Windows
Analysis Report
Riko Ekos d.o.o. RFQ #PO51842018.xlsx
Overview
General Information
Detection
Score: | 64 |
Range: | 0 - 100 |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
EXCEL.EXE (PID: 6636 cmdline:
"C:\Progra m Files (x 86)\Micros oft Office \Root\Offi ce16\EXCEL .EXE" /aut omation -E mbedding MD5: 4A871771235598812032C822E6F68F19) splwow64.exe (PID: 3044 cmdline:
C:\Windows \splwow64. exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
INDICATOR_XML_LegacyDrawing_AutoLoad_Document | detects AutoLoad documents using LegacyDrawing | ditekSHen |
|
System Summary |
---|
Source: | Author: Christopher Peacock '@securepeacock', SCYTHE '@scythe_io', Florian Roth '@Neo23x0", Tim Shelton: |
Source: | Author: X__Junior (Nextron Systems): |
Timestamp | SID | Severity | Classtype | Source IP | Source Port | Destination IP | Destination Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-28T11:24:36.120269+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.7 | 49697 | 13.107.246.40 | 443 | TCP |
2025-03-28T11:24:42.001220+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.7 | 49698 | 13.107.246.40 | 443 | TCP |
2025-03-28T11:24:42.004085+0100 | 2028371 | 3 | Unknown Traffic | 192.168.2.7 | 49699 | 13.107.246.40 | 443 | TCP |
- • AV Detection
- • Compliance
- • Software Vulnerabilities
- • Networking
- • System Summary
- • Hooking and other Techniques for Hiding and Protection
- • Malware Analysis System Evasion
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | File opened: | Jump to behavior |
Source: | HTTPS traffic detected: |
Source: | DNS query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | JA3 fingerprint: |
Source: | Suricata IDS: | ||
Source: | Suricata IDS: | ||
Source: | Suricata IDS: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | HTTPS traffic detected: |
System Summary |
---|
Source: | Matched rule: |
Source: | Matched rule: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | OLE indicator, Workbook stream: |
Source: | File read: | Jump to behavior |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | Key opened: | Jump to behavior |
Source: | Static file information: |
Source: | File opened: | Jump to behavior |
Source: | Initial sample: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Window / User API: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 3 Exploitation for Client Execution | Path Interception | 1 Process Injection | 2 Masquerading | OS Credential Dumping | 1 Process Discovery | Remote Services | Data from Local System | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | Boot or Logon Initialization Scripts | 1 Virtualization/Sandbox Evasion | LSASS Memory | 1 Virtualization/Sandbox Evasion | Remote Desktop Protocol | Data from Removable Media | 2 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 1 Process Injection | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 3 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | Binary Padding | NTDS | 1 File and Directory Discovery | Distributed Component Object Model | Input Capture | 1 Ingress Tool Transfer | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 1 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
62% | Virustotal | Browse | ||
72% | ReversingLabs | Document-Office.Exploit.CVE-2017-11882 | ||
100% | Avira | EXP/CVE-2017-11882.Gen |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
s-part-0012.t-0009.t-msedge.net | 13.107.246.40 | true | false | high | |
bg.microsoft.map.fastly.net | 151.101.46.172 | true | false | high | |
s-0005.dual-s-msedge.net | 52.123.129.14 | true | false | high | |
otelrules.svc.static.microsoft | unknown | unknown | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
false | high | ||
false | high | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
13.107.246.40 | s-part-0012.t-0009.t-msedge.net | United States | 8068 | MICROSOFT-CORP-MSN-AS-BLOCKUS | false |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1651032 |
Start date and time: | 2025-03-28 11:22:26 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 43s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | defaultwindowsofficecookbook.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 134, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | Riko Ekos d.o.o. RFQ #PO51842018.xlsx |
Detection: | MAL |
Classification: | mal64.winXLSX@3/2@1/1 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis
(whitelisted): MpCmdRun.exe, d llhost.exe, sppsvc.exe, SIHCli ent.exe, SgrmBroker.exe, conho st.exe, svchost.exe - Excluded IPs from analysis (wh
itelisted): 52.109.0.91, 23.20 4.23.20, 52.109.8.36, 151.101. 46.172, 20.42.72.131, 52.123.1 29.14, 20.190.151.132, 4.175.8 7.197 - Excluded domains from analysis
(whitelisted): slscr.update.m icrosoft.com, fs-wildcard.micr osoft.com.edgekey.net, fs-wild card.microsoft.com.edgekey.net .globalredir.akadns.net, e1660 4.dscf.akamaiedge.net, roaming .officeapps.live.com, dual-s-0 005-office.config.skype.com, o siprod-cus-buff-azsc-000.centr alus.cloudapp.azure.com, login .live.com, wus-azsc-config.off iceapps.live.com, officeclient .microsoft.com, prod.fs.micros oft.com.akadns.net, c.pki.goog , wu-b-net.trafficmanager.net, ecs.office.com, self-events-d ata.trafficmanager.net, fs.mic rosoft.com, ctldl.windowsupdat e.com.delivery.microsoft.com, prod.configsvc1.live.com.akadn s.net, self.events.data.micros oft.com, ctldl.windowsupdate.c om, prod.roaming1.live.com.aka dns.net, cus-azsc-000.roaming. officeapps.live.com, fe3cr.del ivery.mp.microsoft.com, us1.ro aming1.live.com.akadns.net, co nfig.officeapps.live.com, us.c onfigsvc1.live.com.akadns.net, onedscolprdeus00.eastus.cloud app.azure.com, ecs.office.traf ficmanager.net - Not all processes where analyz
ed, report is missing behavior information - Report size getting too big, t
oo many NtCreateKey calls foun d. - Report size getting too big, t
oo many NtQueryAttributesFile calls found. - Report size getting too big, t
oo many NtQueryValueKey calls found. - Report size getting too big, t
oo many NtReadVirtualMemory ca lls found. - Some HTTPS proxied raw data pa
ckets have been limited to 10 per session. Please view the P CAPs for the complete data.
Time | Type | Description |
---|---|---|
06:24:30 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
13.107.246.40 | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
s-0005.dual-s-msedge.net | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
bg.microsoft.map.fastly.net | Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| |
Get hash | malicious | AsyncRAT, DcRat | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | HTMLPhisher, Invisible JS, Tycoon2FA | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | ScreenConnect Tool | Browse |
| ||
Get hash | malicious | Orcus | Browse |
| ||
Get hash | malicious | AgentTesla | Browse |
| ||
s-part-0012.t-0009.t-msedge.net | Get hash | malicious | HTMLPhisher | Browse |
| |
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | CAPTCHA Scam ClickFix | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
a0e9f5d64349fb13191bc781f81f42e1 | Get hash | malicious | Unknown | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
| ||
Get hash | malicious | LummaC Stealer | Browse |
