Windows
Analysis Report
Invdoc80.pdf
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- Acrobat.exe (PID: 7520 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \Desktop\I nvdoc80.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7684 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7884 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 56 --field -trial-han dle=1576,i ,480780792 4822789699 ,114709840 4271959711 0,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- chrome.exe (PID: 8608 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --st art-maximi zed "https ://oulkiat e.s3.ap-so utheast-1. amazonaws. com/index. html" MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4) - chrome.exe (PID: 8796 cmdline:
"C:\Progra m Files\Go ogle\Chrom e\Applicat ion\chrome .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --mojo-pla tform-chan nel-handle =2016 --fi eld-trial- handle=199 2,i,172731 6769156087 8123,81731 3934269220 9947,26214 4 /prefetc h:8 MD5: 45DE480806D1B5D462A7DDE4DCEFC4E4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_HtmlPhish_44 | Yara detected HtmlPhish_44 | Joe Security |
Click to jump to signature section
AV Detection |
---|
Source: | Avira URL Cloud: |
Phishing |
---|
Source: | File source: |
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: | ||
Source: | Joe Sandbox AI: |
Source: | HTTP Parser: | ||
Source: | HTTP Parser: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | Classification label: |
Source: | Initial sample: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Window detected: |
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: | ||
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Spearphishing Link | Windows Management Instrumentation | 2 Browser Extensions | 1 Process Injection | 1 Masquerading | OS Credential Dumping | 1 System Information Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Process Injection | LSASS Memory | Application Window Discovery | Remote Desktop Protocol | Data from Removable Media | 4 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | Obfuscated Files or Information | Security Account Manager | Query Registry | SMB/Windows Admin Shares | Data from Network Shared Drive | 5 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira URL Cloud | phishing | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | high | |
a.nel.cloudflare.com | 35.190.80.1 | true | false | high | |
code.jquery.com | 151.101.130.137 | true | false | high | |
www.google.com | 216.58.206.36 | true | false | high | |
s3-r-w.ap-southeast-1.amazonaws.com | 52.219.125.106 | true | false | high | |
sgd.trilivarnor.ru | 104.21.18.22 | true | true | unknown | |
oulkiate.s3.ap-southeast-1.amazonaws.com | unknown | unknown | true | unknown | |
x1.i.lencr.org | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
true | unknown | ||
false | high | ||
false | unknown | ||
false |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
true | unknown | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
104.21.18.22 | sgd.trilivarnor.ru | United States | 13335 | CLOUDFLARENETUS | true | |
52.219.125.106 | s3-r-w.ap-southeast-1.amazonaws.com | United States | 16509 | AMAZON-02US | false | |
216.58.206.36 | www.google.com | United States | 15169 | GOOGLEUS | false | |
151.101.130.137 | code.jquery.com | United States | 54113 | FASTLYUS | false | |
239.255.255.250 | unknown | Reserved | unknown | unknown | false | |
151.101.66.137 | unknown | United States | 54113 | FASTLYUS | false | |
35.190.80.1 | a.nel.cloudflare.com | United States | 15169 | GOOGLEUS | false |
IP |
---|
192.168.2.4 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591561 |
Start date and time: | 2025-01-15 04:44:37 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 49s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowspdfcookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 13 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Invdoc80.pdf |
Detection: | MAL |
Classification: | mal64.phis.winPDF@44/56@13/8 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, WmiPrvSE.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 3.219.243.226, 52.22.41.97, 52.6.155.20, 3.233.129.217, 2.16.168.105, 2.16.168.107, 172.64.41.3, 162.159.61.3, 23.209.209.135, 199.232.210.172, 184.30.131.245, 216.58.206.67, 216.58.212.142, 74.125.133.84, 142.250.185.110, 142.250.184.206, 142.250.185.170, 142.250.185.138, 142.250.186.74, 142.250.184.234, 142.250.186.138, 142.250.185.74, 142.250.185.234, 142.250.185.202, 142.250.186.170, 142.250.186.106, 172.217.16.202, 172.217.18.10, 216.58.212.138, 142.250.186.42, 216.58.206.74, 142.250.185.106, 172.217.23.106, 142.250.74.202, 216.58.206.78, 142.250.186.46, 172.217.16.206, 142.250.64.78, 74.125.0.102, 172.217.18.14, 142.250.65.174, 142.250.185.131, 142.250.184.238, 2.23.242.162, 23.56.162.204, 4.175.87.197, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, clientservices.googleapis.com, acroipm2.adobe.com, clients2.google.com, ocsp.digicert.com, redirector.gvt1.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, update.googleapis.com, r1---sn-t0aekn7e.gvt1.com, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, optimizationguide-pa.googleapis.com, clients1.google.com, fs.microsoft.com, accounts.google.com, content-autofill.googleapis.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, edgedl.me.gvt1.com, armmf.adobe.com, r1.sn-t0aekn7e.gvt1.com, clients.l.google.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Some HTTPS proxied raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
22:45:50 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
239.255.255.250 | Get hash | malicious | HTMLPhisher | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
151.101.66.137 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
151.101.130.137 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s3-r-w.ap-southeast-1.amazonaws.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Phisher | Browse |
| ||
code.jquery.com | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
FASTLYUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
FASTLYUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.208515410706153 |
Encrypted: | false |
SSDEEP: | 6:iO83V8yq2Pwkn2nKuAl9OmbnIFUtW3Vxz1Zmwo3VxlRkwOwkn2nKuAl9OmbjLJ:7KV8yvYfHAahFUt4VxZ/GVxlR5JfHAae |
MD5: | C5A738CC604F4A4A3CC9205388712C24 |
SHA1: | 42A037F59EEB9CBD27E73A6328B271AFF9A74E90 |
SHA-256: | 92E183F18330FC1DD166147A71D6BCDB41AB8D0D990AF332C22850819B4CE5EE |
SHA-512: | 97B1557D6BADC7A2A6538B4C12B2ECC79C633804E0163017058201BD46BE698CB643D6349FC57F64E04B8B730DEF5D084B87C1C766B3337FAEF6E2CC58C08E39 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.208515410706153 |
Encrypted: | false |
SSDEEP: | 6:iO83V8yq2Pwkn2nKuAl9OmbnIFUtW3Vxz1Zmwo3VxlRkwOwkn2nKuAl9OmbjLJ:7KV8yvYfHAahFUt4VxZ/GVxlR5JfHAae |
MD5: | C5A738CC604F4A4A3CC9205388712C24 |
SHA1: | 42A037F59EEB9CBD27E73A6328B271AFF9A74E90 |
SHA-256: | 92E183F18330FC1DD166147A71D6BCDB41AB8D0D990AF332C22850819B4CE5EE |
SHA-512: | 97B1557D6BADC7A2A6538B4C12B2ECC79C633804E0163017058201BD46BE698CB643D6349FC57F64E04B8B730DEF5D084B87C1C766B3337FAEF6E2CC58C08E39 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.24274809173656 |
Encrypted: | false |
SSDEEP: | 6:iO83VyFL+q2Pwkn2nKuAl9Ombzo2jMGIFUtW3Vfm1Zmwo3VfLVkwOwkn2nKuAl97:7KVmyvYfHAa8uFUt4VY/GVfR5JfHAa8z |
MD5: | 23AB952C55108F2FDE3512FC917B1107 |
SHA1: | D780D8540A344F39FF4FFCFE783D4FD7AD5EA19A |
SHA-256: | 0E57F12A8667FEA9B8D9660FBD5B46F6A2300467B870E37CA56425505EBFAB69 |
SHA-512: | C6942C50C19DCAE57381FAD57A63E22A9F72D42C3D44948ADE6F0E5A7B9A510C339E12E08D271D3D6C502C0D57C50053759AA3024F01A926647460812369C94A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.24274809173656 |
Encrypted: | false |
SSDEEP: | 6:iO83VyFL+q2Pwkn2nKuAl9Ombzo2jMGIFUtW3Vfm1Zmwo3VfLVkwOwkn2nKuAl97:7KVmyvYfHAa8uFUt4VY/GVfR5JfHAa8z |
MD5: | 23AB952C55108F2FDE3512FC917B1107 |
SHA1: | D780D8540A344F39FF4FFCFE783D4FD7AD5EA19A |
SHA-256: | 0E57F12A8667FEA9B8D9660FBD5B46F6A2300467B870E37CA56425505EBFAB69 |
SHA-512: | C6942C50C19DCAE57381FAD57A63E22A9F72D42C3D44948ADE6F0E5A7B9A510C339E12E08D271D3D6C502C0D57C50053759AA3024F01A926647460812369C94A |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\3df44dd0-786a-4f0d-93f6-2d651fac7a64.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.9720157075394615 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq5lIDsBdOg2H1caq3QYiubInP7E4T3y:Y2sRdsAGEdMH03QYhbG7nby |
MD5: | A02EAFBF38032CA262ED5382AB459F50 |
SHA1: | BFCE73EF00E94FC19339B217AEEA8A94AA639F80 |
SHA-256: | C6781F8EC7020B0A1DFC02E74DEA6BC4B95AF196061ED2FD77B9E481D7029A72 |
SHA-512: | 9B4DACFEC2C7986E976687AEB9E1008F5DECE6959088C06360579F67653AA139851C8B78DE4FB0C1B9A8558EB28F76DF4A9A9AA0652704FF12017E89D9F69ABF |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.9720157075394615 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq5lIDsBdOg2H1caq3QYiubInP7E4T3y:Y2sRdsAGEdMH03QYhbG7nby |
MD5: | A02EAFBF38032CA262ED5382AB459F50 |
SHA1: | BFCE73EF00E94FC19339B217AEEA8A94AA639F80 |
SHA-256: | C6781F8EC7020B0A1DFC02E74DEA6BC4B95AF196061ED2FD77B9E481D7029A72 |
SHA-512: | 9B4DACFEC2C7986E976687AEB9E1008F5DECE6959088C06360579F67653AA139851C8B78DE4FB0C1B9A8558EB28F76DF4A9A9AA0652704FF12017E89D9F69ABF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4730 |
Entropy (8bit): | 5.25457266241917 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7iD3wD65Z:etJCV4FiN/jTN/2r8Mta02fEhgO73goI |
MD5: | B35A74D2D42064FECEE7E64E9E93B974 |
SHA1: | 6335BEE08926DB02B8EACFA514DA0A1F53A2C691 |
SHA-256: | 79C597F3456C8CEDD12A5B54D6B4E374F1B7CD0001BDDF71899C2FCFB0B2B71D |
SHA-512: | 15371FD8668F388DEB58C22FF43AF1AAB6A88D5ADF24CE866055A9A84FD1ED9EC4744DFA71D2E84FCAE469BE7ACA6B2657A1DEBBAC834BEB2C0FFB3A7C0A5A3E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.253858478870673 |
Encrypted: | false |
SSDEEP: | 6:iO83VXL+q2Pwkn2nKuAl9OmbzNMxIFUtW3V/T1Zmwo3VtIdjLVkwOwkn2nKuAl9c:7KVXyvYfHAa8jFUt4V/5/GVSdjR5JfHP |
MD5: | 19C4CC67AD21FECF906C37BAA3E02E63 |
SHA1: | 59CFC69FCCACEAB678FD647850DBC1F8A1208145 |
SHA-256: | F77E411A16BD78B7468AE70C8D6691184C28F74DAFEB2D386961F23A3A356074 |
SHA-512: | 5783093E417D7E1C5A6C99E087B6268947959D473D07D4F87551C4324A843D891AEB4D2EBDA86EC3E325A322582A7A7E1D827834F5DA2C604EF9406EA6232A92 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.253858478870673 |
Encrypted: | false |
SSDEEP: | 6:iO83VXL+q2Pwkn2nKuAl9OmbzNMxIFUtW3V/T1Zmwo3VtIdjLVkwOwkn2nKuAl9c:7KVXyvYfHAa8jFUt4V/5/GVSdjR5JfHP |
MD5: | 19C4CC67AD21FECF906C37BAA3E02E63 |
SHA1: | 59CFC69FCCACEAB678FD647850DBC1F8A1208145 |
SHA-256: | F77E411A16BD78B7468AE70C8D6691184C28F74DAFEB2D386961F23A3A356074 |
SHA-512: | 5783093E417D7E1C5A6C99E087B6268947959D473D07D4F87551C4324A843D891AEB4D2EBDA86EC3E325A322582A7A7E1D827834F5DA2C604EF9406EA6232A92 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\Acrobat\DC\ConnectorIcons\icon-250115034541Z-155.bmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71190 |
Entropy (8bit): | 0.9434962480212884 |
Encrypted: | false |
SSDEEP: | 48:nK+R34h98xFM9Zcdt6f7NGM9MYtG3AFBQppppppppppppppppppppppppppppppQ:U98zM9OdOJGM9MY8AFmNMMWGM9ycZn |
MD5: | 0B65B25FCDFFEFD4EA8B98C7628BEC90 |
SHA1: | 6C69854487CBF65F31B08BF38F4E144BA949D045 |
SHA-256: | 816C80A163661DAB0538CE968DBB412F1118CADF361762858BB2FF5AAEA50481 |
SHA-512: | 4B8CA3C8E5E2477D23DFA8CFD86C061D1A639B79436F8967803D3869C614CEB0ED3826CA9CFC3731B3E8E2CACCAA3312ED38A1D5B68A5F95E2E5137605508622 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445251049092317 |
Encrypted: | false |
SSDEEP: | 384:yezci5t4iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:rfs3OazzU89UTTgUL |
MD5: | E5F7AE9604AD802146C9EA276F31D341 |
SHA1: | 73FD7FA812CD86669A48DF9B188B7942004072F6 |
SHA-256: | CA2E42D6D31604C91C7B87D9F6B74F89DBE8101B6AF6BE6F09EFF980494FE1A1 |
SHA-512: | 17C6CA88A70F42ECB888E8170F35436ABB700940A29A6B899907844EFB771825F81E3717B00570D3D9B4284D8688C85A063A59D1C8D1D3F9A9B63A58CE399D23 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 3.7775637056845643 |
Encrypted: | false |
SSDEEP: | 48:7Mwp/E2ioyVo9ioy9oWoy1Cwoy1pmKOioy1noy1AYoy1Wioy1hioybioyzCoy1nT:7Tpjuo9F6eXKQsAQnb9IVXEBodRBks |
MD5: | 10BE2CFB8B78DF0F23E36ED55616F63B |
SHA1: | F69972AF1BE601C18BE28E796B24287CF32506E2 |
SHA-256: | 745C062DA8A1BF39A61BC5D9E40D7CA45F9C55FB7744476B27734FE3C0BF87B4 |
SHA-512: | 0EA30D7F9A8852DA906616BB788F8E2378BBFD4BADD7F2F01820091E05F6C787F65CA0F0832BE44600E085933B83DD8D6546B29AA68FB4AE9E3031F197ADDE81 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFkl/Rju+k31fllXlE/HT8kwJ1NNX8RolJuRdxLlGB9lQRYwpDdt:kKv+kmT8V7NMa8RdWBwRd |
MD5: | 67CC7B7E869FA30E39B9ED7A50C44D5C |
SHA1: | 61A8FBF149D40735E57BE7722B50CFDE69E17C37 |
SHA-256: | C269E46F7D6E529F1FAA5557F80FD012CA8EBC705959ED76DAE3B21334805053 |
SHA-512: | 164DFE58E1747EABCDFAFD6AA5AB6331874011C2AA0D83786A26AAED8400CC87DA307A9FD6C585615B04C24F75FD33877FEB568A3A926ED422FCE0ECA85723C1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2181539600449063 |
Encrypted: | false |
SSDEEP: | 6:kK449UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:gDDImsLNkPlE99SNxAhUe/3 |
MD5: | 27816EE3626C6064CDBE4CF0EB647490 |
SHA1: | E9AD370577F581F387DC3A8B0C304A9420A05D35 |
SHA-256: | 911917558CFEDA06A357A268BCFE7F200729F3FA64AEE96385F4B56EB488373F |
SHA-512: | D7BC6CE781DF993808B23656B182ECCDF7F82BB4F80E3F22ECA04ED5AC7CC2C33D11837E5C28E3A90EA69E13C8CADC37BE7152AE3D2F29241FE79C76A16B3073 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 243196 |
Entropy (8bit): | 3.3450692389394283 |
Encrypted: | false |
SSDEEP: | 1536:vKPCPiyzDtrh1cK3XEivK7VK/3AYvYwgqErRo+RQn:yPClJ/3AYvYwghFo+RQn |
MD5: | F5567C4FF4AB049B696D3BE0DD72A793 |
SHA1: | EBEADDE9FF0AF2C201A5F7CC747C9EA61CFA6916 |
SHA-256: | D8DBFE71873929825A420F73821F3FF0254D51984FAAA82E1B89D31188F77C04 |
SHA-512: | E769735991E5B1331E259608854D00CDA4F3E92285FDC500158CBD09CBCCEAD8A387F78256A43919B13EBE70C995D19242377C315B0CCBBD4F813251608C1D56 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.344188704136046 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJM3g98kUwPeUkwRe9:YvXKXfbI4SDkZc0v6zGMbLUkee9 |
MD5: | 5D55199F99C701E94FF503C1A4EF1C40 |
SHA1: | 04AC3B5D303AB167A4C9481AF4237E10FD2EEB73 |
SHA-256: | 639D2BF61060EBEBD16ECC2FED0A52B718E507456A65AA75DED9767FDE4422D8 |
SHA-512: | C001D6E61B9E36B7E68A1CCEB6329AB928EEA9B1135D424DF2ED482175FA117E6A33E0A9CBBB02E50611AC9CCFD70ABF7DF908134B7B9D4C28C41A41F32FD14E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.295142401082559 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfBoTfXpnrPeUkwRe9:YvXKXfbI4SDkZc0v6zGWTfXcUkee9 |
MD5: | A0EBD0D0F75CCB661628AB497648BC65 |
SHA1: | 2760FA0D31425D891D4CC4F584CDF218F5D9D16B |
SHA-256: | F2433551B0CBBB3193664C304E31C093071BBA2324931DF8E7D3E406F72D5111 |
SHA-512: | 0FC0792BBEDB5D0B29F47F24A0CA03192209F5B5083C7E58FB6DCB2206696858590F33BD11BCE160DEAA8907E4EBA9A6822334B609EA452031DBA2DA2044A19B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2726146502861875 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfBD2G6UpnrPeUkwRe9:YvXKXfbI4SDkZc0v6zGR22cUkee9 |
MD5: | CF26F5C5F0332D2F2D02830AB06E0651 |
SHA1: | B07D864C9246AD387C820144D6F26669F40CE3B7 |
SHA-256: | FE7414AF3844B2C2F7123BB646AA28FA77BB53C75C9BE212DCE2B5881CEC3CA8 |
SHA-512: | C242F43CED9A2ECCA5B7E898B4646FDD3326DCA8D4AC81BC9A62A247478A8AB3BFC5DC45ABF5DC23EF68D5DD3889916E6C1C2B87DEFBA58C2F85F55A15128201 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.330526414465201 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfPmwrPeUkwRe9:YvXKXfbI4SDkZc0v6zGH56Ukee9 |
MD5: | 7EC5BCD301C38914D9E2789A07B382E9 |
SHA1: | 35A451D815B19B8F129EBBA271AD9AA5CEFDC188 |
SHA-256: | DCA174C68305F9A65E4A597EDD4130742035B13E9CBDEC723BFD761BBDF2A46E |
SHA-512: | 8C34566F1C7B9710D57B7FCC60E814289B71FF347A666F66789295D32AFA61DDBDBC121276E6978404862925C68D8911E8E7AC2A194FD34040793593AD685E7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.683455292741471 |
Encrypted: | false |
SSDEEP: | 24:Yv6XU4SDkzv6opLgE9cQx8LennAvzBvkn0RCmK8czOCCSH:YvoSDsXhgy6SAFv5Ah8cv/H |
MD5: | 1AA29D083EBD14AB5AB7F35990BEC20D |
SHA1: | C32C019538D645172AE5D33B78DBFB6887730419 |
SHA-256: | 003AA4D563F7A238BB90DF53597FEEA0E101D21A4BD554A8A5A691E22B7CA38A |
SHA-512: | 4247C7D2CE02FD4ECC4C7E6F3835D5F7F97338DB94984A4641F396D5F5A88BF12F07F54BAC2D7A7D151AA582D6912FB7C94A38BDC148CB0A80ED8E5F9DDD2E43 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.27733501151744 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJf8dPeUkwRe9:YvXKXfbI4SDkZc0v6zGU8Ukee9 |
MD5: | 98B4C013007A2248FFE0175A9A94EBA4 |
SHA1: | EB66B16554BD7C245669FBD6718C795F5A53C0C4 |
SHA-256: | A9B1EE80B2BD3DF2D0E7293491DC12CDD9359676D82AE18DBB14C6DC0F48DE7C |
SHA-512: | 6915489A71BB526E1B0C395E63361E0FF0F99429AAB7968956171B2E1F44867A94A303FCFF1E6DD7AF0609ABD72AF2AB0E649C1E3E8AB0AA37A51F687D16BBB6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.282050105403242 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfQ1rPeUkwRe9:YvXKXfbI4SDkZc0v6zGY16Ukee9 |
MD5: | 48E7449ABC07F3AB74F6E47A9EB8C1D0 |
SHA1: | 499729C588B2E5D2ACA9359C29B481103022BB0B |
SHA-256: | B47686959632E842F0E6C37BCEE81B152AC4BF1929123BC2BF9AC943F88BD187 |
SHA-512: | EF0FAB1119053F785D64B8D8E29495C09C1FBCD3E0FBD53D1D468F42A1B5790A3ACF75230052F862C1C8C0491874E724C6E67F812FDCDECAC81DB94364B69C1F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.288514197742661 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfFldPeUkwRe9:YvXKXfbI4SDkZc0v6zGz8Ukee9 |
MD5: | B4EEDBD89298741A76A1727E221827B9 |
SHA1: | D647B1D587E8C8FDC15861F921AE9A835FF59CB8 |
SHA-256: | E253E0052CA39ACD14B434F5B70CACCA83E0BA64B54E974800C1882734B45A99 |
SHA-512: | A07F0629DF56FF50D79CAAC5A29A928B38EC45DDB425969A38A26702AF794E9B1D2B62804B881B8AF01EB6132E0B57A692F5EC69A3086E2690CAEEC8DCC2B78C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.304184362897416 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfzdPeUkwRe9:YvXKXfbI4SDkZc0v6zGb8Ukee9 |
MD5: | E27EF90BA1209A97AC1B7FBE1BAC06DC |
SHA1: | DEC1A60D67A9EC12312DC0CDEEE4AD43168C9D39 |
SHA-256: | B0CB3CC664506B9A95E1272F834993A6A076BC0C9229C16304EE5E8696DDE878 |
SHA-512: | F71EAB540C326246DE7B57489BDECAF9652A7D546474406A72607F1BD812BDCBCD99F225E6B4B4C1ED0D4B85B06B76CB21E3C732EA7C617B1BB2B08DD5CD06DE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.284790442891288 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfYdPeUkwRe9:YvXKXfbI4SDkZc0v6zGg8Ukee9 |
MD5: | 555197FAEAB718ECCF41AEF28672618C |
SHA1: | 0DDDCE76E0C52C5CAA83C2046C428052D56AA66F |
SHA-256: | 41229E73E03A1085C85B89DD8DC79492754D308223AC60FE6D958C5EF5098526 |
SHA-512: | 1516AB15616E4848976A5CFAA9332E2B926F8EBF8D6A1A98609E06B76C6D01DB39A46521B9A4C9AF780C52D8BD86FF92025320982532D43FCA9EBCF3908B3EFD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.270573041821403 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJf+dPeUkwRe9:YvXKXfbI4SDkZc0v6zG28Ukee9 |
MD5: | D5777B640CE06635FE861FDBF952320F |
SHA1: | 008D197F71AFF24AECD44067E76A1541D7558DE5 |
SHA-256: | C1B0A588E14DE8F1A953F10CA7F133F5F2EC16973FE497C5D16757437DF7BA56 |
SHA-512: | 434C53FA7E762C40291C482E7559A415A6F39F3186FAC4835BAA2E4520C49EE4C11458CDBBCB6DB7ACEDDA491DC0F19097C4D18E576CED838651380EEC1BC29A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.2684420736037 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfbPtdPeUkwRe9:YvXKXfbI4SDkZc0v6zGDV8Ukee9 |
MD5: | B4FD5E09598CC0EDE6ADE0F7076B0829 |
SHA1: | D437D52FCC2AFA6E3DF08CE61B48DC33607EABB3 |
SHA-256: | D2D900344C1130D2DD37FD11ACE1C4C6EA952AD4FE265271A84437733F0316D9 |
SHA-512: | 77BC933A491003D87FE073B202C20A9433B20904897804B234CF9892B15CD3248C28833BB095A32672F256481821444653C7168CC56730BA0249C3B32564BA5A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.273178868843303 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJf21rPeUkwRe9:YvXKXfbI4SDkZc0v6zG+16Ukee9 |
MD5: | 21A0E181FFD047B860BD33C2E730AE6C |
SHA1: | 616CC0DBBAC0B826505E5014D1E6189C2380D2D7 |
SHA-256: | CE069E4695DF62C8CAC54AF5C3E7EE32C0BBA888D20C42D719F95200793B7E59 |
SHA-512: | 756A6359CCE26B22FE901111F40D5F231EE490B10CAD3D6E11B2AE6B508F4EC4D77DEE3E0FEDF6FD4100AE7289301CE23B0452C2F252D3D102EF43FE594E18D8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.658679046198159 |
Encrypted: | false |
SSDEEP: | 24:Yv6XU4SDkzv6camXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSH:YvoSDsHBgkDMUJUAh8cvMH |
MD5: | BC4F879BF41814B138092FD2926066B6 |
SHA1: | EDB92A3175E8FB98C4FF33471057D6D58B513508 |
SHA-256: | 9618007B8322F9B33D54E292D48719B8CE3A9EADE96BC0B2B3B8E0F12E0740C6 |
SHA-512: | ADCF27F165AFE6D4D4C2D38859F88CE93D0E1BCB3F851F64938657CDB6E30776B2CB2D4D020040777E70D42E5EA2F783ED7A8FC867AFFFB74D86700CFBA91096 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.249189611771682 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJfshHHrPeUkwRe9:YvXKXfbI4SDkZc0v6zGUUUkee9 |
MD5: | 6370BD531949089E8158C1BAD0590109 |
SHA1: | 84093263C09DCA1C2ECBD42E49C63E9B8FD741B2 |
SHA-256: | FB5DAC8945BE2D3F2CFE24F2504A12AEC3749B694CD92BC736019AB3660913F9 |
SHA-512: | B3935A33B6AEAE9DACB8D798336EA7CDBD9C55DB2133922A72195B1B01E68EB175729B74178891915E0A7B3B58C357315AC151AA516D93A4077A4B2CAF1DCDB8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.259737593525384 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXfbI4XC7HdVoZcg1vRcR0YlXZeoAvJTqgFCrPeUkwRe9:YvXKXfbI4SDkZc0v6zGTq16Ukee9 |
MD5: | B8835145F4870A9DADF12D7494B01C24 |
SHA1: | 2B0FA604BD4D05ED3A5AD8134807EC9FAF260C71 |
SHA-256: | 127F99128ACC0B0713D08110A08DC1EC041394A8A7C1B6B82B0FC3AE72AE2D89 |
SHA-512: | 1887DC8CA235F827618F8C869133CD7EBA27E0EF5FF5488D4552E228CE1A73A17C7A5D13ADECBCCE37ED0531962FEBD98AE1B06E83FC0BBCA82AA740178392F5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.141927270813135 |
Encrypted: | false |
SSDEEP: | 24:YSxqasjayjvOGzrqSKZZdR0UWPGxBj3SX8j0SnMLP2b2LS5Cw5YhcS2hU5P9vtkF:YhkYrqDZD713Se4TiPn5YSS2ux9WQY |
MD5: | B8EAC46FD11E9A9B1D7451B0F72C1316 |
SHA1: | FD9B2A0DDC3995F1E0AD504CEA408076D0A3500C |
SHA-256: | F06D295557E75276BCB70115F456A7699C032650BC752A53B17B7DD3A95240A4 |
SHA-512: | 16B87634AE481BB5FC2F7FBD127C1F159CC78BCA9CFED3F6B8C05293EBDDC2D6DDF26468A2E3C5844FB97972A3E4F303BF2B13C4A3F018EFA4FB206696BC268D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1882412400208848 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUULSvR9H9vxFGiDIAEkGVvp/:lNVmswUUUUUUUUL+FGSItj |
MD5: | 158B7C552FCD58A778A7ACFD5CF36955 |
SHA1: | 4C45F827A9A3891760F13258A46B260EDC1B203D |
SHA-256: | C3E2A53AE3A56137C159852ABED92C14FA22CCB4C544EB68FDFE94507E923BF0 |
SHA-512: | ADF5FAE5F19192E59EE56557ADE4276FB8FBCB81F4CE816F16A0D566BC08D72415702A49042A7A424B296B3F45D0E75058DCF1B53369A916C6E44DA437EAF6BF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6085542434546876 |
Encrypted: | false |
SSDEEP: | 48:7MhKUUUUUUUUUUfvR9H9vxFGiDIAEkGVvSqFl2GL7msj:7nUUUUUUUUUUXFGSItsKVmsj |
MD5: | 95F92C6FE51A414DAFC023293B281E05 |
SHA1: | BC9B5709D85AF043D0CBE817F924042D96884356 |
SHA-256: | F6222BF371E04D8D09F17C2E370A1CCFA2AD89AA9ED625515C6E64F947E7BA51 |
SHA-512: | 9A6C3532F4ED9248670F224F5CEA19FD0B0636190C8827BF789CC25693BB209AEED5C5D2E5CCEF3696C60C29D492DDA911E049D2CBA48A36716465C66B362279 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgrI3VCxQ0L2M6HW4vEDTHP7PfYyu:6a6TZ44ADErI3QxQXM6ADvfK |
MD5: | 530018F111061FBF07EC508F06A71A69 |
SHA1: | 0DC791698F25C02B186E832AD9FFFA1929823257 |
SHA-256: | 95CB085CC4AF575931B5FCFCD7DF8441FF4411D3CA1227A81041F41B2FF015CF |
SHA-512: | 3393F67B28C55DA153DEC5BD7225C23295496D54AAB5349B28C00016DF0FE848465B98705532B12D2142E3FB0A15477B2D1AAC286C67567B5B59A84AAC2B51C7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.505069684106714 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K84sClAQKw:Qw946cPbiOxDlbYnuRKIqH |
MD5: | 9AD0BF51FF16A228255FD7AF6C281309 |
SHA1: | 1010D019C7B2E87870EA4E935B945659186C3EB0 |
SHA-256: | 5F7035DB990396AEB84AB9BA85D7AC0642F973ED4FADC6FBD0A3C6DF6948678B |
SHA-512: | 1F28926A40CABED50EB32300E6F7D89CF0141BBFF962023B8209E37C746E72176E218B1330AC3C51CC39C24B30AF1DEDB677F0C1AED4AEB198737C47477ADBB9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 358 |
Entropy (8bit): | 5.05993646744761 |
Encrypted: | false |
SSDEEP: | 6:IngVMrexJzJT0y9VEQIFVmb/eu2g/86S1kxROOnQRCedrCedamCSyAAO:IngVMre9T0HQIDmy9g06JXgRCelCePlX |
MD5: | 75EA308467FE386098C189E914C3E651 |
SHA1: | 561464B1B3CFB238EB8343A2C66DC4656FDEE8EC |
SHA-256: | 4C9CA21C349778CD0CCC441773F8ED845E3AFB887C94144AF51884277881467A |
SHA-512: | BD8C08A77A162045633E4A7C690EC0F891924525A93C8CF442CB5D7DED57F62D6ACB338D44FF481ADB3357098F8A921362F5FEBE7F8A2020BB4EE01E44668888 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-14 22-45-39-701.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15099 |
Entropy (8bit): | 5.347704735611812 |
Encrypted: | false |
SSDEEP: | 384:frBOJP435iP5q0lW87xwcOR0gPSDrll1yt8WAomCeDZcZp2pYfYf+jdTqWwG3kcR:3AC |
MD5: | 95287833D3F81559344331CD3F48E8FD |
SHA1: | F3E0D090B1C2A2F2B2E2376EFFAA743050A796B3 |
SHA-256: | 6A96169C5A00F1170057B2B79CE5436B32EA27BA53A48DCB44EA635D4999A67B |
SHA-512: | 960B577966E1736438C8DABD472A75C98794A2F3851EE1C21A01E748BC2A238A1D001AF89A1D25127F7848B445600F09419135C193B487EFA69F8F1514481B69 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.389303297959968 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rw:k |
MD5: | 3F6C0E4FEEEC4DF1AE38EF05AB6E7558 |
SHA1: | AE54FEA37E2718FC6445D95675696526D9878E68 |
SHA-256: | 127A39A3A4CED109EF3F0843A39321BA28C881600F227A49F0CA243FC5B1FA7A |
SHA-512: | D0A3E03C6906E59CB5D0ED338CDCC050C8256D29685DF054E38AADCCBC190459C44A93C838582CC72726E1E282B705E6E885F9C2A01EF89216E34F3AB04914E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLcGZtwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLcGZtwZGk3mlind9i4ufFXpAXkru |
MD5: | A46246FAEAB95D87F5B4FE236C2B3D3E |
SHA1: | 7F018DB9238A63FEAD8D11A92297E7366058A75A |
SHA-256: | 7E822FECC47177C5A7F4C250E7D53509D104DE68B0D0CE9445877B508400988E |
SHA-512: | 8AAB79958BF39F014FBA7F69287FE0C357746E63FA3482DE3231BDF4A97B964A0815DAF7BFE9751C55BA6BE618E0A964CEB23FC30B4FA9DFEB284F42EBA897BF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 444454 |
Entropy (8bit): | 3.1220497889039023 |
Encrypted: | false |
SSDEEP: | 768:UktYmG/kw9taq0IvAjd+pimktYmG/kw9taq0IvAjd+piylrMlrS:UIYR/kw9tr4Z+bIYR/kw9tr4Z+7G0 |
MD5: | 514EB42974108D4FFCFF3642FA814243 |
SHA1: | AE9819ED21BB647379E20EEC44F229DDE3F37A06 |
SHA-256: | 570E7939B205E3E251011EDDC0FBC275AF96C923A4D5911FD7146502F45589F4 |
SHA-512: | 787EA88FB2CE35BBAE40296511B4958082769B88191E558138323A386958B16E59409275A1C4295C8FCE2CA682F41DAD684591831724A599BC946EF514171577 |
Malicious: | false |
URL: | https://sgd.trilivarnor.ru/NiKU3ISg/ |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 1071 |
Entropy (8bit): | 4.433770534824219 |
Encrypted: | false |
SSDEEP: | 12:hYky7DE/4C3ffv5+4r4HLnKvl6SjFCIXta3FIVxXtH1uexXU9DFHCU1OSmKB4Nbb:hYkCD24CPfY4841CIXMHr3Ht4NWPY |
MD5: | 374264DC6A4950B7C5957B44C2604C8E |
SHA1: | D169A5660C8419517A86544DE621D9DD4246A210 |
SHA-256: | 6AC3934323B4C7407F8EE519C60F16A9B610A0495BB868CA34883CC8710E6FF2 |
SHA-512: | 559F0827A5C4D61C4F671A027D717331CB46534F574D9B86F2DE2B7815425A4C28F3D9B533EA19028E72BB1178CA0059DE4894EBBA9E0E6C5F16D9C5FE6EE822 |
Malicious: | false |
URL: | https://oulkiate.s3.ap-southeast-1.amazonaws.com/index.html |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 89501 |
Entropy (8bit): | 5.289893677458563 |
Encrypted: | false |
SSDEEP: | 1536:DjExXUqJnxDjoXEZxkMV4QYSt0zvDL6gP3h8cApwEIOzVTB/UjPazMdLiX4mQ1v9:DIh8GgP3hujzwbhd3XvSiDQ47GKn |
MD5: | 8FB8FEE4FCC3CC86FF6C724154C49C42 |
SHA1: | B82D238D4E31FDF618BAE8AC11A6C812C03DD0D4 |
SHA-256: | FF1523FB7389539C84C65ABA19260648793BB4F5E29329D2EE8804BC37A3FE6E |
SHA-512: | F3DE1813A4160F9239F4781938645E1589B876759CD50B7936DBD849A35C38FFAED53F6A61DBDD8A1CF43CF4A28AA9FFFBFDDEEC9A3811A1BB4EE6DF58652B31 |
Malicious: | false |
URL: | https://code.jquery.com/jquery-3.6.0.min.js |
Preview: |
Process: | C:\Program Files\Google\Chrome\Application\chrome.exe |
File Type: | |
Category: | downloaded |
Size (bytes): | 16 |
Entropy (8bit): | 3.5 |
Encrypted: | false |
SSDEEP: | 3:H+rYn:D |
MD5: | F1C9C44E663E7E62582E3F5B236C1C72 |
SHA1: | E142F3A0C2D1CDF175A5C3AF43AD66FEFE208B1F |
SHA-256: | D843E67FBFA1F5CB0024062861EE26860C5A866F80755CF39B3465459A8538B9 |
SHA-512: | 19FE62CB9D884BB3424C51DD15E74EB22E5A639BABF8398BACEBB781862296FA0D7AEE39C88CB9C7AF5791FD58830AC3433F5C6BD94B1BA3912AB33151E93452 |
Malicious: | false |
URL: | https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xMzISEAkkV5TRar4rkxIFDTcwqTA=?alt=proto |
Preview: |
File type: | |
Entropy (8bit): | 7.658884130752926 |
TrID: |
|
File name: | Invdoc80.pdf |
File size: | 42'254 bytes |
MD5: | 10d528b39a9373b88db284de96e1fddf |
SHA1: | 5ed0ecfc82feca91301f40901f574343a7e86db0 |
SHA256: | 98e62c61733cb015fb68c76dc36def4861cbff9ecec1c5cb8dab86544b84fd8b |
SHA512: | 806755faa820d702a71b73237cd4b61646b8ef0d482f8284c839a7299905b5ff96ea619e9bc634101b70e526e2b1dc839423035353bdc33be372828a73dbf2fb |
SSDEEP: | 768:UwoDQXhcIcmkmQm7WudQapVkokUkzn3wpjqsuqSRtUdcGXCE8H6HzHHHS9zDL8yd:g/bpTpmMHOVHKfK75BiJC2YOfe5i |
TLSH: | 97136B70FA9E9C0CE9C2D70F89BD348E8E2CF44B66CD788501784A19B4069D6B7632D7 |
File Content Preview: | %PDF-1.4.%.....1 0 obj.<</Title (lists - Staff Payroll for January 2025)./Creator (Chromium)./Producer (Skia/PDF m128)./CreationDate (D:20250114154959+00'00')./ModDate (D:20250114154959+00'00')>>.endobj.3 0 obj.<</ca 1./BM /Normal>>.endobj.8 0 obj.<</Type |
Icon Hash: | 62cc8caeb29e8ae0 |
General | |
---|---|
Header: | %PDF-1.4 |
Total Entropy: | 7.658884 |
Total Bytes: | 42254 |
Stream Entropy: | 7.992821 |
Stream Bytes: | 30076 |
Entropy outside Streams: | 5.071409 |
Bytes outside Streams: | 12178 |
Number of EOF found: | 1 |
Bytes after EOF: |
Name | Count |
---|---|
obj | 72 |
endobj | 72 |
stream | 9 |
endstream | 9 |
xref | 1 |
trailer | 1 |
startxref | 1 |
/Page | 1 |
/Encrypt | 0 |
/ObjStm | 0 |
/URI | 2 |
/JS | 0 |
/JavaScript | 0 |
/AA | 0 |
/OpenAction | 0 |
/AcroForm | 0 |
/JBIG2Decode | 0 |
/RichMedia | 0 |
/Launch | 0 |
/EmbeddedFile | 0 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 04:45:38.801831961 CET | 49675 | 443 | 192.168.2.4 | 173.222.162.32 |
Jan 15, 2025 04:46:03.601562977 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:03.601650953 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:03.601730108 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:03.602358103 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:03.602440119 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.652120113 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.652540922 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.652602911 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.654277086 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.654462099 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.654522896 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.654997110 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.655399084 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.655514002 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.655544043 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.655683041 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.708233118 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:04.708292961 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:04.754158974 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:05.257395983 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:05.257673025 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:05.257889986 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:05.326415062 CET | 49754 | 443 | 192.168.2.4 | 52.219.125.106 |
Jan 15, 2025 04:46:05.326479912 CET | 443 | 49754 | 52.219.125.106 | 192.168.2.4 |
Jan 15, 2025 04:46:05.419810057 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.419878960 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.419964075 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.420310020 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.420397997 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.420510054 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.420526028 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.420702934 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.421041012 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.421125889 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.920166969 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.921396017 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.921458960 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.922960997 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.923032999 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.924340010 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.924525023 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.924640894 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.925024033 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.925046921 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.925493002 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.925513029 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.926469088 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.926525116 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.928277969 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.928365946 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.968316078 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:05.968327045 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:05.968492985 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.015489101 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.585266113 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.585381985 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.585495949 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.585551977 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.585592985 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.585609913 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.585609913 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.585675955 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.586296082 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.586333990 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.586469889 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.586469889 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.586540937 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.590400934 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.590444088 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.590605021 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.590670109 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.593378067 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.671747923 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.671823978 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672014952 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.672079086 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672230959 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672310114 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672400951 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.672467947 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672538042 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672538042 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.672555923 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672636986 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.672832012 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.672897100 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.673630953 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.673686981 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.673707008 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.673759937 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.673938036 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.673952103 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.674221039 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.674263000 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.674297094 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.674314022 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.674379110 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.674711943 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.676739931 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.676835060 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.676848888 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.718836069 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.719099998 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.719163895 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758631945 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758671999 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758820057 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.758821964 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758871078 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758888006 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.758888960 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.758930922 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.758956909 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759004116 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759167910 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759169102 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759238005 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759288073 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759349108 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759381056 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759416103 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759448051 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759491920 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759491920 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759514093 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759560108 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759747028 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759815931 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759903908 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759903908 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.759919882 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.759968996 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.760020971 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.760020971 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.760595083 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.760663986 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.760689974 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.760740042 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.764394999 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.764456034 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.764483929 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.764694929 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.805886030 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.806015015 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.847573996 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.847707033 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.847770929 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.847771883 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.847836971 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.847872019 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.847887993 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.847906113 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.847930908 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.847997904 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848052979 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848119020 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848174095 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848175049 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848175049 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848242998 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848311901 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848361015 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848371983 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848412037 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848440886 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848443985 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848488092 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848503113 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848526001 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848576069 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848581076 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848597050 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848651886 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848695993 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848696947 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848710060 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.848748922 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848748922 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.848957062 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849006891 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849065065 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849112988 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849124908 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849172115 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849196911 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849244118 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849245071 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849258900 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849289894 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849313021 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849358082 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.849371910 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.849936962 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.854130030 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854209900 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.854293108 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854418993 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854477882 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.854479074 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.854542971 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854593039 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854660988 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.854680061 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.854731083 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.900665045 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.900741100 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.900760889 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.900774002 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.900804996 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.934375048 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.934592009 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.934653997 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.934691906 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.934731960 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.934752941 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.934771061 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.934802055 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935050011 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935071945 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935113907 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935138941 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935164928 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935194016 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935233116 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935250998 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935265064 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935322046 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935642004 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935667038 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935705900 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935723066 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935745955 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935770035 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935861111 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935885906 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935920000 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.935939074 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.935964108 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.936450005 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936477900 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936515093 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.936532021 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936557055 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.936563015 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936593056 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936624050 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.936641932 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.936670065 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.937545061 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.937556028 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.979592085 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.979620934 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:06.979800940 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.979800940 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:06.979871035 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021332026 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021379948 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021538973 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.021538973 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.021610975 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021804094 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021831989 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021842957 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.021997929 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.021997929 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.022066116 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022331953 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022355080 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022401094 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.022427082 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022453070 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.022615910 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022644043 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022675991 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.022696972 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022721052 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.022977114 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.022999048 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023041010 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023056030 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023082972 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023269892 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023298979 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023325920 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023344040 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023366928 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023369074 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023413897 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023427010 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023556948 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.023608923 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023947954 CET | 49759 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.023976088 CET | 443 | 49759 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:07.049762011 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.049806118 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.050029993 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.050143003 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.050174952 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.535252094 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.544852972 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.544928074 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.546490908 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.546716928 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.547893047 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.547975063 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.548042059 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.598593950 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.598654985 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646112919 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646155119 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646240950 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646313906 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.646313906 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.646330118 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646378994 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646435022 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.646492004 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.646492958 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.646513939 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.649162054 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.649350882 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.649424076 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.651668072 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.651705980 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.651849031 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.651916027 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.651985884 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.736275911 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.736294985 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.736506939 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.736506939 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.736506939 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.736599922 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.736639977 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.736674070 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.736674070 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.740458965 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.740484953 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.740672112 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.740673065 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.740736961 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.740794897 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.823961020 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.823997974 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.824162960 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.824162960 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.824229002 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.824300051 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.824570894 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.824594975 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.824754000 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.824754000 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.824820995 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.824873924 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.825176954 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.825297117 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.825366974 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.825366974 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.826958895 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.853178024 CET | 49760 | 443 | 192.168.2.4 | 151.101.130.137 |
Jan 15, 2025 04:46:07.853243113 CET | 443 | 49760 | 151.101.130.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.871416092 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:07.871460915 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.871511936 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:07.871718884 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:07.871731043 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:07.933084011 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:07.938924074 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:07.939009905 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:07.939090967 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:07.939449072 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:07.939486027 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:07.975408077 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:08.237404108 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:08.237592936 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:08.237654924 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:08.239454985 CET | 49758 | 443 | 192.168.2.4 | 104.21.18.22 |
Jan 15, 2025 04:46:08.239470005 CET | 443 | 49758 | 104.21.18.22 | 192.168.2.4 |
Jan 15, 2025 04:46:08.247565031 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.247587919 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.247644901 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.247850895 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.247859001 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.327449083 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.327832937 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.327855110 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.331990957 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.332067013 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.332350016 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.332468033 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.332566977 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.378827095 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.378858089 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.425734997 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.428118944 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436292887 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436314106 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436469078 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.436470032 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.436485052 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436537981 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436561108 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436600924 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436619997 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.436635017 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.436635017 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.436635017 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.436652899 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.488045931 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.515877008 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.515901089 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.516072989 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.516076088 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.516125917 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.516156912 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.516177893 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.516177893 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.516191959 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.523052931 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.523098946 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.523138046 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.523144960 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.523174047 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.523186922 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.584153891 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:08.584448099 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:08.584527969 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:08.586237907 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:08.586478949 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:08.587253094 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:08.587389946 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:08.601821899 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.601870060 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.601902962 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.601912022 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.601927042 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.601947069 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.603420973 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.603461027 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.603482008 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.603491068 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.603506088 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.603532076 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.608124971 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.608201027 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.608208895 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.608298063 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.608351946 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.608371973 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.608388901 CET | 443 | 49761 | 151.101.66.137 | 192.168.2.4 |
Jan 15, 2025 04:46:08.608401060 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.609500885 CET | 49761 | 443 | 192.168.2.4 | 151.101.66.137 |
Jan 15, 2025 04:46:08.628875971 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:08.628937006 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:08.675848007 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:08.720940113 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.721317053 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.721338987 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.722954035 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.723021030 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.723813057 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.723929882 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.723962069 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.769386053 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.769402981 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.816265106 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.847536087 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.847707987 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.847767115 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.847829103 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.847830057 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.847852945 CET | 443 | 49764 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.847913980 CET | 49764 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.848406076 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.848496914 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.848597050 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.848897934 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:08.848978996 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.333453894 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.333875895 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.333937883 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.334636927 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.334959984 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.335047007 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.335077047 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.335104942 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.378953934 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.469557047 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.469726086 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.469873905 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.469944000 CET | 443 | 49765 | 35.190.80.1 | 192.168.2.4 |
Jan 15, 2025 04:46:09.469978094 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:09.470010996 CET | 49765 | 443 | 192.168.2.4 | 35.190.80.1 |
Jan 15, 2025 04:46:18.479150057 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:18.479341030 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:18.479522943 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:18.763771057 CET | 49762 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:46:18.763802052 CET | 443 | 49762 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:46:44.473149061 CET | 49725 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 15, 2025 04:46:44.473189116 CET | 49726 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 15, 2025 04:46:44.478327990 CET | 80 | 49725 | 199.232.214.172 | 192.168.2.4 |
Jan 15, 2025 04:46:44.478493929 CET | 49725 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 15, 2025 04:46:44.478642941 CET | 80 | 49726 | 199.232.214.172 | 192.168.2.4 |
Jan 15, 2025 04:46:44.478708982 CET | 49726 | 80 | 192.168.2.4 | 199.232.214.172 |
Jan 15, 2025 04:46:44.684398890 CET | 57656 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:44.689364910 CET | 53 | 57656 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:44.689498901 CET | 57656 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:44.689554930 CET | 57656 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:44.694391012 CET | 53 | 57656 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:45.144510031 CET | 53 | 57656 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:45.146326065 CET | 57656 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:45.151669025 CET | 53 | 57656 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:45.151779890 CET | 57656 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:01.716820002 CET | 59729 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:01.721782923 CET | 53 | 59729 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:01.721880913 CET | 59729 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:01.721951008 CET | 59729 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:01.726823092 CET | 53 | 59729 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:02.173213005 CET | 53 | 59729 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:02.173639059 CET | 59729 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:02.178759098 CET | 53 | 59729 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:02.178852081 CET | 59729 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:07.990679979 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:07.990770102 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:07.991139889 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:07.991666079 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:07.991739988 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:08.647763014 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:08.648204088 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:08.648262978 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:08.648932934 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:08.649485111 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:08.649578094 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:08.691687107 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:12.793656111 CET | 56634 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:12.799240112 CET | 53 | 56634 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:12.799657106 CET | 56634 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:12.799657106 CET | 56634 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:12.804852962 CET | 53 | 56634 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:13.281836033 CET | 53 | 56634 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:13.282326937 CET | 56634 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:13.287686110 CET | 53 | 56634 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:13.287898064 CET | 56634 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:47:18.556253910 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:18.556379080 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Jan 15, 2025 04:47:18.556632996 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:19.787461042 CET | 59771 | 443 | 192.168.2.4 | 216.58.206.36 |
Jan 15, 2025 04:47:19.787525892 CET | 443 | 59771 | 216.58.206.36 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 04:45:49.864873886 CET | 50223 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:45:55.991725922 CET | 138 | 138 | 192.168.2.4 | 192.168.2.255 |
Jan 15, 2025 04:46:03.572623014 CET | 65445 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:03.572688103 CET | 57671 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:03.580909967 CET | 53 | 62378 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:03.582742929 CET | 53 | 57671 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:03.583719969 CET | 53 | 65445 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:03.587412119 CET | 53 | 62677 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:04.604435921 CET | 53 | 56318 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:05.386466980 CET | 59822 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:05.386537075 CET | 57701 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:05.401702881 CET | 53 | 59822 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:05.454051018 CET | 53 | 57701 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.041918039 CET | 60565 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.042112112 CET | 56273 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.049226046 CET | 53 | 60565 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.049269915 CET | 53 | 56273 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.863220930 CET | 60703 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.863641977 CET | 51573 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.870595932 CET | 53 | 60703 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.871143103 CET | 53 | 51573 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.929987907 CET | 55576 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.930396080 CET | 54860 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:07.937463045 CET | 53 | 55576 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.938103914 CET | 53 | 54860 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:07.939174891 CET | 53 | 63564 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.239075899 CET | 61808 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:08.239180088 CET | 57016 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 04:46:08.246603966 CET | 53 | 57016 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:08.247173071 CET | 53 | 61808 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:15.839922905 CET | 53 | 53179 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:21.825309992 CET | 53 | 62481 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:40.639076948 CET | 53 | 65170 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:46:44.683548927 CET | 53 | 55898 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:01.715042114 CET | 53 | 50908 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:03.280133963 CET | 53 | 53987 | 1.1.1.1 | 192.168.2.4 |
Jan 15, 2025 04:47:12.792797089 CET | 53 | 60236 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Checksum | Code | Type |
---|---|---|---|---|---|
Jan 15, 2025 04:46:05.454277992 CET | 192.168.2.4 | 1.1.1.1 | c27c | (Port unreachable) | Destination Unreachable |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 04:45:49.864873886 CET | 192.168.2.4 | 1.1.1.1 | 0xe9af | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:03.572623014 CET | 192.168.2.4 | 1.1.1.1 | 0x39e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:03.572688103 CET | 192.168.2.4 | 1.1.1.1 | 0xd0ff | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 04:46:05.386466980 CET | 192.168.2.4 | 1.1.1.1 | 0xbd03 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:05.386537075 CET | 192.168.2.4 | 1.1.1.1 | 0x5d4f | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.041918039 CET | 192.168.2.4 | 1.1.1.1 | 0xddef | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.042112112 CET | 192.168.2.4 | 1.1.1.1 | 0x99d0 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.863220930 CET | 192.168.2.4 | 1.1.1.1 | 0xa228 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.863641977 CET | 192.168.2.4 | 1.1.1.1 | 0x9efe | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.929987907 CET | 192.168.2.4 | 1.1.1.1 | 0x8b55 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:07.930396080 CET | 192.168.2.4 | 1.1.1.1 | 0x5f34 | Standard query (0) | 65 | IN (0x0001) | false | |
Jan 15, 2025 04:46:08.239075899 CET | 192.168.2.4 | 1.1.1.1 | 0xa49c | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 04:46:08.239180088 CET | 192.168.2.4 | 1.1.1.1 | 0x92fa | Standard query (0) | 65 | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 04:45:49.873703957 CET | 1.1.1.1 | 192.168.2.4 | 0xe9af | No error (0) | crl.root-x1.letsencrypt.org.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 04:45:50.560925961 CET | 1.1.1.1 | 192.168.2.4 | 0x3e82 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:45:50.560925961 CET | 1.1.1.1 | 192.168.2.4 | 0x3e82 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.582742929 CET | 1.1.1.1 | 192.168.2.4 | 0xd0ff | No error (0) | s3-r-w.ap-southeast-1.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | s3-r-w.ap-southeast-1.amazonaws.com | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 52.219.125.106 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.147.144 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.148.123 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.146.158 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.150.157 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.150.110 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 52.219.164.154 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:03.583719969 CET | 1.1.1.1 | 192.168.2.4 | 0x39e8 | No error (0) | 3.5.146.202 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:05.401702881 CET | 1.1.1.1 | 192.168.2.4 | 0xbd03 | No error (0) | 104.21.18.22 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:05.401702881 CET | 1.1.1.1 | 192.168.2.4 | 0xbd03 | No error (0) | 172.67.179.163 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:05.454051018 CET | 1.1.1.1 | 192.168.2.4 | 0x5d4f | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 04:46:07.049226046 CET | 1.1.1.1 | 192.168.2.4 | 0xddef | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.049226046 CET | 1.1.1.1 | 192.168.2.4 | 0xddef | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.049226046 CET | 1.1.1.1 | 192.168.2.4 | 0xddef | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.049226046 CET | 1.1.1.1 | 192.168.2.4 | 0xddef | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.870595932 CET | 1.1.1.1 | 192.168.2.4 | 0xa228 | No error (0) | 151.101.66.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.870595932 CET | 1.1.1.1 | 192.168.2.4 | 0xa228 | No error (0) | 151.101.194.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.870595932 CET | 1.1.1.1 | 192.168.2.4 | 0xa228 | No error (0) | 151.101.130.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.870595932 CET | 1.1.1.1 | 192.168.2.4 | 0xa228 | No error (0) | 151.101.2.137 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.937463045 CET | 1.1.1.1 | 192.168.2.4 | 0x8b55 | No error (0) | 216.58.206.36 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 04:46:07.938103914 CET | 1.1.1.1 | 192.168.2.4 | 0x5f34 | No error (0) | 65 | IN (0x0001) | false | |||
Jan 15, 2025 04:46:08.247173071 CET | 1.1.1.1 | 192.168.2.4 | 0xa49c | No error (0) | 35.190.80.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.4 | 49754 | 52.219.125.106 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:04 UTC | 693 | OUT | |
2025-01-15 03:46:05 UTC | 414 | IN | |
2025-01-15 03:46:05 UTC | 1071 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.4 | 49759 | 104.21.18.22 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:05 UTC | 716 | OUT | |
2025-01-15 03:46:06 UTC | 1246 | IN | |
2025-01-15 03:46:06 UTC | 733 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 251 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 174 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 1369 | IN | |
2025-01-15 03:46:06 UTC | 476 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.4 | 49760 | 151.101.130.137 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:07 UTC | 624 | OUT | |
2025-01-15 03:46:07 UTC | 611 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN | |
2025-01-15 03:46:07 UTC | 1378 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.4 | 49758 | 104.21.18.22 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:07 UTC | 1324 | OUT | |
2025-01-15 03:46:08 UTC | 1059 | IN | |
2025-01-15 03:46:08 UTC | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.4 | 49761 | 151.101.66.137 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:08 UTC | 358 | OUT | |
2025-01-15 03:46:08 UTC | 611 | IN | |
2025-01-15 03:46:08 UTC | 16384 | IN | |
2025-01-15 03:46:08 UTC | 16384 | IN | |
2025-01-15 03:46:08 UTC | 16384 | IN | |
2025-01-15 03:46:08 UTC | 16384 | IN | |
2025-01-15 03:46:08 UTC | 16384 | IN | |
2025-01-15 03:46:08 UTC | 7581 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.4 | 49764 | 35.190.80.1 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:08 UTC | 533 | OUT | |
2025-01-15 03:46:08 UTC | 336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.4 | 49765 | 35.190.80.1 | 443 | 8796 | C:\Program Files\Google\Chrome\Application\chrome.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 03:46:09 UTC | 472 | OUT | |
2025-01-15 03:46:09 UTC | 434 | OUT | |
2025-01-15 03:46:09 UTC | 168 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 22:45:36 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 22:45:37 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 22:45:37 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 22:46:01 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 22:46:02 |
Start date: | 14/01/2025 |
Path: | C:\Program Files\Google\Chrome\Application\chrome.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff76e190000 |
File size: | 3'242'272 bytes |
MD5 hash: | 45DE480806D1B5D462A7DDE4DCEFC4E4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |