Windows
Analysis Report
1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe
Overview
General Information
Sample name: | 1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
Analysis ID: | 1592213 |
MD5: | 04a1de79844a9148dcbf720090f0bd84 |
SHA1: | 03712e89f2b0b7fe5ed5be05f81a11d3050a71a0 |
SHA256: | 1b0be562bf434314a8d784f0228b72b07fcb4c090c6f06fb16ba6c5af4147b02 |
Tags: | base64-decodedexeuser-abuse_ch |
Infos: | |
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- 1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe (PID: 6484 cmdline:
"C:\Users\ user\Deskt op\1736977 840835b918 4f01bf0b6c 60ce50d66e 7897e18892 b3f9e56b63 03ef4929b2 a1c05b2796 .dat-decod ed.exe" MD5: 04A1DE79844A9148DCBF720090F0BD84)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
AsyncRAT | AsyncRAT is a Remote Access Tool (RAT) designed to remotely monitor and control other computers through a secure encrypted connection. It is an open source remote administration tool, however, it could also be used maliciously because it provides functionality such as keylogger, remote desktop control, and many other functions that may cause harm to the victims computer. In addition, AsyncRAT can be delivered via various methods such as spear-phishing, malvertising, exploit kit and other techniques. | No Attribution |
{"External_config_on_Pastebin": "null", "Server": "w98snw73idknf486g37d9ijn3u.duckdns.org", "Ports": "8808", "Version": "| nelsontriana980", "Autorun": "false", "Install_Folder": "dDNhOHVyQUZVMDk2MEx4TjZJd1FuVkdGUDNTOGVrRDk=", "Install_File": "UVtqsevwfbTQsW/o7jVDQp4iOFQ9p87vCNT8Cv4vzeKyz9mnj0FUSj4K65sbR9xyzyHN/d/Fn0BALZdPP9nJrA==", "AES_key": "t3a8urAFU0960LxN6IwQnVGFP3S8ekD9", "Mutex": "f87lCdXu/3D4BRvk+nTAPEtfF72xI1sZ6RZ3L4nDLCJwAeuwNZam8lKayF3XZRbG0eCrxTzoSITogfm6M8o83PNPFPe4sTTfaMuYWPxJWZflU9WKPhf5VLoB8DnBsqDTnH2s3U0k+FVcAoMG9Gm8mt0Li21KUSO8saYr3A3bhYk8S/5tdLfBQicU5IvbKA/0DTsiJ7x1wjkrqo30SWQf3/c3YsGAltchr3Gv4vLaNo7IEWj0N6pqDuA7T8iEWj5sydxeoyZelMk7WLjsQMFcglm7d3M0PhuriR8pWC5Mb/DSWvbafQuNZ5enn8lvuKYDr/uMpH0Gx0RfTdljqhKOgqf4w9Candvqj3hYW6TPPZV1isyI37gAIASylgkiP+6wYbvQFdq47StjZOXQmdiXhFaIQ64lHYvHRd2ehmFsdjubQAuTlpynY0fD/EJC06AWFS55WBOgRLjsC6wEQNkdbkIId7KKn2Nc/NzUSvzkgnlvIczwi8WvVIpjhb/+o/zhpwoNHu5TCvyMffG/6QwSeJOvH1vumq3r4GUypVqXGTcEAYj8qp5XB/KmIOfKUcQzsGDKVfSKx5uVbKWeGQyCMNh4phxrIKUvHrLnc4C2Ug+x+0epiDV7nw1GwKBiuR8lMbhRBFhxNc4IgQ7kj8E5StnNrpgLOaIqxtB/RLVfMT4=", "Certificate": "false", "ServerSignature": "false", "BDOS": "false", "Startup_Delay": "3", "Group": "null"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Asyncrat_11a11ba1 | unknown | unknown |
| |
rat_win_asyncrat | Detect AsyncRAT based on specific strings | Sekoia.io |
| |
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
| |
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_AsyncRAT | Yara detected AsyncRAT | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
Windows_Trojan_Asyncrat_11a11ba1 | unknown | unknown |
| |
rat_win_asyncrat | Detect AsyncRAT based on specific strings | Sekoia.io |
| |
INDICATOR_SUSPICIOUS_EXE_ASEP_REG_Reverse | Detects file containing reversed ASEP Autorun registry keys | ditekSHen |
|
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T22:52:05.389005+0100 | 2035595 | 1 | Domain Observed Used for C2 Detected | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T22:52:05.389005+0100 | 2035607 | 1 | Domain Observed Used for C2 Detected | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T22:52:05.389005+0100 | 2842478 | 1 | Malware Command and Control Activity Detected | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Malware Configuration Extractor: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | Static PE information: |
Source: | Static PE information: |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | URLs: |
Source: | DNS query: |
Source: | File source: | ||
Source: | File source: |
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_0253D2D8 | |
Source: | Code function: | 0_2_02537038 | |
Source: | Code function: | 0_2_02537908 | |
Source: | Code function: | 0_2_02536CF0 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Boot Survival |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Registry key monitored for changes: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior |
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | WMI Queries: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 1 Windows Management Instrumentation | 1 Scheduled Task/Job | 1 Scheduled Task/Job | 1 Disable or Modify Tools | OS Credential Dumping | 1 Query Registry | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Scheduled Task/Job | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 111 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Obfuscated Files or Information | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 21 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 13 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
68% | Virustotal | Browse | ||
76% | ReversingLabs | ByteCode-MSIL.Trojan.AsyncRATMarte | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
bg.microsoft.map.fastly.net | 199.232.214.172 | true | false | high | |
w98snw73idknf486g37d9ijn3u.duckdns.org | 87.120.112.98 | true | true | unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
87.120.112.98 | w98snw73idknf486g37d9ijn3u.duckdns.org | Bulgaria | 25206 | UNACS-AS-BG8000BurgasBG | true |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1592213 |
Start date and time: | 2025-01-15 22:51:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 6m 7s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 5 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
Detection: | MAL |
Classification: | mal100.troj.evad.winEXE@1/2@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 199.232.214.172, 20.12.23.50, 13.107.246.45
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, wu-b-net.trafficmanager.net, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target 1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe, PID 6484 because it is empty
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- Report size getting too big, too many NtReadVirtualMemory calls found.
Time | Type | Description |
---|---|---|
16:52:06 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
bg.microsoft.map.fastly.net | Get hash | malicious | AgentTesla | Browse |
| |
Get hash | malicious | KnowBe4, PDFPhish | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Wannacry | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
UNACS-AS-BG8000BurgasBG | Get hash | malicious | LiteHTTP Bot | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | XWorm | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | Remcos, PureLog Stealer | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
| ||
Get hash | malicious | RedLine | Browse |
|
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Users\user\Desktop\1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Users\user\Desktop\1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.247897867253902 |
Encrypted: | false |
SSDEEP: | 6:kK5Z9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:+DImsLNkPlE99SNxAhUe/3 |
MD5: | FFFA202BD31C828BE1D884E2D0F750AA |
SHA1: | B4621C1281B889CA0CD9F16B1BE7B9F7B38C7978 |
SHA-256: | 10D926FBBD472B73C46CBCA5A0C33C98B0AA3B1AC1652DF64DE464BB65AD0E5B |
SHA-512: | AAC00A5DBFDDFB997A87963D3EB07B5E4F8696E90FE170BD81DF4B4C25FF5586530D576D32DAE9B379253BF6E547225DD61A37059F2245E6FEB5B4774F38E1C9 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 5.392876211244669 |
TrID: |
|
File name: | 1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
File size: | 64'512 bytes |
MD5: | 04a1de79844a9148dcbf720090f0bd84 |
SHA1: | 03712e89f2b0b7fe5ed5be05f81a11d3050a71a0 |
SHA256: | 1b0be562bf434314a8d784f0228b72b07fcb4c090c6f06fb16ba6c5af4147b02 |
SHA512: | a6fd0ee9fcaaf9908583fa4525b9478acd8e0523ec63acca7ac8dedada5c6d95aca2e2483df8db216bd579f7589d2370ae5c30d1d956fe8dfe2d4efdb06dbc93 |
SSDEEP: | 1536:z2wmkPN1ak1gcKu5UYFFZNh5b0uPAmVqrPlTGFx:z21kPN1ak1Ku5UYFH5b00qdGx |
TLSH: | BF53F8053BE98026F3BE8F7469F6658506F9F4AB2D12C91D0CC910DE0632BC69951BFB |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vjzd................................. ... ....@.. .......................`............`................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x410ece |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x647A6A76 [Fri Jun 2 22:17:26 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x10e7c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x12000 | 0x7ff | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x14000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0xeed4 | 0xf000 | 87eecf007da7bdb27acb7b27df3c5c1f | False | 0.456005859375 | data | 5.430119645902478 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x12000 | 0x7ff | 0x800 | 33cdbc5c50f34a35b4f0e61582ac7f11 | False | 0.41650390625 | data | 4.884866150337139 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x14000 | 0xc | 0x200 | 3722cb6f816dc5b7e4ace4627a19fc91 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_VERSION | 0x120a0 | 0x2cc | data | 0.43575418994413406 | ||
RT_MANIFEST | 0x1236c | 0x493 | exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators | 0.43381725021349277 |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-15T22:52:05.389005+0100 | 2842478 | ETPRO JA3 Hash - Suspected ASYNCRAT Server Cert (ja3s) | 1 | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
2025-01-15T22:52:05.389005+0100 | 2030673 | ET MALWARE Observed Malicious SSL Cert (AsyncRAT Server) | 1 | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
2025-01-15T22:52:05.389005+0100 | 2035595 | ET MALWARE Generic AsyncRAT Style SSL Cert | 1 | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
2025-01-15T22:52:05.389005+0100 | 2035607 | ET MALWARE Observed Malicious SSL Cert (AsyncRAT Server) | 1 | 87.120.112.98 | 8808 | 192.168.2.4 | 49730 | TCP |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 22:52:04.684185982 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:04.689131975 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:04.689260006 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:04.750602961 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:04.755510092 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.326544046 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.326562881 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.326575041 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.326642036 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:05.383224010 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:05.389004946 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.558466911 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:05.603720903 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:07.314969063 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:07.319880962 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:07.319962978 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:07.326217890 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:15.901874065 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:15.906785965 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:15.906864882 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:15.911675930 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:16.210716009 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:16.259881020 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:16.342986107 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:16.353378057 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:16.358298063 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:16.358490944 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:16.363403082 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.494911909 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:24.500052929 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.502274990 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:24.508112907 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.799283981 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.853640079 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:24.933176041 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.935370922 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:24.940186977 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:24.940279961 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:24.945022106 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:28.901907921 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:28.947415113 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:29.030026913 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:29.072763920 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.088752031 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.093744993 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:33.094347954 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.099226952 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:33.385356903 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:33.431802988 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.529659033 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:33.531660080 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.536797047 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:33.538316965 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:33.543642998 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:41.682611942 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:41.687578917 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:41.687700987 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:41.692543983 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:41.986882925 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:42.041249990 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:42.116990089 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:42.119510889 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:42.124291897 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:42.124366045 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:42.129092932 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.275970936 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:50.280869007 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.280971050 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:50.285782099 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.570096970 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.620340109 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:50.702379942 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.704533100 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:50.709417105 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:50.709496021 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:50.714396000 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:58.869761944 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:58.874706984 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:58.874847889 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:58.879662991 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:58.894948006 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:58.947460890 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:59.026885986 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:59.072437048 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:59.139549017 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:59.144004107 