Windows
Analysis Report
YYYY-NNN AUDIT DETAIL REPORT .docx
Overview
General Information
Detection
Score: | 76 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
- WINWORD.EXE (PID: 6640 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Root\ Office16\W INWORD.EXE " /n "C:\U sers\user\ Desktop\YY YY-NNN AUD IT DETAIL REPORT .do cx" /o "" MD5: A9F0EC89897AC6C878D217DFB64CA752)
- rundll32.exe (PID: 6332 cmdline:
C:\Windows \System32\ rundll32.e xe C:\Wind ows\System 32\shell32 .dll,SHCre ateLocalSe rverRunDll {9aa46009 -3ce0-458a -a354-7156 10a075e6} -Embedding MD5: C87FA6FC1D294962EABE44509FE1921C)
- WINWORD.EXE (PID: 6712 cmdline:
"C:\Progra m Files\Mi crosoft Of fice\Root\ Office16\W INWORD.EXE " /n "C:\U sers\user\ Desktop\YY YY-NNN AUD IT DETAIL REPORT .do cx" /o "" MD5: A9F0EC89897AC6C878D217DFB64CA752)
- cleanup
System Summary |
---|
Source: | Author: X__Junior (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-13T11:17:17.216576+0100 | 1810004 | 1 | Potentially Bad Traffic | 192.168.2.24 | 59360 | 159.60.138.212 | 443 | TCP |
2025-01-13T11:18:27.971624+0100 | 1810004 | 1 | Potentially Bad Traffic | 192.168.2.24 | 59391 | 159.60.138.212 | 443 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-13T11:17:14.195599+0100 | 1810005 | 1 | Potentially Bad Traffic | 192.168.2.24 | 59357 | 159.60.138.212 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | ASN Name: |
Source: | JA3 fingerprint: | ||
Source: | JA3 fingerprint: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: | ||
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | OCR: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Word Document stream: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Persistence and Installation Behavior |
---|
Source: | Extracted files from sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | Path Interception | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 3 Exploitation for Client Execution | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Disable or Modify Tools | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Virtualization/Sandbox Evasion | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Process Injection | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Rundll32 | LSA Secrets | 3 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
11% | Virustotal | Browse | ||
16% | ReversingLabs | Document.Exploit.TempInj | ||
100% | Avira | EXP/TempInj.BA |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ves-io-f35000c6-187d-4400-baeb-13d55394e070.ac.vh.ves.io | 159.60.138.212 | true | true | unknown | |
audimex.nexi.it | unknown | unknown | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
159.60.138.212 | ves-io-f35000c6-187d-4400-baeb-13d55394e070.ac.vh.ves.io | Netherlands | 11351 | TWC-11351-NORTHEASTUS | true |
IP |
---|
192.168.2.24 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1589950 |
Start date and time: | 2025-01-13 11:16:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsinteractivecookbook.jbs |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Potential for more IOCs and behavior |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | YYYY-NNN AUDIT DETAIL REPORT .docx |
Detection: | MAL |
Classification: | mal76.evad.winDOCX@5/12@2/2 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, sppsvc.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 104.18.38.233, 172.64.149.23, 52.113.194.132, 52.109.76.243, 52.109.76.144, 52.168.117.175, 95.100.110.77, 95.100.110.74, 2.20.245.216, 2.20.245.225, 2.23.240.50, 52.111.231.26, 52.111.231.25, 52.111.231.24, 52.111.231.23, 199.232.214.172, 13.89.179.13, 52.111.236.33, 52.111.236.35, 52.111.236.32, 52.111.236.34, 2.21.65.149, 2.21.65.130, 20.190.159.71, 4.245.163.56
- Excluded domains from analysis (whitelisted): e1324.dscd.akamaiedge.net, crt.comodoca.com.cdn.cloudflare.net, neu-azsc-000.odc.officeapps.live.com, odc.officeapps.live.com, slscr.update.microsoft.com, europe.odcsm1.live.com.akadns.net, templatesmetadata.office.net.edgekey.net, eur.roaming1.live.com.akadns.net, neu-azsc-000.roaming.officeapps.live.com, mobile.events.data.microsoft.com, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, onedscolprdcus21.centralus.cloudapp.azure.com, login.live.com, templatesmetadata.office.net, c.pki.goog, res-1-tls.cdn.office.net, osiprod-neu-bronze-azsc-000.northeurope.cloudapp.azure.com, ecs.office.com, e40491.dscg.akamaiedge.net, client.wns.windows.com, uci.cdn.office.net, ctldl.windowsupdate.com, onedscolprdeus19.eastus.cloudapp.azure.com, prod.roaming1.live.com.akadns.net, uci.edog.cdn.office.net.edgekey.net, s-0005-office.config.skype.com, crt.comodoca.com, prod1.naturallanguageeditorservice.osi.office.net.akadns.net, x1.c.lencr.org, e26769.dscb.akamaiedge.net,
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtQueryAttributesFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
- Report size getting too big, too many NtSetValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
TWC-11351-NORTHEASTUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai, Okiru | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
258a5a1e95b8a911872bae9081526644 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
6a5d235ee78c6aede6a61448b4e9ff1e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\Users\user\AppData\Local\Temp\Outlook Logging\WINWORD_16_0_18129_20158-20250113T0517220906-6640.etl
Download File
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 8192 |
Entropy (8bit): | 3.349294681572156 |
Encrypted: | false |
SSDEEP: | 48:bwOPKJkYZ9vb6CQTPM+KmtnGNBzCB/5ZNhQIwBgC/eo9Iq:piJDZ9mC+PM+8v1 |
MD5: | AE04E2CCDAC123DDB9C937B7971880B4 |
SHA1: | EE574B2786AE9C92FB4ED94E40C5E0C1B115E39B |
SHA-256: | B24911256276477A4DF3089CC25F003AA662E0236AAF67E1F0607F9200CA737E |
SHA-512: | 479585B4A9279FBF483982F060422C01833BCB28E55C8CB293534D80DC3FB5E7EC59D46C33D75CD54304C430B3862DD7075BBCBF2C5DC3F746619983FE7A5498 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Temp\Outlook Logging\WINWORD_16_0_18129_20158-20250113T0518360534-6712.etl
Download File
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 4096 |
Entropy (8bit): | 1.2636124188091178 |
Encrypted: | false |
SSDEEP: | 12:05JCPPqF69Fq5zzTx2y2PvSJrQ11X34ZpS3lZn:gU1iTx2ywSJkH4ZpSVZn |
MD5: | F8C7D14FE2136D25B07D3865F20EC4E4 |
SHA1: | 4E3E48A0AF2A1D154767562B2501B181F54CBE98 |
SHA-256: | FEB908A9A3FFA40B4E1A94A85D93F3726C94C91C7D6833ADB82D94AA9011C430 |
SHA-512: | E3925C7A77AC71E08D1CAF27C0B5FDAE9DA24B32BF9786CD6CAAA0C220441687E43FF9CA7044F33954DC5F4662D116359E806E84520894C95569750797CB01FE |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 663 |
Entropy (8bit): | 5.949125862393289 |
Encrypted: | false |
SSDEEP: | 12:PlrojAxh4bxdtT/CS3wkxWHMGBJg8E8gKVYQezuYEecp:trPsTTaWKbBCgVqSF |
MD5: | ED3C1C40B68BA4F40DB15529D5443DEC |
SHA1: | 831AF99BB64A04617E0A42EA898756F9E0E0BCCA |
SHA-256: | 039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A |
SHA-512: | C7B765B9AFBB9810B6674DBC5C5064ED96A2682E78D5DFFAB384D81EDBC77D01E0004F230D4207F2B7D89CEE9008D79D5FBADC5CB486DA4BC43293B7AA878041 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 663 |
Entropy (8bit): | 5.949125862393289 |
Encrypted: | false |
SSDEEP: | 12:PlrojAxh4bxdtT/CS3wkxWHMGBJg8E8gKVYQezuYEecp:trPsTTaWKbBCgVqSF |
MD5: | ED3C1C40B68BA4F40DB15529D5443DEC |
SHA1: | 831AF99BB64A04617E0A42EA898756F9E0E0BCCA |
SHA-256: | 039FE79B74E6D3D561E32D4AF570E6CA70DB6BB3718395BE2BF278B9E601279A |
SHA-512: | C7B765B9AFBB9810B6674DBC5C5064ED96A2682E78D5DFFAB384D81EDBC77D01E0004F230D4207F2B7D89CEE9008D79D5FBADC5CB486DA4BC43293B7AA878041 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Temp\prep_soft Office_root_Office16_sdxs_FA000000027_comments_win32_bundle_V8_perf.cache
Download File
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 1127211 |
Entropy (8bit): | 5.812814119457844 |
Encrypted: | false |
SSDEEP: | 24576:y/T48adNSu65QT+wkOA21Pa601IURbx6uhdYwjERkwhgizvU72DV:yb486Su6rwkOA21Pa601IYx6UEGiFh |
MD5: | 5F6A325EFF287D11AEB18114C9D7E973 |
SHA1: | 69B8465D2678615742794C507F69DB28A462D7FD |
SHA-256: | 1605D2FF3197A3864FA48301EBD5420AD41010F6015483F4290097ED1B586B27 |
SHA-512: | DD3D77AD27771DD71710DBB703C60C9E8BA62193620B44E0A30CB91DD24AF7D54B871300EC6BCC6150B9D2C4F6C4434E4B17C0AAA8CA9EEEFD8C485B487F7A90 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 512 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | BF619EAC0CDF3F68D496EA9344137E8B |
SHA1: | 5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5 |
SHA-256: | 076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 |
