Windows
Analysis Report
19MgUpI9tj.dll
Overview
General Information
Sample name: | 19MgUpI9tj.dllrenamed because original name is a hash value |
Original sample name: | 3dd20421f9a536cfdd3a8b5cf7e5d5fc.dll |
Analysis ID: | 1591360 |
MD5: | 3dd20421f9a536cfdd3a8b5cf7e5d5fc |
SHA1: | 9ad38539be5836e2ec27621c32a66670293d52ff |
SHA256: | eb0482a9de2f68aa565c0b30d51b75189f8d2fa881b0b5be47383825b6e8269f |
Tags: | dllexeWannaCryuser-mentality |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- loaddll32.exe (PID: 3708 cmdline:
loaddll32. exe "C:\Us ers\user\D esktop\19M gUpI9tj.dl l" MD5: 51E6071F9CBA48E79F10C84515AAE618) - conhost.exe (PID: 4864 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - cmd.exe (PID: 3280 cmdline:
cmd.exe /C rundll32. exe "C:\Us ers\user\D esktop\19M gUpI9tj.dl l",#1 MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B) - rundll32.exe (PID: 5340 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\19Mg UpI9tj.dll ",#1 MD5: 889B99C52A60DD49227C5E485A016679) - mssecsvr.exe (PID: 6900 cmdline:
C:\WINDOWS \mssecsvr. exe MD5: 0F00DC99F94FDCA3721D0692B2ACACCD) - tasksche.exe (PID: 64 cmdline:
C:\WINDOWS \tasksche. exe /i MD5: E2105F086EAB75BD8CDD2B6975E9CE80) - WerFault.exe (PID: 5276 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 6 4 -s 224 MD5: C31336C1EFC2CCB44B4326EA793040F2) - WerFault.exe (PID: 2216 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 6 4 -s 228 MD5: C31336C1EFC2CCB44B4326EA793040F2) - rundll32.exe (PID: 6116 cmdline:
rundll32.e xe C:\User s\user\Des ktop\19MgU pI9tj.dll, PlayGame MD5: 889B99C52A60DD49227C5E485A016679) - rundll32.exe (PID: 424 cmdline:
rundll32.e xe "C:\Use rs\user\De sktop\19Mg UpI9tj.dll ",PlayGame MD5: 889B99C52A60DD49227C5E485A016679) - mssecsvr.exe (PID: 2580 cmdline:
C:\WINDOWS \mssecsvr. exe MD5: 0F00DC99F94FDCA3721D0692B2ACACCD) - tasksche.exe (PID: 1112 cmdline:
C:\WINDOWS \tasksche. exe /i MD5: E2105F086EAB75BD8CDD2B6975E9CE80) - WerFault.exe (PID: 5032 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 1 112 -s 196 MD5: C31336C1EFC2CCB44B4326EA793040F2) - WerFault.exe (PID: 6316 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -u -p 1 112 -s 200 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- mssecsvr.exe (PID: 3656 cmdline:
C:\WINDOWS \mssecsvr. exe -m sec urity MD5: 0F00DC99F94FDCA3721D0692B2ACACCD)
- svchost.exe (PID: 6896 cmdline:
C:\Windows \System32\ svchost.ex e -k WerSv cGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A) - WerFault.exe (PID: 3536 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -pss -s 436 -p 64 -ip 64 MD5: C31336C1EFC2CCB44B4326EA793040F2) - WerFault.exe (PID: 6288 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -pss -s 464 -p 11 12 -ip 111 2 MD5: C31336C1EFC2CCB44B4326EA793040F2) - WerFault.exe (PID: 4508 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -pss -s 480 -p 64 -ip 64 MD5: C31336C1EFC2CCB44B4326EA793040F2) - WerFault.exe (PID: 4048 cmdline:
C:\Windows \SysWOW64\ WerFault.e xe -pss -s 476 -p 11 12 -ip 111 2 MD5: C31336C1EFC2CCB44B4326EA793040F2)
- svchost.exe (PID: 3960 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
WannaCryptor, WannaCry, WannaCrypt |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
WannaCry_Ransomware | Detects WannaCry Ransomware | Florian Roth (with the help of binar.ly) |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
Click to see the 6 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Wannacry | Yara detected Wannacry ransomware | Joe Security | ||
WannaCry_Ransomware | Detects WannaCry Ransomware | Florian Roth (with the help of binar.ly) |
| |
WannaCry_Ransomware | Detects WannaCry Ransomware | Florian Roth (with the help of binar.ly) |
| |
WannaCry_Ransomware_Gen | Detects WannaCry Ransomware | Florian Roth (based on rule by US CERT) |
| |
WannaCry_Ransomware | Detects WannaCry Ransomware | Florian Roth (with the help of binar.ly) |
| |
Click to see the 35 entries |
System Summary |
---|
Source: | Author: vburov: |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T22:42:15.168227+0100 | 2803304 | 3 | Unknown Traffic | 192.168.2.6 | 50671 | 103.224.212.215 | 80 | TCP |
2025-01-14T22:42:23.865047+0100 | 2803304 | 3 | Unknown Traffic | 192.168.2.6 | 49751 | 103.224.212.215 | 80 | TCP |
2025-01-14T22:42:25.659751+0100 | 2803304 | 3 | Unknown Traffic | 192.168.2.6 | 49763 | 103.224.212.215 | 80 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T22:42:22.947625+0100 | 2830018 | 1 | A Network Trojan was detected | 192.168.2.6 | 65461 | 1.1.1.1 | 53 | UDP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | ReversingLabs: | ||
Source: | ReversingLabs: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Exploits |
---|
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior |
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior | ||
Source: | TCP traffic: | Jump to behavior |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior | ||
Source: | File created: |
Source: | Process created: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Code function: | 6_2_00407C40 | |
Source: | Code function: | 7_2_00407C40 |
Source: | Code function: | 6_2_00407CE0 |
Source: | Code function: | 6_2_00407C40 |
Source: | Code function: | 6_2_00408090 | |
Source: | Code function: | 7_2_00408090 |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: | |||
Source: | Section loaded: |
Source: | Key value queried: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Persistence and Installation Behavior |
---|
Source: | Executable created and started: | Jump to behavior | ||
Source: | Executable created and started: | Jump to behavior |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Code function: | 6_2_00407C40 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: |
Source: | File opened: |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: | ||
Source: | Queries volume information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Service Execution | 4 Windows Service | 4 Windows Service | 12 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | 1 DLL Side-Loading | 11 Process Injection | 41 Virtualization/Sandbox Evasion | LSASS Memory | 131 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 2 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Rundll32 | NTDS | 41 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | 13 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 21 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
94% | Virustotal | Browse | ||
92% | ReversingLabs | Win32.Ransomware.WannaCry | ||
100% | Avira | TR/Ransom.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
38% | ReversingLabs | Win32.Ransomware.WannaCry | ||
38% | ReversingLabs | Win32.Ransomware.WannaCry |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware | ||
100% | Avira URL Cloud | malware |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
77026.bodis.com | 199.59.243.228 | true | false | high | |
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high | |
www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com | 103.224.212.215 | true | false | high | |
ww25.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com | unknown | unknown | false | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false |
| unknown | |
false | high | ||
false | high | ||
false |
| unknown | |
false | high | ||
false | high | ||
false | high | ||
false |
| unknown | |
false | high | ||
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
198.205.43.159 | unknown | United States | 11911 | THE-BANK-OF-NEW-YORK-MELLON-CORPORATION-BASE-ASUS | false | |
107.175.251.1 | unknown | United States | 36352 | AS-COLOCROSSINGUS | false | |
107.175.251.2 | unknown | United States | 36352 | AS-COLOCROSSINGUS | false | |
15.116.122.1 | unknown | United States | 13979 | ATT-IPFRUS | false | |
175.68.141.1 | unknown | China | 9394 | CTTNETChinaTieTongTelecommunicationsCorporationCN | false | |
15.116.122.57 | unknown | United States | 13979 | ATT-IPFRUS | false | |
50.113.28.74 | unknown | United States | 20001 | TWC-20001-PACWESTUS | false | |
98.97.187.115 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
37.134.68.167 | unknown | Spain | 12479 | UNI2-ASES | false | |
18.142.24.211 | unknown | United States | 16509 | AMAZON-02US | false | |
149.173.236.2 | unknown | United States | 12229 | SAS-WHQUS | false | |
109.252.120.234 | unknown | Russian Federation | 25513 | ASN-MGTS-USPDRU | false | |
75.65.143.1 | unknown | United States | 7922 | COMCAST-7922US | false | |
197.9.206.1 | unknown | Tunisia | 5438 | ATI-TN | false | |
149.173.236.1 | unknown | United States | 12229 | SAS-WHQUS | false | |
197.9.206.2 | unknown | Tunisia | 5438 | ATI-TN | false | |
50.113.28.1 | unknown | United States | 20001 | TWC-20001-PACWESTUS | false | |
149.173.236.150 | unknown | United States | 12229 | SAS-WHQUS | false | |
87.122.116.245 | unknown | Germany | 8881 | VERSATELDE | false | |
77.226.237.2 | unknown | Spain | 12430 | VODAFONE_ESES | false | |
77.226.237.1 | unknown | Spain | 12430 | VODAFONE_ESES | false | |
76.252.20.1 | unknown | United States | 7018 | ATT-INTERNET4US | false | |
136.139.192.57 | unknown | United States | 60311 | ONEFMCH | false | |
147.244.118.1 | unknown | United States | 1541 | DNIC-ASBLK-01534-01546US | false | |
147.244.118.2 | unknown | United States | 1541 | DNIC-ASBLK-01534-01546US | false |
IP |
---|
192.168.2.148 |
192.168.2.149 |
192.168.2.146 |
192.168.2.147 |
192.168.2.140 |
192.168.2.141 |
192.168.2.144 |
192.168.2.145 |
192.168.2.142 |
192.168.2.143 |
192.168.2.159 |
192.168.2.157 |
192.168.2.158 |
192.168.2.151 |
192.168.2.152 |
192.168.2.150 |
192.168.2.155 |
192.168.2.156 |
192.168.2.153 |
192.168.2.154 |
192.168.2.126 |
192.168.2.247 |
192.168.2.127 |
192.168.2.248 |
192.168.2.124 |
192.168.2.245 |
192.168.2.125 |
192.168.2.246 |
192.168.2.128 |
192.168.2.249 |
192.168.2.129 |
192.168.2.240 |
192.168.2.122 |
192.168.2.243 |
192.168.2.123 |
192.168.2.244 |
192.168.2.120 |
192.168.2.241 |
192.168.2.121 |
192.168.2.242 |
192.168.2.97 |
192.168.2.137 |
192.168.2.96 |
192.168.2.138 |
192.168.2.99 |
192.168.2.135 |
192.168.2.98 |
192.168.2.136 |
192.168.2.139 |
192.168.2.250 |
192.168.2.130 |
192.168.2.251 |
192.168.2.91 |
192.168.2.90 |
192.168.2.93 |
192.168.2.133 |
192.168.2.254 |
192.168.2.92 |
192.168.2.134 |
192.168.2.95 |
192.168.2.131 |
192.168.2.252 |
192.168.2.94 |
192.168.2.132 |
192.168.2.253 |
192.168.2.104 |
192.168.2.225 |
192.168.2.105 |
192.168.2.226 |
192.168.2.102 |
192.168.2.223 |
192.168.2.103 |
192.168.2.224 |
192.168.2.108 |
192.168.2.229 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591360 |
Start date and time: | 2025-01-14 22:41:14 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 35 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 19MgUpI9tj.dllrenamed because original name is a hash value |
Original Sample Name: | 3dd20421f9a536cfdd3a8b5cf7e5d5fc.dll |
Detection: | MAL |
Classification: | mal100.rans.expl.evad.winDLL@42/31@2/100 |
EGA Information: |
|
HCA Information: | Failed |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, BackgroundTransferHost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
- Excluded IPs from analysis (whitelisted): 20.42.73.29, 217.20.57.19, 2.23.242.162, 13.107.246.45, 20.190.159.71, 4.245.163.56, 20.31.169.57, 2.23.227.215, 150.171.28.10, 2.23.227.208, 20.223.36.55
- Excluded domains from analysis (whitelisted): www.bing.com, fs.microsoft.com, slscr.update.microsoft.com, otelrules.azureedge.net, otelrules.afd.azureedge.net, tse1.mm.bing.net, ctldl.windowsupdate.com, g.bing.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, fe3cr.delivery.mp.microsoft.com, login.live.com, e16604.g.akamaiedge.net, blobcollector.events.data.trafficmanager.net, onedsblobprdeus15.eastus.cloudapp.azure.com, azureedge-t-prod.trafficmanager.net, umwatson.events.data.microsoft.com, prod.fs.microsoft.com.akadns.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
16:42:24 | API Interceptor | |
16:42:30 | API Interceptor | |
16:42:59 | API Interceptor | |
16:43:18 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
77026.bodis.com | Get hash | malicious | Wannacry | Browse |
| |
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
Get hash | malicious | Simda Stealer | Browse |
| ||
www.iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff.com | Get hash | malicious | Wannacry | Browse |
| |
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
ATT-IPFRUS | Get hash | malicious | Wannacry | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
THE-BANK-OF-NEW-YORK-MELLON-CORPORATION-BASE-ASUS | Get hash | malicious | Mirai, Okiru | Browse |
| |
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AS-COLOCROSSINGUS | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
AS-COLOCROSSINGUS | Get hash | malicious | Gafgyt, Mirai | Browse |
| |
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
| ||
Get hash | malicious | Gafgyt, Mirai | Browse |
| ||
Get hash | malicious | Gafgyt | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263298796753942 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0w:9JZj5MiKNnNhoxuF |
MD5: | FCBD3AA8355F8CD53F7D6A9220EC6E3C |
SHA1: | 4C43EDFB539A38EFAB1517C61C3257407A9CE160 |
SHA-256: | 1123202984BC199DDEC9EA55B3CB098BF110E226C17AF751B8E80887E42BFFAF |
SHA-512: | 22C5E946D0BFEB1022B88BDB39FA8387F2460666B2F60BB265C7351C8AAD055AF0CA3D564DF7E7861C178436B19E89B6BE3E0D5F3621F40C10895040E86AD00C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7556073323107159 |
Encrypted: | false |
SSDEEP: | 1536:FSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:FazaSvGJzYj2UlmOlOL |
MD5: | 87357022781ECEBDBC8D9237A4EDEB13 |
SHA1: | 6E33B8375CE13169F9C8F8866F7681DC47857A78 |
SHA-256: | 5E85663AF48AD4FB9536BD79B1405664F0FE532E867E14966FF56AEE46071C3C |
SHA-512: | 8C33DF5A5FD1AF9A2BC7588DB3A2FD291EB5590D6B02B978B4F3C7D5D957532CF5714B456C9F12A569B027541CA5632555FE899F300F850CF775B12D5B0B1F54 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07967290506449429 |
Encrypted: | false |
SSDEEP: | 3:eGtyYeAftVENaAPaU1l4oYqYlluxmO+l/SNxOf:IzktVENDPaUm3gmOH |
MD5: | 3E5CB1CD21D40ABC843E3CA03DC98A97 |
SHA1: | DD4736CA29FFB0D2C6767B6795D92BB9EA9A070F |
SHA-256: | 067DA1372135813F8768947883B911F185CACF9C6D18C3E5DF7857E056FA97D6 |
SHA-512: | 0D9FADB9B6CCC71E9E239F0E53CFABE8D613FE17CE8E026D4EC14313C1E84333D65E3999ABBAB6C85A242E5EE28C18CE7F959423BEA79ACCFD732E473A298871 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tasksche.exe_1db29bc48272f9a3e064985a6d259155e34438c5_5f6e30d1_d2efbb06-4860-4d66-98d8-64977af32a6e\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.6219121116762025 |
Encrypted: | false |
SSDEEP: | 192:SAHzbbIO/S660BU/KmkjlzuiFnZ24IO8vw6:S4zbMOS6BBU/KmkjlzuiFnY4IO8vw |
MD5: | 1F741CFCFB34DCB110E7B51103EB9088 |
SHA1: | 44266A93FA750F0B2E3F665C67E023F539D32C4C |
SHA-256: | E6D9D42C86D52379F2379F948398DE4F017E732AB3004AC6246FB5438F3789D5 |
SHA-512: | E2CCF0C34404C1521B5E75537AE2DCD3DB1D6426D5A76CCC3B55FC9F4B3D4095077D65C97D94B7901E4358E83FC1A404A2B6040B8943A013610DF175B46A5794 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tasksche.exe_1db29bc48272f9a3e064985a6d259155e34438c5_5f6e30d1_f709431c-cb6f-4622-900e-328eeb3f1897\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.6289946910047491 |
Encrypted: | false |
SSDEEP: | 192:NlbI1KS660BU/KmkjEzuiFnZ24IO8vw6:HMoS6BBU/KmkjEzuiFnY4IO8vw |
MD5: | 09A7136B29C6E6FB02A4B993EEBD3A2A |
SHA1: | 6D22F04820136AAA186C90E84C8AEA140D0E7218 |
SHA-256: | E72F1D6E77D5DD25B1BE72AE45ABE6B55FD58334319AA4798C571E37CB008875 |
SHA-512: | 84083295D37148CEED2EE703234DEC4EBF4ABD212E11B3CAE3A3BF18368D50A332F154BD3EC7F151AD977F096CA47626996F333C7BC3AEC19D1CC01118671820 |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tasksche.exe_2145597abd45e1ec793a62f5313526923c64cffc_5f6e30d1_5ffd7061-9a76-4ae3-bd76-d9a0cfc44a15\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.6119799953962769 |
Encrypted: | false |
SSDEEP: | 96:XAuwIHos1hFcH7FhESZQXIDcQzc645cocE1cw345cYm/+HbHsZAX/d5FMT2SlPkG:wbIHoS620tM/smkjlzuiFnZ24IO8vw6 |
MD5: | 58D267BE10EFFC72693DA8285B8005E4 |
SHA1: | EF8B1EA11063D9C227E024DD584A056E157B3BA7 |
SHA-256: | 1E56856746B8999ED0B35B4002B573EC0CBA551EDB610975585B1642CEAD400A |
SHA-512: | 4C5AF6B8D4704B83BB230F903650C868053BA139822B019A2600C2725A618F11F225AF05CFE81B5E34CE312D813BB1FA4F84D76F8B3F57E9130028224B22F66F |
Malicious: | false |
Preview: |
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_tasksche.exe_2145597abd45e1ec793a62f5313526923c64cffc_5f6e30d1_9a817744-2f0d-48f1-86aa-d9ec7610274b\Report.wer
Download File
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.6196003414111629 |
Encrypted: | false |
SSDEEP: | 192:SibIOFS620tM/smkjEzuiFnZ24IO8vw6:SiMMS6dtM/smkjEzuiFnY4IO8vw |
MD5: | 6A3C791DC4FC8908D6005A70B4E7CC4E |
SHA1: | 69B27B641823D0B730C3464A444C4FB7FF577BE4 |
SHA-256: | 314342F11F5E3460548535804953F2C3A5C6C38B4214A6F42B598B8DCE54A9B5 |
SHA-512: | DCDE15BC41F3095E97069CB1D5967571D37BF8024953D11D1F8C7EF9BDAD00132D1BDDC4C87B8ED6EACE97B40B31A44745723136730A47E329D809FCC14170A9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8310 |
Entropy (8bit): | 3.6873684172116605 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJil6y6YKb6STgmfXKvzpNz89bTr1fORm:R6lXJQ6y6YG6STgmfXKvcT5fJ |
MD5: | AE57ABB57B430E0BC8B64CDFB7B08997 |
SHA1: | BF4CEFBF6E4EBD3B8F231F6A4819AEC49649AB63 |
SHA-256: | 597F367F5F27C516537B863398AA728721C24DBE16B03D0DD1CC8F417F464B57 |
SHA-512: | C0325D1DAA20FEB2995A0377E19F1380E63F7A4562FC34B5E87F330AB632816E63258551F9BB9D0178CB3CA8FD79E8488BB8AE13663682FB2274D6B91ACDA00A |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4666 |
Entropy (8bit): | 4.428928527397307 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsBJg77aI9yBCGHWpW8VYl7Ym8M4Jh2FEM+q8vgE06vnBNiLd:uIjfTI72C/7V8eJmKZ065NiLd |
MD5: | 17C8C94F252066E91220465F788E270C |
SHA1: | 3AC4F7BD0088701FBD981B3074FB8CD065942042 |
SHA-256: | 0484ABB248B18B8C1773D7533BB5AB04E1F186373FE2E48A4CAF4D74911CFA71 |
SHA-512: | D74AB78628E6F095C00E0DE1D431CE311B89BC54FD6260F9CDE2EC6039488E857BBE897787A2854860D0BB5208FB5B45235C0E612D5714DE9326BDC727CCC2B8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18704 |
Entropy (8bit): | 1.9311206422551612 |
Encrypted: | false |
SSDEEP: | 96:5t8U+q9HeSHh4i7nOg8nrKVkjS68LWx4WqB3jw71t/CEWIkWIDUIQepddxzxV:kLG6OEyzG1wwepddxF |
MD5: | 152610AB36D86EBD0A6B596B16B61B8B |
SHA1: | 769840B4E8AD7461B5DEE8F52CC70F38F6F4EAFB |
SHA-256: | 321FB93DCAA84AE396077CC323456386778876C0A865F28F35A84B2B2EFDF184 |
SHA-512: | E2081EA3782BF10D2996D8A61B997DCC791A683A1CEB28D82DEC8B5BE775B2B06A74DCC59EBAB4E84F837FC86B88781CCFF3775E09FEE1921A9B0BF0DC12096B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79594 |
Entropy (8bit): | 3.044929998140619 |
Encrypted: | false |
SSDEEP: | 1536:jKjSYpBmJAd4FpnCQ2a7bQvDD+aoBbMjemzXudUNZ:jKjSYpBmJAd4FpnCQ2a7bQvDyaoBbMjX |
MD5: | 2C901E2B53F54C03F70A06C961C0153D |
SHA1: | CD30A197DF4F0A7FD62F988F1C199BB8289613EC |
SHA-256: | 37CE86BD8FFF5938EDF933023352EBCB8DA6F04EA0A099931EB57970CF62CAD7 |
SHA-512: | EB6DCF4E76007038198B43451E9114068C04501C50245BB7AAEE4D4041428F26C7668C857E1CB201A4AADE17508486FA1877D0DF576AD7AAE37F66DAFC7A6F0E |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6314 |
Entropy (8bit): | 3.7108261567412013 |
Encrypted: | false |
SSDEEP: | 96:RSIU6o7wVetbWcA6/mfSYXK7QE/fzLb5aM4Us89bFZnsfOPZm:R6l7wVeJWcA6eaYXK7Rprs89bTnsfORm |
MD5: | 517AF1792E52DBD6192B72F56F986F20 |
SHA1: | 77D38AFA29DB3FF817ADA87F501D961D154A3D8A |
SHA-256: | E91C9E9829945957D16041D11C98B27FD2B77AE7043243241653C3AD504AF586 |
SHA-512: | AE904B7B68D901475EDA894EC13DF3EFAB337C4A1D605AABDB661AE4F724DD5CD4C240AF30FEA0EE6EE17C07150A7E804C726C1433608D6139D17978C8FC7F78 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13340 |
Entropy (8bit): | 2.6848828684578003 |
Encrypted: | false |
SSDEEP: | 96:TiZYW9P7ktZLfYnYkrWIdZHFYEZvAtCiDHL/KwLERhearembMrZUIPe3:2ZDywLdxi44arembMrZDPe3 |
MD5: | B4A32748E8C1AA854070249AE994B6EC |
SHA1: | 9519F104841CAB5126891660CC0B4A63F4DDC9D7 |
SHA-256: | AFC0190EAB8602F74A307284586A36497BC7770BA38648A518DF29FEE34D01BD |
SHA-512: | B2FB92448DB46FAB5929010C61B0E5E0443610A8F8D65F42A6A82CD30F8657E2A8BBC82D9EB355CCFA403198144FC1409FA1A8051DCB7B8D5B6D8810652DF9E9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4666 |
Entropy (8bit): | 4.426803810641066 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsBJg77aI9yBCGHWpW8VYwYm8M4JhIFLP+q8vg/6vnBNind:uIjfTI72C/7VwJgK265Nind |
MD5: | D19A4DA9249D96F99605EE7DE7B5E433 |
SHA1: | BBC0C891367A0920EF2453D6EB68B59E9F2F3EA4 |
SHA-256: | 2D6935D18B5D19BC5FF4ECAFB41569994549239AEEF9C2FD6017155F62EF44B9 |
SHA-512: | 185F670ECA060F97E0C44D54C042ED21E9051A2698D8EB57EC321ECC173D73AF64710CCB0CADE586FBE9CDAC016C72A8587FB4395C4ED93828AAA97CA0881F7B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79622 |
Entropy (8bit): | 3.0448310445544875 |
Encrypted: | false |
SSDEEP: | 1536:9X/iYpBmJAA4FpnCQ2alNQvDD+aoBbMjemzXudUNX:9X/iYpBmJAA4FpnCQ2alNQvDyaoBbMjZ |
MD5: | D0F12D47646161360A8D15082ECBB8DE |
SHA1: | C1D25D58D4727046C90B61A2556DD5EEE2F46C83 |
SHA-256: | 246CB8B2405F8400AB5654200C127455096894A002301233F36352B7947307F8 |
SHA-512: | 8FC6F492EF2915087F4397E77318C4EEE4D6E66584BF1F98488966F7412C1457FAD19C09EBF903B17151321160738FDA7D92C9999BD032CABB1EE62074C28885 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13340 |
Entropy (8bit): | 2.685096634559804 |
Encrypted: | false |
SSDEEP: | 96:TiZYWiP7EiiYNYUWSBHFYEZEVtCilHB/KwYiNKaaerMNZaIee3:2ZDr6PuKTaaerMNZNee3 |
MD5: | 588B468A4A9491230EC9DED23C8DD679 |
SHA1: | 2FE5C0594CC41AFE93E9D1D27471FC1DFE8C0545 |
SHA-256: | 8524C09E905D81D2343EDA46B06FD69E47F700BDFE59EBFDBADEBB60E59F9B2A |
SHA-512: | 0C32E68468C09CA921FD777CD19292405D71DC98E82482BFB6DACBC1CC0EC3947235D60016BDD8AB03BB9A4A849ECD43A2B290AFF4E2127E6869CC03185CD66A |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 18236 |
Entropy (8bit): | 1.9300015863547795 |
Encrypted: | false |
SSDEEP: | 96:5t8i30KGpy/iy0Ci7DO++prKVkjS68LWx4WqjjM77FBC/WIPhWIqzI7s2Xx0Yt:kiXMy0COMOjC7yVZ1B7 |
MD5: | 9199EA2AADC158DB3A648CD2B7F96473 |
SHA1: | B12FADB63180327DF30E88780ECCA7A2426BD47A |
SHA-256: | 0F0B0F06B21FA3B3D980E83F99BF3699F04C3BB7190DB260C03E2EB42A24E028 |
SHA-512: | B5C776754CD3B3430441EDEA6DC19B2380AD025A7BBED682A2F24464BAB7069CA2BE023AC2E6B5AD459CC65B1030620034615CF6F153D647C00CA4E8D232F11E |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6324 |
Entropy (8bit): | 3.706664078278949 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJic6EvYXK7Rprp89bEzsf8pvMm:R6lXJJ6EvYXK76EYf8/ |
MD5: | AD8EA65063F79AD9033A5CEE1A92DC9B |
SHA1: | 3ED1A838C74B694109242EF7607B81020EB5E9AC |
SHA-256: | 66E98BFF572B260E07DC4F10B23873CDFC226962B4B1EA2C84B2D1F5B33161E5 |
SHA-512: | B8D199BA9FF4C709F94F19C2C7741BDCC1FC24352A8635E003835AFAFAE92D23D6E39E5D226ECAEAD8DEACDB918484B64D80A5004E27D91BFDF9D81F452D3B45 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4666 |
Entropy (8bit): | 4.425387389342143 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsBJg77aI9yBCGHWpW8VYsYm8M4JhIF6o+q8vgy06vnBNiKd:uIjfTI72C/7VEJdoKb065NiKd |
MD5: | EED577879EFDCDBBE776B83D564A2AB0 |
SHA1: | 915101DD10C2C285914E1C0DAF30F2ECBD3DB8A7 |
SHA-256: | BF3EBBB868B0120641894F2309F5D0515CE45AEC02417D54939C1FFA6B74A7D9 |
SHA-512: | 22CB1D4F828ADCB50F0FFBE8D21C5CE35829ECBA4E86BA2D67F3FA83D724ED6C3694057C97068B14537E30235527F4E59E9128F20BA1EE48563F939FA67AF39B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79628 |
Entropy (8bit): | 3.0447638106503727 |
Encrypted: | false |
SSDEEP: | 1536:J9IPYpBm/AX4FpnCQ2aM1Qv5D+aoBbMjemzXudUNbGJB:J9IPYpBm/AX4FpnCQ2aM1Qv5yaoBbMjS |
MD5: | 8EC502051605830CA566C604D0CA04A6 |
SHA1: | 71F395F2F7FECC54BE565820E0CE5AB202F92B4B |
SHA-256: | 0EAA1F9ECC8DFC691288D18FB4FBECF17E93FF5A012381F86BCC38D5C29EF958 |
SHA-512: | 66AE6D1D48C0E75DBA53499E8E6E4A422550F4529290CA99B12CD41DB6F12764DC51F86163F756841A104AC8DB23A18F8F93D99643C8086F308C539390A69DF7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13340 |
Entropy (8bit): | 2.6854579069734377 |
Encrypted: | false |
SSDEEP: | 96:TiZYWEXc8uYFY6WtHFYEZrctCitHQK/KwzaXaeeOJMYZZ4I7e3:2ZD/SwAsaeeOJMYZx7e3 |
MD5: | E82F820C26E30ACDCE96F549B92FC348 |
SHA1: | D432C4C301B6B2C079324CE95FAFFBFF0F832D88 |
SHA-256: | 038FBE47147BE696B1DAABEBA5A6630D4223E951F3220971C40D8B35569C1821 |
SHA-512: | F794E2839DE5A1EA603680B4EDCE9C4FD92EB8B4A7AC11090D265E5A0BA380E764100D48F8DC69C1D9D70F5179E74D8C101004DB845D4EC6AA50CA188A02F394 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17980 |
Entropy (8bit): | 1.8543943898518858 |
Encrypted: | false |
SSDEEP: | 96:5GS8tZq9HeSuXqTEi7nOg2xJrKVkjS68LWx4WqqLXTj1tbEWIkWIoUIZ7V:u3FlOGLLXTj1Nw7V |
MD5: | BD159045280B9E352E531DE21EDE91EA |
SHA1: | C27DB93545B99BE32E497C133D699C4FCFF6770F |
SHA-256: | CDCB4A5C5317A543113F4A90513CD945B43B57AD4A8442B57940F8929641F79F |
SHA-512: | B0808EA8B001FB7D2FB3AB32D6D0549C9BB88F33E0DB5DC939E418B33A8EAA2D9A6FBF897917770ECADFD3554ADB2A6792F7DA70B353A485A7C2E8035D55B70D |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6312 |
Entropy (8bit): | 3.7087720565083395 |
Encrypted: | false |
SSDEEP: | 192:R6l7wVeJbU6ezSYYXKvzpNB89bhn1fkCrm:R6lXJI6ezSYYXKvGh1fkX |
MD5: | 60545E0D0CCA2E257BC1A5BFE88A1276 |
SHA1: | 6C91F9E606DBC5E0010D5BF7E47707020168251B |
SHA-256: | 44EED59BF573222A4ECA94831669A828C99FDB7BBCA39281B06E9B8B85C8F42A |
SHA-512: | 34C3164F3F6D750610FB48C02CBA471A8B1F47ADB7966AD96D9212693CDBCEE7BEBC547EA9B1192EBFBF642822BBB5781D021F5BA5AEFD41701AF0CEA7C21E3B |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4666 |
Entropy (8bit): | 4.426958020463009 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsBJg77aI9yBCGHWpW8VY1Ym8M4Jh2FR5x+q8vg16vnBNiWd:uIjfTI72C/7VFJW5xKo65NiWd |
MD5: | B83245F91DD86DADBBB32431C7A0ECCB |
SHA1: | 71DA282460E34654E9D35571BEE1FB5EE58E5EFA |
SHA-256: | 05B4EEDC8FF39A001DCC92506F353450150B3B44635F7FB735B8316621377464 |
SHA-512: | B0BC097FA6C6D3132D9097FEA670EA4A76838882D4A4224FBEC690FFC38845DC3ED6E14BCD97337A10B81B17660888EA32D92E7DB5076D47F400E1069FDFE011 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 79296 |
Entropy (8bit): | 3.0451871142717475 |
Encrypted: | false |
SSDEEP: | 1536:WlX6wYpa9HPh4rnCQ2aLDQvDDuoBbMjemzXudUNxp:WlX6wYpa9HPh4rnCQ2aLDQvDCoBbMjeW |
MD5: | F09A29BCBF76CE8C250E9A2542F00C68 |
SHA1: | 8A3287C930C783C49D55F25814FA2C33AE92AF60 |
SHA-256: | A50A106EED68212066549B7BADA7762E5DF93148C1DCB0D893C9EA095DD61442 |
SHA-512: | D3D4A6B6212EB492FD13E38E94DDE5CE1AFD381D74BF928EA48A85EDC66B2653E494ED56D8B4DA301D6E065D6032B1883E3329113241AF0F662BEFA0972E08F3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 13340 |
Entropy (8bit): | 2.6845017199962435 |
Encrypted: | false |
SSDEEP: | 96:TiZYWBte+N6YhdOY+WkevHFYEZ79tCiPHP/dwNrMajevB92MTZmIRe3:2ZDskOaS4ajeT2MTZhRe3 |
MD5: | 74BC8A1ED5442A3544CDBAAAF1A4F678 |
SHA1: | E070408FCA3552AF977A588C78C689733EE7B915 |
SHA-256: | 41EEFBF57214C9ABFF987F25AD2D206C085C0E57D31AE0128A289DCFE5CA91C5 |
SHA-512: | 16A7F8BE2AAEF77CFFA74064EBDA08E15698F9CEFA7C4FAED357E7628CEC1FC23024D622C49083FA0D7FC0B6F93A2BA67674CC4BCEE2E0DBCC81FDDC5F1FFFB4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 17512 |
Entropy (8bit): | 1.8545484237914842 |
Encrypted: | false |
SSDEEP: | 96:5t8i+0JGpy/sJi7DO+2rLrKVkjS68LWx4WqqGXTj7Ft/WIPfzWIUzIZtU:ki74OOZGXTj7zVHS |
MD5: | 48C61D2E0209B54B0AF217580A37F744 |
SHA1: | 2AFE7FED42C66BE233ADB7EC401E7340DAEA2220 |
SHA-256: | F664AE851043C099FE6464B8631954DBB7C80E7CBF05DF4C38A3338E2132F8B5 |
SHA-512: | E42D87617693C4E8655C7E988367425AD3E6447053F1FDF61DF88D33F912C19F8945F294FDCD706AC377FBFB35A80B0008E3834505F515D0DD0FDDF4B49958E2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\mssecsvr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2061938 |
Entropy (8bit): | 0.06778108869092206 |
Encrypted: | false |
SSDEEP: | 384:Em7TZFtNeEOv2pp6awCQlNilK7sPecqORdIE2qmiFFC+3:13Dvev2pAawCQlsKpzjg |
MD5: | E2105F086EAB75BD8CDD2B6975E9CE80 |
SHA1: | ABE19D68404B538CA524638AF77652992BC20D37 |
SHA-256: | 8C00CFB2696856F4C7E917DBF8B496D40B63D3F498EC51811730BE2E34D91C7F |
SHA-512: | AA1098141E5B47B0639E1863E253BBBDEE31FBD2B2624990D89F447161C6EE69BFCE9BAEEFCE8CCF0A474CFC67C57343847145AE87E1FA01721134814F36A7DB |
Malicious: | true |
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
Process: | C:\Windows\SysWOW64\WerFault.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1835008 |
Entropy (8bit): | 4.468503890387406 |
Encrypted: | false |
SSDEEP: | 6144:wzZfpi6ceLPx9skLmb0fyZWSP3aJG8nAgeiJRMMhA2zX4WABluuNPjDH5S:mZHtyZWOKnMM6bFplj4 |
MD5: | 63AB6782CEE0F1F4F683C39FD64FA9DF |
SHA1: | 640C38DE13D2A8E0375F73E1756C17697F22077D |
SHA-256: | 45962F0E77C283B5C9E2E011C7148126CA6E0CFBEF7D31D5466DA9F0420B1A24 |
SHA-512: | F415F3F6E512CB287249AB6A847999C322F6C47ABD016D482C2B781B025CAA582627046F2B8DE38CFE584FBA8C8AC7A7E7E99EB9E4EC35CDEBD09D6C575B92B2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\mssecsvr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2061938 |
Entropy (8bit): | 0.06778108869092206 |
Encrypted: | false |
SSDEEP: | 384:Em7TZFtNeEOv2pp6awCQlNilK7sPecqORdIE2qmiFFC+3:13Dvev2pAawCQlsKpzjg |
MD5: | E2105F086EAB75BD8CDD2B6975E9CE80 |
SHA1: | ABE19D68404B538CA524638AF77652992BC20D37 |
SHA-256: | 8C00CFB2696856F4C7E917DBF8B496D40B63D3F498EC51811730BE2E34D91C7F |
SHA-512: | AA1098141E5B47B0639E1863E253BBBDEE31FBD2B2624990D89F447161C6EE69BFCE9BAEEFCE8CCF0A474CFC67C57343847145AE87E1FA01721134814F36A7DB |
Malicious: | true |
Antivirus: |
|
Preview: |
File type: | |
Entropy (8bit): | 0.41748207874490023 |
TrID: |
|
File name: | 19MgUpI9tj.dll |
File size: | 5'267'459 bytes |
MD5: | 3dd20421f9a536cfdd3a8b5cf7e5d5fc |
SHA1: | 9ad38539be5836e2ec27621c32a66670293d52ff |
SHA256: | eb0482a9de2f68aa565c0b30d51b75189f8d2fa881b0b5be47383825b6e8269f |
SHA512: | 68662b14f282597a4ea6960734f82c9e9596c0b486766ffaec528df8d9e48ba009f8406b5254b09fad42cecbdcd54620fbf8f9c504575d9587acc47dc68c2b19 |
SSDEEP: | 6144:TE9l9ynRIYVTH5DgSgNajldktM0XXrCI:T1bLgmluC |
TLSH: | A636CF0A6A9CC0F4C449A23198B74E29E6B7BC1E1638C64F1B64DF661F63391B578F13 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}.r_9...9...9.......=...9...6.....A.:.......8.......8.......:...Rich9...........................PE..L...QW.Y...........!....... |
Icon Hash: | 7ae282899bbab082 |
Entrypoint: | 0x100011e9 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x10000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DLL |
DLL Characteristics: | |
Time Stamp: | 0x59145751 [Thu May 11 12:21:37 2017 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | 2e5708ae5fed0403e8117c645fb23e5b |
Instruction |
---|
push ebp |
mov ebp, esp |
push ebx |
mov ebx, dword ptr [ebp+08h] |
push esi |
mov esi, dword ptr [ebp+0Ch] |
push edi |
mov edi, dword ptr [ebp+10h] |
test esi, esi |
jne 00007FA8608923FBh |
cmp dword ptr [10003140h], 00000000h |
jmp 00007FA860892418h |
cmp esi, 01h |
je 00007FA8608923F7h |
cmp esi, 02h |
jne 00007FA860892414h |
mov eax, dword ptr [10003150h] |
test eax, eax |
je 00007FA8608923FBh |
push edi |
push esi |
push ebx |
call eax |
test eax, eax |
je 00007FA8608923FEh |
push edi |
push esi |
push ebx |
call 00007FA86089230Ah |
test eax, eax |
jne 00007FA8608923F6h |
xor eax, eax |
jmp 00007FA860892440h |
push edi |
push esi |
push ebx |
call 00007FA8608921BCh |
cmp esi, 01h |
mov dword ptr [ebp+0Ch], eax |
jne 00007FA8608923FEh |
test eax, eax |
jne 00007FA860892429h |
push edi |
push eax |
push ebx |
call 00007FA8608922E6h |
test esi, esi |
je 00007FA8608923F7h |
cmp esi, 03h |
jne 00007FA860892418h |
push edi |
push esi |
push ebx |
call 00007FA8608922D5h |
test eax, eax |
jne 00007FA8608923F5h |
and dword ptr [ebp+0Ch], eax |
cmp dword ptr [ebp+0Ch], 00000000h |
je 00007FA860892403h |
mov eax, dword ptr [10003150h] |
test eax, eax |
je 00007FA8608923FAh |
push edi |
push esi |
push ebx |
call eax |
mov dword ptr [ebp+0Ch], eax |
mov eax, dword ptr [ebp+0Ch] |
pop edi |
pop esi |
pop ebx |
pop ebp |
retn 000Ch |
jmp dword ptr [10002028h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x2190 | 0x48 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x203c | 0x3c | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x500060 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x505000 | 0x5c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x3c | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x28c | 0x1000 | 8de9a2cb31e4c74bd008b871d14bfafc | False | 0.13037109375 | data | 1.4429971244731552 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x2000 | 0x1d8 | 0x1000 | 3dd394f95ab218593f2bc8eb65184db4 | False | 0.072509765625 | data | 0.7346018133622799 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3000 | 0x154 | 0x1000 | 9b27c3f254416f775f5a51102ef8fb84 | False | 0.016845703125 | Matlab v4 mat-file (little endian) C:\%s\%s, numeric, rows 0, columns 0 | 0.085726967663312 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x4000 | 0x500060 | 0x501000 | 473115fc663b69367826f7671aff3f36 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x505000 | 0x2ac | 0x1000 | 620f0b67a91f7f74151bc5be745b7110 | False | 0.00634765625 | data | 0.0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
W | 0x4060 | 0x500000 | data | English | United States | 0.11054039001464844 |
DLL | Import |
---|---|
KERNEL32.dll | CloseHandle, WriteFile, CreateFileA, SizeofResource, LockResource, LoadResource, FindResourceA, CreateProcessA |
MSVCRT.dll | free, _initterm, malloc, _adjust_fdiv, sprintf |
Name | Ordinal | Address |
---|---|---|
PlayGame | 1 | 0x10001114 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-14T22:42:15.168227+0100 | 2803304 | ETPRO MALWARE Common Downloader Header Pattern HCa | 3 | 192.168.2.6 | 50671 | 103.224.212.215 | 80 | TCP |
2025-01-14T22:42:22.947625+0100 | 2830018 | ETPRO MALWARE Observed WannaCry Domain (iuqerfsodp9ifjaposdfjhgosurijfaewrwergwff .com in DNS Lookup) | 1 | 192.168.2.6 | 65461 | 1.1.1.1 | 53 | UDP |
2025-01-14T22:42:23.865047+0100 | 2803304 | ETPRO MALWARE Common Downloader Header Pattern HCa | 3 | 192.168.2.6 | 49751 | 103.224.212.215 | 80 | TCP |
2025-01-14T22:42:25.659751+0100 | 2803304 | ETPRO MALWARE Common Downloader Header Pattern HCa | 3 | 192.168.2.6 | 49763 | 103.224.212.215 | 80 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 22:42:15.168771982 CET | 49719 | 80 | 192.168.2.6 | 2.23.77.188 |
Jan 14, 2025 22:42:17.257556915 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:17.257560015 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:17.585647106 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:23.255259037 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.260149956 CET | 80 | 49751 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:23.260246992 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.261267900 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.266017914 CET | 80 | 49751 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:23.864964008 CET | 80 | 49751 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:23.865046978 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.865072012 CET | 80 | 49751 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:23.865591049 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.870579958 CET | 49751 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:23.875519991 CET | 80 | 49751 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:24.211116076 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:24.215924025 CET | 80 | 49757 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:24.216023922 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:24.228266001 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:24.233108997 CET | 80 | 49757 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:24.670315027 CET | 80 | 49757 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:24.670336008 CET | 80 | 49757 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:24.670456886 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:24.834256887 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:24.834306002 CET | 49757 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:25.020327091 CET | 49763 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.025170088 CET | 80 | 49763 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.025254011 CET | 49763 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.025501013 CET | 49763 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.030224085 CET | 80 | 49763 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.659610033 CET | 80 | 49763 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.659657955 CET | 80 | 49763 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.659750938 CET | 49763 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.663482904 CET | 49763 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.665836096 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:25.668303013 CET | 80 | 49763 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.670653105 CET | 80 | 49769 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:25.670742035 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:25.670867920 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:25.675611019 CET | 80 | 49769 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:25.817696095 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.822606087 CET | 80 | 49770 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:25.822704077 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.822977066 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:25.827739000 CET | 80 | 49770 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:26.125848055 CET | 80 | 49769 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.125866890 CET | 80 | 49769 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.125921965 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.155220032 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.155256987 CET | 49769 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.195703983 CET | 49776 | 445 | 192.168.2.6 | 18.1.0.168 |
Jan 14, 2025 22:42:26.200632095 CET | 445 | 49776 | 18.1.0.168 | 192.168.2.6 |
Jan 14, 2025 22:42:26.200711012 CET | 49776 | 445 | 192.168.2.6 | 18.1.0.168 |
Jan 14, 2025 22:42:26.200752974 CET | 49776 | 445 | 192.168.2.6 | 18.1.0.168 |
Jan 14, 2025 22:42:26.200969934 CET | 49777 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.205693007 CET | 445 | 49776 | 18.1.0.168 | 192.168.2.6 |
Jan 14, 2025 22:42:26.205751896 CET | 49776 | 445 | 192.168.2.6 | 18.1.0.168 |
Jan 14, 2025 22:42:26.205770969 CET | 445 | 49777 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:26.205857038 CET | 49777 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.205904961 CET | 49777 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.207412004 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.210763931 CET | 445 | 49777 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:26.210815907 CET | 49777 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.212176085 CET | 445 | 49780 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:26.212254047 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.212280989 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:26.217034101 CET | 445 | 49780 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:26.411207914 CET | 80 | 49770 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:26.411288023 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:26.411331892 CET | 80 | 49770 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:26.411479950 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:26.414491892 CET | 49770 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:42:26.419292927 CET | 80 | 49770 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:42:26.432003975 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.436831951 CET | 80 | 49784 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.436929941 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.443507910 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.448299885 CET | 80 | 49784 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.866837978 CET | 49673 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:26.866853952 CET | 49674 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:26.888611078 CET | 80 | 49784 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.888628006 CET | 80 | 49784 | 199.59.243.228 | 192.168.2.6 |
Jan 14, 2025 22:42:26.888684034 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.897428036 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:26.897505999 CET | 49784 | 80 | 192.168.2.6 | 199.59.243.228 |
Jan 14, 2025 22:42:27.195009947 CET | 49672 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:28.198654890 CET | 49808 | 445 | 192.168.2.6 | 6.147.7.88 |
Jan 14, 2025 22:42:28.203609943 CET | 445 | 49808 | 6.147.7.88 | 192.168.2.6 |
Jan 14, 2025 22:42:28.203702927 CET | 49808 | 445 | 192.168.2.6 | 6.147.7.88 |
Jan 14, 2025 22:42:28.203979969 CET | 49808 | 445 | 192.168.2.6 | 6.147.7.88 |
Jan 14, 2025 22:42:28.204170942 CET | 49809 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.208791018 CET | 445 | 49808 | 6.147.7.88 | 192.168.2.6 |
Jan 14, 2025 22:42:28.208941936 CET | 49808 | 445 | 192.168.2.6 | 6.147.7.88 |
Jan 14, 2025 22:42:28.208951950 CET | 445 | 49809 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:28.209012985 CET | 49809 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.209045887 CET | 49809 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.213963985 CET | 445 | 49809 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:28.215495110 CET | 49809 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.219594955 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.224335909 CET | 445 | 49811 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:28.224412918 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.224457026 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:28.229196072 CET | 445 | 49811 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:28.943187952 CET | 443 | 49712 | 173.222.162.64 | 192.168.2.6 |
Jan 14, 2025 22:42:28.943279028 CET | 49712 | 443 | 192.168.2.6 | 173.222.162.64 |
Jan 14, 2025 22:42:30.258531094 CET | 49846 | 445 | 192.168.2.6 | 198.205.43.159 |
Jan 14, 2025 22:42:30.263402939 CET | 445 | 49846 | 198.205.43.159 | 192.168.2.6 |
Jan 14, 2025 22:42:30.263968945 CET | 49846 | 445 | 192.168.2.6 | 198.205.43.159 |
Jan 14, 2025 22:42:30.267569065 CET | 49846 | 445 | 192.168.2.6 | 198.205.43.159 |
Jan 14, 2025 22:42:30.269444942 CET | 49847 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.272392035 CET | 445 | 49846 | 198.205.43.159 | 192.168.2.6 |
Jan 14, 2025 22:42:30.274286985 CET | 445 | 49847 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:30.275346994 CET | 49846 | 445 | 192.168.2.6 | 198.205.43.159 |
Jan 14, 2025 22:42:30.275351048 CET | 49847 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.280179977 CET | 49847 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.285495996 CET | 445 | 49847 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:30.288573027 CET | 49847 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.509612083 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.514419079 CET | 445 | 49849 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:30.514487982 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.514544010 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:30.519408941 CET | 445 | 49849 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:32.258533001 CET | 49873 | 445 | 192.168.2.6 | 77.226.237.97 |
Jan 14, 2025 22:42:32.263459921 CET | 445 | 49873 | 77.226.237.97 | 192.168.2.6 |
Jan 14, 2025 22:42:32.263547897 CET | 49873 | 445 | 192.168.2.6 | 77.226.237.97 |
Jan 14, 2025 22:42:32.263633013 CET | 49873 | 445 | 192.168.2.6 | 77.226.237.97 |
Jan 14, 2025 22:42:32.263923883 CET | 49874 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.268500090 CET | 445 | 49873 | 77.226.237.97 | 192.168.2.6 |
Jan 14, 2025 22:42:32.268570900 CET | 49873 | 445 | 192.168.2.6 | 77.226.237.97 |
Jan 14, 2025 22:42:32.269134998 CET | 445 | 49874 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:32.269412041 CET | 49874 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.269412041 CET | 49874 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.270505905 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.274876118 CET | 445 | 49874 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:32.274935007 CET | 49874 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.275341034 CET | 445 | 49875 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:32.275402069 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.275463104 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:32.280272961 CET | 445 | 49875 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:34.274818897 CET | 49910 | 445 | 192.168.2.6 | 107.175.251.189 |
Jan 14, 2025 22:42:34.279774904 CET | 445 | 49910 | 107.175.251.189 | 192.168.2.6 |
Jan 14, 2025 22:42:34.279923916 CET | 49910 | 445 | 192.168.2.6 | 107.175.251.189 |
Jan 14, 2025 22:42:34.279956102 CET | 49910 | 445 | 192.168.2.6 | 107.175.251.189 |
Jan 14, 2025 22:42:34.280170918 CET | 49911 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.284884930 CET | 445 | 49910 | 107.175.251.189 | 192.168.2.6 |
Jan 14, 2025 22:42:34.284998894 CET | 445 | 49911 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:34.285022020 CET | 49910 | 445 | 192.168.2.6 | 107.175.251.189 |
Jan 14, 2025 22:42:34.285092115 CET | 49911 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.285195112 CET | 49911 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.286701918 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.290112019 CET | 445 | 49911 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:34.290195942 CET | 49911 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.291554928 CET | 445 | 49912 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:34.291723013 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.291723013 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:34.296538115 CET | 445 | 49912 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:36.289863110 CET | 49944 | 445 | 192.168.2.6 | 37.134.68.167 |
Jan 14, 2025 22:42:36.294717073 CET | 445 | 49944 | 37.134.68.167 | 192.168.2.6 |
Jan 14, 2025 22:42:36.294784069 CET | 49944 | 445 | 192.168.2.6 | 37.134.68.167 |
Jan 14, 2025 22:42:36.294895887 CET | 49944 | 445 | 192.168.2.6 | 37.134.68.167 |
Jan 14, 2025 22:42:36.295111895 CET | 49945 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.299866915 CET | 445 | 49944 | 37.134.68.167 | 192.168.2.6 |
Jan 14, 2025 22:42:36.299880981 CET | 445 | 49945 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:36.299921036 CET | 49944 | 445 | 192.168.2.6 | 37.134.68.167 |
Jan 14, 2025 22:42:36.300015926 CET | 49945 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.300015926 CET | 49945 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.300904036 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.304918051 CET | 445 | 49945 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:36.305130005 CET | 49945 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.306018114 CET | 445 | 49946 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:36.306080103 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.306149006 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:36.310921907 CET | 445 | 49946 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:38.361392021 CET | 49981 | 445 | 192.168.2.6 | 219.121.211.91 |
Jan 14, 2025 22:42:38.366178989 CET | 445 | 49981 | 219.121.211.91 | 192.168.2.6 |
Jan 14, 2025 22:42:38.366770983 CET | 49981 | 445 | 192.168.2.6 | 219.121.211.91 |
Jan 14, 2025 22:42:38.366770983 CET | 49981 | 445 | 192.168.2.6 | 219.121.211.91 |
Jan 14, 2025 22:42:38.366942883 CET | 49984 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.371720076 CET | 445 | 49984 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:38.371731043 CET | 445 | 49981 | 219.121.211.91 | 192.168.2.6 |
Jan 14, 2025 22:42:38.371809959 CET | 49984 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.371905088 CET | 49981 | 445 | 192.168.2.6 | 219.121.211.91 |
Jan 14, 2025 22:42:38.371912956 CET | 49984 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.372327089 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.377104044 CET | 445 | 49985 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:38.377728939 CET | 445 | 49984 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:38.378084898 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.378226042 CET | 49984 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.382102966 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:38.386874914 CET | 445 | 49985 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:40.368494034 CET | 50015 | 445 | 192.168.2.6 | 149.173.236.150 |
Jan 14, 2025 22:42:40.373302937 CET | 445 | 50015 | 149.173.236.150 | 192.168.2.6 |
Jan 14, 2025 22:42:40.373408079 CET | 50015 | 445 | 192.168.2.6 | 149.173.236.150 |
Jan 14, 2025 22:42:40.373578072 CET | 50015 | 445 | 192.168.2.6 | 149.173.236.150 |
Jan 14, 2025 22:42:40.373668909 CET | 50016 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.378494024 CET | 445 | 50015 | 149.173.236.150 | 192.168.2.6 |
Jan 14, 2025 22:42:40.378505945 CET | 445 | 50015 | 149.173.236.150 | 192.168.2.6 |
Jan 14, 2025 22:42:40.378515959 CET | 445 | 50016 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:42:40.378653049 CET | 50016 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.378653049 CET | 50016 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.378894091 CET | 50015 | 445 | 192.168.2.6 | 149.173.236.150 |
Jan 14, 2025 22:42:40.378961086 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.383580923 CET | 445 | 50016 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:42:40.383732080 CET | 445 | 50017 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:42:40.383795023 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.383867979 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.384335995 CET | 50016 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:42:40.388647079 CET | 445 | 50017 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:42:42.383521080 CET | 50054 | 445 | 192.168.2.6 | 147.244.118.48 |
Jan 14, 2025 22:42:42.388387918 CET | 445 | 50054 | 147.244.118.48 | 192.168.2.6 |
Jan 14, 2025 22:42:42.388475895 CET | 50054 | 445 | 192.168.2.6 | 147.244.118.48 |
Jan 14, 2025 22:42:42.388572931 CET | 50054 | 445 | 192.168.2.6 | 147.244.118.48 |
Jan 14, 2025 22:42:42.388741016 CET | 50055 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.393404961 CET | 445 | 50054 | 147.244.118.48 | 192.168.2.6 |
Jan 14, 2025 22:42:42.393456936 CET | 50054 | 445 | 192.168.2.6 | 147.244.118.48 |
Jan 14, 2025 22:42:42.393572092 CET | 445 | 50055 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:42:42.393621922 CET | 50055 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.393682003 CET | 50055 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.393976927 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.398531914 CET | 445 | 50055 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:42:42.398576021 CET | 50055 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.398746967 CET | 445 | 50056 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:42:42.398797989 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.398823977 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:42:42.403548002 CET | 445 | 50056 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:42:44.398792982 CET | 50091 | 445 | 192.168.2.6 | 144.165.243.195 |
Jan 14, 2025 22:42:44.403553009 CET | 445 | 50091 | 144.165.243.195 | 192.168.2.6 |
Jan 14, 2025 22:42:44.403718948 CET | 50091 | 445 | 192.168.2.6 | 144.165.243.195 |
Jan 14, 2025 22:42:44.403794050 CET | 50091 | 445 | 192.168.2.6 | 144.165.243.195 |
Jan 14, 2025 22:42:44.403928995 CET | 50093 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.408644915 CET | 445 | 50091 | 144.165.243.195 | 192.168.2.6 |
Jan 14, 2025 22:42:44.408673048 CET | 445 | 50093 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:42:44.408768892 CET | 50091 | 445 | 192.168.2.6 | 144.165.243.195 |
Jan 14, 2025 22:42:44.408806086 CET | 50093 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.408806086 CET | 50093 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.409286976 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.413748026 CET | 445 | 50093 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:42:44.414071083 CET | 445 | 50095 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:42:44.414129019 CET | 50093 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.414129019 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.414767027 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:42:44.419570923 CET | 445 | 50095 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:42:46.414624929 CET | 50131 | 445 | 192.168.2.6 | 134.64.132.107 |
Jan 14, 2025 22:42:46.419447899 CET | 445 | 50131 | 134.64.132.107 | 192.168.2.6 |
Jan 14, 2025 22:42:46.419522047 CET | 50131 | 445 | 192.168.2.6 | 134.64.132.107 |
Jan 14, 2025 22:42:46.419598103 CET | 50131 | 445 | 192.168.2.6 | 134.64.132.107 |
Jan 14, 2025 22:42:46.419780016 CET | 50132 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.424544096 CET | 445 | 50131 | 134.64.132.107 | 192.168.2.6 |
Jan 14, 2025 22:42:46.424566031 CET | 445 | 50132 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:42:46.424601078 CET | 50131 | 445 | 192.168.2.6 | 134.64.132.107 |
Jan 14, 2025 22:42:46.424663067 CET | 50132 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.424752951 CET | 50132 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.425678968 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.429627895 CET | 445 | 50132 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:42:46.429680109 CET | 50132 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.430555105 CET | 445 | 50133 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:42:46.430612087 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.430654049 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:42:46.435571909 CET | 445 | 50133 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:42:47.571841002 CET | 445 | 49780 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:47.571903944 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:47.571955919 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:47.572011948 CET | 49780 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:47.576754093 CET | 445 | 49780 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:47.576766014 CET | 445 | 49780 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:48.429814100 CET | 50176 | 445 | 192.168.2.6 | 101.183.122.42 |
Jan 14, 2025 22:42:48.437288046 CET | 445 | 50176 | 101.183.122.42 | 192.168.2.6 |
Jan 14, 2025 22:42:48.437359095 CET | 50176 | 445 | 192.168.2.6 | 101.183.122.42 |
Jan 14, 2025 22:42:48.437381029 CET | 50176 | 445 | 192.168.2.6 | 101.183.122.42 |
Jan 14, 2025 22:42:48.437536001 CET | 50178 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.445220947 CET | 445 | 50178 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:42:48.446362972 CET | 445 | 50176 | 101.183.122.42 | 192.168.2.6 |
Jan 14, 2025 22:42:48.446477890 CET | 50176 | 445 | 192.168.2.6 | 101.183.122.42 |
Jan 14, 2025 22:42:48.446491957 CET | 50178 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.446578979 CET | 50178 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.447180986 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.451718092 CET | 445 | 50178 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:42:48.451879025 CET | 445 | 50179 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:42:48.451936960 CET | 50178 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.451967001 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.452043056 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:42:48.456875086 CET | 445 | 50179 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:42:49.606513977 CET | 445 | 49811 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:49.606610060 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:49.619988918 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:49.620098114 CET | 49811 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:49.624902010 CET | 445 | 49811 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:49.624922037 CET | 445 | 49811 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.445931911 CET | 50210 | 445 | 192.168.2.6 | 78.63.44.240 |
Jan 14, 2025 22:42:50.450776100 CET | 445 | 50210 | 78.63.44.240 | 192.168.2.6 |
Jan 14, 2025 22:42:50.450866938 CET | 50210 | 445 | 192.168.2.6 | 78.63.44.240 |
Jan 14, 2025 22:42:50.450947046 CET | 50210 | 445 | 192.168.2.6 | 78.63.44.240 |
Jan 14, 2025 22:42:50.451180935 CET | 50211 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.455841064 CET | 445 | 50210 | 78.63.44.240 | 192.168.2.6 |
Jan 14, 2025 22:42:50.455895901 CET | 50210 | 445 | 192.168.2.6 | 78.63.44.240 |
Jan 14, 2025 22:42:50.455903053 CET | 445 | 50211 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.456012964 CET | 50211 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.456053972 CET | 50211 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.456399918 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.461050987 CET | 445 | 50211 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.461208105 CET | 445 | 50212 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.461225033 CET | 50211 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.461272001 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.461323977 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:42:50.466114044 CET | 445 | 50212 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.586312056 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:50.591067076 CET | 445 | 50218 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:50.591130018 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:50.591212034 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:42:50.595938921 CET | 445 | 50218 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:42:51.881254911 CET | 445 | 49849 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:51.881320953 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:51.881371975 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:51.881436110 CET | 49849 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:51.886171103 CET | 445 | 49849 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:51.886209965 CET | 445 | 49849 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.476037025 CET | 50243 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:42:52.480813980 CET | 445 | 50243 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:42:52.480909109 CET | 50243 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:42:52.481061935 CET | 50243 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:42:52.481267929 CET | 50244 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.485865116 CET | 445 | 50243 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:42:52.485923052 CET | 50243 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:42:52.486074924 CET | 445 | 50244 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.486181021 CET | 50244 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.486268044 CET | 50244 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.487143993 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.491842031 CET | 445 | 50244 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.491899967 CET | 50244 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.492227077 CET | 445 | 50246 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.492553949 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.492640018 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:52.497374058 CET | 445 | 50246 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.635761976 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:52.641120911 CET | 445 | 50247 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:52.643028021 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:52.643616915 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:42:52.648446083 CET | 445 | 50247 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:42:53.634722948 CET | 445 | 49875 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:53.634793997 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:53.634830952 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:53.634896040 CET | 49875 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:53.639601946 CET | 445 | 49875 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:53.639614105 CET | 445 | 49875 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.477499962 CET | 50258 | 445 | 192.168.2.6 | 204.188.17.57 |
Jan 14, 2025 22:42:54.482296944 CET | 445 | 50258 | 204.188.17.57 | 192.168.2.6 |
Jan 14, 2025 22:42:54.482412100 CET | 50258 | 445 | 192.168.2.6 | 204.188.17.57 |
Jan 14, 2025 22:42:54.482495070 CET | 50258 | 445 | 192.168.2.6 | 204.188.17.57 |
Jan 14, 2025 22:42:54.482719898 CET | 50259 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.487582922 CET | 445 | 50258 | 204.188.17.57 | 192.168.2.6 |
Jan 14, 2025 22:42:54.487596035 CET | 445 | 50259 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.487651110 CET | 50258 | 445 | 192.168.2.6 | 204.188.17.57 |
Jan 14, 2025 22:42:54.487682104 CET | 50259 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.487732887 CET | 50259 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.488218069 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.492613077 CET | 445 | 50259 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.492679119 CET | 50259 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.493021011 CET | 445 | 50260 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.493560076 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.493685961 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:42:54.498460054 CET | 445 | 50260 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.882805109 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:54.887639046 CET | 445 | 50266 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:54.887712002 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:54.887770891 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:42:54.892482996 CET | 445 | 50266 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.227741003 CET | 445 | 50246 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.227837086 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:55.227905989 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:55.227951050 CET | 50246 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:55.232734919 CET | 445 | 50246 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.232755899 CET | 445 | 50246 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.649303913 CET | 445 | 49912 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.649395943 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:55.652510881 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:55.652621031 CET | 49912 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:55.657449961 CET | 445 | 49912 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:55.657478094 CET | 445 | 49912 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.492439032 CET | 50276 | 445 | 192.168.2.6 | 87.122.116.245 |
Jan 14, 2025 22:42:56.497206926 CET | 445 | 50276 | 87.122.116.245 | 192.168.2.6 |
Jan 14, 2025 22:42:56.497281075 CET | 50276 | 445 | 192.168.2.6 | 87.122.116.245 |
Jan 14, 2025 22:42:56.497354984 CET | 50276 | 445 | 192.168.2.6 | 87.122.116.245 |
Jan 14, 2025 22:42:56.497518063 CET | 50277 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.502347946 CET | 445 | 50276 | 87.122.116.245 | 192.168.2.6 |
Jan 14, 2025 22:42:56.502408028 CET | 50276 | 445 | 192.168.2.6 | 87.122.116.245 |
Jan 14, 2025 22:42:56.503365040 CET | 445 | 50277 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.503427982 CET | 50277 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.503488064 CET | 50277 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.503849983 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.508610010 CET | 445 | 50278 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.508651972 CET | 445 | 50277 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.508671045 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.508697987 CET | 50277 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.508750916 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:42:56.513653994 CET | 445 | 50278 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.648360014 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:56.653183937 CET | 445 | 50280 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:56.653297901 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:56.653350115 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:42:56.658162117 CET | 445 | 50280 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:42:57.714011908 CET | 445 | 49946 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:57.714205980 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:57.714205980 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:57.714322090 CET | 49946 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:42:57.719036102 CET | 445 | 49946 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:57.719258070 CET | 445 | 49946 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.242208004 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:58.247025013 CET | 445 | 50291 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.247646093 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:58.247793913 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:42:58.252605915 CET | 445 | 50291 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.668035984 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:58.791402102 CET | 50295 | 445 | 192.168.2.6 | 136.139.192.57 |
Jan 14, 2025 22:42:58.820204973 CET | 445 | 50294 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.820242882 CET | 445 | 50295 | 136.139.192.57 | 192.168.2.6 |
Jan 14, 2025 22:42:58.820302963 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:58.820480108 CET | 50295 | 445 | 192.168.2.6 | 136.139.192.57 |
Jan 14, 2025 22:42:58.859590054 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:42:58.859672070 CET | 50295 | 445 | 192.168.2.6 | 136.139.192.57 |
Jan 14, 2025 22:42:58.859894991 CET | 50297 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.864434004 CET | 445 | 50294 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.864628077 CET | 445 | 50295 | 136.139.192.57 | 192.168.2.6 |
Jan 14, 2025 22:42:58.864691973 CET | 50295 | 445 | 192.168.2.6 | 136.139.192.57 |
Jan 14, 2025 22:42:58.864743948 CET | 445 | 50297 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.864805937 CET | 50297 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.873986006 CET | 50297 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.878901958 CET | 445 | 50297 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.878962994 CET | 50297 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.895915985 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.900770903 CET | 445 | 50298 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:42:58.900896072 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.900896072 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:42:58.905837059 CET | 445 | 50298 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:42:59.758824110 CET | 445 | 49985 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:59.758903027 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:59.759540081 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:59.759579897 CET | 49985 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:42:59.764394999 CET | 445 | 49985 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:42:59.764436007 CET | 445 | 49985 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.117089987 CET | 445 | 50291 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.117167950 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:43:00.117321014 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:43:00.117367983 CET | 50291 | 445 | 192.168.2.6 | 197.9.206.1 |
Jan 14, 2025 22:43:00.122102022 CET | 445 | 50291 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.122112036 CET | 445 | 50291 | 197.9.206.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.179513931 CET | 50308 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.184423923 CET | 445 | 50308 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:00.184607029 CET | 50308 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.184638977 CET | 50308 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.185066938 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.189579964 CET | 445 | 50308 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:00.189634085 CET | 50308 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.189884901 CET | 445 | 50309 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:00.189955950 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.189976931 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:00.194809914 CET | 445 | 50309 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:00.648876905 CET | 50313 | 445 | 192.168.2.6 | 48.168.78.156 |
Jan 14, 2025 22:43:00.654798031 CET | 445 | 50313 | 48.168.78.156 | 192.168.2.6 |
Jan 14, 2025 22:43:00.655301094 CET | 50313 | 445 | 192.168.2.6 | 48.168.78.156 |
Jan 14, 2025 22:43:00.655448914 CET | 50313 | 445 | 192.168.2.6 | 48.168.78.156 |
Jan 14, 2025 22:43:00.655725002 CET | 50314 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.660612106 CET | 445 | 50314 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.660767078 CET | 445 | 50313 | 48.168.78.156 | 192.168.2.6 |
Jan 14, 2025 22:43:00.660866022 CET | 50314 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.660867929 CET | 50313 | 445 | 192.168.2.6 | 48.168.78.156 |
Jan 14, 2025 22:43:00.660917997 CET | 50314 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.662658930 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.666342020 CET | 445 | 50314 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.667155981 CET | 50314 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.667522907 CET | 445 | 50315 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.668345928 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.668345928 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:00.673124075 CET | 445 | 50315 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.726547956 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:00.731446981 CET | 445 | 50317 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:43:00.736578941 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:00.736578941 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:00.741437912 CET | 445 | 50317 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:43:01.774346113 CET | 445 | 50017 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:01.774451017 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:01.776664972 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:01.776702881 CET | 50017 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:01.781552076 CET | 445 | 50017 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:01.781584978 CET | 445 | 50017 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.524275064 CET | 50327 | 445 | 192.168.2.6 | 75.65.143.16 |
Jan 14, 2025 22:43:02.530083895 CET | 445 | 50327 | 75.65.143.16 | 192.168.2.6 |
Jan 14, 2025 22:43:02.530174971 CET | 50327 | 445 | 192.168.2.6 | 75.65.143.16 |
Jan 14, 2025 22:43:02.530284882 CET | 50327 | 445 | 192.168.2.6 | 75.65.143.16 |
Jan 14, 2025 22:43:02.530524015 CET | 50328 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.535238981 CET | 445 | 50327 | 75.65.143.16 | 192.168.2.6 |
Jan 14, 2025 22:43:02.535290003 CET | 445 | 50328 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.535298109 CET | 50327 | 445 | 192.168.2.6 | 75.65.143.16 |
Jan 14, 2025 22:43:02.535343885 CET | 50328 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.535496950 CET | 50328 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.535805941 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.540329933 CET | 445 | 50328 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.540415049 CET | 50328 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.540591955 CET | 445 | 50329 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.540671110 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.540740967 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:02.545490026 CET | 445 | 50329 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.773279905 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:02.778084993 CET | 445 | 50330 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:02.778158903 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:02.778187990 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:02.782948971 CET | 445 | 50330 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:03.791876078 CET | 445 | 50056 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:03.792006969 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:03.792006969 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:03.792310953 CET | 50056 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:03.796813965 CET | 445 | 50056 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:03.797137022 CET | 445 | 50056 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.273587942 CET | 50331 | 445 | 192.168.2.6 | 98.97.187.115 |
Jan 14, 2025 22:43:04.278444052 CET | 445 | 50331 | 98.97.187.115 | 192.168.2.6 |
Jan 14, 2025 22:43:04.278533936 CET | 50331 | 445 | 192.168.2.6 | 98.97.187.115 |
Jan 14, 2025 22:43:04.278814077 CET | 50331 | 445 | 192.168.2.6 | 98.97.187.115 |
Jan 14, 2025 22:43:04.278968096 CET | 50332 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.283642054 CET | 445 | 50331 | 98.97.187.115 | 192.168.2.6 |
Jan 14, 2025 22:43:04.283730984 CET | 445 | 50332 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.283768892 CET | 50331 | 445 | 192.168.2.6 | 98.97.187.115 |
Jan 14, 2025 22:43:04.283812046 CET | 50332 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.283957005 CET | 50332 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.284344912 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.288781881 CET | 445 | 50332 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.288841009 CET | 50332 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.289132118 CET | 445 | 50333 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.289201021 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.289227962 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:04.294070005 CET | 445 | 50333 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.803194046 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:04.808082104 CET | 445 | 50334 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:04.808155060 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:04.812808990 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:04.817585945 CET | 445 | 50334 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:05.805394888 CET | 445 | 50095 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:05.805461884 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:05.805510998 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:05.805567980 CET | 50095 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:05.810343027 CET | 445 | 50095 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:05.810450077 CET | 445 | 50095 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:05.914290905 CET | 50335 | 445 | 192.168.2.6 | 15.116.122.57 |
Jan 14, 2025 22:43:06.077455044 CET | 445 | 50335 | 15.116.122.57 | 192.168.2.6 |
Jan 14, 2025 22:43:06.077537060 CET | 50335 | 445 | 192.168.2.6 | 15.116.122.57 |
Jan 14, 2025 22:43:06.077604055 CET | 50335 | 445 | 192.168.2.6 | 15.116.122.57 |
Jan 14, 2025 22:43:06.077827930 CET | 50336 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.082475901 CET | 445 | 50335 | 15.116.122.57 | 192.168.2.6 |
Jan 14, 2025 22:43:06.082663059 CET | 445 | 50335 | 15.116.122.57 | 192.168.2.6 |
Jan 14, 2025 22:43:06.082678080 CET | 445 | 50336 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:06.082710028 CET | 50335 | 445 | 192.168.2.6 | 15.116.122.57 |
Jan 14, 2025 22:43:06.082761049 CET | 50336 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.082834005 CET | 50336 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.083226919 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.087899923 CET | 445 | 50336 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:06.087955952 CET | 50336 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.088044882 CET | 445 | 50337 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:06.088108063 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.088404894 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:06.093220949 CET | 445 | 50337 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:06.804723978 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:06.809523106 CET | 445 | 50338 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:06.809765100 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:06.809901953 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:06.814634085 CET | 445 | 50338 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.475043058 CET | 50339 | 445 | 192.168.2.6 | 162.104.87.50 |
Jan 14, 2025 22:43:07.479890108 CET | 445 | 50339 | 162.104.87.50 | 192.168.2.6 |
Jan 14, 2025 22:43:07.482665062 CET | 50339 | 445 | 192.168.2.6 | 162.104.87.50 |
Jan 14, 2025 22:43:07.508075953 CET | 50339 | 445 | 192.168.2.6 | 162.104.87.50 |
Jan 14, 2025 22:43:07.512991905 CET | 445 | 50339 | 162.104.87.50 | 192.168.2.6 |
Jan 14, 2025 22:43:07.513096094 CET | 50339 | 445 | 192.168.2.6 | 162.104.87.50 |
Jan 14, 2025 22:43:07.531529903 CET | 50340 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.536381006 CET | 445 | 50340 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.536490917 CET | 50340 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.536688089 CET | 50340 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.540107965 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.541521072 CET | 445 | 50340 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.541610003 CET | 50340 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.544964075 CET | 445 | 50341 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.545082092 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.545121908 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:07.549962044 CET | 445 | 50341 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.821024895 CET | 445 | 50133 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.821135044 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:07.857773066 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:07.857825041 CET | 50133 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:07.862782955 CET | 445 | 50133 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:43:07.862817049 CET | 445 | 50133 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.820151091 CET | 50343 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:08.825026035 CET | 445 | 50343 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.825113058 CET | 50343 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:08.825131893 CET | 50343 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:08.829960108 CET | 445 | 50343 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.898756027 CET | 50344 | 445 | 192.168.2.6 | 76.252.20.92 |
Jan 14, 2025 22:43:08.903677940 CET | 445 | 50344 | 76.252.20.92 | 192.168.2.6 |
Jan 14, 2025 22:43:08.903762102 CET | 50344 | 445 | 192.168.2.6 | 76.252.20.92 |
Jan 14, 2025 22:43:08.903793097 CET | 50344 | 445 | 192.168.2.6 | 76.252.20.92 |
Jan 14, 2025 22:43:08.903987885 CET | 50345 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.908706903 CET | 445 | 50344 | 76.252.20.92 | 192.168.2.6 |
Jan 14, 2025 22:43:08.908763885 CET | 445 | 50345 | 76.252.20.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.908816099 CET | 50344 | 445 | 192.168.2.6 | 76.252.20.92 |
Jan 14, 2025 22:43:08.908845901 CET | 50345 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.909090996 CET | 50345 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.909302950 CET | 50346 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.913952112 CET | 445 | 50345 | 76.252.20.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.914031029 CET | 50345 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.914120913 CET | 445 | 50346 | 76.252.20.1 | 192.168.2.6 |
Jan 14, 2025 22:43:08.914187908 CET | 50346 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.914236069 CET | 50346 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:08.919014931 CET | 445 | 50346 | 76.252.20.1 | 192.168.2.6 |
Jan 14, 2025 22:43:09.850580931 CET | 445 | 50179 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:09.850698948 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:09.850785017 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:09.850785017 CET | 50179 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:09.855588913 CET | 445 | 50179 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:09.855602980 CET | 445 | 50179 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.226994991 CET | 50347 | 445 | 192.168.2.6 | 18.142.24.211 |
Jan 14, 2025 22:43:10.231765032 CET | 445 | 50347 | 18.142.24.211 | 192.168.2.6 |
Jan 14, 2025 22:43:10.231853008 CET | 50347 | 445 | 192.168.2.6 | 18.142.24.211 |
Jan 14, 2025 22:43:10.232088089 CET | 50347 | 445 | 192.168.2.6 | 18.142.24.211 |
Jan 14, 2025 22:43:10.232088089 CET | 50348 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.236931086 CET | 445 | 50348 | 18.142.24.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.236943007 CET | 445 | 50347 | 18.142.24.211 | 192.168.2.6 |
Jan 14, 2025 22:43:10.237003088 CET | 50347 | 445 | 192.168.2.6 | 18.142.24.211 |
Jan 14, 2025 22:43:10.237102032 CET | 50348 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.237102032 CET | 50348 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.237399101 CET | 50349 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.242024899 CET | 445 | 50348 | 18.142.24.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.242186069 CET | 445 | 50349 | 18.142.24.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.242183924 CET | 50348 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.242249966 CET | 50349 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.242309093 CET | 50349 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:10.247061968 CET | 445 | 50349 | 18.142.24.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.872950077 CET | 50350 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:10.877942085 CET | 445 | 50350 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:43:10.878890038 CET | 50350 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:10.884541988 CET | 50350 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:10.889413118 CET | 445 | 50350 | 134.64.132.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.476682901 CET | 50351 | 445 | 192.168.2.6 | 48.113.108.17 |
Jan 14, 2025 22:43:11.481529951 CET | 445 | 50351 | 48.113.108.17 | 192.168.2.6 |
Jan 14, 2025 22:43:11.481617928 CET | 50351 | 445 | 192.168.2.6 | 48.113.108.17 |
Jan 14, 2025 22:43:11.481698036 CET | 50351 | 445 | 192.168.2.6 | 48.113.108.17 |
Jan 14, 2025 22:43:11.481856108 CET | 50352 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.486639023 CET | 445 | 50352 | 48.113.108.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.486732006 CET | 50352 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.486741066 CET | 50352 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.486771107 CET | 445 | 50351 | 48.113.108.17 | 192.168.2.6 |
Jan 14, 2025 22:43:11.486819029 CET | 50351 | 445 | 192.168.2.6 | 48.113.108.17 |
Jan 14, 2025 22:43:11.487119913 CET | 50353 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.491849899 CET | 445 | 50352 | 48.113.108.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.491905928 CET | 50352 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.492144108 CET | 445 | 50353 | 48.113.108.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.492353916 CET | 50353 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.492468119 CET | 50353 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:11.497358084 CET | 445 | 50353 | 48.113.108.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.850660086 CET | 445 | 50212 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.850723028 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:11.850790977 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:11.850790977 CET | 50212 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:11.855628967 CET | 445 | 50212 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.855663061 CET | 445 | 50212 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.977649927 CET | 445 | 50218 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.977715015 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:43:11.977793932 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:43:11.977833986 CET | 50218 | 445 | 192.168.2.6 | 18.1.0.1 |
Jan 14, 2025 22:43:11.982615948 CET | 445 | 50218 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:43:11.982659101 CET | 445 | 50218 | 18.1.0.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.039038897 CET | 50354 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.043934107 CET | 445 | 50354 | 18.1.0.2 | 192.168.2.6 |
Jan 14, 2025 22:43:12.044013023 CET | 50354 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.044069052 CET | 50354 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.044445992 CET | 50355 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.049138069 CET | 445 | 50354 | 18.1.0.2 | 192.168.2.6 |
Jan 14, 2025 22:43:12.049192905 CET | 50354 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.049262047 CET | 445 | 50355 | 18.1.0.2 | 192.168.2.6 |
Jan 14, 2025 22:43:12.049320936 CET | 50355 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.049370050 CET | 50355 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:12.054203033 CET | 445 | 50355 | 18.1.0.2 | 192.168.2.6 |
Jan 14, 2025 22:43:12.632930040 CET | 50356 | 445 | 192.168.2.6 | 198.74.23.73 |
Jan 14, 2025 22:43:12.637811899 CET | 445 | 50356 | 198.74.23.73 | 192.168.2.6 |
Jan 14, 2025 22:43:12.637897968 CET | 50356 | 445 | 192.168.2.6 | 198.74.23.73 |
Jan 14, 2025 22:43:12.637943029 CET | 50356 | 445 | 192.168.2.6 | 198.74.23.73 |
Jan 14, 2025 22:43:12.638042927 CET | 50357 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.642803907 CET | 445 | 50356 | 198.74.23.73 | 192.168.2.6 |
Jan 14, 2025 22:43:12.642860889 CET | 445 | 50357 | 198.74.23.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.642863989 CET | 50356 | 445 | 192.168.2.6 | 198.74.23.73 |
Jan 14, 2025 22:43:12.642935038 CET | 50357 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.642999887 CET | 50357 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.643261909 CET | 50358 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.647810936 CET | 445 | 50357 | 198.74.23.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.647864103 CET | 50357 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.648072958 CET | 445 | 50358 | 198.74.23.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.648122072 CET | 50358 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.648416042 CET | 50358 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:12.653176069 CET | 445 | 50358 | 198.74.23.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.854867935 CET | 50359 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:12.859723091 CET | 445 | 50359 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:12.859818935 CET | 50359 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:12.860079050 CET | 50359 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:12.864892006 CET | 445 | 50359 | 101.183.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.736614943 CET | 50361 | 445 | 192.168.2.6 | 109.252.120.234 |
Jan 14, 2025 22:43:13.741497993 CET | 445 | 50361 | 109.252.120.234 | 192.168.2.6 |
Jan 14, 2025 22:43:13.743402004 CET | 50361 | 445 | 192.168.2.6 | 109.252.120.234 |
Jan 14, 2025 22:43:13.744924068 CET | 50361 | 445 | 192.168.2.6 | 109.252.120.234 |
Jan 14, 2025 22:43:13.745218992 CET | 50362 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.749756098 CET | 445 | 50361 | 109.252.120.234 | 192.168.2.6 |
Jan 14, 2025 22:43:13.750051975 CET | 445 | 50362 | 109.252.120.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.750112057 CET | 50361 | 445 | 192.168.2.6 | 109.252.120.234 |
Jan 14, 2025 22:43:13.750161886 CET | 50362 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.753412962 CET | 50362 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.758313894 CET | 445 | 50362 | 109.252.120.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.759335041 CET | 50362 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.802012920 CET | 50363 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.806842089 CET | 445 | 50363 | 109.252.120.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.806905985 CET | 50363 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.806977987 CET | 50363 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:13.811733007 CET | 445 | 50363 | 109.252.120.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.993274927 CET | 445 | 50247 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:43:13.994560003 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:43:14.009582996 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:43:14.009644985 CET | 50247 | 445 | 192.168.2.6 | 6.147.7.1 |
Jan 14, 2025 22:43:14.014404058 CET | 445 | 50247 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.014416933 CET | 445 | 50247 | 6.147.7.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.108030081 CET | 50364 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.112893105 CET | 445 | 50364 | 6.147.7.2 | 192.168.2.6 |
Jan 14, 2025 22:43:14.113007069 CET | 50364 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.113069057 CET | 50364 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.118186951 CET | 445 | 50364 | 6.147.7.2 | 192.168.2.6 |
Jan 14, 2025 22:43:14.120549917 CET | 50364 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.210388899 CET | 50365 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.216028929 CET | 445 | 50365 | 6.147.7.2 | 192.168.2.6 |
Jan 14, 2025 22:43:14.217565060 CET | 50365 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.217818022 CET | 50365 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:14.222619057 CET | 445 | 50365 | 6.147.7.2 | 192.168.2.6 |
Jan 14, 2025 22:43:14.726797104 CET | 50366 | 445 | 192.168.2.6 | 50.113.28.74 |
Jan 14, 2025 22:43:14.732424021 CET | 445 | 50366 | 50.113.28.74 | 192.168.2.6 |
Jan 14, 2025 22:43:14.732486010 CET | 50366 | 445 | 192.168.2.6 | 50.113.28.74 |
Jan 14, 2025 22:43:14.732547998 CET | 50366 | 445 | 192.168.2.6 | 50.113.28.74 |
Jan 14, 2025 22:43:14.732711077 CET | 50367 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.737389088 CET | 445 | 50366 | 50.113.28.74 | 192.168.2.6 |
Jan 14, 2025 22:43:14.737435102 CET | 50366 | 445 | 192.168.2.6 | 50.113.28.74 |
Jan 14, 2025 22:43:14.739351988 CET | 445 | 50367 | 50.113.28.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.739409924 CET | 50367 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.739434004 CET | 50367 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.739732981 CET | 50368 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.744379044 CET | 445 | 50367 | 50.113.28.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.744426966 CET | 50367 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.744489908 CET | 445 | 50368 | 50.113.28.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.744658947 CET | 50368 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.744682074 CET | 50368 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:14.750016928 CET | 445 | 50368 | 50.113.28.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.851672888 CET | 50369 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:14.858088970 CET | 445 | 50369 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:43:14.858155966 CET | 50369 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:14.858184099 CET | 50369 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:14.863044977 CET | 445 | 50369 | 78.63.44.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.664318085 CET | 50370 | 445 | 192.168.2.6 | 175.68.141.242 |
Jan 14, 2025 22:43:15.669243097 CET | 445 | 50370 | 175.68.141.242 | 192.168.2.6 |
Jan 14, 2025 22:43:15.669321060 CET | 50370 | 445 | 192.168.2.6 | 175.68.141.242 |
Jan 14, 2025 22:43:15.669362068 CET | 50370 | 445 | 192.168.2.6 | 175.68.141.242 |
Jan 14, 2025 22:43:15.669608116 CET | 50371 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.674302101 CET | 445 | 50370 | 175.68.141.242 | 192.168.2.6 |
Jan 14, 2025 22:43:15.674367905 CET | 50370 | 445 | 192.168.2.6 | 175.68.141.242 |
Jan 14, 2025 22:43:15.674372911 CET | 445 | 50371 | 175.68.141.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.674477100 CET | 50371 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.674571991 CET | 50371 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.675187111 CET | 50372 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.679416895 CET | 445 | 50371 | 175.68.141.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.679873943 CET | 50371 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.679971933 CET | 445 | 50372 | 175.68.141.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.680160999 CET | 50372 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.680160999 CET | 50372 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:15.684973001 CET | 445 | 50372 | 175.68.141.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.869028091 CET | 445 | 50260 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.869111061 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:15.869164944 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:15.869203091 CET | 50260 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:15.874154091 CET | 445 | 50260 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:43:15.874170065 CET | 445 | 50260 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.278532028 CET | 445 | 50266 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.278657913 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:43:16.278707027 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:43:16.278753996 CET | 50266 | 445 | 192.168.2.6 | 198.205.43.1 |
Jan 14, 2025 22:43:16.283551931 CET | 445 | 50266 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.283562899 CET | 445 | 50266 | 198.205.43.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.335990906 CET | 50373 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.340893030 CET | 445 | 50373 | 198.205.43.2 | 192.168.2.6 |
Jan 14, 2025 22:43:16.341010094 CET | 50373 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.341010094 CET | 50373 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.341356993 CET | 50374 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.346013069 CET | 445 | 50373 | 198.205.43.2 | 192.168.2.6 |
Jan 14, 2025 22:43:16.346168995 CET | 50373 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.346183062 CET | 445 | 50374 | 198.205.43.2 | 192.168.2.6 |
Jan 14, 2025 22:43:16.346297026 CET | 50374 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.346297026 CET | 50374 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:16.351092100 CET | 445 | 50374 | 198.205.43.2 | 192.168.2.6 |
Jan 14, 2025 22:43:16.539485931 CET | 50375 | 445 | 192.168.2.6 | 34.215.102.165 |
Jan 14, 2025 22:43:16.544564009 CET | 445 | 50375 | 34.215.102.165 | 192.168.2.6 |
Jan 14, 2025 22:43:16.548563004 CET | 50375 | 445 | 192.168.2.6 | 34.215.102.165 |
Jan 14, 2025 22:43:16.550625086 CET | 50375 | 445 | 192.168.2.6 | 34.215.102.165 |
Jan 14, 2025 22:43:16.551224947 CET | 50376 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.556063890 CET | 445 | 50376 | 34.215.102.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.556171894 CET | 50376 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.556229115 CET | 50376 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.556684017 CET | 50377 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.558357954 CET | 445 | 50375 | 34.215.102.165 | 192.168.2.6 |
Jan 14, 2025 22:43:16.561542034 CET | 445 | 50377 | 34.215.102.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.561764002 CET | 50377 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.561863899 CET | 50377 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:16.562340975 CET | 445 | 50376 | 34.215.102.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.566639900 CET | 445 | 50377 | 34.215.102.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.567327023 CET | 445 | 50375 | 34.215.102.165 | 192.168.2.6 |
Jan 14, 2025 22:43:16.567400932 CET | 50375 | 445 | 192.168.2.6 | 34.215.102.165 |
Jan 14, 2025 22:43:16.567640066 CET | 445 | 50376 | 34.215.102.1 | 192.168.2.6 |
Jan 14, 2025 22:43:16.567714930 CET | 50376 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:17.367353916 CET | 50378 | 445 | 192.168.2.6 | 155.125.170.218 |
Jan 14, 2025 22:43:17.372390032 CET | 445 | 50378 | 155.125.170.218 | 192.168.2.6 |
Jan 14, 2025 22:43:17.372466087 CET | 50378 | 445 | 192.168.2.6 | 155.125.170.218 |
Jan 14, 2025 22:43:17.372493982 CET | 50378 | 445 | 192.168.2.6 | 155.125.170.218 |
Jan 14, 2025 22:43:17.372653961 CET | 50379 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.377495050 CET | 445 | 50379 | 155.125.170.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.377558947 CET | 50379 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.377585888 CET | 50379 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.377636909 CET | 445 | 50378 | 155.125.170.218 | 192.168.2.6 |
Jan 14, 2025 22:43:17.377829075 CET | 50378 | 445 | 192.168.2.6 | 155.125.170.218 |
Jan 14, 2025 22:43:17.377898932 CET | 50380 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.382850885 CET | 445 | 50379 | 155.125.170.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.382863998 CET | 445 | 50380 | 155.125.170.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.382901907 CET | 50379 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.382946014 CET | 50380 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.382989883 CET | 50380 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:17.388117075 CET | 445 | 50380 | 155.125.170.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.901696920 CET | 445 | 50278 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.903598070 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:17.904344082 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:17.904505968 CET | 50278 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:17.909080982 CET | 445 | 50278 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:43:17.909252882 CET | 445 | 50278 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.042232990 CET | 445 | 50280 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.042285919 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:43:18.042612076 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:43:18.042706013 CET | 50280 | 445 | 192.168.2.6 | 77.226.237.1 |
Jan 14, 2025 22:43:18.047367096 CET | 445 | 50280 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.047414064 CET | 445 | 50280 | 77.226.237.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.101610899 CET | 50381 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.106487036 CET | 445 | 50381 | 77.226.237.2 | 192.168.2.6 |
Jan 14, 2025 22:43:18.106589079 CET | 50381 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.106673956 CET | 50381 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.107037067 CET | 50382 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.111696005 CET | 445 | 50381 | 77.226.237.2 | 192.168.2.6 |
Jan 14, 2025 22:43:18.111767054 CET | 50381 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.111840963 CET | 445 | 50382 | 77.226.237.2 | 192.168.2.6 |
Jan 14, 2025 22:43:18.112013102 CET | 50382 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.112013102 CET | 50382 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:18.116822004 CET | 445 | 50382 | 77.226.237.2 | 192.168.2.6 |
Jan 14, 2025 22:43:18.133538008 CET | 50383 | 445 | 192.168.2.6 | 124.171.123.90 |
Jan 14, 2025 22:43:18.138381958 CET | 445 | 50383 | 124.171.123.90 | 192.168.2.6 |
Jan 14, 2025 22:43:18.138482094 CET | 50383 | 445 | 192.168.2.6 | 124.171.123.90 |
Jan 14, 2025 22:43:18.138571978 CET | 50383 | 445 | 192.168.2.6 | 124.171.123.90 |
Jan 14, 2025 22:43:18.138741970 CET | 50384 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.143441916 CET | 445 | 50383 | 124.171.123.90 | 192.168.2.6 |
Jan 14, 2025 22:43:18.143479109 CET | 445 | 50384 | 124.171.123.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.143510103 CET | 50383 | 445 | 192.168.2.6 | 124.171.123.90 |
Jan 14, 2025 22:43:18.143549919 CET | 50384 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.143620968 CET | 50384 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.144217968 CET | 50385 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.148484945 CET | 445 | 50384 | 124.171.123.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.148932934 CET | 50384 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.148977041 CET | 445 | 50385 | 124.171.123.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.149056911 CET | 50385 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.149523020 CET | 50385 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:18.154259920 CET | 445 | 50385 | 124.171.123.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.883130074 CET | 50387 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:18.887975931 CET | 445 | 50387 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:43:18.888036013 CET | 50387 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:18.888102055 CET | 50387 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:18.892812967 CET | 445 | 50387 | 204.188.17.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.195276022 CET | 445 | 50294 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.195341110 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:43:20.195389032 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:43:20.195527077 CET | 50294 | 445 | 192.168.2.6 | 107.175.251.1 |
Jan 14, 2025 22:43:20.200208902 CET | 445 | 50294 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.200275898 CET | 445 | 50294 | 107.175.251.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.258085012 CET | 50395 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.263019085 CET | 445 | 50395 | 107.175.251.2 | 192.168.2.6 |
Jan 14, 2025 22:43:20.263104916 CET | 50395 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.263168097 CET | 50395 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.263613939 CET | 50396 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.268131018 CET | 445 | 50395 | 107.175.251.2 | 192.168.2.6 |
Jan 14, 2025 22:43:20.268188953 CET | 50395 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.268368006 CET | 445 | 50396 | 107.175.251.2 | 192.168.2.6 |
Jan 14, 2025 22:43:20.268446922 CET | 50396 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.268740892 CET | 50396 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:20.273278952 CET | 445 | 50298 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.273339033 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:20.273514986 CET | 445 | 50396 | 107.175.251.2 | 192.168.2.6 |
Jan 14, 2025 22:43:20.275707960 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:20.275825977 CET | 50298 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:20.280504942 CET | 445 | 50298 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.280545950 CET | 445 | 50298 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.913898945 CET | 50400 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:20.918767929 CET | 445 | 50400 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:43:20.919123888 CET | 50400 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:20.919156075 CET | 50400 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:20.923929930 CET | 445 | 50400 | 87.122.116.1 | 192.168.2.6 |
Jan 14, 2025 22:43:21.565135002 CET | 445 | 50309 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:21.565231085 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:21.565231085 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:21.566323996 CET | 50309 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:21.570002079 CET | 445 | 50309 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:21.571073055 CET | 445 | 50309 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:22.069531918 CET | 445 | 50315 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.069598913 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:22.069633007 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:22.069677114 CET | 50315 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:22.075067997 CET | 445 | 50315 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.075103045 CET | 445 | 50315 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.116552114 CET | 445 | 50317 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.116734982 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:22.116734982 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:22.117310047 CET | 50317 | 445 | 192.168.2.6 | 37.134.68.1 |
Jan 14, 2025 22:43:22.121521950 CET | 445 | 50317 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.122042894 CET | 445 | 50317 | 37.134.68.1 | 192.168.2.6 |
Jan 14, 2025 22:43:22.179753065 CET | 50409 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.184611082 CET | 445 | 50409 | 37.134.68.2 | 192.168.2.6 |
Jan 14, 2025 22:43:22.184675932 CET | 50409 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.184711933 CET | 50409 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.185731888 CET | 50410 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.189754963 CET | 445 | 50409 | 37.134.68.2 | 192.168.2.6 |
Jan 14, 2025 22:43:22.189851999 CET | 50409 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.191628933 CET | 445 | 50410 | 37.134.68.2 | 192.168.2.6 |
Jan 14, 2025 22:43:22.191687107 CET | 50410 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.191869020 CET | 50410 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:22.198101997 CET | 445 | 50410 | 37.134.68.2 | 192.168.2.6 |
Jan 14, 2025 22:43:23.288898945 CET | 50420 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:23.293711901 CET | 445 | 50420 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:43:23.293828011 CET | 50420 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:23.293828011 CET | 50420 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:23.298599958 CET | 445 | 50420 | 136.139.192.1 | 192.168.2.6 |
Jan 14, 2025 22:43:23.944607019 CET | 445 | 50329 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:23.944664955 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:23.944694996 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:23.944744110 CET | 50329 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:23.949506044 CET | 445 | 50329 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:23.949518919 CET | 445 | 50329 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:24.147810936 CET | 445 | 50330 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:24.147895098 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:24.147958994 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:24.147988081 CET | 50330 | 445 | 192.168.2.6 | 219.121.211.1 |
Jan 14, 2025 22:43:24.152874947 CET | 445 | 50330 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:24.152903080 CET | 445 | 50330 | 219.121.211.1 | 192.168.2.6 |
Jan 14, 2025 22:43:24.211024046 CET | 50432 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.215872049 CET | 445 | 50432 | 219.121.211.2 | 192.168.2.6 |
Jan 14, 2025 22:43:24.215934038 CET | 50432 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.215954065 CET | 50432 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.216303110 CET | 50433 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.221174002 CET | 445 | 50433 | 219.121.211.2 | 192.168.2.6 |
Jan 14, 2025 22:43:24.221321106 CET | 445 | 50432 | 219.121.211.2 | 192.168.2.6 |
Jan 14, 2025 22:43:24.221379995 CET | 50432 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.221390009 CET | 50433 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.221404076 CET | 50433 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:24.226535082 CET | 445 | 50433 | 219.121.211.2 | 192.168.2.6 |
Jan 14, 2025 22:43:24.571594000 CET | 50439 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:24.576414108 CET | 445 | 50439 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:24.576519966 CET | 50439 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:24.576661110 CET | 50439 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:24.582345009 CET | 445 | 50439 | 197.9.206.2 | 192.168.2.6 |
Jan 14, 2025 22:43:25.070116997 CET | 50446 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:25.074862003 CET | 445 | 50446 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:25.074930906 CET | 50446 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:25.074961901 CET | 50446 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:25.079698086 CET | 445 | 50446 | 48.168.78.1 | 192.168.2.6 |
Jan 14, 2025 22:43:25.664139986 CET | 445 | 50333 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:25.664242983 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:25.664242983 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:25.664275885 CET | 50333 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:25.669168949 CET | 445 | 50333 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:25.669183016 CET | 445 | 50333 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:26.164263010 CET | 445 | 50334 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:26.164349079 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:26.164419889 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:26.164457083 CET | 50334 | 445 | 192.168.2.6 | 149.173.236.1 |
Jan 14, 2025 22:43:26.169262886 CET | 445 | 50334 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:26.169290066 CET | 445 | 50334 | 149.173.236.1 | 192.168.2.6 |
Jan 14, 2025 22:43:26.226418018 CET | 50468 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.231291056 CET | 445 | 50468 | 149.173.236.2 | 192.168.2.6 |
Jan 14, 2025 22:43:26.231369972 CET | 50468 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.231451035 CET | 50468 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.231770992 CET | 50469 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.236319065 CET | 445 | 50468 | 149.173.236.2 | 192.168.2.6 |
Jan 14, 2025 22:43:26.236430883 CET | 50468 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.236607075 CET | 445 | 50469 | 149.173.236.2 | 192.168.2.6 |
Jan 14, 2025 22:43:26.236670017 CET | 50469 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.236706018 CET | 50469 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:26.241622925 CET | 445 | 50469 | 149.173.236.2 | 192.168.2.6 |
Jan 14, 2025 22:43:26.945442915 CET | 50487 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:26.950347900 CET | 445 | 50487 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:26.950506926 CET | 50487 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:26.950506926 CET | 50487 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:26.955349922 CET | 445 | 50487 | 75.65.143.1 | 192.168.2.6 |
Jan 14, 2025 22:43:27.475986958 CET | 445 | 50337 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:27.476119041 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:27.476218939 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:27.476218939 CET | 50337 | 445 | 192.168.2.6 | 15.116.122.1 |
Jan 14, 2025 22:43:27.481014967 CET | 445 | 50337 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:27.481024981 CET | 445 | 50337 | 15.116.122.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.214255095 CET | 445 | 50338 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.214325905 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:28.214742899 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:28.214742899 CET | 50338 | 445 | 192.168.2.6 | 147.244.118.1 |
Jan 14, 2025 22:43:28.220400095 CET | 445 | 50338 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.220413923 CET | 445 | 50338 | 147.244.118.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.273483992 CET | 50528 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.278472900 CET | 445 | 50528 | 147.244.118.2 | 192.168.2.6 |
Jan 14, 2025 22:43:28.278548002 CET | 50528 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.278644085 CET | 50528 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.278959036 CET | 50529 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.283555031 CET | 445 | 50528 | 147.244.118.2 | 192.168.2.6 |
Jan 14, 2025 22:43:28.283606052 CET | 50528 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.283746958 CET | 445 | 50529 | 147.244.118.2 | 192.168.2.6 |
Jan 14, 2025 22:43:28.283802986 CET | 50529 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.283864975 CET | 50529 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:28.288589001 CET | 445 | 50529 | 147.244.118.2 | 192.168.2.6 |
Jan 14, 2025 22:43:28.680483103 CET | 50548 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:28.685468912 CET | 445 | 50548 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.685610056 CET | 50548 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:28.685972929 CET | 50548 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:28.690749884 CET | 445 | 50548 | 98.97.187.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.981524944 CET | 445 | 50341 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.983568907 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:28.983568907 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:28.987191916 CET | 50341 | 445 | 192.168.2.6 | 162.104.87.1 |
Jan 14, 2025 22:43:28.988890886 CET | 445 | 50341 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:28.992070913 CET | 445 | 50341 | 162.104.87.1 | 192.168.2.6 |
Jan 14, 2025 22:43:30.210352898 CET | 445 | 50343 | 144.165.243.1 | 192.168.2.6 |
Jan 14, 2025 22:43:30.210406065 CET | 50343 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:30.274518967 CET | 445 | 50346 | 76.252.20.1 | 192.168.2.6 |
Jan 14, 2025 22:43:30.274578094 CET | 50346 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:31.602730036 CET | 445 | 50349 | 18.142.24.1 | 192.168.2.6 |
Jan 14, 2025 22:43:31.602801085 CET | 50349 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:31.778955936 CET | 50363 | 445 | 192.168.2.6 | 109.252.120.1 |
Jan 14, 2025 22:43:31.779053926 CET | 50350 | 445 | 192.168.2.6 | 134.64.132.1 |
Jan 14, 2025 22:43:31.779077053 CET | 50358 | 445 | 192.168.2.6 | 198.74.23.1 |
Jan 14, 2025 22:43:31.779119015 CET | 50380 | 445 | 192.168.2.6 | 155.125.170.1 |
Jan 14, 2025 22:43:31.779155016 CET | 50420 | 445 | 192.168.2.6 | 136.139.192.1 |
Jan 14, 2025 22:43:31.779164076 CET | 50382 | 445 | 192.168.2.6 | 77.226.237.2 |
Jan 14, 2025 22:43:31.779403925 CET | 50377 | 445 | 192.168.2.6 | 34.215.102.1 |
Jan 14, 2025 22:43:31.779439926 CET | 50374 | 445 | 192.168.2.6 | 198.205.43.2 |
Jan 14, 2025 22:43:31.779469013 CET | 50400 | 445 | 192.168.2.6 | 87.122.116.1 |
Jan 14, 2025 22:43:31.779500961 CET | 50439 | 445 | 192.168.2.6 | 197.9.206.2 |
Jan 14, 2025 22:43:31.779534101 CET | 50433 | 445 | 192.168.2.6 | 219.121.211.2 |
Jan 14, 2025 22:43:31.779566050 CET | 50469 | 445 | 192.168.2.6 | 149.173.236.2 |
Jan 14, 2025 22:43:31.779645920 CET | 50346 | 445 | 192.168.2.6 | 76.252.20.1 |
Jan 14, 2025 22:43:31.779685974 CET | 50343 | 445 | 192.168.2.6 | 144.165.243.1 |
Jan 14, 2025 22:43:31.779717922 CET | 50349 | 445 | 192.168.2.6 | 18.142.24.1 |
Jan 14, 2025 22:43:31.779736996 CET | 50353 | 445 | 192.168.2.6 | 48.113.108.1 |
Jan 14, 2025 22:43:31.779759884 CET | 50355 | 445 | 192.168.2.6 | 18.1.0.2 |
Jan 14, 2025 22:43:31.779884100 CET | 50359 | 445 | 192.168.2.6 | 101.183.122.1 |
Jan 14, 2025 22:43:31.779897928 CET | 50365 | 445 | 192.168.2.6 | 6.147.7.2 |
Jan 14, 2025 22:43:31.779930115 CET | 50368 | 445 | 192.168.2.6 | 50.113.28.1 |
Jan 14, 2025 22:43:31.780005932 CET | 50369 | 445 | 192.168.2.6 | 78.63.44.1 |
Jan 14, 2025 22:43:31.780036926 CET | 50372 | 445 | 192.168.2.6 | 175.68.141.1 |
Jan 14, 2025 22:43:31.780106068 CET | 50385 | 445 | 192.168.2.6 | 124.171.123.1 |
Jan 14, 2025 22:43:31.780122995 CET | 50387 | 445 | 192.168.2.6 | 204.188.17.1 |
Jan 14, 2025 22:43:31.780147076 CET | 50396 | 445 | 192.168.2.6 | 107.175.251.2 |
Jan 14, 2025 22:43:31.780185938 CET | 50410 | 445 | 192.168.2.6 | 37.134.68.2 |
Jan 14, 2025 22:43:31.780251026 CET | 50446 | 445 | 192.168.2.6 | 48.168.78.1 |
Jan 14, 2025 22:43:31.780282974 CET | 50548 | 445 | 192.168.2.6 | 98.97.187.1 |
Jan 14, 2025 22:43:31.780361891 CET | 50487 | 445 | 192.168.2.6 | 75.65.143.1 |
Jan 14, 2025 22:43:31.781163931 CET | 50529 | 445 | 192.168.2.6 | 147.244.118.2 |
Jan 14, 2025 22:43:55.039382935 CET | 49707 | 80 | 192.168.2.6 | 2.23.77.188 |
Jan 14, 2025 22:43:55.039558887 CET | 49706 | 80 | 192.168.2.6 | 199.232.210.172 |
Jan 14, 2025 22:43:55.039617062 CET | 49705 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:43:55.044620037 CET | 80 | 49707 | 2.23.77.188 | 192.168.2.6 |
Jan 14, 2025 22:43:55.044696093 CET | 49707 | 80 | 192.168.2.6 | 2.23.77.188 |
Jan 14, 2025 22:43:55.045069933 CET | 80 | 49706 | 199.232.210.172 | 192.168.2.6 |
Jan 14, 2025 22:43:55.045084953 CET | 443 | 49705 | 40.126.32.138 | 192.168.2.6 |
Jan 14, 2025 22:43:55.045125008 CET | 49706 | 80 | 192.168.2.6 | 199.232.210.172 |
Jan 14, 2025 22:43:55.045156956 CET | 49705 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:43:57.007627010 CET | 49708 | 80 | 192.168.2.6 | 2.23.77.188 |
Jan 14, 2025 22:43:57.007746935 CET | 49711 | 80 | 192.168.2.6 | 199.232.210.172 |
Jan 14, 2025 22:43:57.012769938 CET | 80 | 49708 | 2.23.77.188 | 192.168.2.6 |
Jan 14, 2025 22:43:57.012836933 CET | 49708 | 80 | 192.168.2.6 | 2.23.77.188 |
Jan 14, 2025 22:43:57.013057947 CET | 80 | 49711 | 199.232.210.172 | 192.168.2.6 |
Jan 14, 2025 22:43:57.013109922 CET | 49711 | 80 | 192.168.2.6 | 199.232.210.172 |
Jan 14, 2025 22:43:57.554503918 CET | 49709 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:43:57.554728031 CET | 49713 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:43:57.565479040 CET | 443 | 49709 | 40.126.32.138 | 192.168.2.6 |
Jan 14, 2025 22:43:57.565566063 CET | 443 | 49713 | 40.126.32.138 | 192.168.2.6 |
Jan 14, 2025 22:43:57.565612078 CET | 49709 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:43:57.565639973 CET | 49713 | 443 | 192.168.2.6 | 40.126.32.138 |
Jan 14, 2025 22:44:31.808182955 CET | 50671 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:44:31.813070059 CET | 80 | 50671 | 103.224.212.215 | 192.168.2.6 |
Jan 14, 2025 22:44:31.813152075 CET | 50671 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:44:31.813306093 CET | 50671 | 80 | 192.168.2.6 | 103.224.212.215 |
Jan 14, 2025 22:44:31.819082975 CET | 80 | 50671 | 103.224.212.215 | 192.168.2.6 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 14, 2025 22:42:22.947624922 CET | 65461 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 14, 2025 22:42:23.249906063 CET | 53 | 65461 | 1.1.1.1 | 192.168.2.6 |
Jan 14, 2025 22:42:23.871413946 CET | 50064 | 53 | 192.168.2.6 | 1.1.1.1 |
Jan 14, 2025 22:42:24.198791981 CET | 53 | 50064 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 14, 2025 22:42:22.947624922 CET | 192.168.2.6 | 1.1.1.1 | 0x98f | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 14, 2025 22:42:23.871413946 CET | 192.168.2.6 | 1.1.1.1 | 0xbc49 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 14, 2025 22:42:17.753376961 CET | 1.1.1.1 | 192.168.2.6 | 0x6c4f | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 22:42:17.753376961 CET | 1.1.1.1 | 192.168.2.6 | 0x6c4f | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 22:42:23.249906063 CET | 1.1.1.1 | 192.168.2.6 | 0x98f | No error (0) | 103.224.212.215 | A (IP address) | IN (0x0001) | false | ||
Jan 14, 2025 22:42:24.198791981 CET | 1.1.1.1 | 192.168.2.6 | 0xbc49 | No error (0) | 77026.bodis.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 14, 2025 22:42:24.198791981 CET | 1.1.1.1 | 192.168.2.6 | 0xbc49 | No error (0) | 199.59.243.228 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 49751 | 103.224.212.215 | 80 | 6900 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:23.261267900 CET | 100 | OUT | |
Jan 14, 2025 22:42:23.864964008 CET | 365 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 49757 | 199.59.243.228 | 80 | 6900 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:24.228266001 CET | 169 | OUT | |
Jan 14, 2025 22:42:24.670315027 CET | 1236 | IN | |
Jan 14, 2025 22:42:24.670336008 CET | 696 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 49763 | 103.224.212.215 | 80 | 3656 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:25.025501013 CET | 100 | OUT | |
Jan 14, 2025 22:42:25.659610033 CET | 365 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 49769 | 199.59.243.228 | 80 | 3656 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:25.670867920 CET | 169 | OUT | |
Jan 14, 2025 22:42:26.125848055 CET | 1236 | IN | |
Jan 14, 2025 22:42:26.125866890 CET | 696 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 49770 | 103.224.212.215 | 80 | 2580 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:25.822977066 CET | 134 | OUT | |
Jan 14, 2025 22:42:26.411207914 CET | 269 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 49784 | 199.59.243.228 | 80 | 2580 | C:\Windows\mssecsvr.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:42:26.443507910 CET | 231 | OUT | |
Jan 14, 2025 22:42:26.888611078 CET | 1236 | IN | |
Jan 14, 2025 22:42:26.888628006 CET | 688 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
6 | 192.168.2.6 | 50671 | 103.224.212.215 | 80 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 14, 2025 22:44:31.813306093 CET | 100 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.6 | 50141 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:47 UTC | 346 | OUT | |
2025-01-14 21:42:47 UTC | 854 | IN | |
2025-01-14 21:42:47 UTC | 15530 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16067 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.6 | 50144 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:47 UTC | 375 | OUT | |
2025-01-14 21:42:47 UTC | 854 | IN | |
2025-01-14 21:42:47 UTC | 15530 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16067 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.6 | 50145 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:47 UTC | 346 | OUT | |
2025-01-14 21:42:47 UTC | 854 | IN | |
2025-01-14 21:42:47 UTC | 15530 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16067 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.6 | 50149 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:47 UTC | 346 | OUT | |
2025-01-14 21:42:47 UTC | 854 | IN | |
2025-01-14 21:42:47 UTC | 15530 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16067 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN | |
2025-01-14 21:42:47 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.6 | 50163 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:48 UTC | 375 | OUT | |
2025-01-14 21:42:48 UTC | 856 | IN | |
2025-01-14 21:42:48 UTC | 15528 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16069 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN | |
2025-01-14 21:42:48 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.6 | 50183 | 150.171.28.10 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-14 21:42:49 UTC | 346 | OUT | |
2025-01-14 21:42:49 UTC | 854 | IN | |
2025-01-14 21:42:49 UTC | 15530 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16067 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN | |
2025-01-14 21:42:49 UTC | 16384 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\System32\loaddll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xa90000 |
File size: | 126'464 bytes |
MD5 hash: | 51E6071F9CBA48E79F10C84515AAE618 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1c0000 |
File size: | 236'544 bytes |
MD5 hash: | D0FCE3AFA6AA1D58CE9FA336CC2B675B |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2e0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2e0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 16:42:21 |
Start date: | 14/01/2025 |
Path: | C:\Windows\mssecsvr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'281'472 bytes |
MD5 hash: | 0F00DC99F94FDCA3721D0692B2ACACCD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 7 |
Start time: | 16:42:23 |
Start date: | 14/01/2025 |
Path: | C:\Windows\mssecsvr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'281'472 bytes |
MD5 hash: | 0F00DC99F94FDCA3721D0692B2ACACCD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 8 |
Start time: | 16:42:24 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\rundll32.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x2e0000 |
File size: | 61'440 bytes |
MD5 hash: | 889B99C52A60DD49227C5E485A016679 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 16:42:24 |
Start date: | 14/01/2025 |
Path: | C:\Windows\mssecsvr.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'281'472 bytes |
MD5 hash: | 0F00DC99F94FDCA3721D0692B2ACACCD |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 10 |
Start time: | 16:42:25 |
Start date: | 14/01/2025 |
Path: | C:\Windows\tasksche.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'061'938 bytes |
MD5 hash: | E2105F086EAB75BD8CDD2B6975E9CE80 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Antivirus matches: |
|
Reputation: | low |
Has exited: | true |
Target ID: | 11 |
Start time: | 16:42:25 |
Start date: | 14/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 16:42:25 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 16:42:25 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 16:42:26 |
Start date: | 14/01/2025 |
Path: | C:\Windows\tasksche.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 2'061'938 bytes |
MD5 hash: | E2105F086EAB75BD8CDD2B6975E9CE80 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 15 |
Start time: | 16:42:26 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 16 |
Start time: | 16:42:26 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 17 |
Start time: | 16:42:26 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 18 |
Start time: | 16:42:27 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 19 |
Start time: | 16:42:27 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 20 |
Start time: | 16:42:27 |
Start date: | 14/01/2025 |
Path: | C:\Windows\SysWOW64\WerFault.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x640000 |
File size: | 483'680 bytes |
MD5 hash: | C31336C1EFC2CCB44B4326EA793040F2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 31 |
Start time: | 16:43:18 |
Start date: | 14/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Execution Graph
Execution Coverage: | 71.7% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 63.2% |
Total number of Nodes: | 38 |
Total number of Limit Nodes: | 9 |
Graph
Callgraph
Function 00407CE0 Relevance: 50.9, APIs: 18, Strings: 11, Instructions: 175libraryloaderfileCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409A16 Relevance: 16.6, APIs: 11, Instructions: 111COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00408140 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 45networkCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00407C40 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 54serviceCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00408090 Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 49serviceCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Execution Graph
Execution Coverage: | 34.8% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 0% |
Total number of Nodes: | 36 |
Total number of Limit Nodes: | 2 |
Graph
Callgraph
Function 00408090 Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 49serviceCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00408140 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 45networkCOMMON
Control-flow Graph
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00407C40 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 54serviceCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00407CE0 Relevance: 40.4, APIs: 12, Strings: 11, Instructions: 175libraryloaderCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Function 00409A16 Relevance: 16.6, APIs: 11, Instructions: 111COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|