Windows
Analysis Report
Sample1.exe
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
- Sample1.exe (PID: 7448 cmdline:
"C:\Users\ user\Deskt op\Sample1 .exe" MD5: 45A47D815F2291BC7FC0112D36AAAD83)
- SystemSettingsBroker.exe (PID: 1160 cmdline:
C:\Windows \System32\ SystemSett ingsBroker .exe -Embe dding MD5: 899E65893CDEE7F9022DC9B583F94F0F)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_DLInjector04 | Detects downloader / injector | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_GenericDownloader_4 | Yara detected Generic Downloader | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T15:11:32.036088+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49723 | 162.159.130.233 | 443 | TCP |
2025-01-15T15:13:19.348426+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49747 | 162.159.130.233 | 443 | TCP |
2025-01-15T15:15:42.800221+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49791 | 162.159.129.233 | 443 | TCP |
2025-01-15T15:15:48.409941+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49792 | 162.159.129.233 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: |
Source: | Process Stats: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 1 Disable or Modify Tools | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 31 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 12 System Information Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
83% | Virustotal | Browse | ||
82% | ReversingLabs | ByteCode-MSIL.Trojan.AgentTesla | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
cdn.discordapp.com | 162.159.130.233 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.159.130.233 | cdn.discordapp.com | United States | 13335 | CLOUDFLARENETUS | false | |
162.159.129.233 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
162.159.134.233 | unknown | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591875 |
Start date and time: | 2025-01-15 15:10:25 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 51s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Number of analysed new started processes analysed: | 42 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Sample1.exe |
Detection: | MAL |
Classification: | mal84.troj.evad.winEXE@2/0@3/3 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, SecurityHealthHost.exe, dllhost.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.242.162, 4.175.87.197, 20.190.160.14
- Excluded domains from analysis (whitelisted): assets.msn.com, client.wns.windows.com, fs.microsoft.com, slscr.update.microsoft.com, otelrules.svc.static.microsoft, login.live.com, browser.events.data.msn.cn, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
09:11:30 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
162.159.130.233 | Get hash | malicious | RedLine, zgRAT | Browse |
| |
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | AgentTesla, AveMaria | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | Vidar | Browse |
| ||
Get hash | malicious | Amadey RedLine SmokeLoader | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
162.159.129.233 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla, GuLoader | Browse |
| ||
Get hash | malicious | DCRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Amadey | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
cdn.discordapp.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Metasploit, Meterpreter | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CStealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
Get hash | malicious | Remcos | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Phemedrone Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Phemedrone Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| |
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Phemedrone Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6a5d235ee78c6aede6a61448b4e9ff1e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 4.677687653335447 |
TrID: |
|
File name: | Sample1.exe |
File size: | 8'192 bytes |
MD5: | 45a47d815f2291bc7fc0112d36aaad83 |
SHA1: | db1dc02b2d64c4c3db89b5df3124dd87d43059d5 |
SHA256: | 416e63fb614101d5644592d5f589f358f8d5a41dd6812a717cbf05470864ac6f |
SHA512: | a7d98145cf949a42ace2da725a22847ad814a28137d32b0b220430b91c89aabed7144b85f20c2fd9a1a02f5b92520bf5f0afbe8202028f9832cbc29c2a9e776e |
SSDEEP: | 96:gJOElmu1B9ilJJMOfEkdEKozt1ExQf8cqkTzNt:gLkJwGE3Eez1 |
TLSH: | 72F1D506B7E90737DCBE4B7E98B3471053B2E7154D12CB1E58C8825E6CA27140EA2BB6 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...r..a.............................4... ...@....@.. ....................................@................................ |
Icon Hash: | 2086969696969600 |
Entrypoint: | 0x4034de |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x611BC772 [Tue Aug 17 14:28:02 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x348c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x4d8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x14e4 | 0x1600 | 71accce4880151301c6683520f45fc07 | False | 0.5411931818181818 | data | 5.242023678463902 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4000 | 0x4d8 | 0x600 | 3b4c8babac32e70e40c87171057e73fb | False | 0.373046875 | data | 3.7074957304627785 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6000 | 0xc | 0x200 | 1dac35429d587a58026a5138f17bfbfe | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x40a0 | 0x244 | data | 0.4706896551724138 | ||
RT_MANIFEST | 0x42e8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T15:11:32.036088+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49723 | 162.159.130.233 | 443 | TCP |
2025-01-15T15:13:19.348426+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49747 | 162.159.130.233 | 443 | TCP |
2025-01-15T15:15:42.800221+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49791 | 162.159.129.233 | 443 | TCP |
2025-01-15T15:15:48.409941+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49792 | 162.159.129.233 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 15:11:25.597353935 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:25.597388983 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:25.597457886 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:25.616450071 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:25.616466045 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.076100111 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.076200962 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:26.080287933 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:26.080300093 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.080645084 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.134562016 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:26.138394117 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:26.179331064 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.247549057 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.247718096 CET | 443 | 49722 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:26.247831106 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:26.377192974 CET | 49722 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:31.389693022 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:31.389724016 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:31.389843941 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:31.390201092 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:31.390211105 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:31.881439924 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:31.883322954 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:31.883335114 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:32.036174059 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:32.036340952 CET | 443 | 49723 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:32.036427021 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:32.036911964 CET | 49723 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.042905092 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.043015957 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.043117046 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.043442965 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.043459892 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.507646084 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.509346008 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.509381056 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.637959003 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.638036013 CET | 443 | 49724 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:37.638212919 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:37.638683081 CET | 49724 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:42.651515007 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:42.651561975 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:42.651635885 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:42.651936054 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:42.651947021 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:43.142391920 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:43.143908024 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:43.143939972 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:43.304099083 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:43.304177999 CET | 443 | 49726 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:43.304260015 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:43.304873943 CET | 49726 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.307478905 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.307566881 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.307648897 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.307863951 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.307905912 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.784207106 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.785516024 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.785547018 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.922404051 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.922585964 CET | 443 | 49727 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:48.922775030 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:48.923077106 CET | 49727 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:53.933514118 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:53.933561087 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:53.933645010 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:53.933929920 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:53.933944941 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:54.388892889 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:54.390470028 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:54.390480995 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:54.586500883 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:54.586663008 CET | 443 | 49729 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:54.586725950 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:54.587342978 CET | 49729 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:59.592102051 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:59.592149973 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:11:59.592247009 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:59.592581987 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:11:59.592593908 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:00.089660883 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:00.091290951 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:00.091308117 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:00.310642004 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:00.310808897 CET | 443 | 49732 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:00.310872078 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:00.311276913 CET | 49732 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.323750019 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.323780060 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.323874950 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.324126005 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.324141979 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.797301054 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.798569918 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.798582077 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.936539888 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.936613083 CET | 443 | 49733 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:05.936769009 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:05.937181950 CET | 49733 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:10.948944092 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:10.948990107 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:10.949141979 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:10.949321985 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:10.949340105 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:11.403784990 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:11.405617952 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:11.405648947 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:11.546925068 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:11.546987057 CET | 443 | 49734 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:11.547095060 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:11.547658920 CET | 49734 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:16.560904980 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:16.560961008 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:16.561041117 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:16.561297894 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:16.561310053 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:17.055139065 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:17.091953993 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:17.092001915 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:17.201776981 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:17.201848030 CET | 443 | 49735 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:17.201915979 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:17.204695940 CET | 49735 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.214663982 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.214704990 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.214771986 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.214993000 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.214999914 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.688909054 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.690121889 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.690140009 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.847289085 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.847472906 CET | 443 | 49737 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:22.847547054 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:22.848006964 CET | 49737 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:27.855654001 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:27.855698109 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:27.855875969 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:27.856064081 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:27.856071949 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:28.314723969 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:28.316097021 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:28.316108942 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:28.500720024 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:28.500860929 CET | 443 | 49738 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:28.501163006 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:28.501576900 CET | 49738 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:33.514266014 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:33.514306068 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:33.514431953 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:33.514684916 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:33.514700890 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:33.969640017 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:33.970992088 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:33.971004009 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:34.123321056 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:34.123406887 CET | 443 | 49739 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:34.123456955 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:34.123857021 CET | 49739 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.137949944 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.138011932 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.138079882 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.138341904 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.138360977 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.604501963 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.616300106 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.616328001 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.768815994 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.768915892 CET | 443 | 49740 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:39.769078970 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:39.780558109 CET | 49740 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:44.795866013 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:44.795916080 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:44.795972109 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:44.796462059 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:44.796473026 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:45.257098913 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:45.258461952 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:45.258491993 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:45.435900927 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:45.435955048 CET | 443 | 49741 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:45.436009884 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:45.436602116 CET | 49741 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:50.453190088 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:50.453252077 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:50.453394890 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:50.453594923 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:50.453623056 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:50.915057898 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:50.916389942 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:50.916419983 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:51.073522091 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:51.073587894 CET | 443 | 49742 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:51.073638916 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:51.074090958 CET | 49742 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.075869083 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.075962067 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.076050997 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.076314926 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.076344013 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.567004919 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.568144083 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.568172932 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.709013939 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.709183931 CET | 443 | 49743 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:12:56.709292889 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:12:56.709749937 CET | 49743 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:01.733946085 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:01.733989000 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:01.734062910 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:01.734694958 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:01.734707117 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:02.221596003 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:02.228846073 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:02.228859901 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:02.379707098 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:02.379770994 CET | 443 | 49744 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:02.380016088 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:02.380522966 CET | 49744 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:07.392105103 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:07.392158985 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:07.392218113 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:07.392601967 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:07.392611980 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:07.888967037 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:07.890765905 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:07.890783072 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:08.032418013 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:08.032485008 CET | 443 | 49745 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:08.032675982 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:08.033333063 CET | 49745 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.044220924 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.044265032 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.044403076 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.046904087 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.046926022 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.532471895 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.533865929 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.533893108 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.687005043 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.687189102 CET | 443 | 49746 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:13.687273979 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:13.687939882 CET | 49746 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:18.702909946 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:18.702958107 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:18.703094959 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:18.707007885 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:18.707022905 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:19.183717966 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:19.188949108 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:19.188983917 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:19.348459005 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:19.348628044 CET | 443 | 49747 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:19.348675013 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:19.349698067 CET | 49747 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.361907959 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.361955881 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.362270117 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.362581968 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.362592936 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.817348003 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.835460901 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.835488081 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.971637011 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.971708059 CET | 443 | 49748 | 162.159.130.233 | 192.168.2.25 |
Jan 15, 2025 15:13:24.972920895 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:24.973567963 CET | 49748 | 443 | 192.168.2.25 | 162.159.130.233 |
Jan 15, 2025 15:13:29.989430904 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:29.989471912 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:29.989556074 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:29.989826918 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:29.989836931 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:30.443635941 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:30.448873997 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:30.448889017 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:30.593374014 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:30.593451023 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:30.593662024 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:30.594096899 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:35.609569073 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:35.609621048 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:35.610322952 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:35.610614061 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:35.610630035 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:36.078521967 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:36.079809904 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:36.079857111 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:36.236402035 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:36.236463070 CET | 443 | 49752 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:36.236614943 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:36.237288952 CET | 49752 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.252545118 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.252585888 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.252660036 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.253112078 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.253128052 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.730170012 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.733165026 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.733247995 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.877001047 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.877065897 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:41.877155066 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:41.877758026 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:46.892033100 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:46.892082930 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:46.892144918 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:46.892560005 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:46.892574072 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:47.358380079 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:47.360286951 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:47.360328913 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:47.499224901 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:47.499294043 CET | 443 | 49756 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:13:47.499444962 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:47.500004053 CET | 49756 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:13:52.523488045 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:52.523515940 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:52.523752928 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:52.524039030 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:52.524068117 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:52.997859001 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:53.000149965 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:53.000165939 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:53.157126904 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:53.157190084 CET | 443 | 49759 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:53.157274008 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:53.157890081 CET | 49759 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.174904108 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.174947977 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.178347111 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.178347111 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.178385019 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.636656046 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.638662100 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.638690948 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.792589903 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.792769909 CET | 443 | 49760 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:13:58.792819977 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:13:58.793510914 CET | 49760 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:03.797427893 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:03.797482014 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:03.799207926 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:03.799207926 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:03.799251080 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:04.259296894 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:04.262125015 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:04.262165070 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:04.403912067 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:04.403976917 CET | 443 | 49761 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:04.404019117 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:04.404844046 CET | 49761 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:09.406900883 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:09.407005072 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:09.411052942 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:09.411556959 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:09.411597013 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:09.889688969 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:09.891068935 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:09.891160011 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:10.020690918 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:10.020780087 CET | 443 | 49764 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:10.021192074 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:10.022922039 CET | 49764 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.034785032 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.034848928 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.034925938 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.035393953 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.035409927 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.530381918 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.532145977 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.532176018 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.700290918 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.700371027 CET | 443 | 49765 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:15.700464010 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:15.701150894 CET | 49765 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:20.706948042 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:20.707010031 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:20.707377911 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:20.707674980 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:20.707699060 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:21.175271034 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:21.178169966 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:21.178230047 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:21.341521978 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:21.341691971 CET | 443 | 49766 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:21.341844082 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:21.342938900 CET | 49766 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.345840931 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.345879078 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.346218109 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.346218109 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.346247911 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.825390100 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.828989029 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.829009056 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.969607115 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.969682932 CET | 443 | 49768 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:26.969806910 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:26.970355034 CET | 49768 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:31.985686064 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:31.985742092 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:31.985812902 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:31.986145973 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:31.986159086 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:32.448499918 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:32.450665951 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:32.450680971 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:32.611500025 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:32.611660957 CET | 443 | 49771 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:32.611983061 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:32.612719059 CET | 49771 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:37.626292944 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:37.626354933 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:37.626465082 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:37.626713037 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:37.626729965 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:38.104548931 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:38.106249094 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:38.106286049 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:38.261974096 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:38.262041092 CET | 443 | 49773 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:38.262088060 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:38.262777090 CET | 49773 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.266967058 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.267008066 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.267222881 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.267481089 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.267488003 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.728470087 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.730004072 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.730021954 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.864656925 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.864744902 CET | 443 | 49774 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:43.864788055 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:43.865343094 CET | 49774 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:48.878644943 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:48.878700972 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:48.878988981 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:48.879355907 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:48.879368067 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:49.342541933 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:49.345155954 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:49.345185995 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:49.475361109 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:49.475451946 CET | 443 | 49776 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:49.475519896 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:49.476172924 CET | 49776 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:54.487014055 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:54.487057924 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:54.491116047 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:54.491400003 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:54.491415024 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:54.956403017 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:54.957693100 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:54.957732916 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:55.093377113 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:55.093445063 CET | 443 | 49778 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:14:55.093699932 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:14:55.094172001 CET | 49778 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.110733986 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.110797882 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.110905886 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.111143112 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.111155033 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.570008039 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.572495937 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.572536945 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.703933954 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.704010963 CET | 443 | 49782 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:00.704109907 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:00.704730988 CET | 49782 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:05.724087000 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:05.724123955 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:05.724179983 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:05.724509001 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:05.724519968 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:06.179347038 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:06.185225964 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:06.185235977 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:06.339375019 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:06.339435101 CET | 443 | 49783 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:06.339631081 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:06.339975119 CET | 49783 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.346085072 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.346143961 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.349184036 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.349468946 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.349488974 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.805428982 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.806876898 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.806910992 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.962676048 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.962769032 CET | 443 | 49784 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:11.962810993 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:11.963663101 CET | 49784 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:16.970201015 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:16.970314026 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:16.970393896 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:16.970782042 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:16.970822096 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:17.424014091 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:17.425333977 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:17.425393105 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:17.574661970 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:17.574724913 CET | 443 | 49785 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:17.574851990 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:17.575525045 CET | 49785 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:22.581682920 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:22.581748962 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:22.581829071 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:22.582149029 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:22.582169056 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:23.067135096 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:23.068407059 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:23.068444014 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:23.240552902 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:23.240619898 CET | 443 | 49786 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:23.240685940 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:23.241343021 CET | 49786 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.251391888 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.251461029 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.251657963 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.252090931 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.252106905 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.745363951 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.746445894 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.746474028 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.900721073 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.900834084 CET | 443 | 49788 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:28.900882006 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:28.901298046 CET | 49788 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:36.610655069 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:36.610749006 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:36.610863924 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:36.611119032 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:36.611159086 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:37.064400911 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:37.065696001 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:37.065727949 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:37.215900898 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:37.215975046 CET | 443 | 49790 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:37.216440916 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:37.216440916 CET | 49790 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.219630957 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.219680071 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.219748020 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.219973087 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.219985962 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.675256968 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.676332951 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.676364899 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.800239086 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.800306082 CET | 443 | 49791 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:42.801034927 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:42.801439047 CET | 49791 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:47.813467026 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:47.813544989 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:47.813926935 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:47.813926935 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:47.813973904 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:48.277091980 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:48.279151917 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:48.279233932 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:48.409820080 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:48.409914017 CET | 443 | 49792 | 162.159.129.233 | 192.168.2.25 |
Jan 15, 2025 15:15:48.410514116 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Jan 15, 2025 15:15:48.411140919 CET | 49792 | 443 | 192.168.2.25 | 162.159.129.233 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 15:11:25.584099054 CET | 52517 | 53 | 192.168.2.25 | 1.1.1.1 |
Jan 15, 2025 15:11:25.590739965 CET | 53 | 52517 | 1.1.1.1 | 192.168.2.25 |
Jan 15, 2025 15:13:29.981620073 CET | 56204 | 53 | 192.168.2.25 | 1.1.1.1 |
Jan 15, 2025 15:13:29.988631010 CET | 53 | 56204 | 1.1.1.1 | 192.168.2.25 |
Jan 15, 2025 15:13:52.515533924 CET | 56204 | 53 | 192.168.2.25 | 1.1.1.1 |
Jan 15, 2025 15:13:52.522655010 CET | 53 | 56204 | 1.1.1.1 | 192.168.2.25 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 15:11:25.584099054 CET | 192.168.2.25 | 1.1.1.1 | 0xca0e | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 15:13:29.981620073 CET | 192.168.2.25 | 1.1.1.1 | 0xb8ba | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 15:13:52.515533924 CET | 192.168.2.25 | 1.1.1.1 | 0x4a34 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 15:11:25.590739965 CET | 1.1.1.1 | 192.168.2.25 | 0xca0e | No error (0) | 162.159.130.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:11:25.590739965 CET | 1.1.1.1 | 192.168.2.25 | 0xca0e | No error (0) | 162.159.133.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:11:25.590739965 CET | 1.1.1.1 | 192.168.2.25 | 0xca0e | No error (0) | 162.159.129.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:11:25.590739965 CET | 1.1.1.1 | 192.168.2.25 | 0xca0e | No error (0) | 162.159.135.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:11:25.590739965 CET | 1.1.1.1 | 192.168.2.25 | 0xca0e | No error (0) | 162.159.134.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:29.988631010 CET | 1.1.1.1 | 192.168.2.25 | 0xb8ba | No error (0) | 162.159.134.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:29.988631010 CET | 1.1.1.1 | 192.168.2.25 | 0xb8ba | No error (0) | 162.159.130.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:29.988631010 CET | 1.1.1.1 | 192.168.2.25 | 0xb8ba | No error (0) | 162.159.133.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:29.988631010 CET | 1.1.1.1 | 192.168.2.25 | 0xb8ba | No error (0) | 162.159.135.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:29.988631010 CET | 1.1.1.1 | 192.168.2.25 | 0xb8ba | No error (0) | 162.159.129.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:52.522655010 CET | 1.1.1.1 | 192.168.2.25 | 0x4a34 | No error (0) | 162.159.129.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:52.522655010 CET | 1.1.1.1 | 192.168.2.25 | 0x4a34 | No error (0) | 162.159.134.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:52.522655010 CET | 1.1.1.1 | 192.168.2.25 | 0x4a34 | No error (0) | 162.159.130.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:52.522655010 CET | 1.1.1.1 | 192.168.2.25 | 0x4a34 | No error (0) | 162.159.135.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:13:52.522655010 CET | 1.1.1.1 | 192.168.2.25 | 0x4a34 | No error (0) | 162.159.133.233 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.25 | 49722 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:26 UTC | 128 | OUT | |
2025-01-15 14:11:26 UTC | 1045 | IN | |
2025-01-15 14:11:26 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.25 | 49723 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:31 UTC | 104 | OUT | |
2025-01-15 14:11:32 UTC | 1051 | IN | |
2025-01-15 14:11:32 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.25 | 49724 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:37 UTC | 128 | OUT | |
2025-01-15 14:11:37 UTC | 1057 | IN | |
2025-01-15 14:11:37 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.25 | 49726 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:43 UTC | 128 | OUT | |
2025-01-15 14:11:43 UTC | 1047 | IN | |
2025-01-15 14:11:43 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.25 | 49727 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:48 UTC | 128 | OUT | |
2025-01-15 14:11:48 UTC | 1047 | IN | |
2025-01-15 14:11:48 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.25 | 49729 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:11:54 UTC | 128 | OUT | |
2025-01-15 14:11:54 UTC | 1047 | IN | |
2025-01-15 14:11:54 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.25 | 49732 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:00 UTC | 128 | OUT | |
2025-01-15 14:12:00 UTC | 1051 | IN | |
2025-01-15 14:12:00 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.25 | 49733 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:05 UTC | 128 | OUT | |
2025-01-15 14:12:05 UTC | 1047 | IN | |
2025-01-15 14:12:05 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.25 | 49734 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:11 UTC | 128 | OUT | |
2025-01-15 14:12:11 UTC | 1053 | IN | |
2025-01-15 14:12:11 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.25 | 49735 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:17 UTC | 128 | OUT | |
2025-01-15 14:12:17 UTC | 1043 | IN | |
2025-01-15 14:12:17 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.25 | 49737 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:22 UTC | 128 | OUT | |
2025-01-15 14:12:22 UTC | 1049 | IN | |
2025-01-15 14:12:22 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.25 | 49738 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:28 UTC | 128 | OUT | |
2025-01-15 14:12:28 UTC | 1041 | IN | |
2025-01-15 14:12:28 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.25 | 49739 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:33 UTC | 128 | OUT | |
2025-01-15 14:12:34 UTC | 1051 | IN | |
2025-01-15 14:12:34 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.25 | 49740 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:39 UTC | 128 | OUT | |
2025-01-15 14:12:39 UTC | 1051 | IN | |
2025-01-15 14:12:39 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.25 | 49741 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:45 UTC | 128 | OUT | |
2025-01-15 14:12:45 UTC | 1047 | IN | |
2025-01-15 14:12:45 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.25 | 49742 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:50 UTC | 128 | OUT | |
2025-01-15 14:12:51 UTC | 1047 | IN | |
2025-01-15 14:12:51 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.25 | 49743 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:12:56 UTC | 128 | OUT | |
2025-01-15 14:12:56 UTC | 1047 | IN | |
2025-01-15 14:12:56 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.25 | 49744 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:02 UTC | 128 | OUT | |
2025-01-15 14:13:02 UTC | 1051 | IN | |
2025-01-15 14:13:02 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.25 | 49745 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:07 UTC | 128 | OUT | |
2025-01-15 14:13:08 UTC | 1051 | IN | |
2025-01-15 14:13:08 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.25 | 49746 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:13 UTC | 128 | OUT | |
2025-01-15 14:13:13 UTC | 1051 | IN | |
2025-01-15 14:13:13 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.25 | 49747 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:19 UTC | 104 | OUT | |
2025-01-15 14:13:19 UTC | 1051 | IN | |
2025-01-15 14:13:19 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.25 | 49748 | 162.159.130.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:24 UTC | 128 | OUT | |
2025-01-15 14:13:24 UTC | 1053 | IN | |
2025-01-15 14:13:24 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.25 | 49749 | 162.159.134.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:30 UTC | 128 | OUT | |
2025-01-15 14:13:30 UTC | 1055 | IN | |
2025-01-15 14:13:30 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.25 | 49752 | 162.159.134.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:36 UTC | 128 | OUT | |
2025-01-15 14:13:36 UTC | 1055 | IN | |
2025-01-15 14:13:36 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.25 | 49755 | 162.159.134.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:41 UTC | 128 | OUT | |
2025-01-15 14:13:41 UTC | 1043 | IN | |
2025-01-15 14:13:41 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.25 | 49756 | 162.159.134.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:47 UTC | 128 | OUT | |
2025-01-15 14:13:47 UTC | 1047 | IN | |
2025-01-15 14:13:47 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.25 | 49759 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:52 UTC | 128 | OUT | |
2025-01-15 14:13:53 UTC | 1053 | IN | |
2025-01-15 14:13:53 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.25 | 49760 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:13:58 UTC | 128 | OUT | |
2025-01-15 14:13:58 UTC | 1051 | IN | |
2025-01-15 14:13:58 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.25 | 49761 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:04 UTC | 128 | OUT | |
2025-01-15 14:14:04 UTC | 1055 | IN | |
2025-01-15 14:14:04 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.25 | 49764 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:09 UTC | 128 | OUT | |
2025-01-15 14:14:10 UTC | 1047 | IN | |
2025-01-15 14:14:10 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.25 | 49765 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:15 UTC | 128 | OUT | |
2025-01-15 14:14:15 UTC | 1045 | IN | |
2025-01-15 14:14:15 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.25 | 49766 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:21 UTC | 128 | OUT | |
2025-01-15 14:14:21 UTC | 1047 | IN | |
2025-01-15 14:14:21 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.25 | 49768 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:26 UTC | 128 | OUT | |
2025-01-15 14:14:26 UTC | 1049 | IN | |
2025-01-15 14:14:26 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
33 | 192.168.2.25 | 49771 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:32 UTC | 128 | OUT | |
2025-01-15 14:14:32 UTC | 1049 | IN | |
2025-01-15 14:14:32 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
34 | 192.168.2.25 | 49773 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:38 UTC | 128 | OUT | |
2025-01-15 14:14:38 UTC | 1053 | IN | |
2025-01-15 14:14:38 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
35 | 192.168.2.25 | 49774 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:43 UTC | 128 | OUT | |
2025-01-15 14:14:43 UTC | 1051 | IN | |
2025-01-15 14:14:43 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
36 | 192.168.2.25 | 49776 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:49 UTC | 128 | OUT | |
2025-01-15 14:14:49 UTC | 1051 | IN | |
2025-01-15 14:14:49 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
37 | 192.168.2.25 | 49778 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:14:54 UTC | 128 | OUT | |
2025-01-15 14:14:55 UTC | 1045 | IN | |
2025-01-15 14:14:55 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
38 | 192.168.2.25 | 49782 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:00 UTC | 128 | OUT | |
2025-01-15 14:15:00 UTC | 1049 | IN | |
2025-01-15 14:15:00 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
39 | 192.168.2.25 | 49783 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:06 UTC | 128 | OUT | |
2025-01-15 14:15:06 UTC | 1045 | IN | |
2025-01-15 14:15:06 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
40 | 192.168.2.25 | 49784 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:11 UTC | 128 | OUT | |
2025-01-15 14:15:11 UTC | 1049 | IN | |
2025-01-15 14:15:11 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
41 | 192.168.2.25 | 49785 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:17 UTC | 128 | OUT | |
2025-01-15 14:15:17 UTC | 1057 | IN | |
2025-01-15 14:15:17 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
42 | 192.168.2.25 | 49786 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:23 UTC | 128 | OUT | |
2025-01-15 14:15:23 UTC | 1045 | IN | |
2025-01-15 14:15:23 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
43 | 192.168.2.25 | 49788 | 162.159.129.233 | 443 | 7448 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:28 UTC | 128 | OUT | |
2025-01-15 14:15:28 UTC | 1047 | IN | |
2025-01-15 14:15:28 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
44 | 192.168.2.25 | 49790 | 162.159.129.233 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:37 UTC | 128 | OUT | |
2025-01-15 14:15:37 UTC | 1053 | IN | |
2025-01-15 14:15:37 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
45 | 192.168.2.25 | 49791 | 162.159.129.233 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:42 UTC | 104 | OUT | |
2025-01-15 14:15:42 UTC | 1047 | IN | |
2025-01-15 14:15:42 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port |
---|---|---|---|---|
46 | 192.168.2.25 | 49792 | 162.159.129.233 | 443 |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:15:48 UTC | 104 | OUT | |
2025-01-15 14:15:48 UTC | 1055 | IN | |
2025-01-15 14:15:48 UTC | 36 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:11:23 |
Start date: | 15/01/2025 |
Path: | C:\Users\user\Desktop\Sample1.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x10000 |
File size: | 8'192 bytes |
MD5 hash: | 45A47D815F2291BC7FC0112D36AAAD83 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 40 |
Start time: | 09:14:19 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\SystemSettingsBroker.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6baff0000 |
File size: | 220'536 bytes |
MD5 hash: | 899E65893CDEE7F9022DC9B583F94F0F |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |