Windows
Analysis Report
009.vbe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5548 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\009.v be" MD5: A47CBE969EA935BDD3AB568BB126BC80)
- wscript.exe (PID: 5844 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\App Data\Roami ng\bEvujII dkyIbOgF.v bs" MD5: A47CBE969EA935BDD3AB568BB126BC80) - powershell.exe (PID: 6004 cmdline:
"C:\Window s\system32 \WindowsPo werShell\v 1.0\powers hell.exe" MD5: 04029E121A0CFA5991749937DD22A1D9) - conhost.exe (PID: 432 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - MSBuild.exe (PID: 380 cmdline:
"C:\Window s\Microsof t.NET\Fram ework\v4.0 .30319\MSB uild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232) - wermgr.exe (PID: 5532 cmdline:
"C:\Window s\system32 \wermgr.ex e" "-outpr oc" "0" "6 004" "2764 " "2772" " 2788" "0" "0" "2828" "0" "0" " 0" "0" "0" MD5: 74A0194782E039ACE1F7349544DC1CF4)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
Agent Tesla, AgentTesla | A .NET based information stealer readily available to actors due to leaked builders. The malware is able to log keystrokes, can access the host's clipboard and crawls the disk for credentials or other valuable information. It has the capability to send information back to its C&C via HTTP(S), SMTP, FTP, or towards a Telegram channel. |
{"Exfil Mode": "SMTP", "Port": "587", "Host": "162.254.34.31", "Username": "sendxsenses@vetrys.shop", "Password": "M992uew1mw6Z"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 3 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_AgentTesla_1 | Yara detected AgentTesla | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_VaultSchemaGUID | Detects executables referencing Windows vault credential objects. Observed in infostealers | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC | Detects PowerShell scripts containing patterns of base64 encoded files, concatenation and execution | ditekSHen |
|
Networking |
---|
Source: | Author: Joe Security: |
System Summary |
---|
Source: | Author: frack113, Florian Roth: |
Source: | Author: Kiran kumar s, oscd.community: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Tim Shelton: |
Source: | Author: frack113: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T21:29:15.100589+0100 | 2030171 | 1 | A Network Trojan was detected | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T21:27:36.637872+0100 | 2855542 | 1 | A Network Trojan was detected | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T21:27:36.637872+0100 | 2855245 | 1 | A Network Trojan was detected | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T21:29:15.100589+0100 | 2840032 | 1 | A Network Trojan was detected | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | HTTPS traffic detected: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Software Vulnerabilities |
---|
Source: | Child: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | Network Connect: | Jump to behavior |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | JA3 fingerprint: |
Source: | DNS query: | ||
Source: | DNS query: |
Source: | TCP traffic: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior | ||
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 5_2_00C0C52C | |
Source: | Code function: | 5_2_00C0A978 | |
Source: | Code function: | 5_2_00C04AA0 | |
Source: | Code function: | 5_2_00C0DBE0 | |
Source: | Code function: | 5_2_00C03E88 | |
Source: | Code function: | 5_2_00C041D0 | |
Source: | Code function: | 5_2_00C0E439 | |
Source: | Code function: | 5_2_05FA45C0 | |
Source: | Code function: | 5_2_05FA3560 | |
Source: | Code function: | 5_2_05FA5D50 | |
Source: | Code function: | 5_2_05FAA150 | |
Source: | Code function: | 5_2_05FAE0D9 | |
Source: | Code function: | 5_2_05FA0308 | |
Source: | Code function: | 5_2_05FA9208 | |
Source: | Code function: | 5_2_05FA3CC0 | |
Source: | Code function: | 5_2_05FA5670 | |
Source: | Code function: | 5_2_05FAC370 | |
Source: | Code function: | 5_2_060FA198 | |
Source: | Code function: | 5_2_060FBC48 | |
Source: | Code function: | 5_2_00C0DF88 |
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Process created: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 5_2_00C00C7A | |
Source: | Code function: | 5_2_05FAFE40 | |
Source: | Code function: | 5_2_060F4D60 |
Persistence and Installation Behavior |
---|
Source: | File created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | Dropped file: | Jump to dropped file |
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior | ||
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | WMI Queries: |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Network Connect: | Jump to behavior |
Source: | Memory written: | Jump to behavior |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 311 Scripting | Valid Accounts | 121 Windows Management Instrumentation | 311 Scripting | 1 DLL Side-Loading | 1 Disable or Modify Tools | 2 OS Credential Dumping | 2 File and Directory Discovery | Remote Services | 1 Archive Collected Data | 1 Ingress Tool Transfer | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 311 Process Injection | 1 Obfuscated Files or Information | 1 Credentials in Registry | 24 System Information Discovery | Remote Desktop Protocol | 2 Data from Local System | 11 Encrypted Channel | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 1 DLL Side-Loading | Security Account Manager | 111 Security Software Discovery | SMB/Windows Admin Shares | 1 Email Collection | 1 Non-Standard Port | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Masquerading | NTDS | 1 Process Discovery | Distributed Component Object Model | Input Capture | 2 Non-Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 141 Virtualization/Sandbox Evasion | LSA Secrets | 141 Virtualization/Sandbox Evasion | SSH | Keylogging | 23 Application Layer Protocol | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 311 Process Injection | Cached Domain Credentials | 1 Application Window Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 System Network Configuration Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
44% | Virustotal | Browse | ||
21% | ReversingLabs | Script-WScript.Trojan.AgentTesla |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.210.172 | true | false | high | |
s-part-0017.t-0009.fb-t-msedge.net | 13.107.253.45 | true | false | high | |
api.ipify.org | 172.67.74.152 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
144.91.79.54 | unknown | Germany | 51167 | CONTABODE | true | |
162.254.34.31 | unknown | United States | 64200 | VIVIDHOSTINGUS | true | |
172.67.74.152 | api.ipify.org | United States | 13335 | CLOUDFLARENETUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592175 |
Start date and time: | 2025-01-15 21:26:25 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 009.vbe |
Detection: | MAL |
Classification: | mal100.spre.troj.spyw.expl.evad.winVBE@9/12@1/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 40.126.32.140, 40.126.32.72, 20.190.160.17, 40.126.32.76, 40.126.32.136, 40.126.32.74, 20.190.160.22, 20.190.160.20, 199.232.210.172, 2.17.190.73, 4.245.163.56, 40.69.42.241, 52.168.117.173, 20.3.187.198, 199.232.214.172, 13.107.253.45
- Excluded domains from analysis (whitelisted): onedsblobprdeus16.eastus.cloudapp.azure.com, azurefd-t-fb-prod.trafficmanager.net, slscr.update.microsoft.com, e3913.cd.akamaiedge.net, otelrules.afd.azureedge.net, ocsp.digicert.com, login.live.com, ocsp.edge.digicert.com, glb.cws.prod.dcat.dsp.trafficmanager.net, sls.update.microsoft.com, wu-b-net.trafficmanager.net, glb.sls.prod.dcat.dsp.trafficmanager.net, prdv4a.aadg.msidentity.com, ctldl.windowsupdate.com.delivery.microsoft.com, otelrules.azureedge.net, www.tm.v4.a.prd.aadg.trafficmanager.net, ctldl.windowsupdate.com, login.msa.msidentity.com, fe3cr.delivery.mp.microsoft.com, cac-ocsp.digicert.com.edgekey.net, fe3.delivery.mp.microsoft.com, blobcollector.events.data.trafficmanager.net, azureedge-t-prod.trafficmanager.net, umwatson.events.data.microsoft.com, www.tm.lg.prod.aadmsa.trafficmanager.net
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Some HTTP raw data packets have been limited to 10 per session. Please view the PCAPs for the complete data.
Time | Type | Description |
---|---|---|
15:27:23 | API Interceptor | |
15:27:28 | API Interceptor | |
15:27:33 | API Interceptor | |
15:27:51 | API Interceptor | |
21:27:24 | Task Scheduler |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
144.91.79.54 | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | MicroClip | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
162.254.34.31 | Get hash | malicious | AgentTesla | Browse | ||
Get hash | malicious | MassLogger RAT | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
Get hash | malicious | AgentTesla | Browse | |||
172.67.74.152 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Targeted Ransomware, TrojanRansom | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | RDPWrap Tool | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | KnowBe4, PDFPhish | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
s-part-0017.t-0009.fb-t-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher, ReCaptcha Phish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
api.ipify.org | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
VIVIDHOSTINGUS | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
CONTABODE | Get hash | malicious | Mirai | Browse |
| |
Get hash | malicious | AgentTesla | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | KnowBe4, PDFPhish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | DanaBot, PureLog Stealer, Vidar | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3b5074b1b5d032e5620f69f9f700ff0e | Get hash | malicious | Wannacry | Browse |
| |
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LiteHTTP Bot | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
