Windows
Analysis Report
Sample1.exe
Overview
General Information
Detection
Score: | 84 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w11x64_office
- Sample1.exe (PID: 8064 cmdline:
"C:\Users\ user\Deskt op\Sample1 .exe" MD5: 45A47D815F2291BC7FC0112D36AAAD83)
- SystemSettingsBroker.exe (PID: 1800 cmdline:
C:\Windows \System32\ SystemSett ingsBroker .exe -Embe dding MD5: 899E65893CDEE7F9022DC9B583F94F0F)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
MALWARE_Win_DLInjector04 | Detects downloader / injector | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_GenericDownloader_4 | Yara detected Generic Downloader | Joe Security |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T15:18:56.208229+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49725 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:01.854714+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49726 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:07.485230+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49728 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:13.110015+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49729 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:18.847202+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49733 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:24.464986+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49734 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:30.235710+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49735 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:35.857290+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49736 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:41.496340+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49738 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:47.151638+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49739 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:52.784463+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49740 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:58.602679+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49741 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:04.267335+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49742 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:09.899303+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49743 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:15.597093+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49744 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:21.219129+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49745 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:26.894034+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49746 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:32.497357+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49747 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:38.233099+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49748 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:43.861268+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49749 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:49.470785+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49750 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:55.238474+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49751 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:00.915491+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49755 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:06.530355+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49757 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:12.188694+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49760 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:17.839514+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49761 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:23.438596+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49762 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:29.086049+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49765 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:34.705037+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49766 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:40.342449+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49767 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:46.012112+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49768 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:51.634893+0100 | 2803305 | 3 | Unknown Traffic | 192.168.2.25 | 49773 | 162.159.134.233 | 443 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | HTTPS traffic detected: |
Source: | Static PE information: |
Networking |
---|
Source: | File source: | ||
Source: | File source: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | Windows Management Instrumentation | 1 DLL Side-Loading | 1 Process Injection | 1 Disable or Modify Tools | OS Credential Dumping | 11 Security Software Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 31 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 3 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 4 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 12 System Information Discovery | Distributed Component Object Model | Input Capture | 3 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
83% | Virustotal | Browse | ||
82% | ReversingLabs | ByteCode-MSIL.Trojan.AgentTesla | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
cdn.discordapp.com | 162.159.134.233 | true | false | high | |
assets.msn.com | unknown | unknown | false | high | |
browser.events.data.msn.cn | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.159.134.233 | cdn.discordapp.com | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1591875 |
Start date and time: | 2025-01-15 15:17:52 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 10s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 11 23H2 with Office Professional Plus 2021, Chrome 131, Firefox 133, Adobe Reader DC 24, Java 8 Update 431, 7zip 24.09 |
Run name: | Run with higher sleep bypass |
Number of analysed new started processes analysed: | 42 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Sample1.exe |
Detection: | MAL |
Classification: | mal84.troj.evad.winEXE@2/0@3/1 |
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, SecurityHealthHost.exe, dllhost.exe, RuntimeBroker.exe, ShellExperienceHost.exe, WMIADAP.exe, SIHClient.exe, appidcertstorecheck.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.227.209, 2.23.227.197, 2.23.227.207, 2.23.227.212, 2.23.227.213, 2.23.227.196, 40.79.167.8, 2.23.242.162, 4.175.87.197, 20.12.23.50, 40.126.32.74
- Excluded domains from analysis (whitelisted): assets.msn.com.edgekey.net, client.wns.windows.com, fs.microsoft.com, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, onedscolprdaue02.australiaeast.cloudapp.azure.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com, otelrules.svc.static.microsoft, login.live.com, global.asimov.events.data.trafficmanager.net, wu-b-net.trafficmanager.net, e28578.d.akamaiedge.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
162.159.134.233 | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AveMaria | Browse |
| ||
Get hash | malicious | Amadey | Browse |
| ||
Get hash | malicious | Amadey RedLine SmokeLoader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
cdn.discordapp.com | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Metasploit, Meterpreter | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CStealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Xmrig | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | Wannacry | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | PureCrypter, LummaC, LummaC Stealer | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | PXRECVOWEIWOEI Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Phemedrone Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | MassLogger RAT, PureLog Stealer | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
6a5d235ee78c6aede6a61448b4e9ff1e | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
File type: | |
Entropy (8bit): | 4.677687653335447 |
TrID: |
|
File name: | Sample1.exe |
File size: | 8'192 bytes |
MD5: | 45a47d815f2291bc7fc0112d36aaad83 |
SHA1: | db1dc02b2d64c4c3db89b5df3124dd87d43059d5 |
SHA256: | 416e63fb614101d5644592d5f589f358f8d5a41dd6812a717cbf05470864ac6f |
SHA512: | a7d98145cf949a42ace2da725a22847ad814a28137d32b0b220430b91c89aabed7144b85f20c2fd9a1a02f5b92520bf5f0afbe8202028f9832cbc29c2a9e776e |
