7E0 Relevance: 1.5, APIs: 1, Instructions: 42windowCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D9EB0 Relevance: 1.4, Strings: 1, Instructions: 119COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D4620 Relevance: 1.4, Strings: 1, Instructions: 101COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D8729 Relevance: 1.3, Strings: 1, Instructions: 65COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D4664 Relevance: 1.3, Strings: 1, Instructions: 45COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2C175 Relevance: .3, Instructions: 322COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2C173 Relevance: .3, Instructions: 319COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D6C98 Relevance: .2, Instructions: 201COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2FAB8 Relevance: .2, Instructions: 189COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F27920 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2CC28 Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D3168 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D92C3 Relevance: .1, Instructions: 124COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2D370 Relevance: .1, Instructions: 88COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D6F40 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2FAA8 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DB1B7 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2D360 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D52B8 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2B985 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D18C8 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F27922 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000AD030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DB2C2 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D0EC8 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D324D Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFE60 Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D17B8 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D52C8 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2B9C8 Relevance: .1, Instructions: 56COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000AD02B Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D4E5F Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2F098 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2EBD4 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DB2F0 Relevance: .0, Instructions: 49COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2CE51 Relevance: .0, Instructions: 45COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFC3E Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2CE60 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2962C Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2964C Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2D4C9 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DB168 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D1877 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2BD98 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFE1B Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFE20 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFF22 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D1888 Relevance: .0, Instructions: 19COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D7EC0 Relevance: .0, Instructions: 18COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D56FF Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D9F6D Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2D49D Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2CF31 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2961C Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFF30 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2BD48 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F29544 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D5710 Relevance: .0, Instructions: 12COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000DFFC8 Relevance: .0, Instructions: 4COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404B10 Relevance: 63.5, APIs: 33, Strings: 3, Instructions: 481windowmemoryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040335A Relevance: 63.3, APIs: 27, Strings: 9, Instructions: 335stringfilecomCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405772 Relevance: 14.1, APIs: 7, Strings: 1, Instructions: 148filestringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2AFF8 Relevance: 13.0, Strings: 10, Instructions: 461COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2AFE8 Relevance: 12.9, Strings: 10, Instructions: 371COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F2AFF7 Relevance: 12.9, Strings: 10, Instructions: 361COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040653F Relevance: 5.4, APIs: 4, Instructions: 382COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F24820 Relevance: 1.5, Strings: 1, Instructions: 268COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F27B4F Relevance: .6, Instructions: 607COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EBD88 Relevance: .3, Instructions: 275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EF042 Relevance: .3, Instructions: 274COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EB07F Relevance: .3, Instructions: 274COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EE790 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EDEE1 Relevance: .3, Instructions: 272COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EE339 Relevance: .3, Instructions: 271COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EDA89 Relevance: .3, Instructions: 271COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EEBF7 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F24DB0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F22560 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F274C8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F21CB0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F26C18 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F21400 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F267C0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F20FA8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F23F70 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F25F10 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F236C0 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F25660 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F22E10 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F229B8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F22108 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F27070 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F21858 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F243C8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F26368 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F23B18 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F25AB8 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F23268 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 35F25208 Relevance: .3, Instructions: 268COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EC1F2 Relevance: .3, Instructions: 267COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EB944 Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 331EB4EC Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004052D3 Relevance: 65.0, APIs: 36, Strings: 1, Instructions: 282windowclipboardmemoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004038B4 Relevance: 40.5, APIs: 15, Strings: 8, Instructions: 216stringregistrylibraryCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405C08 Relevance: 29.9, APIs: 12, Strings: 5, Instructions: 136stringmemoryfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004045CA Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 269stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402DBC Relevance: 19.5, APIs: 5, Strings: 6, Instructions: 203memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405F0C Relevance: 17.7, APIs: 8, Strings: 2, Instructions: 207stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404196 Relevance: 12.1, APIs: 8, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402573 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 142fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404A5E Relevance: 10.5, APIs: 5, Strings: 1, Instructions: 48windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402C7F Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 36timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040317D Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 108fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004024EE Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 54filestringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401CE5 Relevance: 7.5, APIs: 5, Instructions: 39windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401D41 Relevance: 7.5, APIs: 5, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404978 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401BCA Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 76windowtimeCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004015B9 Relevance: 6.1, APIs: 4, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401F08 Relevance: 6.1, APIs: 4, Instructions: 55memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405108 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 46windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405665 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 24processCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406974 Relevance: 5.2, APIs: 4, Instructions: 236COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406B75 Relevance: 5.2, APIs: 4, Instructions: 208COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040688B Relevance: 5.2, APIs: 4, Instructions: 205COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406390 Relevance: 5.2, APIs: 4, Instructions: 198COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004067DE Relevance: 5.2, APIs: 4, Instructions: 180COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004068FC Relevance: 5.2, APIs: 4, Instructions: 170COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406848 Relevance: 5.2, APIs: 4, Instructions: 168COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D1A40 Relevance: 5.1, Strings: 4, Instructions: 97COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 000D58E8 Relevance: 5.0, Strings: 4, Instructions: 49COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405ABB Relevance: 5.0, APIs: 4, Instructions: 37stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|