|
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 118 |
Entropy (8bit): | 3.5700810731231707 |
Encrypted: | false |
SSDEEP: | 3:QaklTlAlXMLLmHlIlFLlmIK/5lTn84vlJlhlXlDHlA6l3l6Als:QFulcLk04/5p8GVz6QRq |
MD5: | 573220372DA4ED487441611079B623CD |
SHA1: | 8F9D967AC6EF34640F1F0845214FBC6994C0CB80 |
SHA-256: | BE84B842025E4241BFE0C9F7B8F86A322E4396D893EF87EA1E29C74F47B6A22D |
SHA-512: | F19FA3583668C3AF92A9CEF7010BD6ECEC7285F9C8665F2E9528DBA606F105D9AF9B1DB0CF6E7F77EF2E395943DC0D5CB37149E773319078688979E4024F9DD7 |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
File Type: | |
Category: | dropped |
Size (bytes): | 165 |
Entropy (8bit): | 1.7769794087092887 |
Encrypted: | false |
SSDEEP: | 3:iXKG/4N+RMlW8td:iXlMlW8/ |
MD5: | 37BD8218D560948827D3B948CAFA579C |
SHA1: | 24347FB0A66F2DA8AD3BAB818E3C24977104E5DA |
SHA-256: | 189E2D5600E0CC41F498D2EB22FA451F81746DCDBAA3EC1146A22C3A74452DA6 |
SHA-512: | A34D703FEBFD9E45A57BF047D9CCF890482B0F7CD3788F9BFD89DECA13B96DD4F43BDB0C4D81CC716DEAC37BCD1C393A7BCB159B471B5721B367E4884B17C699 |
Malicious: | true |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.998371707667736 |
TrID: |
|
File name: | Riko Ekos d.o.o. RFQ #PO51842018.xlsx |
File size: | 1'103'568 bytes |
MD5: | 2c265f3f5136de58896ec5bd9d814a5d |
SHA1: | 5930e285662ab9b3ae5228acb16802a9c1eb1bdd |
SHA256: | b6daa340200ee967ef4a7c2a2378014c978aa553ca4d6aa5cb6317ed049378b7 |
SHA512: | d2dd2208ee985527d29c101d6328c139d6cde1f847f18b4cb66c4631e510a9a9c114ea66c2aec543adf0b7c3e886bf4959eb4d7eede4c0079cbbfa8e05463cac |
SSDEEP: | 24576:R66CVMUqOytEFmXT0X7JvyTih0SinIEC7sKZA1r1r1si:lCVMxOytEFsTAJvyuaSECwwA1hr1si |
TLSH: | 623533C5E9BBB0B5CC0F823040E715754BBF6A6D43B13E92DF786848E67B99E8053258 |
File Content Preview: | PK.........YzZ.9......f.......[Content_Types].xmlUT......g...g...g.UKK.1.....%W..U..n{...A....d...&!.k...l.......lX..1..1..j.-!D.l..y.e`.S.....t..dYDa.0.B....xt|4|Z{...m,X...8...Z..y.43s..H.a....1.~.._p.,...&.6......d."...I...Gb..w....&.`.....h)....U?T{n6 |
Icon Hash: | 35e58a8c0c8a85b9 |
Document Type: | OpenXML |
Number of OLE Files: | 1 |
Has Summary Info: | |
Application Name: | |
Encrypted Document: | False |
Contains Word Document Stream: | False |
Contains Workbook/Book Stream: | True |
Contains PowerPoint Document Stream: | False |
Contains Visio Document Stream: | False |
Contains ObjectPool Stream: | False |
Flash Objects Count: | 0 |
Contains VBA Macros: | False |
Author: | |
Last Saved By: | |
Create Time: | 2022-11-18T02:05:27Z |
Last Saved Time: | 2022-11-18T02:07:12Z |
Creating Application: | |
Security: | 0 |
Thumbnail Scaling Desired: | false |
Contains Dirty Links: | false |
Shared Document: | false |
Changed Hyperlinks: | false |
Application Version: | 12.0000 |
General | |
Stream Path: | \x1ole10nAtIVe |
CLSID: | |
File Type: | data |
Stream Size: | 1316230 |
Entropy: | 7.120941598223329 |
Base64 Encoded: | True |
Data ASCII: | < . . Z " / . . . . 7 S . . . . } w 3 w l ; R . . 7 G - 0 G + . E . \\ 7 " . h W . } . p S O . 9 . ^ + [ b ^ q . . a = O _ n S " . . \\ . o . a . H % | ? . \\ . . H . O ) . : . ` i 7 { Y ? . S c h . [ ) 6 x x . ] . s ` R / 9 - : $ . 9 . K . . . { . . . 6 . . P . : . L . . . V . g B W . L ( Z x q % 3 z E . 8 O . k . . w } X t l c 0 . . c . . - q s . q . 0 . ] . | . > g E P . . . " _ x A . ) . K v H R B . + B W . l . V 4 . . . 4 t j ` 6 m G = . _ u . . T z 4 x n + \\ . . * . . . . . G . C a . . Z ' K X ] u V . |
Data Raw: | fa f2 3c 01 02 5a 22 2f 06 e0 01 08 af c5 be f1 37 53 f7 81 f6 cd 8a 16 f7 8b 06 8b 10 bb 7d f0 77 93 81 c3 33 77 ce 6c 8b 3b 52 ff d7 05 af 1d 37 47 2d 95 f3 30 47 ff e0 2b c9 0d 45 00 5c 37 22 b6 19 ff e2 68 57 c7 f3 a4 1a 7d 1a be c3 c1 70 dd e2 53 4f bd 2e e9 39 b1 f5 da 88 5e 2b 5b 62 bb 5e d6 71 de 09 a8 99 09 61 3d 9e fa 4f 5f 6e ba 53 22 8b 0d 07 cc 20 5c d6 aa 83 6f e2 a7 |
General | |
Stream Path: | QFsLkMXbXUscZMY3 |
CLSID: | |
File Type: | empty |
Stream Size: | 0 |
Entropy: | 0.0 |
Base64 Encoded: | False |
Data ASCII: | |
Data Raw: |
Download Network PCAP: filtered – full
Timestamp | SID | Signature | Severity | Source IP | Source Port | Dest IP | Dest Port | Protocol |
---|---|---|---|---|---|---|---|---|
2025-03-28T11:24:36.120269+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.7 | 49697 | 13.107.246.40 | 443 | TCP |
2025-03-28T11:24:42.001220+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.7 | 49698 | 13.107.246.40 | 443 | TCP |
2025-03-28T11:24:42.004085+0100 | 2028371 | ET JA3 Hash - Possible Malware - Fake Firefox Font Update | 3 | 192.168.2.7 | 49699 | 13.107.246.40 | 443 | TCP |
- Total Packets: 201
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 28, 2025 11:24:35.847431898 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:35.847469091 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:35.847577095 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:35.848088980 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:35.848098993 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.120204926 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.120269060 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.121984959 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.121993065 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.122623920 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.124052048 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.164263964 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.407840014 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.407869101 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.407885075 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.407948971 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.407977104 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.407993078 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.408029079 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.428812027 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.428844929 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.428919077 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.428932905 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.428981066 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.493107080 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.493134022 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.493244886 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.493271112 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.493334055 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.509376049 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.509423018 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.509501934 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.509522915 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.509551048 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.509577036 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.529340982 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.529369116 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.529412031 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.529437065 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.529464006 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.529483080 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.580418110 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.580449104 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.580543995 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.580552101 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.580591917 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.580599070 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.607505083 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.607528925 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.607584000 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.607592106 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.607635975 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.630611897 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.630636930 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.630688906 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.630696058 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.630754948 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.665868044 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.665904999 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.665949106 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.665960073 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.666007996 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.694140911 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.694169998 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.694259882 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.694267035 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.694331884 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.719944000 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.719974995 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.720010996 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.720037937 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.720065117 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.720083952 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.755790949 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.755821943 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.755883932 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.755892038 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.755934000 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.780899048 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.780920982 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.780963898 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.780968904 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.781027079 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.801862001 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.801884890 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.801933050 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.801955938 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.801980019 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.801995039 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.834516048 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.834537983 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.834573984 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.834583044 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.834621906 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.857701063 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.857722044 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.857801914 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.857808113 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.857836008 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.857855082 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.879688978 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.879709959 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.879744053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.879761934 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.879784107 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.879801989 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.902987957 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.903007030 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.903048992 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.903072119 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.903095961 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.903115988 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.933926105 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.933962107 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.934020996 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.934027910 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.934056044 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.934072971 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.958921909 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.958950043 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.959047079 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.959053993 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.959086895 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.981383085 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.981405020 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.981511116 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:36.981538057 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:36.981580019 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.005157948 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.005178928 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.005234003 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.005239964 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.005273104 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.005294085 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.030370951 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.030395985 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.030545950 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.030553102 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.030595064 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.051956892 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.051992893 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.052079916 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.052084923 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.052126884 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.074012995 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.074039936 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.074136972 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.074160099 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.074179888 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.074206114 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.096843958 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.096865892 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.096957922 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.096965075 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.097002983 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.121145964 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.121167898 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.121279955 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.121287107 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.121324062 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.142003059 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.142024040 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.142177105 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.142183065 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.142221928 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.159287930 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.159310102 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.159396887 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.159420013 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.159457922 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.187980890 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.188014030 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.188055992 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.188061953 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.188108921 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.209357977 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.209379911 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.209434986 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.209445953 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.209471941 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.209487915 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.227174997 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.227195978 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.227260113 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.227268934 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.227319002 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.227760077 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.245831966 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.245852947 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.245889902 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.245913982 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.245956898 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.246032953 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.262999058 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.263020992 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.263061047 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.263067007 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.263092995 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.263111115 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.288707972 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.288759947 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.288777113 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.288784981 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.288806915 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.288825989 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.308818102 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.308891058 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.308917046 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.308944941 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.308959007 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.308984995 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.327292919 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.327327013 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.327373028 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.327400923 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.327433109 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.327455044 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.348769903 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.348818064 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.348849058 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.348875046 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.348901987 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.348922968 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.368535995 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.368591070 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.368626118 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.368650913 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.368668079 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.368690014 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.390659094 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.390712023 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.390743971 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.390769958 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.390788078 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.390813112 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.404695034 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.404730082 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.404850006 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.404874086 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.404911995 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.424519062 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.424549103 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.424593925 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.424616098 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.424647093 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.424664974 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.441329956 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.441376925 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.441406965 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.441427946 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.441453934 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.441473007 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.460216999 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.460289001 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.460303068 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.460331917 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.460356951 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.460376024 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.480897903 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.480946064 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.481003046 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.481033087 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.481057882 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.481076956 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.497106075 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.497149944 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.497179985 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.497206926 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.497225046 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.497250080 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.511444092 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.511464119 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.511506081 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.511531115 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.511554003 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.511570930 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.529320955 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.529342890 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.529386997 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.529413939 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.529432058 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.529453993 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.549571991 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.549617052 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.549643040 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.549668074 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.549694061 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.549711943 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.569878101 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.569922924 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.569974899 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.570004940 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.570018053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.570175886 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.586391926 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.586436987 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.586544991 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.586544991 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.586572886 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.586626053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.603765965 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.603821993 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.603835106 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.603847027 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.603885889 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.603905916 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.615480900 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.615523100 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.615551949 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.615561008 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.615592003 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.615609884 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.634888887 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.634941101 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.634965897 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.634977102 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.635014057 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.635020971 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.653069019 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.653114080 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.653148890 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.653156996 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.653192043 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.653214931 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.667509079 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.667567968 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.667587996 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.667597055 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.667644978 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.684933901 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.684953928 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.684998035 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.685005903 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.685045958 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.698306084 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.698331118 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.698499918 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.698523045 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.698594093 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.717600107 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.717627048 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.717681885 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.717710018 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.717727900 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.717771053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.730536938 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.730565071 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.730614901 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.730622053 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.730673075 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.750634909 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.750654936 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.750778913 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.750780106 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.750802040 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.750854969 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.765183926 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.765201092 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.765294075 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.765302896 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.765352011 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.779597998 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.779613972 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.779720068 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.779743910 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.779807091 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.793926001 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.793955088 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.793996096 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.794003010 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.794044018 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.808613062 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.808631897 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.808698893 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.808706045 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.808747053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.830899000 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.830923080 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.830981016 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.830991983 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.831043959 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.843672037 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.843692064 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.843754053 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.843760967 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.843796015 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.855133057 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.855153084 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.855211973 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.855221987 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.855262995 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.857321978 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.857402086 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.857455015 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.857475996 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.857489109 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.857489109 CET | 49697 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:37.857496023 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:37.857503891 CET | 443 | 49697 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:41.731759071 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.731821060 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:41.731883049 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.732142925 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.732160091 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:41.732372999 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.732419014 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:41.732474089 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.732639074 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:41.732651949 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.000761032 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.001219988 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.001267910 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.002140045 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.002150059 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.003593922 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.004085064 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.004108906 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.005254984 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.005260944 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.174524069 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.174577951 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.174746990 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.174772024 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.175462008 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.175611019 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.175709009 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.175724983 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.175740957 CET | 49699 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.175745964 CET | 443 | 49699 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.190112114 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.190206051 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.190380096 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.191453934 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.191487074 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Mar 28, 2025 11:24:42.191504955 CET | 49698 | 443 | 192.168.2.7 | 13.107.246.40 |
Mar 28, 2025 11:24:42.191514015 CET | 443 | 49698 | 13.107.246.40 | 192.168.2.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Mar 28, 2025 11:24:05.162138939 CET | 53 | 55451 | 162.159.36.2 | 192.168.2.7 |
Mar 28, 2025 11:24:35.761569023 CET | 54314 | 53 | 192.168.2.7 | 1.1.1.1 |
Mar 28, 2025 11:24:35.846549988 CET | 53 | 54314 | 1.1.1.1 | 192.168.2.7 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Mar 28, 2025 11:24:35.761569023 CET | 192.168.2.7 | 1.1.1.1 | 0x37a1 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Mar 28, 2025 11:23:31.072367907 CET | 1.1.1.1 | 192.168.2.7 | 0xa45f | No error (0) | s-0005.dual-s-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 28, 2025 11:23:31.072367907 CET | 1.1.1.1 | 192.168.2.7 | 0xa45f | No error (0) | 52.123.129.14 | A (IP address) | IN (0x0001) | false | ||
Mar 28, 2025 11:23:31.072367907 CET | 1.1.1.1 | 192.168.2.7 | 0xa45f | No error (0) | 52.123.128.14 | A (IP address) | IN (0x0001) | false | ||
Mar 28, 2025 11:23:32.571656942 CET | 1.1.1.1 | 192.168.2.7 | 0xa970 | No error (0) | 151.101.46.172 | A (IP address) | IN (0x0001) | false | ||
Mar 28, 2025 11:24:35.846549988 CET | 1.1.1.1 | 192.168.2.7 | 0x37a1 | No error (0) | otelrules-bzhndjfje8dvh5fd.z01.azurefd.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 28, 2025 11:24:35.846549988 CET | 1.1.1.1 | 192.168.2.7 | 0x37a1 | No error (0) | star-azurefd-prod.trafficmanager.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 28, 2025 11:24:35.846549988 CET | 1.1.1.1 | 192.168.2.7 | 0x37a1 | No error (0) | shed.dual-low.s-part-0012.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 28, 2025 11:24:35.846549988 CET | 1.1.1.1 | 192.168.2.7 | 0x37a1 | No error (0) | s-part-0012.t-0009.t-msedge.net | CNAME (Canonical name) | IN (0x0001) | false | ||
Mar 28, 2025 11:24:35.846549988 CET | 1.1.1.1 | 192.168.2.7 | 0x37a1 | No error (0) | 13.107.246.40 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
0 | 192.168.2.7 | 49697 | 13.107.246.40 | 443 | 6636 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-28 10:24:36 UTC | 226 | OUT | |
2025-03-28 10:24:36 UTC | 500 | IN | |
2025-03-28 10:24:36 UTC | 15884 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN | |
2025-03-28 10:24:36 UTC | 16384 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
1 | 192.168.2.7 | 49698 | 13.107.246.40 | 443 | 6636 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-28 10:24:41 UTC | 214 | OUT | |
2025-03-28 10:24:42 UTC | 491 | IN | |
2025-03-28 10:24:42 UTC | 204 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | PID | Process |
---|---|---|---|---|---|---|
2 | 192.168.2.7 | 49699 | 13.107.246.40 | 443 | 6636 | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Timestamp | Bytes transferred | Direction | Data |
---|---|---|---|
2025-03-28 10:24:42 UTC | 214 | OUT | |
2025-03-28 10:24:42 UTC | 494 | IN | |
2025-03-28 10:24:42 UTC | 2128 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 06:23:26 |
Start date: | 28/03/2025 |
Path: | C:\Program Files (x86)\Microsoft Office\root\Office16\EXCEL.EXE |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xcd0000 |
File size: | 53'161'064 bytes |
MD5 hash: | 4A871771235598812032C822E6F68F19 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 06:24:30 |
Start date: | 28/03/2025 |
Path: | C:\Windows\splwow64.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff618760000 |
File size: | 163'840 bytes |
MD5 hash: | 77DE7761B037061C7C112FD3C5B91E73 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |