Windows
Analysis Report
0969686.vbe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5028 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\09696 86.vbe" MD5: A47CBE969EA935BDD3AB568BB126BC80)
- wscript.exe (PID: 6256 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\App Data\Roami ng\uaDoJtH ubxengYS.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 5244 cmdline:
"C:\Window s\system32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 1164 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - MSBuild.exe (PID: 2920 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\MSB uild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232) - wermgr.exe (PID: 1240 cmdline:
"C:\Window s\system32 \wermgr.ex e" "-outpr oc" "0" "5 244" "2828 " "2700" " 2832" "0" "0" "2836" "0" "0" " 0" "0" "0" MD5: 74A0194782E039ACE1F7349544DC1CF4)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "SMTP", "Port": "587", "Host": "162.254.34.31", "Username": "sendxsenses@vetrys.shop", "Password": "M992uew1mw6Z"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
|
Networking |
---|
Source: | Author: Joe Security: |
System Summary |
---|
Source: | Author: frack113, Florian Roth: |
Source: | Author: Kiran kumar s, oscd.community: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Tim Shelton: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T10:19:58.058747+0100 | 2030171 | 1 | A Network Trojan was detected | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T10:20:12.096752+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T10:20:12.096752+0100 | 2855245 | 1 | A Network Trojan was detected | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T10:19:58.058747+0100 | 2840032 | 1 | A Network Trojan was detected | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Integrated Neural Analysis Model: |
Source: | HTTPS traffic detected: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Software Vulnerabilities |
---|
Source: | Child: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 5_2_0156A978 | |
Source: | Code function: | 5_2_0156DBE0 | |
Source: | Code function: | 5_2_01564AA0 | |
Source: | Code function: | 5_2_01563E88 | |
Source: | Code function: | 5_2_015641D0 | |
Source: | Code function: | 5_2_0156E0ED | |
Source: | Code function: | 5_2_068B45C0 | |
Source: | Code function: | 5_2_068B5D50 | |
Source: | Code function: | 5_2_068B3560 | |
Source: | Code function: | 5_2_068B9297 | |
Source: | Code function: | 5_2_068B0308 | |
Source: | Code function: | 5_2_068BE0D9 | |
Source: | Code function: | 5_2_068BA150 | |
Source: | Code function: | 5_2_068B5670 | |
Source: | Code function: | 5_2_068B3CC0 | |
Source: | Code function: | 5_2_068BC370 | |
Source: | Code function: | 5_2_06A0A198 | |
Source: | Code function: | 5_2_0156DF88 |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 5_2_068BFE40 | |
Source: | Code function: | 5_2_06A04D60 | |
Source: | Code function: | 5_2_06A0FAF4 |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Dropped file: | Jump to dropped file |
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior | ||
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 311 Scripting | Valid Accounts | 121 Windows Management Instrumentation | 311 Scripting | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 311 Process Injection | 1 Obfuscated Files or Information | 1 Credentials in Registry | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Masquerading | NTDS | 1 Process Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 141 Virtualization/Sandbox Evasion | LSA Secrets | 141 Virtualization/Sandbox Evasion | SSH | Keylogging | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 311 Process Injection | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
3% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | high | |
s-part-0017.t-0009.t-msedge.net | 13.107.246.45 | true | false | high | |
api.ipify.org | 104.26.13.205 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
144.91.79.54 | unknown | Germany | 51167 | CONTABODE | true | |
104.26.13.205 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false | |
162.254.34.31 | unknown | United States | 64200 | VIVIDHOSTINGUS | true |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591702 |
Start date and time: | 2025-01-15 10:19:09 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 31s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 0969686.vbe |
Detection: | MAL |
Classification: | mal100.spre.troj.spyw.expl.evad.winVBE@9/12@1/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 40.126.32.133, 40.126.32.136, 40.126.32.138, 20.190.160.14, 20.190.160.20, 40.126.32.76, 40.126.32.68, 40.126.32.72, 199.232.210.172, 2.23.77.188, 20.12.23.50, 40.69.42.241, 52.182.143.212, 20.3.187.198, 4.245.163.56, 13.107.246.45
- Excluded domains from analysis (whitelisted): prdv4a.aadg.msidentity.com, ctldl.windowsupdate.com.delivery.microsoft.com, slscr.update.microsoft.com, otelrules.azureedge.net, e3913.cd.akamaiedge.net, otelrules.afd.azureedge.net, www.tm.lg.prod.aadmsa.akadns.net, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, cac-ocsp.digicert.com.edgekey.net, fe3.delivery.mp.microsoft.com, ocsp.digicert.com, onedsblobprdcus15.centralus.cloudapp.azure.com, login.live.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, blobcollector.events.data.trafficmanager.net, sls.update.microsoft.com, azureedge-t-prod.trafficmanager.net, umwatson.events.data.microsoft.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
04:20:00 | API Interceptor | |
04:20:04 | API Interceptor | |
04:20:09 | API Interceptor | |
04:20:22 | API Interceptor | |
10:20:01 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
144.91.79.54 | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
104.26.13.205 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | TrojanRansom | Browse |
| ||
Get hash | malicious | TrojanRansom | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | LummaC, PrivateLoader, Stealc, Vidar | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Node Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-part-0017.t-0009.t-msedge.net | Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | PureCrypter, LummaC, LummaC Stealer | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | PureCrypter | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
api.ipify.org | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Python Stealer, CStealer | Browse |
| |
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
VIVIDHOSTINGUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
CONTABODE | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| |
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Virut, Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_powershell.exe_b4b21b9272f0623778607a435112f88140f556cc_00000000_2268e00b-0190-4843-9f60-f9bf7b44562f\Report.wer
Download File
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.5344064391763494 |
Encrypted: | false |
SSDEEP: | 96:DkFCvjErxYid4RH3Uje0eD/JuNnN9KQXIGZAX/d5FMT2SlPkpXmTAVf/VXT5NHBx:YIEmG4R30wAAzuiFFZ24lO8 |
MD5: | 2AFE0DF777A02D24C31401C6953B099D |
SHA1: | F2B59DFDF1BDF51B7D725FEA42DA3BBD3B91FE2F |
SHA-256: | ADF4C281894EEEB52CAF6D09B45A8644ACAA76D9DFC145DEA5C8E896B4B1377E |
SHA-512: | B7F78C07CBD0571E88C5D0AF6BC02BD279EE1E3132D5E61A157D13832C146404BDC3D7629273C01C365C330567586851AA7099C2A7CAE52831DF6278843FE383 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7414 |
Entropy (8bit): | 3.6826926929513317 |
Encrypted: | false |
SSDEEP: | 96:RSIU6o7wVetbXKf6lvu6YWnBMgmfHNV9rexP45aM4Zzm:R6l7wVeJXKf6tu6YWnqgmftqKpKzm |
MD5: | D65A74C5B788F343623EB953CEF00ED8 |
SHA1: | 851093F1C854955E0B1D203D51EE6378848F61D7 |
SHA-256: | 61915561F3C8AA693E3A958DAE46675812084F37DF3AD02C0C141505F6C39512 |
SHA-512: | 3A0E1BBEEE3E2182663374DE76F79E0E8DEC2BF6C06399E5E40F587C4AF6D1DA4119FF699541539A5313FAD32F9824A9E3B966CF7AAC4F5142314A93242FA21D |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4899 |
Entropy (8bit): | 4.565879470925075 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zs0iJg771I93Z76rWpW8VY1Ym8M4JFKlnOtSFDyq8vT0OthytfJd:uIjf5I7yZ76a7V9JFKlntWT0kufJd |
MD5: | 1A677ABB825C146BBDDEA3B7FEB5D489 |
SHA1: | 8666E11BC3B0522FE466EE1F139E36A33D5AAF2D |
SHA-256: | 09CF758B3BE4B1AC6C8271760187D2D51BA430E69A64417F3CE826282D55CECE |
SHA-512: | 92FB6AE9FF3AED57D714CDA031509F9D4783B119F3426A21BC7750D296C2747FEB1635859A1C2ED375F058CEDF024CBD992D60343ECB59F96CB4AA99A5F71DF4 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11887 |
Entropy (8bit): | 4.901437212034066 |
Encrypted: | false |
SSDEEP: | 192:Zxoe5qpOZxoe54ib4ZVsm5emdqVFn3eGOVpN6K3bkkjo5OgkjDt4iWN3yBGHVQ9L:Srib4ZmVoGIpN6KQkj2Fkjh4iUxsNYWd |
MD5: | ED30A738A05A68D6AB27771BD846A7AA |
SHA1: | 6AFCE0F6E39A9A59FF54956E1461F09747B57B44 |
SHA-256: | 17D48B622292E016CFDF0550340FF6ED54693521D4D457B88BB23BD1AE076A31 |
SHA-512: | 183E9ECAF5C467D7DA83F44FE990569215AFDB40B79BCA5C0D2C021228C7B85DF4793E2952130B772EC0896FBFBCF452078878ADF3A380A6D0A6BD00EA6663F2 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3256 |
Entropy (8bit): | 5.404109340363203 |
Encrypted: | false |
SSDEEP: | 96:gEzlHyIFKL2O9qrh7Kf+oRJ5Eo9AdrxwN:V1yt2jrAfRLL2G |
MD5: | 047B195D3B8C00130835658997B1925D |
SHA1: | 5F77C7A5F798C4C0253839EBD7554B13987704E3 |
SHA-256: | B2C2801565403B2348CAF820F20B4B92C8725A5079D5360DAF455E84D28AC1FB |
SHA-512: | D1724BE394B214B914A236AC1D55DB17B93669880BB3F71057DCD070AF3062FBFF494ABE085345015FCDF5FE6B11BAE9A19FCD20DC4EB749E13F31CD5565D60D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 5.4037343689320885 |
Encrypted: | false |
SSDEEP: | 6:xVwe5ljxsu2xKbLtSXqo83inrHXZuBiA2V0LY+SXFI59:772EtSXqdiTJci1V0LYtXo |
MD5: | 4EBB9486C86C05A7C6888B977EA15FA8 |
SHA1: | 7C9421A3CAA33767F9DADD5A7369865B07978FC2 |
SHA-256: | 599EF81EC13CE5139CE8C5B77A8D56E66C17C4F8193ECAE14976E4691DBD2373 |
SHA-512: | 6C9423222490C42FEECE32BA38A1F92DA0CB5A0BC8882CB6919E41C9FA06FAE05DE5A1419E063E9794EAC57862E98F253723F546F9AA83FE7C7BF25DA6C7EF45 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\0SFF35UD0M82MZNFFLNE.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7098800246239754 |
Encrypted: | false |
SSDEEP: | 96:AL+XC6oRykvhkvCCtu2/X9u+Hd2/X99+H+:s+lQuu2/QU2/Dh |
MD5: | 3545863F759F8D4DC5497C03481DF1DA |
SHA1: | 6D05C0773B7EB520E8816300D14173F0E348608B |
SHA-256: | 7245AFBB18FF5552808C2CA7FC9F2F120968F24430EF705332CF4BA0E1548802 |
SHA-512: | 2EE3D8FAD7498052D782A86EB5110B7350F30DE1892119B7C68A7F17C1D691E43CD08170E781763CC2BEE543D03D15DDA3A5C92C7CAF96138E518949DA2C20CB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7098800246239754 |
Encrypted: | false |
SSDEEP: | 96:AL+XC6oRykvhkvCCtu2/X9u+Hd2/X99+H+:s+lQuu2/QU2/Dh |
MD5: | 3545863F759F8D4DC5497C03481DF1DA |
SHA1: | 6D05C0773B7EB520E8816300D14173F0E348608B |
SHA-256: | 7245AFBB18FF5552808C2CA7FC9F2F120968F24430EF705332CF4BA0E1548802 |
SHA-512: | 2EE3D8FAD7498052D782A86EB5110B7350F30DE1892119B7C68A7F17C1D691E43CD08170E781763CC2BEE543D03D15DDA3A5C92C7CAF96138E518949DA2C20CB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2915 |
Entropy (8bit): | 5.027561445008011 |
Encrypted: | false |
SSDEEP: | 48:aJrvgJXVv0qD4p7pYazIZYANMaBoqpotJ8gfng++E/uTcb6OqaBXl8zmqgjHVVk3:UL4VvlDQeADaK8gPOOqav97Zma+cmaS3 |
MD5: | 477E3B6CBF610F72373118D4CA9CDBB2 |
SHA1: | CA88C1B80FA6248644497449C294F92B5A32B300 |
SHA-256: | 9D75154B064FC63A3DE686569088EF8C7AC31F2826DC4557D5E7074535BBDF3C |
SHA-512: | AD3D81784CB1199839E66C7B88AC1DA0C14A7F8A6F3F9A7BBB496FC953F02253733E5F7370EFE5C08D9C5F4A9F037D84D814E958EA8715732D9E3DF14B94B119 |
Malicious: | true |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1457 |
Entropy (8bit): | 4.4508014556500015 |
Encrypted: | false |
SSDEEP: | 24:ELh/vNa2V269+IzISjeKm3uSmcHSMxOAX4WLeX4WgeX4WgeX4WneX4WueX4WEeXP:EL+WxZzzyS+OAX+X5XpXKX/XFXoXQXDp |
MD5: | 65D28DAC5EEFA063E84B6DEA64710012 |
SHA1: | BA4786D60A050CB5BC7863576796A1363486042E |
SHA-256: | 1DD4D009604A92CE4D26AC74E98366153E8A7BF4EDF73AFE24F6CD45CF6EDE60 |
SHA-512: | 8B22218A20825E7285193A38CB513F8DE505836E4196DDECAD9A13DAABD1E8A55ECBD4CD53A1BFE4E2CEDA18058173808A1E2C1E072F63C511110E86487DBC44 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 3.96389475873218 |
TrID: |
|
File name: | 0969686.vbe |
File size: | 12'232 bytes |
MD5: | 4565da69d82d3d17f33436b132261de7 |
SHA1: | 5e124ae25d9ec64cc681546299e0fa2d4f4b50d4 |
SHA256: | e2604e06a1d397760f22a668b48821dc20f06a8c3a28d165b9c96569b0e88bbb |
SHA512: | 7390abe671d2ad1a430bfb69888cdcb7f6e9284cc9432338a5b1eddeb0624987b92a56009e50c283c46894256ca1ab43640cac3ecbf09bd4b69867cccb6f4329 |
SSDEEP: | 192:YeHNd/sigyX/tr7b7RMAv0Evwfk5Pv4fX//CxHQ6V62nN4je5K:zHMiTFPXHvwfk5PvQiHQ6EGijT |
TLSH: | 34420D58DFDD11C0F3116B969BC99B929B1F9A205B0F46C20D6102C6372EE81FDA9F39 |
File Content Preview: | ..#.@.~.^.y.h.c.A.A.A.=.=.v.,.'.x.{.P.j.....D.k.6.k.1.C.Y.b.W.U./.,./.z.d.D.....:.+.,.x.'.{.@.#.@.&.w.;.U.m.D.k.K.x.~.|.P.K.I.`.b.@.#.@.&.~.P.,.P.6.U.,.2.D...G.M.P.].+.k.;.s.+.~.g.+.X.Y.@.#.@.&.P.,.~.P.G.k.h.P.o.A.J.K.B.P.p.\...I.B.P.K.t.].F.@.#.@.&.P.,.P |
Icon Hash: | 68d69b8f86ab9a86 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T10:19:58.058747+0100 | 2030171 | ET MALWARE AgentTesla Exfil Via SMTP | 1 | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
2025-01-15T10:19:58.058747+0100 | 2840032 | ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 1 | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
2025-01-15T10:20:12.096752+0100 | 2855245 | ETPRO MALWARE Agent Tesla Exfil via SMTP | 1 | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
2025-01-15T10:20:12.096752+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.5 | 49707 | 162.254.34.31 | 587 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 10:19:58.058747053 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:19:58.058795929 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:19:58.224956989 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:20:00.622574091 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:00.627722979 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:00.627805948 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:00.628182888 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:00.633028030 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281866074 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281893969 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281929016 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281938076 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.281944036 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281959057 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281974077 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.281984091 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.281990051 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.282007933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.282011986 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.282021999 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.282038927 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.282043934 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.282067060 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.286901951 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.286917925 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.286936998 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.286952019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.286971092 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.286994934 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.374613047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.374630928 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.374648094 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.374663115 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.374794960 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.374794960 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.379422903 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.379440069 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.379455090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.379511118 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.379549026 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.379565001 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.379591942 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.384165049 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.384181976 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.384196997 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.384216070 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.384251118 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.519419909 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.525103092 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.711056948 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.714025974 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.718961954 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.904853106 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.904891968 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905071974 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905072927 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905107975 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905143023 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905157089 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905175924 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905210972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905220985 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905246019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905287981 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905802965 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905838013 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905870914 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905879021 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905904055 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905937910 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.905946016 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.905972958 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906023979 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.906646967 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906696081 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906728983 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906734943 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.906761885 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906795025 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906804085 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.906829119 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.906874895 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.907489061 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907521963 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907556057 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907566071 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.907592058 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907624006 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907632113 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.907658100 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.907706976 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.908400059 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908448935 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908482075 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908490896 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.908514977 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908549070 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908551931 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.908586979 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.908637047 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.909231901 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.909261942 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:01.909310102 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.966480970 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:01.971497059 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.157881975 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.199244976 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.335110903 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.340158939 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528203011 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528243065 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528279066 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528311014 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528347015 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.528387070 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.528388023 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.555111885 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.560077906 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750197887 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750253916 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750288963 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750320911 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750370026 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750375032 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750402927 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750406027 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750441074 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750473022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750523090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750588894 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750590086 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750590086 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750622034 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750632048 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750657082 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750688076 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750720978 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750751972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750782967 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750828028 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750858068 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750858068 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750858068 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.750860929 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.750906944 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.751357079 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751406908 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751440048 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751455069 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.751472950 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751507044 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751516104 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.751539946 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.751590967 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.751593113 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752054930 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752156019 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.752156973 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752190113 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752237082 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.752238035 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752273083 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752305984 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752325058 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.752337933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752371073 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752384901 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.752405882 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.752449036 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.752953053 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753010988 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753047943 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753061056 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.753078938 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753113031 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753122091 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.753144979 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753177881 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753185034 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.753211021 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753245115 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753251076 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.753884077 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753937006 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.753938913 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.753973007 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754005909 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754019976 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754040956 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754071951 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754076958 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754105091 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754137039 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754151106 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754170895 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754204988 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754760981 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754820108 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754868031 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754868984 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754904985 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754936934 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.754949093 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.754971027 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.755004883 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.755013943 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.808610916 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.842082024 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842118025 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842150927 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842181921 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842211008 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.842217922 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842231989 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.842252970 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.842458963 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853161097 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853190899 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853240013 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853240967 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853277922 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853310108 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853312016 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853343010 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853388071 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853394985 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853446007 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853473902 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853488922 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853507042 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853540897 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853569031 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853569031 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853573084 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853607893 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853614092 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853641033 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853686094 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853724957 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853774071 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853807926 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853820086 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853857994 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853890896 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853898048 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853924990 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853956938 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.853969097 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.853990078 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854023933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854036093 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854054928 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854089022 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854089022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854425907 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854476929 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854496002 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854530096 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854561090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854574919 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854593039 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854626894 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854649067 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854677916 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854717016 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854737043 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854757071 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854789019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854799032 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854824066 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854856014 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854859114 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854890108 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854922056 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854926109 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.854958057 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.854998112 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855444908 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855495930 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855530024 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855540037 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855562925 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855596066 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855614901 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855648994 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855683088 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855695963 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855715036 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855750084 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855753899 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855782032 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855815887 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855823040 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855848074 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855881929 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855900049 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.855915070 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855950117 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.855953932 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856518984 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856553078 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856559038 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856586933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856620073 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856632948 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856669903 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856703043 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856714964 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856738091 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856770039 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856786013 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856803894 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856836081 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856848955 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856870890 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856904030 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856919050 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.856937885 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856971025 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.856985092 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857006073 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857063055 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857323885 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857649088 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857681036 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857693911 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857714891 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857747078 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857750893 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857780933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857812881 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857821941 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857844114 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857858896 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857875109 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857881069 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857891083 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857906103 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857914925 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857923031 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857939005 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857947111 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.857956886 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.857981920 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858325958 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858351946 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858366013 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858369112 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858381987 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858397961 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858403921 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858413935 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858429909 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858438969 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858462095 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858478069 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858485937 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858491898 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858510017 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858519077 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858525991 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858541012 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858547926 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858557940 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858572960 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.858577013 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.858611107 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.859287024 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.859299898 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.859338999 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.934549093 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.934585094 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.934621096 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.934628963 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945426941 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945486069 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945502996 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945583105 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945617914 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945631027 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945671082 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945704937 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945709944 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945759058 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945795059 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945796013 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945849895 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945879936 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945893049 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.945930958 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945965052 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.945971012 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946017027 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946067095 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946068048 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946122885 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946157932 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946162939 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946187019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946227074 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946243048 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946297884 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946335077 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946350098 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946398973 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946430922 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946441889 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946465969 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946499109 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946508884 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946532011 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946564913 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946573973 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946599007 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946636915 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946650028 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946700096 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946732044 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946737051 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946770906 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946813107 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946825027 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946877956 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946911097 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946921110 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.946945906 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946978092 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.946988106 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947011948 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947043896 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947053909 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947077990 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947109938 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947122097 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947144032 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947176933 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947201014 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947212934 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947242022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947257996 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947278976 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947329998 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947330952 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947364092 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947396994 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947401047 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947437048 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947469950 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947479010 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947504044 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947537899 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947540045 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947570086 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947603941 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947611094 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947638035 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947673082 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947679043 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.947705030 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.947745085 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.952699900 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952750921 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952784061 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952792883 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.952840090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952879906 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.952893019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952925920 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952960014 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.952966928 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.952991962 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953026056 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953032970 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953058004 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953092098 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953098059 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953124046 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953165054 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953176022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953227043 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953265905 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953280926 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953315973 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953350067 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953370094 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953382969 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953417063 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953418970 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953449965 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953485012 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953488111 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953517914 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953552008 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953552961 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953584909 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953619003 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953622103 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953651905 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953685045 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953687906 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953717947 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953752041 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953752995 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953785896 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953819990 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953834057 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953862906 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953902960 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953913927 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953950882 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.953994989 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.953998089 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954032898 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954065084 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954071045 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954098940 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954132080 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954134941 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954165936 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954199076 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954210043 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954232931 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954263926 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954267025 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954302073 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954334974 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954336882 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954370022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954402924 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954410076 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954440117 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954473972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954478979 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954509020 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954540968 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954550028 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954575062 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954608917 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954617977 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954652071 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954684019 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954685926 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954720020 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954766989 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954792023 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:02.954802036 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:02.954835892 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.037870884 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037892103 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037909031 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037924051 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037936926 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037950993 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037965059 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037981987 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.037995100 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038013935 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038013935 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038014889 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038055897 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038222075 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038255930 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038291931 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038326025 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038332939 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038332939 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038377047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038408995 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038410902 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038441896 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038491964 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038495064 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038542986 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038574934 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038585901 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038625002 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038667917 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038674116 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038707972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038738966 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038752079 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038789034 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038825035 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038839102 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038877010 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038918018 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.038927078 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.038980007 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039011955 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039032936 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039046049 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039088011 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039094925 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039129972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039163113 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039170980 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039196968 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039227962 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039237976 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039280891 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039323092 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039354086 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039387941 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039419889 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039428949 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039470911 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039504051 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039506912 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039556026 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039591074 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039602041 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039624929 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039658070 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039670944 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039691925 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039725065 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039731026 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039774895 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039808035 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039813042 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039864063 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039904118 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.039913893 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039947987 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039980888 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.039989948 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040014982 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040052891 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040065050 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040102959 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040150881 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040153027 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040186882 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040219069 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040225029 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040256023 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040290117 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040298939 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040335894 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040369034 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040376902 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040421009 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040453911 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040461063 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040504932 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040554047 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040554047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040590048 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040621996 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040631056 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040656090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040697098 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040705919 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040739059 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040771961 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040780067 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040806055 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040838003 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040847063 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040873051 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040905952 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040915966 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.040941954 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.040992022 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041002035 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041026115 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041059971 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041069031 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041094065 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041126013 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041136026 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041160107 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041193962 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041208982 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041227102 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041260004 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041269064 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041295052 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041327953 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041331053 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041362047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041393995 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041409969 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041426897 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041460991 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041467905 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041493893 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041527033 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041533947 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041559935 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041594028 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041594982 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041627884 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041659117 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041668892 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041692972 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041726112 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041734934 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041759968 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041793108 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041796923 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041826963 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041858912 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041868925 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041893959 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041925907 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041933060 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.041959047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041991949 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.041992903 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.042028904 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042061090 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042073965 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.042099953 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042129993 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042140961 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.042162895 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042197943 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042198896 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.042227030 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.042269945 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130479097 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130520105 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130547047 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130563021 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130579948 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130595922 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130600929 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130600929 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130613089 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130626917 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130641937 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130650043 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130657911 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130672932 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130672932 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130688906 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130690098 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130716085 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130748987 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130779982 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130814075 CET | 80 | 49704 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 10:20:03.130889893 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130889893 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.130889893 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:03.437268972 CET | 49704 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 10:20:07.667937994 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:20:07.667959929 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:20:07.839793921 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:20:08.812769890 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:08.812805891 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:08.812882900 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:08.818449974 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:08.818468094 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.315948009 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.316040039 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:09.321078062 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:09.321090937 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.321436882 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.371033907 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:09.500317097 CET | 443 | 49703 | 23.1.237.91 | 192.168.2.5 |
Jan 15, 2025 10:20:09.500418901 CET | 49703 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 10:20:09.599456072 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:09.643373013 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.737190008 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.737366915 CET | 443 | 49705 | 104.26.13.205 | 192.168.2.5 |
Jan 15, 2025 10:20:09.737422943 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:09.747834921 CET | 49705 | 443 | 192.168.2.5 | 104.26.13.205 |
Jan 15, 2025 10:20:10.421331882 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:10.426592112 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:10.426697969 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.069066048 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.069391966 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.074413061 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.236325026 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.237112045 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.241955996 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.404102087 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.404808044 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.409672022 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.581077099 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.581388950 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.586273909 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.752912998 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.753256083 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.758162975 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.924277067 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:11.924432993 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:11.931014061 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.096105099 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.096690893 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:12.096751928 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:12.096751928 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:12.096793890 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:20:12.104659081 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.104674101 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.104687929 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.104702950 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.378123999 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:20:12.433553934 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:21:50.449656963 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:21:50.454478979 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:21:50.624938011 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:21:50.624953985 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 10:21:50.625164032 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:21:50.627681017 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 10:21:50.632592916 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 10:20:08.791902065 CET | 63282 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 10:20:08.798651934 CET | 53 | 63282 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 10:20:08.791902065 CET | 192.168.2.5 | 1.1.1.1 | 0x5953 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 10:20:08.798651934 CET | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:08.798651934 CET | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:08.798651934 CET | 1.1.1.1 | 192.168.2.5 | 0x5953 | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:10.878921032 CET | 1.1.1.1 | 192.168.2.5 | 0xd650 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:10.878921032 CET | 1.1.1.1 | 192.168.2.5 | 0xd650 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:18.895024061 CET | 1.1.1.1 | 192.168.2.5 | 0x8618 | No error (0) | s-part-0017.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 10:20:18.895024061 CET | 1.1.1.1 | 192.168.2.5 | 0x8618 | No error (0) | 13.107.246.45 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:21:13.122576952 CET | 1.1.1.1 | 192.168.2.5 | 0x8844 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 10:21:13.122576952 CET | 1.1.1.1 | 192.168.2.5 | 0x8844 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49704 | 144.91.79.54 | 80 | 5028 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 15, 2025 10:20:00.628182888 CET | 152 | OUT | |
Jan 15, 2025 10:20:01.281866074 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.281893969 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.281929016 CET | 448 | IN | |
Jan 15, 2025 10:20:01.281944036 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.281959057 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.281974077 CET | 448 | IN | |
Jan 15, 2025 10:20:01.281990051 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.282007933 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.282021999 CET | 448 | IN | |
Jan 15, 2025 10:20:01.282038927 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.286901951 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.519419909 CET | 152 | OUT | |
Jan 15, 2025 10:20:01.711056948 CET | 761 | IN | |
Jan 15, 2025 10:20:01.714025974 CET | 152 | OUT | |
Jan 15, 2025 10:20:01.904853106 CET | 1236 | IN | |
Jan 15, 2025 10:20:01.966480970 CET | 153 | OUT | |
Jan 15, 2025 10:20:02.157881975 CET | 347 | IN | |
Jan 15, 2025 10:20:02.335110903 CET | 155 | OUT | |
Jan 15, 2025 10:20:02.528203011 CET | 1236 | IN | |
Jan 15, 2025 10:20:02.555111885 CET | 175 | OUT | |
Jan 15, 2025 10:20:02.750197887 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49705 | 104.26.13.205 | 443 | 2920 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 09:20:09 UTC | 155 | OUT | |
2025-01-15 09:20:09 UTC | 425 | IN | |
2025-01-15 09:20:09 UTC | 12 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Jan 15, 2025 10:20:11.069066048 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 220 server1.educt.shop ESMTP Postfix |
Jan 15, 2025 10:20:11.069391966 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | EHLO 066656 |
Jan 15, 2025 10:20:11.236325026 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 250-server1.educt.shop 250-PIPELINING 250-SIZE 204800000 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250 CHUNKING |
Jan 15, 2025 10:20:11.237112045 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | AUTH login c2VuZHhzZW5zZXNAdmV0cnlzLnNob3A= |
Jan 15, 2025 10:20:11.404102087 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 334 UGFzc3dvcmQ6 |
Jan 15, 2025 10:20:11.581077099 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 235 2.7.0 Authentication successful |
Jan 15, 2025 10:20:11.581388950 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | MAIL FROM:<sendxsenses@vetrys.shop> |
Jan 15, 2025 10:20:11.752912998 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 250 2.1.0 Ok |
Jan 15, 2025 10:20:11.753256083 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | RCPT TO:<senses@vetrys.shop> |
Jan 15, 2025 10:20:11.924277067 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 250 2.1.5 Ok |
Jan 15, 2025 10:20:11.924432993 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | DATA |
Jan 15, 2025 10:20:12.096105099 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 354 End data with <CR><LF>.<CR><LF> |
Jan 15, 2025 10:20:12.096793890 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | . |
Jan 15, 2025 10:20:12.378123999 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 250 2.0.0 Ok: queued as CDEED60911 |
Jan 15, 2025 10:21:50.449656963 CET | 49707 | 587 | 192.168.2.5 | 162.254.34.31 | QUIT |
Jan 15, 2025 10:21:50.624938011 CET | 587 | 49707 | 162.254.34.31 | 192.168.2.5 | 221 2.0.0 Bye |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 04:19:59 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77db20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 04:20:01 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77db20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 04:20:02 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 04:20:02 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 04:20:07 |
Start date: | 15/01/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xc90000 |
File size: | 262'432 bytes |
MD5 hash: | 8FDF47E0FF70C40ED3A17014AEEA4232 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 04:20:07 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wermgr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6070d0000 |
File size: | 229'728 bytes |
MD5 hash: | 74A0194782E039ACE1F7349544DC1CF4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Execution Graph
Execution Coverage: | 8.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 72 |
Total number of Limit Nodes: | 6 |
Graph
Function 068B0308 Relevance: 9.0, Strings: 6, Instructions: 1493COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B9297 Relevance: 3.2, Strings: 2, Instructions: 720COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B5D50 Relevance: 3.0, Strings: 2, Instructions: 485COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068BE0D9 Relevance: 2.8, Strings: 2, Instructions: 334COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A978 Relevance: 2.8, Instructions: 2805COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156DBE0 Relevance: 2.3, Instructions: 2275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B3560 Relevance: 1.9, Strings: 1, Instructions: 604COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01563E88 Relevance: 1.5, Strings: 1, Instructions: 238COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B45C0 Relevance: .8, Instructions: 817COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068BA150 Relevance: .6, Instructions: 645COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01564AA0 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156480C Relevance: 2.7, Strings: 2, Instructions: 182COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01564818 Relevance: 2.7, Strings: 2, Instructions: 180COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068BE571 Relevance: 1.6, APIs: 1, Instructions: 130COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A0D4E4 Relevance: 1.6, APIs: 1, Instructions: 119COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A0D4F0 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A0E46C Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068BE658 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01563E7E Relevance: 1.5, Strings: 1, Instructions: 237COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01566EE8 Relevance: 1.4, Strings: 1, Instructions: 177COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01567DA8 Relevance: 1.3, Strings: 1, Instructions: 95COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01567D98 Relevance: 1.3, Strings: 1, Instructions: 94COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01566BB0 Relevance: 1.3, Strings: 1, Instructions: 75COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01568739 Relevance: .6, Instructions: 555COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01568748 Relevance: .6, Instructions: 550COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01564A96 Relevance: .3, Instructions: 260COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A1C2 Relevance: .3, Instructions: 251COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A6D8 Relevance: .2, Instructions: 211COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A510 Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01566CEE Relevance: .1, Instructions: 137COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01566CF8 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A502 Relevance: .1, Instructions: 121COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01561138 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015626E4 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015626F0 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A080 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A090 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015616A8 Relevance: .1, Instructions: 76COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01569F80 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01561880 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01561382 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01564F90 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 014FD030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01561890 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01569F90 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015616B8 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01564FA0 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 014FD006 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01560838 Relevance: .1, Instructions: 63COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01560848 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015617C8 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01561492 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015614A0 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156A6D2 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01568F20 Relevance: .0, Instructions: 42COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01567EC0 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 01568F30 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B5670 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068B3CC0 Relevance: 2.9, Strings: 2, Instructions: 414COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0156E0ED Relevance: 2.0, Instructions: 1956COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 068BC370 Relevance: 1.8, Strings: 1, Instructions: 573COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 015641D0 Relevance: 1.5, Strings: 1, Instructions: 281COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 06A0A198 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|