SHA-512: | DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 162 |
Entropy (8bit): | 2.6938792386294015 |
Encrypted: | false |
SSDEEP: | 3:HlGzV/V/RtllflAktll01+k20oVMCf/njn:Fy/V/R1ek101b20oV3L |
MD5: | D744FCBE49634E8F3BE045A894ED00A1 |
SHA1: | 370CAFF19310DF22214EEF9979463FE78D5BE40D |
SHA-256: | 3D955BC0586F3B25C6A315673A2FB8EF2E5892991C57B3305FF7BA07B088FB48 |
SHA-512: | 8CAD072C712547922D56BA66CEA445AAC90A24B0FE278CD426F9C97162680E1848F9A7244481F73BE382856CC6B47E695A1F7752FBBDA8CF12046A370678D7D1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 271360 |
Entropy (8bit): | 0.9473359866501169 |
Encrypted: | false |
SSDEEP: | 384:MMIjcNm5NexSBPLF/88lNk7Lg0sg77wYEW7BH2bBOMPLkZABzNuTe0Qf34IeoJaK:MMQcNmlBj1tlm8PbjNjkZABx43QfoIe |
MD5: | F938A2F463C94D643DCED2E39E88B57E |
SHA1: | 69D1D85D414A90EAA4A9F30D3B1E5E6D3F6D3421 |
SHA-256: | BF3F98CAE5A9A1A0B109F62E31561800A5CEC9598B3D85843EBA0F013CB30C49 |
SHA-512: | 79BE2D4E455D2E233FD97C549C1566F94D9369CC45F33C919F104D77E63BF64CF9173E5E12B09995F9DF773B64F7ECC117998CEEE48560F2AD4FA24C8624FA3D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 131072 |
Entropy (8bit): | 0.2134293527357944 |
Encrypted: | false |
SSDEEP: | 48:OcYKnNpFticlJiRqG0Bvl8DHC5kZgnxBF5KMZ2Zko:OcYYpFtfQgGe98LfMn |
MD5: | 6EA25A15971410D35813BE9C47811C22 |
SHA1: | F4F158C961CD8DB0A9453477FD13317A0B029BB1 |
SHA-256: | EE11E822C73AA3682BE6209AA5116F1F5A54A001B69370AD07575FB342CCD962 |
SHA-512: | 25514E0A92B06F7CD715B1077126DFB0376D24410DCA53F8A965BF18CE6A6069B953ECDE711B9A1258FDD252BF4B0CB6045AB607A8AF06DF4E07A039027C9663 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 7.7905210436397505 |
TrID: |
|
File name: | YYYY-NNN AUDIT DETAIL REPORT .docx |
File size: | 111'689 bytes |
MD5: | 0475b8190723d39625ff0f476d11a9ea |
SHA1: | 6a8ff09cad3b66a9b69a289df76e729580c4135b |
SHA256: | 2c0b31d47ed0d44046c1a010cc26098507147783bd49c76fbf7daf678ce4343b |
SHA512: | db6347f4c7f8b1ed41b4d1e2498ed2b1c873d6091f2c9cb05a87954fa7fc911efc4419f3952a265497183832c2b5b60c15aa6c7da2aba8c3ff557efc874c50ae |
SSDEEP: | 1536:teZ3dqp8LDF0POlO+/IK85309yRzA9H2YfbwJQ8TVEt+okwsQVx2XUK1koAlRk9:tcNqePF0ml80IzEHFbwJQ8TFYdKvERM |
TLSH: | 13B3F128D814B82DC6232E78D46D44F4B3554902D75BAA1B7C18FBAC9B843CB963E7C7 |
File Content Preview: | PK..........!..m..............[Content_Types].xml ...(......................................................................................................................................................................................................... |
Icon Hash: | 35e5c48caa8a8599 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | True |
Contains Workbook/Book Stream: | False |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-13T11:17:14.195599+0100 | 1810005 | Joe Security ANOMALY Microsoft Office WebDAV Discovery | 1 | 192.168.2.24 | 59357 | 159.60.138.212 | 443 | TCP |
2025-01-13T11:17:17.216576+0100 | 1810004 | Joe Security ANOMALY Microsoft Office HTTP activity | 1 | 192.168.2.24 | 59360 | 159.60.138.212 | 443 | TCP |
2025-01-13T11:18:27.971624+0100 | 1810004 | Joe Security ANOMALY Microsoft Office HTTP activity | 1 | 192.168.2.24 | 59391 | 159.60.138.212 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 13, 2025 11:17:10.942939997 CET | 59355 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:11.161293030 CET | 53 | 59355 | 1.1.1.1 | 192.168.2.24 |
Jan 13, 2025 11:17:11.162621021 CET | 59355 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:11.215284109 CET | 59355 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:11.220067978 CET | 53 | 59355 | 1.1.1.1 | 192.168.2.24 |
Jan 13, 2025 11:17:11.738006115 CET | 53 | 59355 | 1.1.1.1 | 192.168.2.24 |
Jan 13, 2025 11:17:11.770755053 CET | 59355 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:11.771723032 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:11.771743059 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:11.771801949 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:11.772393942 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:11.772403955 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:11.776667118 CET | 53 | 59355 | 1.1.1.1 | 192.168.2.24 |
Jan 13, 2025 11:17:11.776724100 CET | 59355 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:12.530567884 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.530677080 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.533617973 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.533623934 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.533829927 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.534823895 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.575320959 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.920135021 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.920361996 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.920424938 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.920954943 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.920964956 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.920974970 CET | 59356 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.920979023 CET | 443 | 59356 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.938319921 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.938409090 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:12.938512087 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.940295935 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:12.940330029 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.811814070 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.811903954 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.843741894 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.843774080 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.844955921 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.845027924 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.846745014 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.846831083 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.847068071 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.847084045 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:13.847141981 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.869292974 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:13.915326118 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.195601940 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.195658922 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.195674896 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.195713043 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.195822001 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.195868015 CET | 443 | 59357 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.195898056 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.195938110 CET | 59357 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.209295988 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.209321022 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.209443092 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.209773064 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.209784031 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.978948116 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.979974031 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.979988098 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:14.980602026 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:14.980607033 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.345079899 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.345129013 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.345200062 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.345331907 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.345331907 CET | 59358 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.345344067 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.345351934 CET | 443 | 59358 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.385267973 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.385302067 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:15.385468006 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.386703014 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:15.386713028 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:16.138647079 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:16.138767004 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.140569925 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.140579939 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:16.140889883 