C:\ProgramData\Microsoft\Windows\WER\ReportQueue\Critical_powershell.exe_b4b21b9272f0623778607a435112f88140f556cc_00000000_b22f938c-8372-4bf2-9794-99185ba16953\Report.wer
Download File
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.5347245515993327 |
Encrypted: | false |
SSDEEP: | 96:NJFTjQ+rxYid6BRH3Uje0eD/JuNnN9KQXIGZAX/d5FMT2SlPkpXmTABnf/VXT5NH:7NjmG6BR30wAAzuiFpZ24lO8 |
MD5: | 89C8FD736BFC92D70DB54975789B18D6 |
SHA1: | B21A43A0EEF572F0A2DD5CE6F144D03BFD2257A8 |
SHA-256: | F07C8B52B33C0C29C09272ED33889C333F00767A8865E0EF9E9D42286D3C4954 |
SHA-512: | BFD48E31356535A7C58E404BA1EC95CD741B948A7836E64325BB6EED5C72E23DBDD75FA86CEBB556E86BCC334AB734AEF20099C8427D2EB1DC11D2FA9198FC2A |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 7414 |
Entropy (8bit): | 3.6862432953872517 |
Encrypted: | false |
SSDEEP: | 96:RSIU6o7wVetb8RCCBr7eCM6Y8bu3hgmfHNV9reKI65aMTTom:R6l7wVeJ8RCCBI6Y8buxgmftqspTTom |
MD5: | 7D6402212401D972C6840F0775BE85A2 |
SHA1: | CDDCCA22A7AB167B8151874128A1156E49C71659 |
SHA-256: | 8091BB22E11913E4930BAEDDD9507854F89C205C7E47893D03A7069E76ADE2A5 |
SHA-512: | 0DDACA5777C2C763CFF51F45422F4402995B468F8A0CF9744F5E819E86A359FBD4361712B45B4E9B7943A9D593F171826689CEEF2DCAE20F74F02540E103B94E |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\wermgr.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4899 |
Entropy (8bit): | 4.574548020508516 |
Encrypted: | false |
SSDEEP: | 48:cvIwWl8zsLJg771I9sPWpW8VYJYm8M4JFKlnOtSFuyq8vT0OtNYytfe+d:uIjflI77e7VhJFKln8WT0zufFd |
MD5: | 8262EB19E9CBBB24652832DD14714B78 |
SHA1: | 825702E0CF238E039ADABCF59C4D48A7E82ED6C0 |
SHA-256: | 3D464D0320EE0B55DC981072912658AB6A7044C8EFB6E222D37F73A5EA2EDBF5 |
SHA-512: | A5964AA846635FB6B0BD6F2BD870E4BB1ED8186A3168D5DDAA28A433E1F5E45D90D7E96E910B1A7622530419BE38F4AD982D0771342454198B5F5BE5F4CF5497 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 11887 |
Entropy (8bit): | 4.901437212034066 |
Encrypted: | false |
SSDEEP: | 192:Zxoe5qpOZxoe54ib4ZVsm5emdqVFn3eGOVpN6K3bkkjo5OgkjDt4iWN3yBGHVQ9L:Srib4ZmVoGIpN6KQkj2Fkjh4iUxsNYWd |
MD5: | ED30A738A05A68D6AB27771BD846A7AA |
SHA1: | 6AFCE0F6E39A9A59FF54956E1461F09747B57B44 |
SHA-256: | 17D48B622292E016CFDF0550340FF6ED54693521D4D457B88BB23BD1AE076A31 |
SHA-512: | 183E9ECAF5C467D7DA83F44FE990569215AFDB40B79BCA5C0D2C021228C7B85DF4793E2952130B772EC0896FBFBCF452078878ADF3A380A6D0A6BD00EA6663F2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3256 |
Entropy (8bit): | 5.404109340363203 |
Encrypted: | false |
SSDEEP: | 96:gEzlHyIFKL2O9qrh7Kf+oRJ5Eo9AdrxwN:V1yt2jrAfRLL2G |
MD5: | 047B195D3B8C00130835658997B1925D |
SHA1: | 5F77C7A5F798C4C0253839EBD7554B13987704E3 |
SHA-256: | B2C2801565403B2348CAF820F20B4B92C8725A5079D5360DAF455E84D28AC1FB |
SHA-512: | D1724BE394B214B914A236AC1D55DB17B93669880BB3F71057DCD070AF3062FBFF494ABE085345015FCDF5FE6B11BAE9A19FCD20DC4EB749E13F31CD5565D60D |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 252 |
Entropy (8bit): | 5.461689719340332 |
Encrypted: | false |
SSDEEP: | 6:xVwe5ljxsu2xKbLtSXqo83mWngzsHg4HXZuBiA2V0LYC7zsHgB2eFI59:772EtSXqd27zmg4HJci1V0LYIzmg0eo |
MD5: | C7CDD3174DC32767F2CC2DF349ECA42D |
SHA1: | 12F4B14FAD7684BDEA591434D442B6E08090BA81 |
SHA-256: | 5CE8777F785CD74A693EEA29A30284D5EF2C8C1EB7C8343BC211F6821DBA0862 |
SHA-512: | FC15820CCD44797983B213C6B57CC8AC19491BCE94BDB0D44637287D5C9878445B98B542AC7F3EA4646C6FA5609AC99EBE72BA5FCD5F88F68D1433EAA722B3CF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms (copy)
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7113587394857896 |
Encrypted: | false |
SSDEEP: | 96:ZOG/IlcMlplfCKlcoQykvhkvCCtB1/LVT+HO1/LVI+HH:ZOGAqMPNiMB1/J1/x |
MD5: | 6403DB26A881DF1E40891C0B4400C843 |
SHA1: | ACA630130FDB2F10942624F62E816B76E9CC9AAC |
SHA-256: | FEDEC3E4237E4CD2DF15D7432BB238FE718467FCAC5DCD89FF08875DF569505A |
SHA-512: | 58458F791961E1EE99AB79D5BB398320DAE0DF72D6CB7FC6B0ACD51F27596E1CA98B29DA91AED084E234AA90AF040FD3A8163DCFFD6E6AA47D7BFF9227E947DF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\77SO8JQ65TB924MXZW6G.temp
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6222 |
Entropy (8bit): | 3.7113587394857896 |
Encrypted: | false |
SSDEEP: | 96:ZOG/IlcMlplfCKlcoQykvhkvCCtB1/LVT+HO1/LVI+HH:ZOGAqMPNiMB1/J1/x |
MD5: | 6403DB26A881DF1E40891C0B4400C843 |
SHA1: | ACA630130FDB2F10942624F62E816B76E9CC9AAC |
SHA-256: | FEDEC3E4237E4CD2DF15D7432BB238FE718467FCAC5DCD89FF08875DF569505A |
SHA-512: | 58458F791961E1EE99AB79D5BB398320DAE0DF72D6CB7FC6B0ACD51F27596E1CA98B29DA91AED084E234AA90AF040FD3A8163DCFFD6E6AA47D7BFF9227E947DF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\wscript.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2915 |
Entropy (8bit): | 5.0505975283730935 |
Encrypted: | false |
SSDEEP: | 48:lnJrvgJXVv0qD4p7pYazwHYMH9KHaANMaBoqpotJ8gfng++E/uTcb6OqaBXl8zma:lJL4VvlDQepHXH4HaDaK8gPOOqav97ZS |
MD5: | DDF1E2F5DE2CE71CCF56AF38DEDB27D0 |
SHA1: | 0033A0EB6BABB97203CB8BB7F68287CFAC9D96DC |
SHA-256: | 0A988536FC481BD16AF5469D5FAA1BBB9DC321601DFA858479C01844A3CDD1C8 |
SHA-512: | F4E451051D3BF74FAF142973EF1F2A8C008D654F6D7178DBC426DCEEE2F16FB88C90980E3E12E77B3499D9F7A0BC4F36FAAFAD35FB52BB9C8F8BA03AE2585941 |
Malicious: | true |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1445 |
Entropy (8bit): | 4.464907235348319 |
Encrypted: | false |
SSDEEP: | 24:Ei/vNa2V269+Iz2HUdSjeKm3uSmcHsU9MxOAX4WLeX4WgeX4WgeX4WneX4WueX4s:ERWxZz2HUwysU9+OAX+X5XpXKX/XFXoK |
MD5: | 976A9FDC8F52DAD9B9A03DFECA170F68 |
SHA1: | EC3FB14B0167F56439E3D8055DD19C58141AD1DD |
SHA-256: | 464B9C4450203483760D4189FAFDC35419AF00C5AE3126DA3BFA19E873CD7F0F |
SHA-512: | CB8AC704F8CDA1F178F44A4A4310F0F369FC07E2896290A1FA80155DDD175CAE5AD65BA3BED6AE72A2D31F85FF6A30516B8A7913B1FFA5F5073EE3FB960A72CF |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 3.9908336623105405 |
TrID: |
|
File name: | 009.vbe |
File size: | 10'722 bytes |
MD5: | 9ff77002fbcbdd6e749722541b423034 |
SHA1: | ea5ff219e2dde3cc57a1668ff0526be5b84e1250 |
SHA256: | 5b3b169b48056c1cd8b84093c312de2f9ec1c7a1edcd7591743f6eac62c98ab9 |
SHA512: | 609f25739f34355e0e37fd244cd743f3442be6cb2518ff9fa0ec58ec5ec103e730d5f005ca86c040a7b3a078d49dd6b2363659085eaecc2de2fd24159da13388 |
SSDEEP: | 192:meHNd/sigyXaoMutGV+GCCYSyC+QvdyNhnKxtKlK:5HMiTDV+xnYSH+QVyNhnctKM |
TLSH: | F522EA58DFDD44C0F7216B864BC9D7629B1F6A245B0F4AC20D61428B373ED80ADA9F39 |
File Content Preview: | ..#.@.~.^.1.x.Q.A.A.A.=.=.v.,.'.x.{.P.j.....D.k.6.k.1.C.Y.b.W.U./.,./.z.d.D.....:.+.,.x.'.{.@.#.@.&.w.;.U.m.D.k.K.x.~.|.P.K.I.`.b.@.#.@.&.~.P.,.P.6.U.,.2.D...G.M.P.].+.k.;.s.+.~.g.+.X.Y.@.#.@.&.P.,.~.P.G.k.h.P.o.A.J.K.B.P.p.\...I.B.P.K.t.].F.@.#.@.&.P.,.P |
Icon Hash: | 68d69b8f86ab9a86 |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T21:27:36.637872+0100 | 2855245 | ETPRO MALWARE Agent Tesla Exfil via SMTP | 1 | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
2025-01-15T21:27:36.637872+0100 | 2855542 | ETPRO MALWARE Agent Tesla CnC Exfil Activity | 1 | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
2025-01-15T21:29:15.100589+0100 | 2030171 | ET MALWARE AgentTesla Exfil Via SMTP | 1 | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
2025-01-15T21:29:15.100589+0100 | 2840032 | ETPRO MALWARE Win32/AgentTesla/OriginLogger Data Exfil via SMTP M2 | 1 | 192.168.2.5 | 49709 | 162.254.34.31 | 587 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 21:27:21.318677902 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:21.318677902 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:21.443718910 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:24.078821898 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.128331900 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.128416061 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.128643036 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.133459091 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750247002 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750298023 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750334978 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750368118 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750376940 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.750401974 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750435114 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750437021 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.750468969 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750494957 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.750502110 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750535965 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750549078 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.750570059 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.750608921 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.755580902 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.755615950 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.755666971 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.840816975 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.840919018 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841018915 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841044903 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.841053963 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841108084 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.841144085 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841196060 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841228962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841254950 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.841279030 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841311932 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841351986 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.841943026 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.841991901 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.841995955 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:24.896747112 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.924185991 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:24.929239035 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.112163067 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.117398024 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.122330904 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301640034 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301666975 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301686049 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301691055 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301696062 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301759958 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.301820040 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.301980972 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.301992893 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302020073 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.302298069 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302309036 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302321911 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302331924 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302335024 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.302347898 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.302942991 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302953959 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.302964926 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303002119 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303014040 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303024054 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.303060055 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.303858042 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303869009 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303880930 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303894043 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303904057 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.303905964 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.303924084 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.304770947 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.304781914 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.304802895 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.304809093 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.304820061 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.304820061 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.304860115 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.305648088 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.305659056 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.305700064 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.305721045 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.305743933 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.305754900 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.305773020 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.306535006 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.306562901 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.306575060 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.349891901 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.386248112 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.391339064 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.569441080 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.600626945 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.605492115 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784152031 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784200907 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784236908 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784270048 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784298897 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784326077 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.784332991 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784368992 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.784425974 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:25.784440994 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.820831060 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:25.825716019 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.016869068 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.016937971 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.016973972 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017005920 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017015934 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017040968 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017055988 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017074108 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017118931 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017153025 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017204046 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017250061 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017256975 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017288923 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017322063 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017333031 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017354012 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017386913 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017393112 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017419100 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017452002 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017463923 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017484903 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017529964 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.017537117 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.017992020 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018027067 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018043041 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018060923 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018093109 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018111944 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018127918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018160105 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018184900 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018193007 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018228054 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018237114 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018682957 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018732071 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018734932 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018785954 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018817902 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018829107 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018866062 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018899918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018908978 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.018933058 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018966913 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.018976927 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.019001961 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019045115 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.019681931 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019715071 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019757986 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.019766092 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019798994 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019840956 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.019849062 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019881964 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019916058 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019923925 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.019947052 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019980907 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.019989014 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.020648956 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020682096 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020697117 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.020731926 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020764112 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020776987 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.020797014 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020838976 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.020847082 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020880938 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020911932 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020922899 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.020946026 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.020988941 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.021622896 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021678925 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021730900 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021763086 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021795988 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.021795988 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021830082 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021835089 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.021864891 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.021876097 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.068639040 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.103082895 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106004000 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106013060 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106062889 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106069088 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106115103 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106116056 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106123924 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106153011 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106153011 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106164932 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106211901 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106223106 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106229067 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106234074 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106266975 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106488943 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106498957 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106528044 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106570005 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106581926 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106594086 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106606007 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106640100 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106647015 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106657028 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106668949 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106709003 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.106966972 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106977940 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.106991053 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107002020 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107003927 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107039928 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107050896 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107060909 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107073069 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107085943 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107124090 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107124090 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107136965 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107186079 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107481003 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107522011 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107532024 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107564926 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107583046 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107593060 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107604027 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107615948 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107618093 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107645035 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107738972 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107749939 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107760906 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107772112 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107783079 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107785940 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107794046 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107798100 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107805967 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107816935 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.107834101 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.107861042 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.108556986 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108567953 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108578920 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108584881 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108596087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108601093 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.108607054 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108618021 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108647108 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.108675957 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108685970 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108689070 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.108696938 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108707905 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108719110 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108728886 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108740091 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108751059 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.108767986 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.108798981 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109416962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109427929 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109440088 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109481096 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109488010 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109498978 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109509945 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109522104 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109525919 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109560966 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109627962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109638929 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109649897 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109661102 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109664917 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109672070 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109683037 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109688044 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109694004 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109711885 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.109719992 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.109755993 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110361099 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110372066 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110383987 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110398054 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110421896 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110447884 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110459089 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110470057 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110481977 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110496044 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110534906 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110563040 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110573053 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110583067 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110594034 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110605001 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110615969 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110626936 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110627890 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110665083 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.110668898 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.110707045 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.111310005 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111330032 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111341000 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111361027 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.111371994 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111383915 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111396074 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111407042 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111429930 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.111498117 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111509085 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111521006 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111531973 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111542940 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.111545086 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111562967 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111572981 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111587048 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.111588001 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.111614943 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.112242937 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.112278938 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.112281084 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.112292051 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.112307072 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.112319946 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.112334967 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.112374067 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196322918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196393967 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196446896 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196454048 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196499109 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196533918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196553946 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196582079 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196625948 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196633101 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196666002 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196707010 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196712017 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196755886 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196789026 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196800947 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196851015 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196897984 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.196901083 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196933985 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196966887 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.196978092 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197002888 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197036028 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197046995 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197068930 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197112083 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197114944 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197124958 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197137117 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197168112 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197186947 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197218895 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197231054 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197252989 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197285891 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197304964 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197319984 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197370052 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197371960 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197403908 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197437048 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197451115 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197469950 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197519064 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197520018 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197571039 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197603941 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197618008 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197637081 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197669983 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197690964 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197702885 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197736025 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197756052 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197768927 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197802067 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197812080 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197834969 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197866917 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.197952986 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.197983027 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198019028 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198029041 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198051929 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198085070 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198097944 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198120117 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198162079 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198170900 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198172092 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198184013 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198218107 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198227882 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198251009 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198266029 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198283911 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198317051 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198327065 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198348999 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198380947 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198396921 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198414087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198446035 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198456049 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198479891 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198512077 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198533058 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198555946 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198590994 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198597908 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.198620081 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.198662043 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203511000 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203542948 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203591108 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203594923 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203644991 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203685999 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203691006 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203733921 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203783989 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203789949 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203816891 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203850985 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203874111 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203882933 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203916073 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203931093 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203948021 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.203986883 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.203996897 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204047918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204082012 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204094887 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204130888 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204164982 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204174042 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204214096 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204248905 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204258919 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204277039 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204313993 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204322100 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204335928 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204369068 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204372883 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204401970 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204433918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204442978 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204483986 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204516888 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204528093 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204566002 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204597950 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204618931 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204629898 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204662085 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204680920 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204710960 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204744101 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204756021 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204778910 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204809904 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204829931 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204843998 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204874992 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204886913 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204907894 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204941034 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.204966068 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.204973936 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205004930 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205015898 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205038071 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205070019 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205089092 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205104113 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205136061 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205149889 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205168962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205200911 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205229044 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205234051 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205265999 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205277920 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205300093 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205331087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205343962 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205363989 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205398083 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205424070 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205430984 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205462933 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205473900 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.205497026 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205524921 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.205543041 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.256144047 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283078909 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283153057 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283188105 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283222914 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283236980 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283286095 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283294916 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283374071 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283426046 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283433914 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283484936 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283534050 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283534050 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283567905 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283600092 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283617973 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283648014 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283679962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283701897 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283714056 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283761024 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283776999 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283808947 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283842087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283847094 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283893108 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283929110 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283956051 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.283962011 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.283993959 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284013987 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284027100 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284060001 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284071922 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284092903 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284126997 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284158945 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284162998 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284197092 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284209013 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284243107 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284276009 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284285069 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284307957 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284347057 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284349918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284404039 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284435034 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284446955 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284468889 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284512997 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284517050 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284548998 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284581900 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284589052 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284615993 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284647942 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284672976 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284698009 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284730911 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284744024 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284764051 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284796953 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284806967 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284836054 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284867048 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284881115 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284900904 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284933090 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.284945011 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.284981012 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285013914 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285026073 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285047054 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285080910 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285090923 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285115004 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285146952 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285172939 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285191059 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285223961 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285233021 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285273075 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285305977 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285319090 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285337925 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285366058 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285382032 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285397053 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285430908 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285440922 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285464048 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285496950 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285507917 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285530090 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285564899 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285571098 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285595894 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285629034 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285640001 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285661936 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285695076 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285706043 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285727978 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285761118 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285769939 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285793066 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285825014 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285839081 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285856962 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285890102 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285898924 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285923004 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285955906 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.285964966 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.285988092 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286020994 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286031961 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286055088 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286097050 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286104918 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286148071 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286192894 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286192894 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286210060 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286233902 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286245108 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286247015 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286262035 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286274910 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286283016 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286286116 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286303043 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286313057 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286323071 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286324978 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286334991 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286346912 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286355972 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286360025 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286365986 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286377907 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286385059 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286393881 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286405087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286413908 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286413908 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286423922 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286433935 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286442995 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286444902 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286478996 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286494970 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286505938 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286516905 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286529064 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286539078 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286556005 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286623001 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286633968 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286643028 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286650896 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286659956 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286663055 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286706924 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.286736965 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286746025 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.286775112 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.322148085 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.327732086 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.327801943 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.327836990 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.327851057 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.327869892 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.327905893 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.327931881 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.329281092 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.329314947 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.329335928 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.329348087 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.329390049 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.370318890 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370366096 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370403051 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370429993 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.370436907 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370470047 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370484114 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.370503902 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370537043 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370549917 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.370572090 CET | 80 | 49706 | 144.91.79.54 | 192.168.2.5 |
Jan 15, 2025 21:27:26.370686054 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:26.918318033 CET | 49706 | 80 | 192.168.2.5 | 144.91.79.54 |
Jan 15, 2025 21:27:30.928028107 CET | 49674 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:30.928040981 CET | 49675 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:31.053039074 CET | 49673 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:32.716711044 CET | 443 | 49705 | 23.1.237.91 | 192.168.2.5 |
Jan 15, 2025 21:27:32.716963053 CET | 49705 | 443 | 192.168.2.5 | 23.1.237.91 |
Jan 15, 2025 21:27:33.086209059 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.086253881 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.086322069 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.102427006 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.102471113 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.574888945 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.574970961 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.609138012 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.609154940 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.609524965 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.662399054 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.827617884 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:33.875333071 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.936165094 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.936250925 CET | 443 | 49707 | 172.67.74.152 | 192.168.2.5 |
Jan 15, 2025 21:27:33.936306953 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:34.009609938 CET | 49707 | 443 | 192.168.2.5 | 172.67.74.152 |
Jan 15, 2025 21:27:34.768743992 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:34.773524046 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:34.773597002 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:35.553765059 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:35.561285019 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:35.566066980 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:35.733308077 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:35.734217882 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:35.739000082 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:35.904500008 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:35.905477047 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:35.910268068 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.083173990 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.083385944 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.088159084 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.282025099 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.282362938 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.287178040 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.468002081 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.468200922 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.472997904 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.637281895 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.637821913 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.637871981 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.637921095 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.637921095 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:27:36.642607927 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.642633915 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.642755985 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.642769098 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.923307896 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:27:36.974894047 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:29:14.787906885 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:29:14.793283939 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:29:15.100421906 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:29:15.100472927 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:29:15.100517988 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Jan 15, 2025 21:29:15.100589037 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:29:15.100589037 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:29:15.100589037 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 |
Jan 15, 2025 21:29:15.106040955 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 21:27:33.073895931 CET | 64400 | 53 | 192.168.2.5 | 1.1.1.1 |
Jan 15, 2025 21:27:33.080662012 CET | 53 | 64400 | 1.1.1.1 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 21:27:33.073895931 CET | 192.168.2.5 | 1.1.1.1 | 0x198e | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 21:27:33.080662012 CET | 1.1.1.1 | 192.168.2.5 | 0x198e | No error (0) | 172.67.74.152 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:33.080662012 CET | 1.1.1.1 | 192.168.2.5 | 0x198e | No error (0) | 104.26.12.205 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:33.080662012 CET | 1.1.1.1 | 192.168.2.5 | 0x198e | No error (0) | 104.26.13.205 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:35.272358894 CET | 1.1.1.1 | 192.168.2.5 | 0xe9cb | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:35.272358894 CET | 1.1.1.1 | 192.168.2.5 | 0xe9cb | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:36.289161921 CET | 1.1.1.1 | 192.168.2.5 | 0x1603 | No error (0) | azurefd-t-fb-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:36.289161921 CET | 1.1.1.1 | 192.168.2.5 | 0x1603 | No error (0) | s-part-0017.t-0009.fb-t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Jan 15, 2025 21:27:36.289161921 CET | 1.1.1.1 | 192.168.2.5 | 0x1603 | No error (0) | 13.107.253.45 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:28:37.900217056 CET | 1.1.1.1 | 192.168.2.5 | 0xe37a | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 21:28:37.900217056 CET | 1.1.1.1 | 192.168.2.5 | 0xe37a | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49706 | 144.91.79.54 | 80 | 5548 | C:\Windows\System32\wscript.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
Jan 15, 2025 21:27:24.128643036 CET | 152 | OUT | |
Jan 15, 2025 21:27:24.750247002 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750298023 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750334978 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750368118 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750401974 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750435114 CET | 1120 | IN | |
Jan 15, 2025 21:27:24.750468969 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750502110 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750535965 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.750570059 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.755580902 CET | 1236 | IN | |
Jan 15, 2025 21:27:24.924185991 CET | 152 | OUT | |
Jan 15, 2025 21:27:25.112163067 CET | 761 | IN | |
Jan 15, 2025 21:27:25.117398024 CET | 152 | OUT | |
Jan 15, 2025 21:27:25.301640034 CET | 1236 | IN | |
Jan 15, 2025 21:27:25.386248112 CET | 153 | OUT | |
Jan 15, 2025 21:27:25.569441080 CET | 347 | IN | |
Jan 15, 2025 21:27:25.600626945 CET | 155 | OUT | |
Jan 15, 2025 21:27:25.784152031 CET | 1236 | IN | |
Jan 15, 2025 21:27:25.820831060 CET | 175 | OUT | |
Jan 15, 2025 21:27:26.016869068 CET | 1236 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.5 | 49707 | 172.67.74.152 | 443 | 380 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-01-15 20:27:33 UTC | 155 | OUT | |
2025-01-15 20:27:33 UTC | 424 | IN | |
2025-01-15 20:27:33 UTC | 12 | IN |
Timestamp | Source Port | Dest Port | Source IP | Dest IP | Commands |
---|---|---|---|---|---|
Jan 15, 2025 21:27:35.553765059 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 220 server1.educt.shop ESMTP Postfix |
Jan 15, 2025 21:27:35.561285019 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | EHLO 936905 |
Jan 15, 2025 21:27:35.733308077 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 250-server1.educt.shop 250-PIPELINING 250-SIZE 204800000 250-ETRN 250-STARTTLS 250-AUTH PLAIN LOGIN 250-AUTH=PLAIN LOGIN 250-ENHANCEDSTATUSCODES 250-8BITMIME 250-DSN 250 CHUNKING |
Jan 15, 2025 21:27:35.734217882 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | AUTH login c2VuZHhzZW5zZXNAdmV0cnlzLnNob3A= |
Jan 15, 2025 21:27:35.904500008 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 334 UGFzc3dvcmQ6 |
Jan 15, 2025 21:27:36.083173990 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 235 2.7.0 Authentication successful |
Jan 15, 2025 21:27:36.083385944 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | MAIL FROM:<sendxsenses@vetrys.shop> |
Jan 15, 2025 21:27:36.282025099 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 250 2.1.0 Ok |
Jan 15, 2025 21:27:36.282362938 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | RCPT TO:<senses@vetrys.shop> |
Jan 15, 2025 21:27:36.468002081 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 250 2.1.5 Ok |
Jan 15, 2025 21:27:36.468200922 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | DATA |
Jan 15, 2025 21:27:36.637281895 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 354 End data with <CR><LF>.<CR><LF> |
Jan 15, 2025 21:27:36.637921095 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | . |
Jan 15, 2025 21:27:36.923307896 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 250 2.0.0 Ok: queued as 5E41F6087D |
Jan 15, 2025 21:29:14.787906885 CET | 49709 | 587 | 192.168.2.5 | 162.254.34.31 | QUIT |
Jan 15, 2025 21:29:15.100421906 CET | 587 | 49709 | 162.254.34.31 | 192.168.2.5 | 221 2.0.0 Bye |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:27:22 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66c420000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:27:24 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66c420000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 3 |
Start time: | 15:27:25 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:27:25 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 15:27:30 |
Start date: | 15/01/2025 |
Path: | C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x240000 |
File size: | 262'432 bytes |
MD5 hash: | 8FDF47E0FF70C40ED3A17014AEEA4232 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 15:27:32 |
Start date: | 15/01/2025 |
Path: | C:\Windows\System32\wermgr.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6070d0000 |
File size: | 229'728 bytes |
MD5 hash: | 74A0194782E039ACE1F7349544DC1CF4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Execution Graph
Execution Coverage: | 8.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 79 |
Total number of Limit Nodes: | 7 |
Graph
Function 05FA0308 Relevance: 9.0, Strings: 6, Instructions: 1490COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA9208 Relevance: 8.3, Strings: 6, Instructions: 767COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA5D50 Relevance: 3.0, Strings: 2, Instructions: 473COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FAE0D9 Relevance: 2.8, Strings: 2, Instructions: 331COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A978 Relevance: 2.8, Instructions: 2797COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0DBE0 Relevance: 2.3, Instructions: 2275COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0C52C Relevance: 2.1, Instructions: 2143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA3560 Relevance: 1.8, Strings: 1, Instructions: 598COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA45C0 Relevance: .8, Instructions: 817COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FAA150 Relevance: .6, Instructions: 640COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C04AA0 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C03E88 Relevance: .2, Instructions: 238COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FAE571 Relevance: 1.6, APIs: 1, Instructions: 127COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060FD4E4 Relevance: 1.6, APIs: 1, Instructions: 119COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060FD4F0 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060FE46C Relevance: 1.6, APIs: 1, Instructions: 97COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FAE658 Relevance: 1.6, APIs: 1, Instructions: 52COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C06EE8 Relevance: 1.4, Strings: 1, Instructions: 179COMMON
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C07D98 Relevance: 1.4, Strings: 1, Instructions: 100COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C07DA8 Relevance: 1.3, Strings: 1, Instructions: 95COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C06BB0 Relevance: 1.3, Strings: 1, Instructions: 79COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C08739 Relevance: .6, Instructions: 556COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C08748 Relevance: .6, Instructions: 550COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C04A97 Relevance: .3, Instructions: 260COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A1C2 Relevance: .3, Instructions: 251COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C03E7F Relevance: .2, Instructions: 234COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A6D8 Relevance: .2, Instructions: 216COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0480C Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C04818 Relevance: .2, Instructions: 180COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A510 Relevance: .1, Instructions: 144COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C06CF3 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C06CF8 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01123 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A503 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01138 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C026E4 Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C026F0 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01383 Relevance: .1, Instructions: 86COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A080 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C016A8 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C017C8 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01493 Relevance: .1, Instructions: 81COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A090 Relevance: .1, Instructions: 78COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C09F80 Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BBD030 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C04F90 Relevance: .1, Instructions: 72COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01880 Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C01890 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C09F90 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00BBD006 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C016B8 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C04FA0 Relevance: .1, Instructions: 68COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C00848 Relevance: .1, Instructions: 62COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C00838 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C014A0 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0A6D3 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C08F20 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C07EC0 Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C08F30 Relevance: .0, Instructions: 33COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA5670 Relevance: 13.0, Strings: 10, Instructions: 468COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FA3CC0 Relevance: 2.9, Strings: 2, Instructions: 402COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C0E439 Relevance: 2.0, Instructions: 1956COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 05FAC370 Relevance: 1.8, Strings: 1, Instructions: 569COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00C041D0 Relevance: .3, Instructions: 281COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060FA198 Relevance: .3, Instructions: 264COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 060FBC48 Relevance: .2, Instructions: 217COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|