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:59.194192886 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:52:59.194325924 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:52:59.199136019 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.463749886 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:07.468589067 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.468648911 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:07.473421097 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.767827988 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.822468996 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:07.896995068 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.899574995 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:07.904731035 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:07.906358004 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:07.911712885 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.541723967 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:11.546581030 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.546652079 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:11.551461935 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.841042995 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.884970903 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:11.970468044 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.972268105 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:11.977143049 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:11.977222919 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:11.982055902 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.135588884 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:13.140474081 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.140571117 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:13.145359993 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.442272902 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.497879982 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:13.572820902 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.574959040 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:13.579891920 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:13.579950094 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:13.584830046 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.229317904 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:15.234755993 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.234883070 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:15.240243912 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.531672955 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.572499990 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:15.664908886 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.667423010 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:15.672429085 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:15.672498941 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:15.677373886 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:23.823223114 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:23.828058004 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:23.828121901 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:23.832947969 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:24.120587111 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:24.166359901 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:24.358551979 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:24.358747959 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:24.358917952 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:24.380141020 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:24.384974957 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:24.390351057 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:24.395219088 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:28.912826061 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:29.025666952 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:29.046317101 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:29.228745937 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.416812897 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.421757936 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:32.421834946 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.426671028 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:32.717784882 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:32.843399048 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:32.843477964 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.845824957 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.850605011 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:32.850656986 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:32.855523109 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:34.903053999 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:34.908010960 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:34.908082008 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:34.913007021 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:35.195374012 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:35.328730106 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:35.328915119 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:35.330689907 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:35.335463047 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:35.335655928 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:35.340447903 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.073117018 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:43.078078032 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.078449965 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:43.083285093 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.382986069 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.517777920 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.517899990 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:43.519771099 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:43.525053024 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:43.525113106 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:43.530390978 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:51.668786049 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:51.673783064 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:51.673937082 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:51.678788900 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:51.975259066 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.025716066 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.100713015 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.102535009 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.107445955 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.107517004 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.112358093 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.150069952 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.154973984 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.155028105 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.159836054 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.402076960 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.447570086 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.531829119 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.535651922 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.540555954 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:52.540610075 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:52.545589924 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:55.838671923 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:55.843580008 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:55.843667030 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:55.848510981 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:56.147531986 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:56.197598934 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:56.593501091 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:56.595110893 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:56.599983931 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:56.600059986 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:56.604896069 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:58.906018019 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:58.947608948 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:53:59.031400919 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:53:59.088226080 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:04.432610035 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:04.437391043 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:04.437457085 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:04.442301035 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:04.810395956 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:04.853868961 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:05.020960093 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:05.026029110 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:05.031544924 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:05.033052921 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:05.037868023 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.026257992 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.031205893 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.031276941 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.036103010 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.057545900 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.062638998 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.062705994 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.067491055 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.400738955 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.447630882 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.531539917 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.533881903 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.539638996 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:13.539705992 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:13.544503927 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.450465918 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:16.455482006 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.455655098 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:16.460557938 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.783641100 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.838357925 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:16.912641048 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.915987015 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:16.920902967 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:16.921022892 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:16.925889015 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.010950089 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.015913010 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.015995979 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.020827055 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.303572893 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.369652987 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.438340902 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.478915930 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.535446882 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.540441036 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.540529013 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.545408010 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.564177990 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.569073915 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.569143057 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.574002981 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.834239960 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:21.885288000 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:21.973612070 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:22.029422045 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:22.134182930 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:22.139075994 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:22.143151999 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:22.148006916 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:29.596745968 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:29.597168922 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:29.597193003 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:29.597220898 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:29.597372055 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:29.597372055 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:29.598232985 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.151376009 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.156383991 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:30.156462908 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.161273956 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:30.444297075 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:30.541532993 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.563114882 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:30.565237999 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.570650101 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:30.570720911 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:30.575603008 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.323105097 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:33.330018044 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.330085993 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:33.336460114 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.628031015 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.771992922 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.772134066 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:33.773783922 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:33.784109116 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:33.784198999 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:33.794140100 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:41.916883945 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:41.921854973 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:41.921921015 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:41.926722050 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:42.219089985 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:42.348639011 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:42.349330902 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:42.354876041 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:42.359734058 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:42.360910892 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:42.365699053 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.510912895 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:50.516014099 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.516083002 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:50.520916939 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.812463045 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.854028940 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:50.940459967 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.942384005 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:50.947240114 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:50.947309017 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:50.952152014 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:58.893677950 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:58.947905064 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.020500898 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.072880983 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.104582071 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.109436035 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.109802008 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.114620924 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.405225992 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.447885036 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.532708883 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.534883976 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.539875984 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:54:59.540020943 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:54:59.544866085 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.432785034 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:03.437876940 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.438111067 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:03.442994118 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.739510059 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.791718006 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:03.868618011 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.870713949 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:03.875574112 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:03.876730919 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:03.881587029 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.261404037 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.266536951 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.266736984 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.271611929 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.563018084 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.619991064 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.730561972 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.780673981 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.823615074 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.828558922 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:09.828742981 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:09.833599091 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:17.856796026 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:17.861771107 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:17.862839937 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:17.867662907 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:18.159080982 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:18.213591099 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:18.282835007 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:18.284914017 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:18.291640043 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:18.291722059 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:18.296664000 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.448646069 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:26.453991890 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.454062939 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:26.458971977 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.791188002 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.838653088 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:26.924468040 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.932004929 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:26.936768055 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:26.936928034 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:26.941864967 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:28.908441067 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:28.963677883 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:29.067039967 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:29.119968891 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:33.873317957 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:33.878154039 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:33.878429890 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:33.883145094 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:34.166393995 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:34.213722944 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:34.314770937 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:34.316828012 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:34.321656942 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:34.321712017 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:34.326478004 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.464266062 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:42.469701052 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.469774008 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:42.474720955 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.767788887 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.823250055 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:42.902117968 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.907454014 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:42.912468910 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:42.913243055 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:42.919389963 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.058304071 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:51.063245058 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.063307047 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:51.068125010 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.351180077 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.403069973 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:51.480602980 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.484782934 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:51.489557981 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:51.489869118 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:51.494611025 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:56.901998997 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:56.906877995 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:56.906989098 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:56.911787033 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:57.197650909 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:57.245297909 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:57.330775976 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:57.335865021 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:57.340646982 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:57.341619968 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:57.346396923 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:58.893454075 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:58.948334932 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:55:59.020955086 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:55:59.073373079 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:05.729995966 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:05.734795094 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:56:05.735193014 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:05.739988089 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:56:06.034573078 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:56:06.089020014 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:06.159202099 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:56:06.160176039 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:06.164942980 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Jan 15, 2025 22:56:06.165023088 CET | 49730 | 8808 | 192.168.2.4 | 87.120.112.98 |
Jan 15, 2025 22:56:06.169966936 CET | 8808 | 49730 | 87.120.112.98 | 192.168.2.4 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 15, 2025 22:52:04.242549896 CET | 64800 | 53 | 192.168.2.4 | 1.1.1.1 |
Jan 15, 2025 22:52:04.680459023 CET | 53 | 64800 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 15, 2025 22:52:04.242549896 CET | 192.168.2.4 | 1.1.1.1 | 0xf128 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 15, 2025 22:52:04.680459023 CET | 1.1.1.1 | 192.168.2.4 | 0xf128 | No error (0) | 87.120.112.98 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 22:52:06.117882013 CET | 1.1.1.1 | 192.168.2.4 | 0xee6b | No error (0) | 199.232.214.172 | A (IP address) | IN (0x0001) | false | ||
Jan 15, 2025 22:52:06.117882013 CET | 1.1.1.1 | 192.168.2.4 | 0xee6b | No error (0) | 199.232.210.172 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 16:51:59 |
Start date: | 15/01/2025 |
Path: | C:\Users\user\Desktop\1736977840835b9184f01bf0b6c60ce50d66e7897e18892b3f9e56b6303ef4929b2a1c05b2796.dat-decoded.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x360000 |
File size: | 64'512 bytes |
MD5 hash: | 04A1DE79844A9148DCBF720090F0BD84 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Function 02537038 Relevance: 1.5, Strings: 1, Instructions: 281COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253D2D8 Relevance: 1.0, Instructions: 1019COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02537908 Relevance: .3, Instructions: 266COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025320E8 Relevance: 6.7, Strings: 5, Instructions: 449COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532322 Relevance: 5.2, Strings: 4, Instructions: 183COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530F80 Relevance: 2.7, Strings: 2, Instructions: 162COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530DE8 Relevance: 2.6, Strings: 2, Instructions: 130COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A6B0 Relevance: 2.6, Strings: 2, Instructions: 111COMMON
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253B808 Relevance: 1.6, Instructions: 1574COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02539DA5 Relevance: 1.5, Strings: 1, Instructions: 295COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253702C Relevance: 1.5, Strings: 1, Instructions: 276COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02534250 Relevance: 1.5, Strings: 1, Instructions: 247COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253B3B0 Relevance: 1.5, Strings: 1, Instructions: 213COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253AC60 Relevance: 1.4, Strings: 1, Instructions: 127COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025345B8 Relevance: 1.4, Strings: 1, Instructions: 122COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A699 Relevance: 1.4, Strings: 1, Instructions: 115COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02531401 Relevance: 1.3, Strings: 1, Instructions: 93COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530DD9 Relevance: 1.3, Strings: 1, Instructions: 87COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253AB48 Relevance: 1.3, Strings: 1, Instructions: 86COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A5C8 Relevance: 1.3, Strings: 1, Instructions: 67COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253466C Relevance: 1.3, Strings: 1, Instructions: 62COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253AB58 Relevance: 1.3, Strings: 1, Instructions: 57COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253D100 Relevance: 1.3, Strings: 1, Instructions: 53COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530F07 Relevance: 1.3, Strings: 1, Instructions: 46COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A020 Relevance: 1.3, Strings: 1, Instructions: 44COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02533320 Relevance: .9, Instructions: 931COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02533310 Relevance: .7, Instructions: 708COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025378FE Relevance: .3, Instructions: 259COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A860 Relevance: .2, Instructions: 200COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530B49 Relevance: .1, Instructions: 126COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532CFF Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02531298 Relevance: .1, Instructions: 118COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025309A8 Relevance: .1, Instructions: 114COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025309B8 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02534740 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253554C Relevance: .1, Instructions: 93COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02535558 Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A33A Relevance: .1, Instructions: 71COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A4C8 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253AEA9 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253B7F9 Relevance: .1, Instructions: 65COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253AEB8 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 025314F9 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02531508 Relevance: .1, Instructions: 53COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A592 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532BB0 Relevance: .1, Instructions: 51COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02534730 Relevance: .0, Instructions: 50COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A0A8 Relevance: .0, Instructions: 43COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253A0B0 Relevance: .0, Instructions: 41COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532E83 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02531C60 Relevance: .0, Instructions: 35COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02531C4F Relevance: .0, Instructions: 34COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253ADFE Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530F48 Relevance: .0, Instructions: 24COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02539BC8 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253B758 Relevance: .0, Instructions: 20COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532EBF Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0253B768 Relevance: .0, Instructions: 16COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532ED0 Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530B19 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02530B35 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02532EA8 Relevance: .0, Instructions: 8COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 02536CF0 Relevance: 1.5, Strings: 1, Instructions: 238COMMON
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|