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:16.140954018 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.141855955 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.141908884 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:16.141957998 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.142085075 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:16.187319994 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.216569901 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.216648102 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.221652985 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.221659899 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.221716881 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.221728086 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.221748114 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.221801996 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.221801996 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.223606110 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.223619938 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.223707914 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.223707914 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.223716021 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.224023104 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.226659060 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.226674080 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.226759911 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.226766109 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.226886034 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.228908062 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.228921890 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.228972912 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.228977919 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.229005098 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.229181051 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.231533051 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.231547117 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.231597900 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.231609106 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.231651068 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.233139038 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.233150959 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.233210087 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.233216047 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.233261108 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.234473944 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.234487057 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.234559059 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.234564066 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.234705925 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.236061096 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236076117 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236148119 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.236152887 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236280918 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.236860991 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236881018 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236931086 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.236937046 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.236975908 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.236975908 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.237211943 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.237226009 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.237350941 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.237355947 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.237637043 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.238344908 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.238359928 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.238423109 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.238430023 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.238442898 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.238470078 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.239387035 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239399910 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239687920 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.239694118 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239784002 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.239845991 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239860058 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239907980 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.239912987 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.239949942 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.239949942 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.240096092 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.240108967 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.240168095 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.240180016 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.240307093 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.241394997 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241408110 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241472006 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.241472006 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.241477966 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241552114 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.241755009 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241771936 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241827965 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.241832972 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.241887093 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242266893 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242280960 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242331982 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242337942 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242355108 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242513895 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242522001 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242533922 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242600918 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242605925 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.242641926 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.242641926 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.243444920 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243458033 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243558884 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.243565083 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243627071 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.243721008 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243733883 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243781090 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.243786097 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.243819952 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.243819952 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244143009 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244157076 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244214058 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244219065 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244234085 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244294882 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244524956 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244538069 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244611025 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244611025 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244616985 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244676113 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.244967937 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.244980097 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245028973 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245040894 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245122910 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245122910 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245306015 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245318890 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245402098 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245408058 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245415926 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245448112 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245805025 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245819092 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245868921 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245888948 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245893002 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.245951891 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.245951891 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247210979 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247221947 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247267962 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247342110 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247344971 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247381926 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247559071 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247571945 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247641087 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247641087 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247646093 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247714996 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.247936964 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.247948885 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248032093 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248037100 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248145103 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248445988 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248459101 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248527050 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248527050 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248533010 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248589039 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248778105 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248795033 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248851061 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.248857975 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.248904943 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249228954 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249243021 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249319077 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249319077 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249322891 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249332905 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249377012 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249386072 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249386072 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249409914 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249459028 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249459028 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249917030 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249928951 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249975920 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.249983072 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.249986887 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250022888 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250052929 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250058889 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250097990 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250225067 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250528097 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250539064 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250590086 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250602961 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250653982 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250660896 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250675917 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250724077 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250729084 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.250757933 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.250824928 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251385927 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251399994 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251461983 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251466990 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251494884 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251498938 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251528978 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251543045 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251590014 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251595974 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.251626968 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.251646042 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252352953 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252372026 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252398968 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252434969 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252434969 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252445936 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252470016 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252480984 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252507925 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252547026 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252558947 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252588987 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252594948 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.252648115 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.252648115 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253284931 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253298044 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253354073 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253359079 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253382921 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253402948 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253439903 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253453016 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253493071 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253499985 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253510952 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253549099 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253585100 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253591061 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.253607988 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.253634930 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.254262924 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254278898 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254347086 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.254352093 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254390955 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254409075 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254436970 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.254436970 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.254446030 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.254477024 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.254477024 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.255028963 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.255040884 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.255106926 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.255110979 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.255147934 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.255147934 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.287995100 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288008928 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288070917 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288074970 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288165092 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288395882 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288410902 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288676023 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288676023 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288681984 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288742065 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288798094 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288815022 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288866997 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288872957 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.288889885 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.288950920 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.289077044 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.289096117 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.289144993 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.289149046 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.289195061 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.289195061 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.309542894 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.309556961 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.309689045 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.309694052 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.309791088 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328329086 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328341007 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328389883 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328396082 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328442097 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328442097 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328669071 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328681946 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328762054 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328767061 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.328782082 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.328845024 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.329071045 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.329085112 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.329138994 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.329144001 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.329180002 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.329180002 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.537226915 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.537250042 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.537306070 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.537317991 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.537349939 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.537404060 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.537404060 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.537682056 CET | 59360 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.537699938 CET | 443 | 59360 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.572601080 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.572623014 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:17.572712898 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.574171066 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:17.574181080 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.329125881 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.329180956 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.331337929 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.331351042 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.331680059 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.331762075 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.332607985 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.332667112 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.332721949 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.332721949 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.375329018 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.721714020 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.721780062 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.721844912 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.721956968 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.721975088 CET | 443 | 59362 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.721996069 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.722017050 CET | 59362 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.781431913 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.781483889 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:18.781574965 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.782490969 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:18.782512903 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.563141108 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.563235044 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.564816952 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.564845085 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.566086054 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.566148996 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.567157030 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.567276001 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.567406893 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.567475080 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958477020 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.958551884 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958600998 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.958631992 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.958652020 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958683014 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958853960 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958853960 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:19.958887100 CET | 443 | 59363 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:17:19.958941936 CET | 59363 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:17:50.131386995 CET | 49728 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 13, 2025 11:17:50.131488085 CET | 49727 | 443 | 192.168.2.24 | 48.209.144.71 |
Jan 13, 2025 11:17:50.136651039 CET | 80 | 49728 | 192.229.221.95 | 192.168.2.24 |
Jan 13, 2025 11:17:50.136759996 CET | 49728 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 13, 2025 11:17:50.136878014 CET | 443 | 49727 | 48.209.144.71 | 192.168.2.24 |
Jan 13, 2025 11:17:50.136929035 CET | 49727 | 443 | 192.168.2.24 | 48.209.144.71 |
Jan 13, 2025 11:17:51.081768036 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:17:51.086744070 CET | 80 | 59377 | 142.250.184.227 | 192.168.2.24 |
Jan 13, 2025 11:17:51.086903095 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:17:51.087457895 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:17:51.092751026 CET | 80 | 59377 | 142.250.184.227 | 192.168.2.24 |
Jan 13, 2025 11:17:51.720120907 CET | 80 | 59377 | 142.250.184.227 | 192.168.2.24 |
Jan 13, 2025 11:17:51.768033981 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:17:51.782851934 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:17:51.787796021 CET | 80 | 59378 | 23.209.209.135 | 192.168.2.24 |
Jan 13, 2025 11:17:51.787909031 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:17:51.788048983 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:17:51.792864084 CET | 80 | 59378 | 23.209.209.135 | 192.168.2.24 |
Jan 13, 2025 11:17:52.415100098 CET | 80 | 59378 | 23.209.209.135 | 192.168.2.24 |
Jan 13, 2025 11:17:52.422369003 CET | 49730 | 80 | 192.168.2.24 | 199.232.210.172 |
Jan 13, 2025 11:17:52.422386885 CET | 49729 | 80 | 192.168.2.24 | 199.232.210.172 |
Jan 13, 2025 11:17:52.427508116 CET | 80 | 49730 | 199.232.210.172 | 192.168.2.24 |
Jan 13, 2025 11:17:52.427597046 CET | 49730 | 80 | 192.168.2.24 | 199.232.210.172 |
Jan 13, 2025 11:17:52.427916050 CET | 80 | 49729 | 199.232.210.172 | 192.168.2.24 |
Jan 13, 2025 11:17:52.428000927 CET | 49729 | 80 | 192.168.2.24 | 199.232.210.172 |
Jan 13, 2025 11:17:52.467492104 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:18:14.903366089 CET | 49673 | 443 | 192.168.2.24 | 20.198.118.190 |
Jan 13, 2025 11:18:14.903470993 CET | 443 | 49673 | 20.198.118.190 | 192.168.2.24 |
Jan 13, 2025 11:18:15.562108994 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:15.562185049 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:15.562295914 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:15.563258886 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:15.563293934 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:16.373308897 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:16.373450041 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:16.382683039 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:16.382705927 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:16.383120060 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:16.434221983 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:17.702655077 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:17.702723980 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:17.702755928 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:17.702856064 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:17.743377924 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:18.022782087 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:18.022888899 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:18.022964001 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:18.023183107 CET | 59382 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:18.023220062 CET | 443 | 59382 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:18.646214008 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:18.646313906 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:18.646469116 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:18.647562027 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:18.647603035 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:19.437889099 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:19.438107967 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:19.441380024 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:19.441399097 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:19.441740990 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:19.487482071 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.348328114 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.348386049 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.348413944 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:21.348553896 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.395325899 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:21.520468950 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:21.520554066 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:21.520740032 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.522070885 CET | 59384 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:21.522106886 CET | 443 | 59384 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:23.972440004 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Jan 13, 2025 11:18:23.972528934 CET | 443 | 49726 | 2.16.158.192 | 192.168.2.24 |
Jan 13, 2025 11:18:23.972573042 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Jan 13, 2025 11:18:23.972642899 CET | 49726 | 443 | 192.168.2.24 | 2.16.158.192 |
Jan 13, 2025 11:18:24.457755089 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.457806110 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:24.457890034 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.458424091 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.458437920 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:24.459006071 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.459037066 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:24.459104061 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.459249973 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:24.459264040 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.212837934 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.213048935 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.215770006 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.215786934 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.216145039 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.217252016 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.229526043 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.229595900 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.231941938 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.231952906 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.232342958 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.233300924 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.259363890 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.275326967 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.540600061 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.540668964 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.540745974 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.540844917 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.540844917 CET | 59387 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.540860891 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.540872097 CET | 443 | 59387 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.551455021 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.551523924 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.551611900 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.552196026 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.552229881 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.612483978 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.612634897 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.612657070 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.612687111 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.612699986 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.612699986 CET | 59388 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.612706900 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.612714052 CET | 443 | 59388 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.624366999 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.624391079 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:25.624455929 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.625009060 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:25.625024080 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.340773106 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.340873003 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.343466043 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.343487024 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.343827009 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.345031023 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.387351990 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.419107914 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.419671059 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.419691086 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.420301914 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.420309067 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.704081059 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.704132080 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.704204082 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.704354048 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.704395056 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.704425097 CET | 59389 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.704441071 CET | 443 | 59389 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.786739111 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.786883116 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.786936998 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.787014008 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.787029028 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.787041903 CET | 59390 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.787050962 CET | 443 | 59390 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.813745975 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.813821077 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:26.813910007 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.815538883 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:26.815582037 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.610670090 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.611308098 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.613094091 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.613121986 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.614595890 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.614701986 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.616060972 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.616161108 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.616221905 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.616240025 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.617433071 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.617463112 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.663326025 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.971647978 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.971713066 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.971787930 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.971788883 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.971893072 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.971893072 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.971935987 CET | 443 | 59391 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.971998930 CET | 59391 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.981307030 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.981338978 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:27.981462002 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.983195066 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:27.983211040 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:28.765896082 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:28.766014099 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:28.767852068 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:28.767863989 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:28.768682957 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:28.768743038 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:28.769642115 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:28.769789934 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:28.769855976 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:28.769917965 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.185559034 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.185630083 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.185647964 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.185697079 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.185712099 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.185740948 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.185746908 CET | 443 | 59392 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.185794115 CET | 59392 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.225001097 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.225039005 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.225119114 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.226979971 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.226998091 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.997126102 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.997201920 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.998539925 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:29.998553991 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.999159098 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:29.999206066 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.000031948 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.000119925 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.000178099 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.000264883 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.043374062 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.325201035 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.325272083 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.325293064 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.325342894 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.325371027 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.325421095 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.328378916 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.328398943 CET | 443 | 59394 | 159.60.138.212 | 192.168.2.24 |
Jan 13, 2025 11:18:30.328442097 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:30.328588963 CET | 59394 | 443 | 192.168.2.24 | 159.60.138.212 |
Jan 13, 2025 11:18:31.865796089 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:31.865818024 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:31.865921021 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:31.866848946 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:31.866861105 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:32.484936953 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:32.485029936 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:32.487904072 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:32.487907887 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:32.488873959 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:32.536042929 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.742508888 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.742584944 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.742590904 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:33.742786884 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.783320904 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:33.919630051 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:33.919851065 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:33.919933081 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.936976910 CET | 59396 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:33.936985016 CET | 443 | 59396 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:41.788697004 CET | 49733 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 13, 2025 11:18:41.793761969 CET | 80 | 49733 | 192.229.221.95 | 192.168.2.24 |
Jan 13, 2025 11:18:41.793828011 CET | 49733 | 80 | 192.168.2.24 | 192.229.221.95 |
Jan 13, 2025 11:18:46.422883034 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:46.422981024 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:46.423141956 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:46.423993111 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:46.424030066 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:46.444130898 CET | 49741 | 443 | 192.168.2.24 | 2.23.242.162 |
Jan 13, 2025 11:18:46.519488096 CET | 443 | 49741 | 2.23.242.162 | 192.168.2.24 |
Jan 13, 2025 11:18:46.519579887 CET | 49741 | 443 | 192.168.2.24 | 2.23.242.162 |
Jan 13, 2025 11:18:47.303862095 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:47.303985119 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:47.306596994 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:47.306617022 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:47.306951046 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:47.348156929 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:47.881191015 CET | 49742 | 443 | 192.168.2.24 | 2.23.242.162 |
Jan 13, 2025 11:18:47.886600018 CET | 443 | 49742 | 2.23.242.162 | 192.168.2.24 |
Jan 13, 2025 11:18:47.886662960 CET | 49742 | 443 | 192.168.2.24 | 2.23.242.162 |
Jan 13, 2025 11:18:48.563520908 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:48.563587904 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:48.563616037 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:48.563746929 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:48.607342958 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:48.740740061 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:48.740953922 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:48.741039991 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:48.741170883 CET | 59402 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:18:48.741190910 CET | 443 | 59402 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:18:53.107176065 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:18:53.107297897 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:18:53.114394903 CET | 80 | 59378 | 23.209.209.135 | 192.168.2.24 |
Jan 13, 2025 11:18:53.114432096 CET | 80 | 59377 | 142.250.184.227 | 192.168.2.24 |
Jan 13, 2025 11:18:53.114484072 CET | 59378 | 80 | 192.168.2.24 | 23.209.209.135 |
Jan 13, 2025 11:18:53.114530087 CET | 59377 | 80 | 192.168.2.24 | 142.250.184.227 |
Jan 13, 2025 11:19:08.146462917 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:08.146495104 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:08.146578074 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:08.147475958 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:08.147485018 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:08.936208010 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:08.936321020 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:09.105534077 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:09.105556011 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:09.105853081 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:09.148323059 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.355844021 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.355907917 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.355916023 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:10.356014967 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.399323940 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:10.527971983 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:10.528222084 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:10.528289080 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.528944969 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Jan 13, 2025 11:19:10.528956890 CET | 443 | 59408 | 40.115.3.253 | 192.168.2.24 |
Jan 13, 2025 11:19:10.528975964 CET | 59408 | 443 | 192.168.2.24 | 40.115.3.253 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 13, 2025 11:17:09.918081045 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Jan 13, 2025 11:17:10.673151016 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Jan 13, 2025 11:17:10.935937881 CET | 50886 | 53 | 192.168.2.24 | 1.1.1.1 |
Jan 13, 2025 11:17:10.942522049 CET | 53 | 50886 | 1.1.1.1 | 192.168.2.24 |
Jan 13, 2025 11:17:11.428303003 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Jan 13, 2025 11:18:23.923585892 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Jan 13, 2025 11:18:24.680627108 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Jan 13, 2025 11:18:25.435231924 CET | 137 | 137 | 192.168.2.24 | 192.168.2.255 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 13, 2025 11:17:10.935937881 CET | 192.168.2.24 | 1.1.1.1 | 0x2ec | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 13, 2025 11:17:11.215284109 CET | 192.168.2.24 | 1.1.1.1 | 0x1 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 13, 2025 11:17:11.738006115 CET | 1.1.1.1 | 192.168.2.24 | 0x1 | No error (0) | ves-io-f35000c6-187d-4400-baeb-13d55394e070.ac.vh.ves.io | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 13, 2025 11:17:11.738006115 CET | 1.1.1.1 | 192.168.2.24 | 0x1 | No error (0) | 159.60.138.212 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
0 | 192.168.2.24 | 59377 | 142.250.184.227 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 13, 2025 11:17:51.087457895 CET | 200 | OUT | |
Jan 13, 2025 11:17:51.720120907 CET | 223 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
1 | 192.168.2.24 | 59378 | 23.209.209.135 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 13, 2025 11:17:51.788048983 CET | 227 | OUT | |
Jan 13, 2025 11:17:52.415100098 CET | 1023 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.24 | 59356 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:12 UTC | 343 | OUT | |
2025-01-13 10:17:12 UTC | 788 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.24 | 59357 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:13 UTC | 246 | OUT | |
2025-01-13 10:17:14 UTC | 788 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.24 | 59358 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:14 UTC | 717 | OUT | |
2025-01-13 10:17:15 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.24 | 59360 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:16 UTC | 412 | OUT | |
2025-01-13 10:17:17 UTC | 852 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN | |
2025-01-13 10:17:17 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.24 | 59362 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:18 UTC | 435 | OUT | |
2025-01-13 10:17:18 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.24 | 59363 | 159.60.138.212 | 443 | 6640 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:17:19 UTC | 435 | OUT | |
2025-01-13 10:17:19 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.24 | 59382 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:17 UTC | 71 | OUT | |
2025-01-13 10:18:17 UTC | 260 | OUT | |
2025-01-13 10:18:17 UTC | 1084 | OUT | |
2025-01-13 10:18:17 UTC | 224 | OUT | |
2025-01-13 10:18:18 UTC | 14 | IN | |
2025-01-13 10:18:18 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
7 | 192.168.2.24 | 59384 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:21 UTC | 71 | OUT | |
2025-01-13 10:18:21 UTC | 260 | OUT | |
2025-01-13 10:18:21 UTC | 1084 | OUT | |
2025-01-13 10:18:21 UTC | 224 | OUT | |
2025-01-13 10:18:21 UTC | 14 | IN | |
2025-01-13 10:18:21 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.24 | 59387 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:25 UTC | 395 | OUT | |
2025-01-13 10:18:25 UTC | 788 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.24 | 59388 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:25 UTC | 343 | OUT | |
2025-01-13 10:18:25 UTC | 788 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.24 | 59389 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:26 UTC | 338 | OUT | |
2025-01-13 10:18:26 UTC | 788 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.24 | 59390 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:26 UTC | 532 | OUT | |
2025-01-13 10:18:26 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.24 | 59391 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:27 UTC | 307 | OUT | |
2025-01-13 10:18:27 UTC | 427 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.24 | 59392 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:28 UTC | 435 | OUT | |
2025-01-13 10:18:29 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.24 | 59394 | 159.60.138.212 | 443 | 6712 | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:29 UTC | 435 | OUT | |
2025-01-13 10:18:30 UTC | 852 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
15 | 192.168.2.24 | 59396 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:33 UTC | 71 | OUT | |
2025-01-13 10:18:33 UTC | 260 | OUT | |
2025-01-13 10:18:33 UTC | 1084 | OUT | |
2025-01-13 10:18:33 UTC | 224 | OUT | |
2025-01-13 10:18:33 UTC | 14 | IN | |
2025-01-13 10:18:33 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
16 | 192.168.2.24 | 59402 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:18:48 UTC | 71 | OUT | |
2025-01-13 10:18:48 UTC | 260 | OUT | |
2025-01-13 10:18:48 UTC | 1084 | OUT | |
2025-01-13 10:18:48 UTC | 224 | OUT | |
2025-01-13 10:18:48 UTC | 14 | IN | |
2025-01-13 10:18:48 UTC | 58 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
17 | 192.168.2.24 | 59408 | 40.115.3.253 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-13 10:19:10 UTC | 71 | OUT | |
2025-01-13 10:19:10 UTC | 260 | OUT | |
2025-01-13 10:19:10 UTC | 1084 | OUT | |
2025-01-13 10:19:10 UTC | 224 | OUT | |
2025-01-13 10:19:10 UTC | 14 | IN | |
2025-01-13 10:19:10 UTC | 58 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 05:17:07 |
Start date: | 13/01/2025 |
Path: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff676390000 |
File size: | 1'637'952 bytes |
MD5 hash: | A9F0EC89897AC6C878D217DFB64CA752 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |
Target ID: | 7 |
Start time: | 05:17:26 |
Start date: | 13/01/2025 |
Path: | C:\Windows\System32\rundll32.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61b310000 |
File size: | 90'112 bytes |
MD5 hash: | C87FA6FC1D294962EABE44509FE1921C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 05:18:22 |
Start date: | 13/01/2025 |
Path: | C:\Program Files\Microsoft Office\root\Office16\WINWORD.EXE |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff676390000 |
File size: | 1'637'952 bytes |
MD5 hash: | A9F0EC89897AC6C878D217DFB64CA752 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | false |