SSDEEP: | 96:gJOElmu1B9ilJJMOfEkdEKozt1ExQf8cqkTzNt:gLkJwGE3Eez1 |
TLSH: | 72F1D506B7E90737DCBE4B7E98B3471053B2E7154D12CB1E58C8825E6CA27140EA2BB6 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...r..a.............................4... ...@....@.. ....................................@................................ |
Icon Hash: | 2086969696969600 |
Entrypoint: | 0x4034de |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x611BC772 [Tue Aug 17 14:28:02 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x348c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x4000 | 0x4d8 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x6000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x14e4 | 0x1600 | 71accce4880151301c6683520f45fc07 | False | 0.5411931818181818 | data | 5.242023678463902 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x4000 | 0x4d8 | 0x600 | 3b4c8babac32e70e40c87171057e73fb | False | 0.373046875 | data | 3.7074957304627785 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x6000 | 0xc | 0x200 | 1dac35429d587a58026a5138f17bfbfe | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x40a0 | 0x244 | data | 0.4706896551724138 | ||
RT_MANIFEST | 0x42e8 | 0x1ea | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.5469387755102041 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T15:18:56.208229+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49725 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:01.854714+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49726 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:07.485230+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49728 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:13.110015+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49729 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:18.847202+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49733 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:24.464986+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49734 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:30.235710+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49735 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:35.857290+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49736 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:41.496340+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49738 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:47.151638+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49739 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:52.784463+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49740 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:19:58.602679+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49741 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:04.267335+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49742 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:09.899303+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49743 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:15.597093+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49744 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:21.219129+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49745 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:26.894034+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49746 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:32.497357+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49747 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:38.233099+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49748 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:43.861268+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49749 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:49.470785+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49750 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:20:55.238474+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49751 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:00.915491+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49755 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:06.530355+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49757 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:12.188694+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49760 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:17.839514+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49761 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:23.438596+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49762 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:29.086049+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49765 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:34.705037+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49766 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:40.342449+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49767 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:46.012112+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49768 | 162.159.134.233 | 443 | TCP |
2025-01-15T15:21:51.634893+0100 | 2803305 | ETPRO MALWARE Common Downloader Header Pattern H | 3 | 192.168.2.25 | 49773 | 162.159.134.233 | 443 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 15:18:48.628469944 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:48.628506899 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:48.628669977 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:48.786597967 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:48.786628962 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:49.278188944 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:49.278263092 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:49.290812969 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:49.290827036 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:49.291132927 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:49.338035107 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:50.162987947 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:50.203340054 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:50.303406000 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:50.303472042 CET | 443 | 49724 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:50.303527117 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:50.457145929 CET | 49724 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:55.573623896 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:55.573681116 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:55.577765942 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:55.584276915 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:55.584290028 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:56.048686981 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:56.050597906 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:56.050606966 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:56.208254099 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:56.208403111 CET | 443 | 49725 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:18:56.208473921 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:18:56.209327936 CET | 49725 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.220705032 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.220757961 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.220833063 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.221453905 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.221468925 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.705261946 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.707104921 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.707134962 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.854690075 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.854773998 CET | 443 | 49726 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:01.854911089 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:01.855536938 CET | 49726 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:06.871047974 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:06.871109962 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:06.871356010 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:06.871697903 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:06.871710062 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:07.324158907 