Windows
Analysis Report
20f8b1d9eabf499dbc7a0bff6ee7ddec.ps1
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
powershell.exe (PID: 7700 cmdline:
"C:\Window s\System32 \WindowsPo werShell\v 1.0\powers hell.exe" -noLogo -E xecutionPo licy unres tricted -f ile "C:\Us ers\user\D esktop\20f 8b1d9eabf4 99dbc7a0bf f6ee7ddec. ps1" MD5: 04029E121A0CFA5991749937DD22A1D9) conhost.exe (PID: 7708 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) tmpB20E.exe (PID: 7928 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\tmpB20 E.exe" MD5: F5302ED0307CE30D226D50A45A0DCA9D)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
XWorm | Malware with wide range of capabilities ranging from RAT to ransomware. | No Attribution |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
Click to see the 2 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
MALWARE_Win_AsyncRAT | Detects AsyncRAT | ditekSHen |
| |
JoeSecurity_XWorm | Yara detected XWorm | Joe Security | ||
rat_win_xworm_v3 | Finds XWorm (version XClient, v3) samples based on characteristic strings | Sekoia.io |
| |
Click to see the 5 entries |
System Summary |
---|
Source: | Author: frack113: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-30T10:36:48.589330+0100 | 2853193 | 1 | Malware Command and Control Activity Detected | 192.168.2.7 | 57655 | 3.127.138.57 | 10901 | TCP |
- • AV Detection
- • Spreading
- • Networking
- • System Summary
- • Data Obfuscation
- • Persistence and Installation Behavior
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
- • Anti Debugging
- • HIPS / PFW / Operating System Protection Evasion
- • Language, Device and Operating System Detection
- • Lowering of HIPS / PFW / Operating System Security Settings
- • Stealing of Sensitive Information
- • Remote Access Functionality
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: |
Source: | Integrated Neural Analysis Model: |
Source: | Joe Sandbox ML: |
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: | ||
Source: | String decryptor: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Networking |
---|
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | File source: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: | ||
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | File created: | Jump to dropped file |
Source: | Process Stats: |
Source: | Code function: | 4_2_00007FFAAC5B6B22 | |
Source: | Code function: | 4_2_00007FFAAC5B5D76 |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: | ||
Source: | Cryptographic APIs: |
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: | ||
Source: | Security API names: |
Source: | Classification label: |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | Anti Malware Scan Interface: |
Source: | Code function: | 4_2_00007FFAAC5B785E | |
Source: | Code function: | 4_2_00007FFAAC5B782E | |
Source: | Code function: | 4_2_00007FFAAC5B782E |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior |
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior | ||
Source: | File Volume queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Binary or memory string: |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 11 Windows Management Instrumentation | 1 DLL Side-Loading | 11 Process Injection | 1 Disable or Modify Tools | OS Credential Dumping | 221 Security Software Discovery | Remote Services | 11 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 PowerShell | Boot or Logon Initialization Scripts | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Non-Standard Port | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 131 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Non-Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Deobfuscate/Decode Files or Information | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | 1 Application Layer Protocol | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 Obfuscated Files or Information | LSA Secrets | 2 File and Directory Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 3 Software Packing | Cached Domain Credentials | 13 System Information Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | 1 DLL Side-Loading | DCSync | Remote System Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
22% | ReversingLabs | ByteCode-MSIL.Spyware.AsyncRAT |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | HEUR/AGEN.1305769 | ||
100% | Joe Sandbox ML | |||
72% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
2.tcp.eu.ngrok.io | 3.126.37.18 | true | false | high | |
171.39.242.20.in-addr.arpa | unknown | unknown | false | high |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
3.126.37.18 | 2.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | false | |
3.127.138.57 | unknown | United States | 16509 | AMAZON-02US | true | |
18.192.93.86 | unknown | United States | 16509 | AMAZON-02US | false | |
18.157.68.73 | unknown | United States | 16509 | AMAZON-02US | false | |
18.197.239.5 | unknown | United States | 16509 | AMAZON-02US | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1602905 |
Start date and time: | 2025-01-30 10:34:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 8m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 10 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 20f8b1d9eabf499dbc7a0bff6ee7ddec.ps1 |
Detection: | MAL |
Classification: | mal100.troj.evad.winPS1@4/6@6/5 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, WMIADAP.exe, SIHCl ient.exe, conhost.exe, backgro undTaskHost.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 13.107.246.45, 4.2 45.163.56, 20.242.39.171, 20.1 2.23.50 - Excluded domains from analysis
(whitelisted): otelrules.azur eedge.net, slscr.update.micros oft.com, ctldl.windowsupdate.c om, time.windows.com, fe3cr.de livery.mp.microsoft.com - Execution Graph export aborted
for target powershell.exe, PI D 7700 because it is empty - Execution Graph export aborted
for target tmpB20E.exe, PID 7 928 because it is empty - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtOpenKeyEx calls foun d. - Report size getting too big, t
oo many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
04:35:17 | API Interceptor | |
04:35:21 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
3.126.37.18 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | ZTrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
3.127.138.57 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | AsyncRAT | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Metasploit | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
18.192.93.86 | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
2.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | AsyncRAT | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Sliver | Browse |
| ||
Get hash | malicious | ZTrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | CobaltStrike, Metasploit | Browse |
| |
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
AMAZON-02US | Get hash | malicious | CobaltStrike, Metasploit | Browse |
| |
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
AMAZON-02US | Get hash | malicious | CobaltStrike, Metasploit | Browse |
| |
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
AMAZON-02US | Get hash | malicious | CobaltStrike, Metasploit | Browse |
| |
Get hash | malicious | CobaltStrike, Metasploit | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
|
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1628158735648508 |
Encrypted: | false |
SSDEEP: | 3:Nllluldhz/lL:NllU |
MD5: | 03744CE5681CB7F5E53A02F19FA22067 |
SHA1: | 234FB09010F6714453C83795D8CF3250D871D4DF |
SHA-256: | 88348573B57BA21639837E3AF19A00B4D7889E2D8E90A923151AC022D2946E5D |
SHA-512: | 0C05D6047DBA2286F8F72EB69A69919DC5650F96E8EE759BA9B3FC10BE793F3A88408457E700936BCACA02816CE25DD53F48B962491E7F4F0A4A534D88A855E6 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 33280 |
Entropy (8bit): | 5.595778394593736 |
Encrypted: | false |
SSDEEP: | 384:xlRmhGD91SluSWhnHHxzLmYV3Tm2eaFOL1dRApkFTBLTsOZwpGd2v99IkuisfVFR:TRPD9OQhx/BV3Tw4e1dVFE9jSOjhwb7 |
MD5: | F5302ED0307CE30D226D50A45A0DCA9D |
SHA1: | 9C9F6BA6ED092FFDCECF6DE13E9E618CE26FF2F5 |
SHA-256: | 497F32EB65C30742069CE49A41270EAB82D3A5CD1E36958E3608304F53507A0F |
SHA-512: | 0E9DFE2087B9E76B6504C26ACA0C13CAF72BBD459F1ACA1439805D8CE5D2A554DF8143818F984F526D64BDE4EA271CD87BEF9E0446822E64C063369C10DA5B92 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6225 |
Entropy (8bit): | 3.733655320231587 |
Encrypted: | false |
SSDEEP: | 48:W/S2W0bHCXU20MQzukvhkvklCywi98ijYIl6TsSogZowJAJad8ijYIllTsSogZog:eWsHCEr5ykvhkvCCtBcYI2JHycYIDJH9 |
MD5: | 16C804C6915EAB8CC5392F1CDE971F51 |
SHA1: | FF803AF50F33F76DA0CC5490A94930DAF5226AA6 |
SHA-256: | 1729C7146E6529EA756E2392FDE80C3A2188D596122D92A39EBF56A10C04C639 |
SHA-512: | 7F317726577BAA7ED5F5ED0C559579E3E52AA3A2353EA9E5466BCB36BE469F6520981280C4624EAC4F760C5EF8085C1923626063EB13AABB0FF74447A50B93F3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 6225 |
Entropy (8bit): | 3.733655320231587 |
Encrypted: | false |
SSDEEP: | 48:W/S2W0bHCXU20MQzukvhkvklCywi98ijYIl6TsSogZowJAJad8ijYIllTsSogZog:eWsHCEr5ykvhkvCCtBcYI2JHycYIDJH9 |
MD5: | 16C804C6915EAB8CC5392F1CDE971F51 |
SHA1: | FF803AF50F33F76DA0CC5490A94930DAF5226AA6 |
SHA-256: | 1729C7146E6529EA756E2392FDE80C3A2188D596122D92A39EBF56A10C04C639 |
SHA-512: | 7F317726577BAA7ED5F5ED0C559579E3E52AA3A2353EA9E5466BCB36BE469F6520981280C4624EAC4F760C5EF8085C1923626063EB13AABB0FF74447A50B93F3 |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.9578052016755425 |
TrID: | |
File name: | 20f8b1d9eabf499dbc7a0bff6ee7ddec.ps1 |
File size: | 45'430 bytes |
MD5: | ac45d57d6196e0eb21f4136002fd645d |
SHA1: | d3d32e7473079db2dbbf959c887a16e87a22894c |
SHA256: | 52f1718467ed6617713e995fb1ad595f9040247df74acb489285a00212f7ff7d |
SHA512: | 8ce3075dff3468f72b199b07b87b328c727fd2c9eb0b6ef6d0709040069b5261ce60afae1a24c5cc2a401eb359c4b04011b56f50e4f521ef7ee0337520f6c11e |
SSDEEP: | 768:rqd0pgY5FOZdrLIIz+YrZJLlNeDGjR5TGcygxl92eeG:u2SxdrLII+0XhLjHGcyulkeeG |
TLSH: | 7A135A374922FCD1BB7F2D90F5043A651C88342787A98678FBC4095A38B6250DF6ADF8 |
File Content Preview: | ..$arquivo_bytes = [System.Convert]::FromBase64String('TVqQAAMAAAAEAAAA//8AALgAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgAAAAA4fug4AtAnNIbgBTM0hVGhpcyBwcm9ncmFtIGNhbm5vdCBiZSBydW4gaW4gRE9TIG1vZGUuDQ0KJAAAAAAAAABQRQAATAEDADHMkmcAAAAAAAAAAOAA |
Icon Hash: | 3270d6baae77db44 |
Download Network PCAP: filtered – full
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-01-30T10:36:31.828608+0100 | 2855924 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.7 | 57652 | 3.127.138.57 | 10901 | TCP |
2025-01-30T10:36:48.589330+0100 | 2853193 | ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound | 1 | 192.168.2.7 | 57655 | 3.127.138.57 | 10901 | TCP |
- Total Packets: 303
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2025 10:35:21.990950108 CET | 49725 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:21.997144938 CET | 10901 | 49725 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:21.997221947 CET | 49725 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:22.240994930 CET | 49725 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:22.245821953 CET | 10901 | 49725 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:23.613183022 CET | 10901 | 49725 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:23.613331079 CET | 49725 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:26.229598045 CET | 49725 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:26.231295109 CET | 49752 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:26.234390020 CET | 10901 | 49725 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:26.236099005 CET | 10901 | 49752 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:26.236350060 CET | 49752 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:26.251430035 CET | 49752 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:26.256172895 CET | 10901 | 49752 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:27.894623995 CET | 10901 | 49752 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:27.894720078 CET | 49752 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:30.122191906 CET | 49752 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:30.126604080 CET | 49780 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:30.128134012 CET | 10901 | 49752 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:30.132461071 CET | 10901 | 49780 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:30.132554054 CET | 49780 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:30.182240963 CET | 49780 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:30.187037945 CET | 10901 | 49780 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:31.755564928 CET | 10901 | 49780 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:31.755655050 CET | 49780 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:34.650415897 CET | 49780 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:34.654441118 CET | 49808 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:34.655200005 CET | 10901 | 49780 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:34.659317970 CET | 10901 | 49808 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:34.659389973 CET | 49808 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:34.900612116 CET | 49808 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:34.905441999 CET | 10901 | 49808 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:36.266134977 CET | 10901 | 49808 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:36.266745090 CET | 49808 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:38.526618958 CET | 49808 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:38.528335094 CET | 49834 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:38.531421900 CET | 10901 | 49808 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:38.533159018 CET | 10901 | 49834 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:38.533509016 CET | 49834 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:38.548571110 CET | 49834 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:38.553311110 CET | 10901 | 49834 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:40.162693977 CET | 10901 | 49834 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:40.162945986 CET | 49834 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:42.901607990 CET | 49834 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:42.902971983 CET | 49865 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:42.906457901 CET | 10901 | 49834 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:42.907959938 CET | 10901 | 49865 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:42.908046007 CET | 49865 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:42.923887014 CET | 49865 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:42.930419922 CET | 10901 | 49865 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:44.524271011 CET | 10901 | 49865 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:44.524389982 CET | 49865 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:47.286498070 CET | 49865 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:47.291517019 CET | 10901 | 49865 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:47.297401905 CET | 49891 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:47.302238941 CET | 10901 | 49891 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:47.302321911 CET | 49891 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:47.604543924 CET | 49891 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:47.609328032 CET | 10901 | 49891 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:48.943802118 CET | 57556 | 53 | 192.168.2.7 | 162.159.36.2 |
Jan 30, 2025 10:35:48.948596001 CET | 53 | 57556 | 162.159.36.2 | 192.168.2.7 |
Jan 30, 2025 10:35:48.951186895 CET | 57556 | 53 | 192.168.2.7 | 162.159.36.2 |
Jan 30, 2025 10:35:48.956265926 CET | 53 | 57556 | 162.159.36.2 | 192.168.2.7 |
Jan 30, 2025 10:35:48.964245081 CET | 10901 | 49891 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:48.966569901 CET | 49891 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:49.415673018 CET | 57556 | 53 | 192.168.2.7 | 162.159.36.2 |
Jan 30, 2025 10:35:49.420727968 CET | 53 | 57556 | 162.159.36.2 | 192.168.2.7 |
Jan 30, 2025 10:35:49.420830011 CET | 57556 | 53 | 192.168.2.7 | 162.159.36.2 |
Jan 30, 2025 10:35:51.620111942 CET | 49891 | 10901 | 192.168.2.7 | 3.126.37.18 |
Jan 30, 2025 10:35:51.624918938 CET | 10901 | 49891 | 3.126.37.18 | 192.168.2.7 |
Jan 30, 2025 10:35:51.644072056 CET | 57576 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:51.648921013 CET | 10901 | 57576 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:51.649034023 CET | 57576 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:51.667026997 CET | 57576 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:51.671835899 CET | 10901 | 57576 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:53.308489084 CET | 10901 | 57576 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:53.308597088 CET | 57576 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:55.729573965 CET | 57576 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:55.731884956 CET | 57605 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:55.734426022 CET | 10901 | 57576 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:55.738245964 CET | 10901 | 57605 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:55.738351107 CET | 57605 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:55.756119967 CET | 57605 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:55.760996103 CET | 10901 | 57605 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:57.395215988 CET | 10901 | 57605 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:57.396661043 CET | 57605 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:59.245270967 CET | 57605 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:59.249573946 CET | 57628 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:59.250108957 CET | 10901 | 57605 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:59.254373074 CET | 10901 | 57628 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:35:59.254504919 CET | 57628 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:59.350455999 CET | 57628 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:35:59.355272055 CET | 10901 | 57628 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:00.913491964 CET | 10901 | 57628 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:00.913589954 CET | 57628 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:03.198389053 CET | 57628 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:03.200401068 CET | 57641 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:03.203373909 CET | 10901 | 57628 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:03.205233097 CET | 10901 | 57641 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:03.205312014 CET | 57641 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:03.219688892 CET | 57641 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:03.224464893 CET | 10901 | 57641 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:04.851828098 CET | 10901 | 57641 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:04.851918936 CET | 57641 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:06.792020082 CET | 57641 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:06.793628931 CET | 57642 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:06.797094107 CET | 10901 | 57641 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:06.798813105 CET | 10901 | 57642 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:06.798892975 CET | 57642 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:06.823189020 CET | 57642 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:06.828571081 CET | 10901 | 57642 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:08.467432976 CET | 10901 | 57642 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:08.467556953 CET | 57642 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:09.510832071 CET | 57642 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:09.512044907 CET | 57643 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:09.517913103 CET | 10901 | 57642 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:09.518884897 CET | 10901 | 57643 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:09.518963099 CET | 57643 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:09.534013987 CET | 57643 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:09.540903091 CET | 10901 | 57643 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:11.183276892 CET | 10901 | 57643 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:11.185611963 CET | 57643 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:11.745310068 CET | 57643 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:11.748497009 CET | 57644 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:11.750228882 CET | 10901 | 57643 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:11.757121086 CET | 10901 | 57644 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:11.757205963 CET | 57644 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:11.785902977 CET | 57644 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:11.790720940 CET | 10901 | 57644 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:13.398426056 CET | 10901 | 57644 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:13.399154902 CET | 57644 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:14.901563883 CET | 57644 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:14.902976036 CET | 57645 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:14.906691074 CET | 10901 | 57644 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:14.908010006 CET | 10901 | 57645 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:14.908107996 CET | 57645 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:14.923120975 CET | 57645 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:14.927985907 CET | 10901 | 57645 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:16.537183046 CET | 10901 | 57645 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:16.538757086 CET | 57645 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:17.420156002 CET | 57645 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:17.423302889 CET | 57646 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:17.425096035 CET | 10901 | 57645 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:17.428169012 CET | 10901 | 57646 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:17.428232908 CET | 57646 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:17.567450047 CET | 57646 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:17.572350979 CET | 10901 | 57646 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:19.071722984 CET | 10901 | 57646 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:19.072025061 CET | 57646 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:19.526509047 CET | 57646 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:19.527875900 CET | 57647 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:19.531445026 CET | 10901 | 57646 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:19.532851934 CET | 10901 | 57647 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:19.532970905 CET | 57647 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:19.553215981 CET | 57647 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:19.558150053 CET | 10901 | 57647 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:21.182110071 CET | 10901 | 57647 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:21.182220936 CET | 57647 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:21.463938951 CET | 57647 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:21.465656996 CET | 57648 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:21.469012022 CET | 10901 | 57647 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:21.470513105 CET | 10901 | 57648 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:21.470582008 CET | 57648 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:21.487997055 CET | 57648 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:21.493022919 CET | 10901 | 57648 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:23.115958929 CET | 10901 | 57648 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:23.116029978 CET | 57648 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:23.120462894 CET | 57648 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:23.121601105 CET | 57649 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:23.125283003 CET | 10901 | 57648 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:23.126483917 CET | 10901 | 57649 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:23.126547098 CET | 57649 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:23.145858049 CET | 57649 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:23.150706053 CET | 10901 | 57649 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:24.793307066 CET | 10901 | 57649 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:24.793412924 CET | 57649 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:24.807785034 CET | 57649 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:24.809772968 CET | 57650 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:24.812717915 CET | 10901 | 57649 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:24.814636946 CET | 10901 | 57650 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:24.814716101 CET | 57650 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:24.834207058 CET | 57650 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:24.838969946 CET | 10901 | 57650 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:26.465965033 CET | 10901 | 57650 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:26.466053963 CET | 57650 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:26.467936993 CET | 57650 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:26.471085072 CET | 57651 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:26.472770929 CET | 10901 | 57650 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:26.475989103 CET | 10901 | 57651 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:26.476083994 CET | 57651 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:26.509310961 CET | 57651 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:26.514281988 CET | 10901 | 57651 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:28.116590023 CET | 10901 | 57651 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:28.116736889 CET | 57651 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.605005980 CET | 57651 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.609862089 CET | 10901 | 57651 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:31.611696959 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.616565943 CET | 10901 | 57652 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:31.616643906 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.660885096 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.665703058 CET | 10901 | 57652 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:31.828608036 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:31.833391905 CET | 10901 | 57652 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:33.260293007 CET | 10901 | 57652 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:33.262665033 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:36.971477985 CET | 57652 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:36.974751949 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:36.976491928 CET | 10901 | 57652 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:36.979567051 CET | 10901 | 57653 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:36.979754925 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:37.078603983 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:37.085719109 CET | 10901 | 57653 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:37.672334909 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:37.679038048 CET | 10901 | 57653 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:38.616494894 CET | 10901 | 57653 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:38.616589069 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.198534966 CET | 57653 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.200196981 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.203327894 CET | 10901 | 57653 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.204967976 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.205025911 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.239377975 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.244236946 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.245510101 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.250314951 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.260953903 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.265782118 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.323683023 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.328501940 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.339567900 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.344506979 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.433837891 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.438606977 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.448571920 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.453361988 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.495517015 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.500293016 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.543006897 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.547765017 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.667397976 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.674190998 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.682907104 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.687683105 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.714229107 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.719892025 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.729908943 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.737323999 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:42.761066914 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:42.767465115 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:43.850296021 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:43.852607965 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.778261900 CET | 57654 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.778269053 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.784883022 CET | 10901 | 57654 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:47.784903049 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:47.785156965 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.850152016 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.855053902 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:47.870776892 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:47.875562906 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.011141062 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.016053915 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.042602062 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.047475100 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.183140039 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.187930107 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.261296034 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.266133070 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.370738029 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.375708103 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.386167049 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.391082048 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.448565006 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.453358889 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.495461941 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.500308037 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.511193991 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.515986919 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.526947021 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.531829119 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.589329958 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.594122887 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.698925972 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.703704119 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.715904951 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.720710993 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:48.948924065 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:48.953732967 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:49.430716038 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:49.430891037 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:53.948616982 CET | 57655 | 10901 | 192.168.2.7 | 3.127.138.57 |
Jan 30, 2025 10:36:53.954117060 CET | 10901 | 57655 | 3.127.138.57 | 192.168.2.7 |
Jan 30, 2025 10:36:53.959577084 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:53.964467049 CET | 10901 | 57656 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:53.964541912 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:54.003854990 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:54.010417938 CET | 10901 | 57656 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:54.104937077 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:54.109761953 CET | 10901 | 57656 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:55.603547096 CET | 10901 | 57656 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:55.603667974 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:59.120290995 CET | 57656 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:59.123374939 CET | 57657 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:59.125322104 CET | 10901 | 57656 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:59.128381968 CET | 10901 | 57657 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:36:59.130975962 CET | 57657 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:59.244467974 CET | 57657 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:36:59.249459028 CET | 10901 | 57657 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:00.756272078 CET | 10901 | 57657 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:00.756350040 CET | 57657 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.292327881 CET | 57657 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.294945002 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.297660112 CET | 10901 | 57657 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:04.299762011 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:04.299829006 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.333409071 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.338249922 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:04.354899883 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.359627962 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:04.651977062 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.658756018 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:04.941998005 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:04.948028088 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:05.946290970 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:05.946361065 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:10.761200905 CET | 57658 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:10.763534069 CET | 57659 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:10.766093969 CET | 10901 | 57658 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:10.768429041 CET | 10901 | 57659 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:10.768491030 CET | 57659 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:10.811338902 CET | 57659 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:10.816912889 CET | 10901 | 57659 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:12.396845102 CET | 10901 | 57659 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:12.396946907 CET | 57659 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:15.840631962 CET | 57659 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:15.842350006 CET | 57660 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:15.846910954 CET | 10901 | 57659 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:15.848676920 CET | 10901 | 57660 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:15.852824926 CET | 57660 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:15.910897970 CET | 57660 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:15.915718079 CET | 10901 | 57660 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:17.514550924 CET | 10901 | 57660 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:17.514705896 CET | 57660 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:21.035471916 CET | 57660 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:21.040437937 CET | 10901 | 57660 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:21.043509960 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:21.048403978 CET | 10901 | 57661 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:21.048491001 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:21.256206989 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:21.261193037 CET | 10901 | 57661 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:22.276865005 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:22.281774044 CET | 10901 | 57661 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:22.701013088 CET | 10901 | 57661 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:22.701361895 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.667274952 CET | 57661 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.670644045 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.672161102 CET | 10901 | 57661 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:26.676014900 CET | 10901 | 57662 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:26.676084995 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.724782944 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.729688883 CET | 10901 | 57662 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:26.792742014 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:26.797707081 CET | 10901 | 57662 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:28.320971966 CET | 10901 | 57662 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:28.321070910 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:32.292471886 CET | 57662 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:32.295434952 CET | 57663 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:32.297405958 CET | 10901 | 57662 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:32.300334930 CET | 10901 | 57663 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:32.300409079 CET | 57663 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:32.336568117 CET | 57663 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:32.341496944 CET | 10901 | 57663 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:33.964153051 CET | 10901 | 57663 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:33.964271069 CET | 57663 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:37.464632988 CET | 57663 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:37.466072083 CET | 57664 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:37.469502926 CET | 10901 | 57663 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:37.470870018 CET | 10901 | 57664 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:37.470962048 CET | 57664 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:37.520677090 CET | 57664 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:37.525537014 CET | 10901 | 57664 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:39.142970085 CET | 10901 | 57664 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:39.144747019 CET | 57664 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.558387995 CET | 57664 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.563267946 CET | 10901 | 57664 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:42.570966959 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.575781107 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:42.575850010 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.613106012 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.617970943 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:42.667632103 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.672493935 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:42.777019024 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.781806946 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:42.808274984 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:42.813157082 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:44.211123943 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:44.211190939 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:47.981359005 CET | 57665 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:47.984342098 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:47.986167908 CET | 10901 | 57665 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:48.004143953 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:48.004282951 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:48.077176094 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:48.082011938 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:49.308326960 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:49.313152075 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:49.339999914 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:49.344815016 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:49.648435116 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:49.648494959 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:54.432982922 CET | 57666 | 10901 | 192.168.2.7 | 18.157.68.73 |
Jan 30, 2025 10:37:54.437942982 CET | 10901 | 57666 | 18.157.68.73 | 192.168.2.7 |
Jan 30, 2025 10:37:54.453933954 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:54.458838940 CET | 10901 | 57667 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:54.459284067 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:54.557818890 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:54.562720060 CET | 10901 | 57667 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:54.995685101 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:55.000650883 CET | 10901 | 57667 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:56.105164051 CET | 10901 | 57667 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:56.105251074 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.573793888 CET | 57667 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.576157093 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.580737114 CET | 10901 | 57667 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:59.584726095 CET | 10901 | 57668 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:59.584825993 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.628803015 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.633883953 CET | 10901 | 57668 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:37:59.871062994 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:37:59.876085043 CET | 10901 | 57668 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:01.227205038 CET | 10901 | 57668 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:01.227269888 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:04.651842117 CET | 57668 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:04.653728008 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:04.656755924 CET | 10901 | 57668 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:04.658597946 CET | 10901 | 57669 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:04.660706043 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:04.912641048 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:04.917548895 CET | 10901 | 57669 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:05.121000051 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:05.125981092 CET | 10901 | 57669 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:06.289416075 CET | 10901 | 57669 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:06.291167021 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:09.948702097 CET | 57669 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:09.951306105 CET | 57670 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:09.953552008 CET | 10901 | 57669 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:09.956108093 CET | 10901 | 57670 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:09.956181049 CET | 57670 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:10.192672014 CET | 57670 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:10.197665930 CET | 10901 | 57670 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:11.602144003 CET | 10901 | 57670 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:11.602204084 CET | 57670 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:15.417479038 CET | 57670 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:15.420582056 CET | 57671 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:15.422338009 CET | 10901 | 57670 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:15.425482988 CET | 10901 | 57671 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:15.425549030 CET | 57671 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:15.466865063 CET | 57671 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:15.471852064 CET | 10901 | 57671 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:17.057416916 CET | 10901 | 57671 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:17.057521105 CET | 57671 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:20.556529999 CET | 57671 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:20.559832096 CET | 57672 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:20.561393023 CET | 10901 | 57671 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:20.564656019 CET | 10901 | 57672 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:20.564728975 CET | 57672 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:20.767353058 CET | 57672 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:20.772161007 CET | 10901 | 57672 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:22.214958906 CET | 10901 | 57672 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:22.218981028 CET | 57672 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:25.839349985 CET | 57672 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:25.840858936 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:25.844319105 CET | 10901 | 57672 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:25.845885992 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:25.845977068 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:25.921814919 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:25.926717043 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:25.995872021 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:26.002348900 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:26.058334112 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:26.064897060 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:26.073956013 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:26.080418110 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:27.402332067 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:27.407309055 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:27.479413033 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:27.479471922 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:32.402349949 CET | 57673 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:32.403395891 CET | 57674 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:32.407423019 CET | 10901 | 57673 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:32.408319950 CET | 10901 | 57674 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:32.408441067 CET | 57674 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:32.552517891 CET | 57674 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:32.557720900 CET | 10901 | 57674 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:34.055593014 CET | 10901 | 57674 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:34.056797981 CET | 57674 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:37.855010986 CET | 57674 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:37.857455015 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:37.859930992 CET | 10901 | 57674 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:37.862251043 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:37.862937927 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:37.910545111 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:37.915415049 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:38.011377096 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:38.016355038 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:38.214618921 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:38.219605923 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:38.245779991 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:38.250662088 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:39.493108988 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:39.493257999 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:43.293766975 CET | 57675 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:43.293795109 CET | 57676 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:43.298882008 CET | 10901 | 57675 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:43.298899889 CET | 10901 | 57676 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:43.299048901 CET | 57676 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:43.371170998 CET | 57676 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:43.376213074 CET | 10901 | 57676 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:44.946768999 CET | 10901 | 57676 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:44.946824074 CET | 57676 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.495614052 CET | 57676 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.497935057 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.500524998 CET | 10901 | 57676 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:48.502808094 CET | 10901 | 57677 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:48.502870083 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.535140038 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.539998055 CET | 10901 | 57677 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:48.558352947 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:48.563124895 CET | 10901 | 57677 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:50.167699099 CET | 10901 | 57677 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:50.167841911 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.652710915 CET | 57677 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.656716108 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.657668114 CET | 10901 | 57677 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:53.661721945 CET | 10901 | 57678 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:53.664792061 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.883095980 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.888130903 CET | 10901 | 57678 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:53.904707909 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:53.909569025 CET | 10901 | 57678 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:55.311453104 CET | 10901 | 57678 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:55.311568975 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:58.933492899 CET | 57678 | 10901 | 192.168.2.7 | 18.197.239.5 |
Jan 30, 2025 10:38:58.938402891 CET | 10901 | 57678 | 18.197.239.5 | 192.168.2.7 |
Jan 30, 2025 10:38:58.946693897 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:38:58.951543093 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:38:58.951606989 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:38:58.986691952 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:38:58.991472006 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:38:58.996093988 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:38:59.001015902 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:38:59.996691942 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:00.002202988 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:00.606966972 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:00.607036114 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.292625904 CET | 57679 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.294785976 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.297729969 CET | 10901 | 57679 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:04.299712896 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:04.299797058 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.330831051 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.335834980 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:04.433383942 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.438373089 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:04.464713097 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.470155001 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:04.667781115 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:04.672800064 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:05.245850086 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:05.250842094 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:05.951605082 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:05.951697111 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:09.685322046 CET | 57681 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:09.685401917 CET | 57680 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:09.691145897 CET | 10901 | 57681 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:09.691160917 CET | 10901 | 57680 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:09.691807985 CET | 57681 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:09.741091967 CET | 57681 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:09.745975018 CET | 10901 | 57681 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:11.322204113 CET | 10901 | 57681 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:11.322284937 CET | 57681 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:15.129206896 CET | 57681 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:15.134715080 CET | 10901 | 57681 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:15.134875059 CET | 57682 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:15.140153885 CET | 10901 | 57682 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:15.144715071 CET | 57682 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:15.944771051 CET | 57682 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:15.949714899 CET | 10901 | 57682 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:16.774224043 CET | 10901 | 57682 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:16.774285078 CET | 57682 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:21.089592934 CET | 57682 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:21.092289925 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:21.094626904 CET | 10901 | 57682 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:21.097206116 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:21.097290039 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:21.136751890 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:21.141609907 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.121028900 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:23.391454935 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.391479015 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.391552925 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.391551971 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:23.391551971 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:23.391628981 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:23.393574953 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.433222055 CET | 57683 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:23.566592932 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.566611052 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.566625118 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:23.566637039 CET | 10901 | 57683 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:28.121970892 CET | 57684 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:28.126914024 CET | 10901 | 57684 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:28.126986027 CET | 57684 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:28.153206110 CET | 57684 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:28.163665056 CET | 10901 | 57684 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:29.781505108 CET | 10901 | 57684 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:29.781636000 CET | 57684 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:35.340419054 CET | 57685 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:35.340424061 CET | 57684 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:35.345963955 CET | 10901 | 57684 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:35.345977068 CET | 10901 | 57685 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:35.346126080 CET | 57685 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:35.357016087 CET | 57685 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:35.362478018 CET | 10901 | 57685 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:36.980582952 CET | 10901 | 57685 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:36.980777979 CET | 57685 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:42.761590004 CET | 57685 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:42.762521029 CET | 57686 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:42.766438961 CET | 10901 | 57685 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:42.767414093 CET | 10901 | 57686 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:42.767535925 CET | 57686 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:42.779767036 CET | 57686 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:42.784558058 CET | 10901 | 57686 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:44.419195890 CET | 10901 | 57686 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:44.419290066 CET | 57686 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:46.261502981 CET | 57686 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:46.262667894 CET | 57687 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:46.266328096 CET | 10901 | 57686 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:46.267430067 CET | 10901 | 57687 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:46.267699957 CET | 57687 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:46.276721001 CET | 57687 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:46.281562090 CET | 10901 | 57687 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:47.902784109 CET | 10901 | 57687 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:47.902956963 CET | 57687 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:50.667932034 CET | 57687 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:50.671227932 CET | 57688 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:50.672914028 CET | 10901 | 57687 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:50.676090956 CET | 10901 | 57688 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:50.676306009 CET | 57688 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:50.688138962 CET | 57688 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:50.692985058 CET | 10901 | 57688 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:52.306368113 CET | 10901 | 57688 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:52.306462049 CET | 57688 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:56.230230093 CET | 57688 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:56.231309891 CET | 57689 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:56.235234022 CET | 10901 | 57688 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:56.236200094 CET | 10901 | 57689 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:56.236273050 CET | 57689 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:56.249556065 CET | 57689 | 10901 | 192.168.2.7 | 18.192.93.86 |
Jan 30, 2025 10:39:56.254429102 CET | 10901 | 57689 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:57.889343977 CET | 10901 | 57689 | 18.192.93.86 | 192.168.2.7 |
Jan 30, 2025 10:39:57.889481068 CET | 57689 | 10901 | 192.168.2.7 | 18.192.93.86 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jan 30, 2025 10:35:21.972789049 CET | 56957 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:35:21.983191967 CET | 53 | 56957 | 1.1.1.1 | 192.168.2.7 |
Jan 30, 2025 10:35:48.939321995 CET | 53 | 61641 | 162.159.36.2 | 192.168.2.7 |
Jan 30, 2025 10:35:49.445229053 CET | 55235 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:35:49.452373981 CET | 53 | 55235 | 1.1.1.1 | 192.168.2.7 |
Jan 30, 2025 10:35:51.624041080 CET | 54063 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:35:51.643030882 CET | 53 | 54063 | 1.1.1.1 | 192.168.2.7 |
Jan 30, 2025 10:36:53.950140953 CET | 51621 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:36:53.958761930 CET | 53 | 51621 | 1.1.1.1 | 192.168.2.7 |
Jan 30, 2025 10:37:54.435703039 CET | 62102 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:37:54.452755928 CET | 53 | 62102 | 1.1.1.1 | 192.168.2.7 |
Jan 30, 2025 10:38:58.936367989 CET | 50998 | 53 | 192.168.2.7 | 1.1.1.1 |
Jan 30, 2025 10:38:58.945949078 CET | 53 | 50998 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Jan 30, 2025 10:35:21.972789049 CET | 192.168.2.7 | 1.1.1.1 | 0x2c11 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2025 10:35:49.445229053 CET | 192.168.2.7 | 1.1.1.1 | 0x5819 | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false | |
Jan 30, 2025 10:35:51.624041080 CET | 192.168.2.7 | 1.1.1.1 | 0x498a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2025 10:36:53.950140953 CET | 192.168.2.7 | 1.1.1.1 | 0x56c2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2025 10:37:54.435703039 CET | 192.168.2.7 | 1.1.1.1 | 0xd940 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Jan 30, 2025 10:38:58.936367989 CET | 192.168.2.7 | 1.1.1.1 | 0xbcf6 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Jan 30, 2025 10:35:21.983191967 CET | 1.1.1.1 | 192.168.2.7 | 0x2c11 | No error (0) | 3.126.37.18 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2025 10:35:49.452373981 CET | 1.1.1.1 | 192.168.2.7 | 0x5819 | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false | |
Jan 30, 2025 10:35:51.643030882 CET | 1.1.1.1 | 192.168.2.7 | 0x498a | No error (0) | 3.127.138.57 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2025 10:36:53.958761930 CET | 1.1.1.1 | 192.168.2.7 | 0x56c2 | No error (0) | 18.157.68.73 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2025 10:37:54.452755928 CET | 1.1.1.1 | 192.168.2.7 | 0xd940 | No error (0) | 18.197.239.5 | A (IP address) | IN (0x0001) | false | ||
Jan 30, 2025 10:38:58.945949078 CET | 1.1.1.1 | 192.168.2.7 | 0xbcf6 | No error (0) | 18.192.93.86 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 04:35:15 |
Start date: | 30/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 04:35:15 |
Start date: | 30/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 04:35:18 |
Start date: | 30/01/2025 |
Path: | C:\Users\user\AppData\Local\Temp\tmpB20E.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0xf10000 |
File size: | 33'280 bytes |
MD5 hash: | F5302ED0307CE30D226D50A45A0DCA9D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | low |
Has exited: | false |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|