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:07.325685978 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:07.325701952 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:07.485188961 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:07.485384941 CET | 443 | 49728 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:07.485594988 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:07.485937119 CET | 49728 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:12.496097088 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:12.496157885 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:12.496248007 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:12.496642113 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:12.496655941 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:12.958465099 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:12.959937096 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:12.959969044 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:13.110002041 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:13.110069990 CET | 443 | 49729 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:13.110213995 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:13.110740900 CET | 49729 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.121264935 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.121368885 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.121483088 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.121889114 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.121921062 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.705935001 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.707271099 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.707320929 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.847285986 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.847512007 CET | 443 | 49733 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:18.847584009 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:18.848200083 CET | 49733 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:23.855499029 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:23.855564117 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:23.855658054 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:23.856111050 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:23.856137991 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:24.306392908 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:24.307898045 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:24.307971001 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:24.464987993 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:24.465063095 CET | 443 | 49734 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:24.465126991 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:24.465758085 CET | 49734 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:29.483308077 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:29.483383894 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:29.483468056 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:29.483782053 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:29.483800888 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:29.969970942 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:29.971467972 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:29.971497059 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:30.235749006 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:30.235835075 CET | 443 | 49735 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:30.235893965 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:30.236495972 CET | 49735 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.246419907 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.246464014 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.246562958 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.246954918 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.246972084 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.719644070 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.721415043 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.721446991 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.857295990 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.857379913 CET | 443 | 49736 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:35.857448101 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:35.858256102 CET | 49736 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:40.882287025 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:40.882329941 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:40.882412910 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:40.882776976 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:40.882791042 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:41.341495037 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:41.343513966 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:41.343533039 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:41.496423960 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:41.496591091 CET | 443 | 49738 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:41.496655941 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:41.497191906 CET | 49738 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:46.519453049 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:46.519512892 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:46.519598007 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:46.526566029 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:46.526585102 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:46.993549109 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:46.994977951 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:46.995012999 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:47.151721001 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:47.151897907 CET | 443 | 49739 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:47.151956081 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:47.152452946 CET | 49739 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.169152021 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.169244051 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.169337988 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.169810057 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.169830084 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.628513098 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.629954100 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.630023956 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.784463882 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.784533978 CET | 443 | 49740 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:52.784617901 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:52.785240889 CET | 49740 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:57.793705940 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:57.793766975 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:57.794039011 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:57.794550896 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:57.794563055 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:58.467201948 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:58.468698025 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:58.468714952 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:58.602766991 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:58.602863073 CET | 443 | 49741 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:19:58.602905035 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:19:58.603401899 CET | 49741 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:03.606257915 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:03.606373072 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:03.606511116 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:03.606951952 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:03.606993914 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:04.093141079 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:04.094816923 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:04.094866991 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:04.267275095 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:04.267349958 CET | 443 | 49742 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:04.267565012 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:04.268155098 CET | 49742 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.277976036 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.278023958 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.278179884 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.278533936 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.278548002 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.747689962 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.749201059 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.749219894 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.899311066 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.899393082 CET | 443 | 49743 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:09.899455070 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:09.900243044 CET | 49743 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:14.903036118 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:14.903090000 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:14.903176069 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:14.903542042 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:14.903557062 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:15.445282936 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:15.446856022 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:15.446878910 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:15.596992016 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:15.597060919 CET | 443 | 49744 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:15.597127914 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:15.597781897 CET | 49744 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:20.606245995 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:20.606296062 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:20.606406927 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:20.606750965 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:20.606769085 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:21.082346916 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:21.083975077 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:21.084001064 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:21.219127893 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:21.219192028 CET | 443 | 49745 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:21.219243050 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:21.219856024 CET | 49745 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.231822968 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.231945038 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.232111931 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.232464075 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.232501030 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.696187019 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.697734118 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.697825909 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.893876076 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.893939972 CET | 443 | 49746 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:26.894021988 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:26.894753933 CET | 49746 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:31.904011011 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:31.904057026 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:31.904172897 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:31.904496908 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:31.904505968 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:32.357969046 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:32.360884905 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:32.360918045 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:32.497308969 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:32.497371912 CET | 443 | 49747 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:32.497523069 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:32.498106956 CET | 49747 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:37.587236881 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:37.587296009 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:37.587712049 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:37.587712049 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:37.587748051 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:38.071667910 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:38.073343039 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:38.073359966 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:38.233099937 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:38.233172894 CET | 443 | 49748 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:38.233283997 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:38.233931065 CET | 49748 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.247859955 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.247904062 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.248022079 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.248362064 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.248382092 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.721849918 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.723360062 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.723396063 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.861259937 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.861331940 CET | 443 | 49749 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:43.861489058 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:43.862065077 CET | 49749 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:48.875426054 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:48.875467062 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:48.875613928 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:48.875919104 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:48.875933886 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:49.332915068 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:49.355331898 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:49.355345964 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:49.470787048 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:49.470850945 CET | 443 | 49750 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:49.478257895 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:49.482832909 CET | 49750 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:54.487901926 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:54.487960100 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:54.488341093 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:54.488703966 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:54.488720894 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:55.076354980 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:55.077958107 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:55.077999115 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:55.238454103 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:55.238517046 CET | 443 | 49751 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:20:55.238569975 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:20:55.239151001 CET | 49751 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.250893116 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.250930071 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.250998020 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.252049923 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.252063036 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.755834103 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.757452011 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.757482052 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.915502071 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.915570974 CET | 443 | 49755 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:00.915620089 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:00.916240931 CET | 49755 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:05.923739910 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:05.923851013 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:05.923976898 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:05.924329042 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:05.924375057 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:06.377069950 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:06.390872002 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:06.390961885 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:06.530364037 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:06.530425072 CET | 443 | 49757 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:06.530482054 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:06.542407990 CET | 49757 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:11.548736095 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:11.548794031 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:11.548887968 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:11.549151897 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:11.549170017 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:12.023483992 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:12.025027037 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:12.025051117 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:12.188699961 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:12.188751936 CET | 443 | 49760 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:12.188910961 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:12.189508915 CET | 49760 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.205454111 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.205508947 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.205627918 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.205912113 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.205921888 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.686233044 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.687823057 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.687863111 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.839530945 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.839608908 CET | 443 | 49761 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:17.839904070 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:17.840852976 CET | 49761 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:22.845237970 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:22.845294952 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:22.845397949 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:22.845791101 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:22.845808029 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:23.314791918 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:23.316097975 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:23.316133022 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:23.438607931 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:23.438694954 CET | 443 | 49762 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:23.438771009 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:23.441231966 CET | 49762 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:28.454643965 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:28.454689026 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:28.454790115 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:28.455451965 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:28.455466986 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:28.939367056 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:28.954863071 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:28.954912901 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:29.086072922 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:29.086150885 CET | 443 | 49765 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:29.086208105 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:29.087042093 CET | 49765 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.095412970 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.095462084 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.095603943 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.096002102 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.096014977 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.558499098 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.559926033 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.559962034 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.705068111 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.705152988 CET | 443 | 49766 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:34.705199957 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:34.705682039 CET | 49766 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:39.720493078 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:39.720561028 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:39.720662117 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:39.721086025 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:39.721105099 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:40.207102060 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:40.208895922 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:40.208936930 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:40.342513084 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:40.342679024 CET | 443 | 49767 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:40.342757940 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:40.343221903 CET | 49767 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:45.352475882 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:45.352540970 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:45.352650881 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:45.353039026 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:45.353049994 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:45.857256889 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:45.859039068 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:45.859066963 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:46.012118101 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:46.012188911 CET | 443 | 49768 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:46.012238026 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:46.012903929 CET | 49768 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:51.021147966 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:51.021248102 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.021354914 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:51.022145987 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:51.022181988 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.493000031 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.499052048 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:51.499106884 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.634990931 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.635164976 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.639342070 CET | 443 | 49773 | 162.159.134.233 | 192.168.2.25 |
Jan 15, 2025 15:21:51.639483929 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Jan 15, 2025 15:21:52.094378948 CET | 49773 | 443 | 192.168.2.25 | 162.159.134.233 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 15:18:48.602514029 CET | 56959 | 53 | 192.168.2.25 | 1.1.1.1 |
Jan 15, 2025 15:18:48.609025002 CET | 53 | 56959 | 1.1.1.1 | 192.168.2.25 |
Jan 15, 2025 15:21:47.699126959 CET | 63865 | 53 | 192.168.2.25 | 1.1.1.1 |
Jan 15, 2025 15:21:57.471528053 CET | 63865 | 53 | 192.168.2.25 | 1.1.1.1 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 15:18:48.602514029 CET | 192.168.2.25 | 1.1.1.1 | 0x83ee | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 15:21:47.699126959 CET | 192.168.2.25 | 1.1.1.1 | 0xcb27 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 15, 2025 15:21:57.471528053 CET | 192.168.2.25 | 1.1.1.1 | 0xe92d | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 15:18:42.067709923 CET | 1.1.1.1 | 192.168.2.25 | 0xc9d2 | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:42.067709923 CET | 1.1.1.1 | 192.168.2.25 | 0xc9d2 | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:48.609025002 CET | 1.1.1.1 | 192.168.2.25 | 0x83ee | No error (0) | 162.159.134.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:48.609025002 CET | 1.1.1.1 | 192.168.2.25 | 0x83ee | No error (0) | 162.159.133.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:48.609025002 CET | 1.1.1.1 | 192.168.2.25 | 0x83ee | No error (0) | 162.159.135.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:48.609025002 CET | 1.1.1.1 | 192.168.2.25 | 0x83ee | No error (0) | 162.159.129.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:18:48.609025002 CET | 1.1.1.1 | 192.168.2.25 | 0x83ee | No error (0) | 162.159.130.233 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 15:21:47.705893040 CET | 1.1.1.1 | 192.168.2.25 | 0xcb27 | No error (0) | assets.msn.com.edgekey.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 15:21:57.478562117 CET | 1.1.1.1 | 192.168.2.25 | 0xe92d | No error (0) | global.asimov.events.data.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.25 | 49724 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:18:50 UTC | 128 | OUT | |
2025-01-15 14:18:50 UTC | 1047 | IN | |
2025-01-15 14:18:50 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.25 | 49725 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:18:56 UTC | 104 | OUT | |
2025-01-15 14:18:56 UTC | 1049 | IN | |
2025-01-15 14:18:56 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.25 | 49726 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:01 UTC | 104 | OUT | |
2025-01-15 14:19:01 UTC | 1045 | IN | |
2025-01-15 14:19:01 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
3 | 192.168.2.25 | 49728 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:07 UTC | 104 | OUT | |
2025-01-15 14:19:07 UTC | 1047 | IN | |
2025-01-15 14:19:07 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
4 | 192.168.2.25 | 49729 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:12 UTC | 104 | OUT | |
2025-01-15 14:19:13 UTC | 1047 | IN | |
2025-01-15 14:19:13 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
5 | 192.168.2.25 | 49733 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:18 UTC | 104 | OUT | |
2025-01-15 14:19:18 UTC | 1053 | IN | |
2025-01-15 14:19:18 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
6 | 192.168.2.25 | 49734 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:24 UTC | 104 | OUT | |
2025-01-15 14:19:24 UTC | 1043 | IN | |
2025-01-15 14:19:24 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
7 | 192.168.2.25 | 49735 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:29 UTC | 104 | OUT | |
2025-01-15 14:19:30 UTC | 1047 | IN | |
2025-01-15 14:19:30 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
8 | 192.168.2.25 | 49736 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:35 UTC | 104 | OUT | |
2025-01-15 14:19:35 UTC | 1043 | IN | |
2025-01-15 14:19:35 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
9 | 192.168.2.25 | 49738 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:41 UTC | 104 | OUT | |
2025-01-15 14:19:41 UTC | 1045 | IN | |
2025-01-15 14:19:41 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
10 | 192.168.2.25 | 49739 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:46 UTC | 104 | OUT | |
2025-01-15 14:19:47 UTC | 1049 | IN | |
2025-01-15 14:19:47 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
11 | 192.168.2.25 | 49740 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:52 UTC | 104 | OUT | |
2025-01-15 14:19:52 UTC | 1047 | IN | |
2025-01-15 14:19:52 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
12 | 192.168.2.25 | 49741 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:19:58 UTC | 104 | OUT | |
2025-01-15 14:19:58 UTC | 1047 | IN | |
2025-01-15 14:19:58 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
13 | 192.168.2.25 | 49742 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:04 UTC | 104 | OUT | |
2025-01-15 14:20:04 UTC | 1053 | IN | |
2025-01-15 14:20:04 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
14 | 192.168.2.25 | 49743 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:09 UTC | 104 | OUT | |
2025-01-15 14:20:09 UTC | 1049 | IN | |
2025-01-15 14:20:09 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
15 | 192.168.2.25 | 49744 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:15 UTC | 104 | OUT | |
2025-01-15 14:20:15 UTC | 1051 | IN | |
2025-01-15 14:20:15 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
16 | 192.168.2.25 | 49745 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:21 UTC | 104 | OUT | |
2025-01-15 14:20:21 UTC | 1049 | IN | |
2025-01-15 14:20:21 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
17 | 192.168.2.25 | 49746 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:26 UTC | 104 | OUT | |
2025-01-15 14:20:26 UTC | 1047 | IN | |
2025-01-15 14:20:26 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
18 | 192.168.2.25 | 49747 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:32 UTC | 104 | OUT | |
2025-01-15 14:20:32 UTC | 1051 | IN | |
2025-01-15 14:20:32 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
19 | 192.168.2.25 | 49748 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:38 UTC | 104 | OUT | |
2025-01-15 14:20:38 UTC | 1051 | IN | |
2025-01-15 14:20:38 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
20 | 192.168.2.25 | 49749 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:43 UTC | 104 | OUT | |
2025-01-15 14:20:43 UTC | 1055 | IN | |
2025-01-15 14:20:43 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
21 | 192.168.2.25 | 49750 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:49 UTC | 104 | OUT | |
2025-01-15 14:20:49 UTC | 1051 | IN | |
2025-01-15 14:20:49 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
22 | 192.168.2.25 | 49751 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:20:55 UTC | 104 | OUT | |
2025-01-15 14:20:55 UTC | 1055 | IN | |
2025-01-15 14:20:55 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
23 | 192.168.2.25 | 49755 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:00 UTC | 104 | OUT | |
2025-01-15 14:21:00 UTC | 1041 | IN | |
2025-01-15 14:21:00 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
24 | 192.168.2.25 | 49757 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:06 UTC | 104 | OUT | |
2025-01-15 14:21:06 UTC | 1047 | IN | |
2025-01-15 14:21:06 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
25 | 192.168.2.25 | 49760 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:12 UTC | 104 | OUT | |
2025-01-15 14:21:12 UTC | 1051 | IN | |
2025-01-15 14:21:12 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
26 | 192.168.2.25 | 49761 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:17 UTC | 104 | OUT | |
2025-01-15 14:21:17 UTC | 1051 | IN | |
2025-01-15 14:21:17 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
27 | 192.168.2.25 | 49762 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:23 UTC | 104 | OUT | |
2025-01-15 14:21:23 UTC | 1049 | IN | |
2025-01-15 14:21:23 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
28 | 192.168.2.25 | 49765 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:28 UTC | 104 | OUT | |
2025-01-15 14:21:29 UTC | 1045 | IN | |
2025-01-15 14:21:29 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
29 | 192.168.2.25 | 49766 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:34 UTC | 104 | OUT | |
2025-01-15 14:21:34 UTC | 1043 | IN | |
2025-01-15 14:21:34 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
30 | 192.168.2.25 | 49767 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:40 UTC | 104 | OUT | |
2025-01-15 14:21:40 UTC | 1045 | IN | |
2025-01-15 14:21:40 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
31 | 192.168.2.25 | 49768 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:45 UTC | 104 | OUT | |
2025-01-15 14:21:46 UTC | 1043 | IN | |
2025-01-15 14:21:46 UTC | 36 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
32 | 192.168.2.25 | 49773 | 162.159.134.233 | 443 | 8064 | C:\Users\user\Desktop\Sample1.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 14:21:51 UTC | 104 | OUT | |
2025-01-15 14:21:51 UTC | 1045 | IN | |
2025-01-15 14:21:51 UTC | 36 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 09:18:46 |
Start date: | 15/01/2025 |
Path: | C:\Users\user\Desktop\Sample1.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x750000 |
File size: | 8'192 bytes |
MD5 hash: | 45A47D815F2291BC7FC0112D36AAAD83 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 39 |
Start time: | 09:21:44 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\SystemSettingsBroker.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70cfb0000 |
File size: | 220'536 bytes |
MD5 hash: | 899E65893CDEE7F9022DC9B583F94F0F |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |