Windows Analysis Report dllhost.exe
Overview
General Information
Detection
Score: | 80 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
No configs have been found |
---|
Yara Overview |
---|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Nanominer | Yara detected Nanominer | Joe Security | ||
JoeSecurity_Nanominer | Yara detected Nanominer | Joe Security |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Nanominer | Yara detected Nanominer | Joe Security |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Machine Learning detection for sample | Show sources |
Source: | Joe Sandbox ML: |
Bitcoin Miner: |
---|
Yara detected Nanominer | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Found strings related to Crypto-Mining | Show sources |
Source: | String found in binary or memory: |
DNS related to crypt mining pools | Show sources |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Networking: |
---|
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | ASN Name: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | Network traffic detected: | ||
Source: | Network traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior | ||
Source: | Memory allocated: | Jump to behavior |
Source: | Process Stats: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | ||
Source: | Process created: |
Source: | Mutant created: |
Source: | Binary or memory string: |
Source: | File created: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Classification label: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | File created: | Jump to dropped file |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion: |
---|
Query firmware table information (likely to detect VMs) | Show sources |
Source: | System information queried: | Jump to behavior |
Tries to detect sandboxes / dynamic malware analysis system (registry check) | Show sources |
Source: | File opened: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior | ||
Source: | Registry key queried: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Anti Debugging: |
---|
Hides threads from debuggers | Show sources |
Source: | Thread information set: | Jump to behavior |
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior | ||
Source: | Process queried: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion: |
---|
System process connects to network (likely due to code injection or exploit) | Show sources |
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Network Connect: | Jump to behavior | ||
Source: | Network Connect: | Jump to behavior | ||
Source: | Domain query: | |||
Source: | Domain query: |
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Command and Scripting Interpreter2 | DLL Side-Loading1 | Process Injection11 | Virtualization/Sandbox Evasion23 | OS Credential Dumping | Security Software Discovery32 | Remote Services | Data from Local System | Exfiltration Over Other Network Medium | Encrypted Channel2 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | DLL Side-Loading1 | Process Injection11 | LSASS Memory | Virtualization/Sandbox Evasion23 | Remote Desktop Protocol | Data from Removable Media | Exfiltration Over Bluetooth | Non-Standard Port1 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | Software Packing2 | Security Account Manager | Process Discovery1 | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | Non-Application Layer Protocol1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | DLL Side-Loading1 | NTDS | Remote System Discovery1 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Application Layer Protocol2 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | System Information Discovery12 | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML |
Dropped Files |
---|
No Antivirus matches |
---|
Unpacked PE Files |
---|
No Antivirus matches |
---|
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
xmr-au1.nanopool.org | 139.99.156.30 | true | false | high | |
jp.moneroocean.stream | 18.180.72.219 | true | false | high | |
fr.moneroocean.stream | 195.201.124.214 | true | false | high | |
xmr-jp1.nanopool.org | 139.162.112.195 | true | false | high | |
us-va.moneroocean.stream | 18.210.126.40 | true | false | high | |
monerooceans.stream | 195.201.124.214 | true | true | unknown | |
fi.moneroocean.stream | 195.201.124.214 | true | false | high | |
xmr-eu1.nanopool.org | 185.71.66.31 | true | false | high | |
xmr-us-west1.nanopool.org | 45.76.65.223 | true | false | high | |
xmr-us-east1.nanopool.org | 192.99.69.170 | true | false | high | |
xmr-eu2.nanopool.org | 51.255.34.79 | true | false | high | |
us-or.moneroocean.stream | 54.188.223.206 | true | false | high | |
xmr.2miners.com | 51.89.96.41 | true | false | high | |
de.moneroocean.stream | 195.201.124.214 | true | false | high | |
us-oh.moneroocean.stream | 18.210.126.40 | true | false | high | |
proxycenter.geekgalaxy.com | 51.83.61.76 | true | true | unknown | |
sg.moneroocean.stream | 54.255.104.167 | true | false | high | |
xmr-asia1.nanopool.org | 139.99.102.73 | true | false | high | |
gulf.moneroocean.stream | unknown | unknown | false | high |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| low | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| low | ||
false |
| low |
Contacted IPs |
---|
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
Public |
---|
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
139.99.102.71 | unknown | Canada | 16276 | OVHFR | true | |
139.99.102.73 | xmr-asia1.nanopool.org | Canada | 16276 | OVHFR | false | |
18.180.72.219 | jp.moneroocean.stream | United States | 16509 | AMAZON-02US | false | |
51.15.54.102 | unknown | France | 12876 | OnlineSASFR | true | |
139.99.156.30 | xmr-au1.nanopool.org | Canada | 16276 | OVHFR | false | |
51.89.96.41 | xmr.2miners.com | France | 16276 | OVHFR | false | |
51.255.34.79 | xmr-eu2.nanopool.org | France | 16276 | OVHFR | false | |
54.255.104.167 | sg.moneroocean.stream | United States | 16509 | AMAZON-02US | false | |
18.210.126.40 | us-va.moneroocean.stream | United States | 14618 | AMAZON-AESUS | false | |
51.83.61.76 | proxycenter.geekgalaxy.com | France | 16276 | OVHFR | true | |
185.71.66.31 | xmr-eu1.nanopool.org | Russian Federation | 59796 | STORMSYSTEMS-ASRU | false | |
192.99.69.170 | xmr-us-east1.nanopool.org | Canada | 16276 | OVHFR | false | |
54.188.223.206 | us-or.moneroocean.stream | United States | 16509 | AMAZON-02US | false | |
207.246.100.198 | unknown | United States | 20473 | AS-CHOOPAUS | true | |
151.80.144.188 | unknown | Italy | 16276 | OVHFR | true | |
139.162.112.195 | xmr-jp1.nanopool.org | Netherlands | 63949 | LINODE-APLinodeLLCUS | false | |
195.201.124.214 | fr.moneroocean.stream | Germany | 24940 | HETZNER-ASDE | false | |
45.76.65.223 | xmr-us-west1.nanopool.org | United States | 20473 | AS-CHOOPAUS | false |
Private |
---|
IP |
---|
192.168.2.1 |
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 486542 |
Start date: | 20.09.2021 |
Start time: | 16:15:57 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 7m 32s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | dllhost.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal80.evad.mine.winEXE@2/1@37/19 |
EGA Information: | Failed |
HDC Information: | Failed |
HCA Information: | Failed |
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
16:17:53 | API Interceptor |
Joe Sandbox View / Context |
---|
IPs |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
139.99.102.73 | Get hash | malicious | Browse | ||
51.15.54.102 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
139.99.156.30 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
51.89.96.41 | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Domains |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
xmr-eu1.nanopool.org | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
xmr-au1.nanopool.org | Get hash | malicious | Browse |
| |
monerooceans.stream | Get hash | malicious | Browse |
|
ASN |
---|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
OVHFR | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
OVHFR | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
JA3 Fingerprints |
---|
No context |
---|
Dropped Files |
---|
No context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\Desktop\dllhost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10752 |
Entropy (8bit): | 1.8790345847683234 |
Encrypted: | false |
SSDEEP: | 48:aOyTG0Cfj3gFu/+LIa0Wh4PYCvo+ocjpaRuqSx:xIG3jr+Ud3Q+f6x |
MD5: | 4D2FFA82BEB49D0C5DC38B4C9107277F |
SHA1: | CB73EE2A22C8B0D732D872B7C0D401790D6B9F99 |
SHA-256: | 9BE643CC30F84C35739966E8907866CD7323097610275A534E0A14CE993EA89C |
SHA-512: | 5F5808FB596DA4F9F9FFCBF622A1F0FD8F03D548A94F344D6FDE231027934F88ABB07A5529A85042FF6BD519FEB857E452F885853558568612A75973628FE8A3 |
Malicious: | false |
Reputation: | low |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 7.5724463090507035 |
TrID: |
|
File name: | dllhost.exe |
File size: | 67306240 |
MD5: | fb4c1f5ec7701209f0a1dcd0726dc403 |
SHA1: | fed324a956bb72fc10928806d887ecd4556a1f3a |
SHA256: | e75d883d14ab80d900fc21bd6ea9bc3bafc77f7fd31ddf66fa715833e71e8013 |
SHA512: | 93975c2ee0e6f6e3180ed2ca4e02ad9efa955a8371aca34378855d92a31e442867d2b3e74a0596e556aedb391df1faa0b0ec70b48c91b82132378e764f29364c |
SSDEEP: | 786432:JzWoUGA77p/YwHBl3o5VbfF3ymyo+JazDxfmwW8XuHNgxQy5D:JqyoBlYFUmyjufm18XuHWH |
File Content Preview: | MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$.......|G..8&..8&..8&..cN..p&..cN..&&..cN...&..jN..1&..jN...&..jN...&..1^:.9&..cN..3&..8&..''....p.9&....q.7&...O..:&...O..*&...O..N'. |
File Icon |
---|
Icon Hash: | f0d0a2f071b2cce8 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x143b94c3c |
Entrypoint Section: | .themida |
Digitally signed: | false |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | TERMINAL_SERVER_AWARE, DYNAMIC_BASE, HIGH_ENTROPY_VA |
Time Stamp: | 0x613A5D1E [Thu Sep 9 19:14:38 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | ea0f3ee678ff96b92572b920efa689ea |
Entrypoint Preview |
---|
Instruction |
---|
push ebp |
jmp 00007FCBDCD15F20h |
pop ebp |
jmp 00007FCBDCCC8DD5h |
fisttp qword ptr [esi] |
add byte ptr [eax], al |
add dl, cl |
add byte ptr [edx-07B510CAh], bh |
mov dl, EDh |
xchg eax, ebx |
cmpsd |
or eax, dword ptr [bx+si] |
retf E800h |
out dx, eax |
mov cl, byte ptr [ecx-66C8ABF6h] |
push ebx |
and al, 9Fh |
scasd |
test al, 19h |
sbb al, FBh |
call far E900h : 04C795E9h |
loopne 00007FCBDCCB49B2h |
or byte ptr [eax], al |
jmp 00007FCBDB4B9E8Bh |
jmp 00007FCBDCC9117Fh |
test al, 0Eh |
add byte ptr [eax], al |
add dl, cl |
add al, bh |
out dx, eax |
in al, 50h |
jmp 00007FCBDCCB4989h |
pop esi |
bound esi, dword ptr [ecx+09h] |
add dl, cl |
add byte ptr [ecx+37h], ch |
out dx, eax |
test dword ptr [ebx-3B30FB43h], esp |
add al, E1h |
jnbe 00007FCBDCCB4952h |
pop ebx |
test cl, cl |
inc ebp |
add dword ptr [ebx], ebp |
and al, B0h |
and dword ptr [eax+01h], ebp |
popad |
add byte ptr [esi], cl |
add byte ptr [eax], al |
add byte ptr [ebp+01h], al |
scasd |
inc edi |
daa |
inc ebp |
add dword ptr [eax], 8BC70061h |
Rich Headers |
---|
Programming Language: |
|
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x2352000 | 0x58 | .edata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x23530a1 | 0xd0 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x233a000 | 0x14f3e | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x40186ac | 0x13788 | .themida |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x403f000 | 0x10 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x2356018 | 0x28 | .tls |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x26eb5c | 0x80 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x1e4093 | 0x1e4200 | False | 0.445640794442 | zlib compressed data | 6.39722119727 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.rdata | 0x1e6000 | 0x8a9b4 | 0x8aa00 | False | 0.37196200124 | data | 5.01719863353 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x271000 | 0x920864 | 0x917400 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.pdata | 0xb92000 | 0x13764 | 0x13800 | False | 0.481733273237 | data | 6.15140087656 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
_RANDOMX | 0xba6000 | 0x556 | 0x600 | False | 0.529947916667 | data | 5.49170654418 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
__nv_mod | 0xba7000 | 0x1b4 | 0x200 | False | 0.265625 | data | 4.16935929547 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
__nv_rel | 0xba8000 | 0x810f88 | 0x811000 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.nvFatBi | 0x13b9000 | 0x90 | 0x200 | False | 0.150390625 | data | 1.20360561451 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.nv_fatb | 0x13ba000 | 0xf7fc30 | 0xf7fe00 | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rsrc | 0x233a000 | 0x14f3e | 0x15000 | False | 0.427722749256 | data | 5.50361278507 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x234f000 | 0x2ff0 | 0x3000 | False | 0.288004557292 | data | 5.45803574263 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.edata | 0x2352000 | 0x1000 | 0x200 | False | 0.1640625 | data | 1.16110503859 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.idata | 0x2353000 | 0x1000 | 0x200 | False | 0.37109375 | data | 2.9470966786 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.tls | 0x2354000 | 0x3000 | 0x2200 | False | 0.00735294117647 | data | 0.0248387677496 | IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.themida | 0x2357000 | 0x1ce8000 | 0x1ce8000 | unknown | unknown | unknown | unknown | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.reloc | 0x403f000 | 0x1000 | 0x10 | False | 1.5 | GLS_BINARY_LSB_FIRST | 2.73345859334 | IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x233a27c | 0xea8 | data | Portuguese | Brazil |
RT_ICON | 0x233b124 | 0x568 | GLS_BINARY_LSB_FIRST | Portuguese | Brazil |
RT_ICON | 0x233b68c | 0xca8 | dBase IV DBT of @.DBF, block length 3072, next free block index 40, next free block 145, next used block 0 | Portuguese | Brazil |
RT_ICON | 0x233c334 | 0x368 | GLS_BINARY_LSB_FIRST | Portuguese | Brazil |
RT_ICON | 0x233c69c | 0x10828 | dBase IV DBT, blocks size 0, block length 2048, next free block index 40, next free block 0, next used block 0 | Portuguese | Brazil |
RT_ICON | 0x234cec4 | 0x10a8 | data | Portuguese | Brazil |
RT_ICON | 0x234df6c | 0x468 | GLS_BINARY_LSB_FIRST | Portuguese | Brazil |
RT_GROUP_ICON | 0x234e3d4 | 0x68 | data | Portuguese | Brazil |
RT_VERSION | 0x234e43c | 0x388 | data | English | United States |
RT_VERSION | 0x234e7c4 | 0x290 | MS Windows COFF PA-RISC object file | Portuguese | Brazil |
RT_MANIFEST | 0x234ea54 | 0x4ea | XML 1.0 document, ASCII text, with CRLF line terminators | Portuguese | Brazil |
Imports |
---|
DLL | Import |
---|---|
kernel32.dll | GetModuleHandleA |
IPHLPAPI.DLL | GetAdaptersInfo |
SHELL32.dll | CommandLineToArgvW |
ADVAPI32.dll | LookupPrivilegeValueA |
dbghelp.dll | ImageNtHeader |
Exports |
---|
Name | Ordinal | Address |
---|---|---|
NvOptimusEnablementCuda | 1 | 0x140b7f89c |
Version Infos |
---|
Description | Data |
---|---|
LegalCopyright | Microsoft Corporation. All rights reserved. |
InternalName | dllhost.exe |
FileVersion | 10.0.19041.546 (WinBuild.160101.0800) |
CompanyName | Microsoft Corporation |
ProductName | Microsoft Windows Operating System |
ProductVersion | 10.0.19041.546 |
FileDescription | COM Surrogate |
OriginalFilename | dllhost.exe |
Translation | 0x0409 0x04b0 |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
Portuguese | Brazil | |
English | United States |
Network Behavior |
---|
Snort IDS Alerts |
---|
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
09/20/21-16:17:52.074810 | UDP | 254 | DNS SPOOF query response with TTL of 1 min. and no authority | 53 | 62208 | 8.8.8.8 | 192.168.2.6 |
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 20, 2021 16:17:51.975172997 CEST | 49761 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:51.978549957 CEST | 49762 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:52.049310923 CEST | 49763 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.049324989 CEST | 49764 | 14444 | 192.168.2.6 | 139.99.102.73 |
Sep 20, 2021 16:17:52.068898916 CEST | 2222 | 49763 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.069183111 CEST | 49763 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.086744070 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.086832047 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.086872101 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.087775946 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.090205908 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.111386061 CEST | 49768 | 14444 | 192.168.2.6 | 51.255.34.79 |
Sep 20, 2021 16:17:52.114509106 CEST | 8080 | 49766 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.114775896 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.116662025 CEST | 80 | 49767 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.118068933 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.126249075 CEST | 49769 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.130592108 CEST | 49770 | 14444 | 192.168.2.6 | 185.71.66.31 |
Sep 20, 2021 16:17:52.134838104 CEST | 10128 | 49761 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.135106087 CEST | 49761 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.137572050 CEST | 14444 | 49768 | 51.255.34.79 | 192.168.2.6 |
Sep 20, 2021 16:17:52.141011953 CEST | 49768 | 14444 | 192.168.2.6 | 51.255.34.79 |
Sep 20, 2021 16:17:52.146661997 CEST | 49771 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:52.147989035 CEST | 10128 | 49769 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.148165941 CEST | 49769 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.153719902 CEST | 49772 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.166229010 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.166245937 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.167704105 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.167712927 CEST | 49763 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.168682098 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.172578096 CEST | 49769 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.172616005 CEST | 49768 | 14444 | 192.168.2.6 | 51.255.34.79 |
Sep 20, 2021 16:17:52.173711061 CEST | 49773 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.173798084 CEST | 49761 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.175466061 CEST | 49774 | 14444 | 192.168.2.6 | 45.76.65.223 |
Sep 20, 2021 16:17:52.175916910 CEST | 10128 | 49772 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.177424908 CEST | 49772 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.183340073 CEST | 49772 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.187194109 CEST | 49775 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.187593937 CEST | 2222 | 49763 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.187657118 CEST | 2222 | 49763 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.188143969 CEST | 49763 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.188164949 CEST | 49763 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.192534924 CEST | 14444 | 49770 | 185.71.66.31 | 192.168.2.6 |
Sep 20, 2021 16:17:52.194190979 CEST | 10128 | 49769 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.194420099 CEST | 49770 | 14444 | 192.168.2.6 | 185.71.66.31 |
Sep 20, 2021 16:17:52.194858074 CEST | 10128 | 49769 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.195213079 CEST | 49769 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.198206902 CEST | 49769 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.198971987 CEST | 14444 | 49768 | 51.255.34.79 | 192.168.2.6 |
Sep 20, 2021 16:17:52.199393988 CEST | 14444 | 49768 | 51.255.34.79 | 192.168.2.6 |
Sep 20, 2021 16:17:52.199449062 CEST | 80 | 49767 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.199502945 CEST | 49768 | 14444 | 192.168.2.6 | 51.255.34.79 |
Sep 20, 2021 16:17:52.200062037 CEST | 49768 | 14444 | 192.168.2.6 | 51.255.34.79 |
Sep 20, 2021 16:17:52.200516939 CEST | 8080 | 49766 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.202172995 CEST | 49770 | 14444 | 192.168.2.6 | 185.71.66.31 |
Sep 20, 2021 16:17:52.204440117 CEST | 49776 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.205497980 CEST | 10128 | 49772 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.205558062 CEST | 49777 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.206331968 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.206376076 CEST | 10128 | 49772 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.206515074 CEST | 49772 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.207071066 CEST | 49772 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.207072973 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.207149029 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.207561970 CEST | 2222 | 49763 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.208699942 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.208756924 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.209013939 CEST | 10128 | 49775 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.210094929 CEST | 49775 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.210190058 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.220017910 CEST | 10128 | 49769 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.221375942 CEST | 49775 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.224356890 CEST | 49779 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.224435091 CEST | 49778 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.225281954 CEST | 49780 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.226279974 CEST | 14444 | 49768 | 51.255.34.79 | 192.168.2.6 |
Sep 20, 2021 16:17:52.229187012 CEST | 10128 | 49772 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.229218006 CEST | 14444 | 49764 | 139.99.102.73 | 192.168.2.6 |
Sep 20, 2021 16:17:52.229754925 CEST | 49764 | 14444 | 192.168.2.6 | 139.99.102.73 |
Sep 20, 2021 16:17:52.232741117 CEST | 80 | 49767 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.232767105 CEST | 49781 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.232872963 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.233757973 CEST | 8080 | 49766 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.233922958 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.235079050 CEST | 80 | 49767 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.235101938 CEST | 80 | 49767 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.235131025 CEST | 49764 | 14444 | 192.168.2.6 | 139.99.102.73 |
Sep 20, 2021 16:17:52.235227108 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.235249043 CEST | 49767 | 80 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.236968040 CEST | 8080 | 49766 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.236998081 CEST | 8080 | 49766 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.237162113 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.237180948 CEST | 49766 | 8080 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.237900972 CEST | 14444 | 49762 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:52.238235950 CEST | 49762 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:52.238792896 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.242317915 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.242336988 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.243508101 CEST | 10128 | 49775 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.244020939 CEST | 10128 | 49775 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.244956970 CEST | 49775 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.245910883 CEST | 10128 | 49779 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.246037960 CEST | 49779 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.251852989 CEST | 2222 | 49781 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.252038956 CEST | 49781 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.257118940 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.257134914 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.257560968 CEST | 49775 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.257678986 CEST | 14444 | 49770 | 185.71.66.31 | 192.168.2.6 |
Sep 20, 2021 16:17:52.259309053 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.259576082 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.260845900 CEST | 49762 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:52.265121937 CEST | 49779 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.265242100 CEST | 49781 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.265364885 CEST | 14444 | 49770 | 185.71.66.31 | 192.168.2.6 |
Sep 20, 2021 16:17:52.279531956 CEST | 10128 | 49775 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.281836033 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.282038927 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.282147884 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.282161951 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.282830954 CEST | 443 | 49765 | 51.83.61.76 | 192.168.2.6 |
Sep 20, 2021 16:17:52.282902956 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.283169985 CEST | 49765 | 443 | 192.168.2.6 | 51.83.61.76 |
Sep 20, 2021 16:17:52.286276102 CEST | 2222 | 49781 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:52.286468029 CEST | 49781 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:52.286716938 CEST | 10128 | 49779 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.287332058 CEST | 10128 | 49779 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.287420988 CEST | 49779 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.296134949 CEST | 49782 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.298305035 CEST | 49783 | 14444 | 192.168.2.6 | 151.80.144.188 |
Sep 20, 2021 16:17:52.304402113 CEST | 49779 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.313348055 CEST | 14444 | 49777 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.313417912 CEST | 10128 | 49773 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.313559055 CEST | 49777 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.313559055 CEST | 49773 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.318506002 CEST | 10128 | 49782 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.319176912 CEST | 49782 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.325891018 CEST | 10128 | 49779 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.327039957 CEST | 14444 | 49783 | 151.80.144.188 | 192.168.2.6 |
Sep 20, 2021 16:17:52.327253103 CEST | 49783 | 14444 | 192.168.2.6 | 151.80.144.188 |
Sep 20, 2021 16:17:52.333321095 CEST | 49784 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.335067034 CEST | 10128 | 49761 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.335099936 CEST | 10128 | 49761 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.335496902 CEST | 49761 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.336318016 CEST | 14444 | 49774 | 45.76.65.223 | 192.168.2.6 |
Sep 20, 2021 16:17:52.337923050 CEST | 49761 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.337927103 CEST | 49774 | 14444 | 192.168.2.6 | 45.76.65.223 |
Sep 20, 2021 16:17:52.340151072 CEST | 49782 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.340675116 CEST | 49773 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.340852976 CEST | 49777 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.342833042 CEST | 10128 | 49776 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.343097925 CEST | 49776 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.345938921 CEST | 49785 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.347137928 CEST | 49786 | 14444 | 192.168.2.6 | 51.15.54.102 |
Sep 20, 2021 16:17:52.355365992 CEST | 10128 | 49784 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.356369972 CEST | 49784 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.362566948 CEST | 10128 | 49782 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.363282919 CEST | 49782 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.367899895 CEST | 10128 | 49785 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.368748903 CEST | 49785 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.391992092 CEST | 14444 | 49786 | 51.15.54.102 | 192.168.2.6 |
Sep 20, 2021 16:17:52.392168045 CEST | 49786 | 14444 | 192.168.2.6 | 51.15.54.102 |
Sep 20, 2021 16:17:52.408998966 CEST | 10128 | 49780 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:52.409193993 CEST | 49780 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.413172007 CEST | 14444 | 49764 | 139.99.102.73 | 192.168.2.6 |
Sep 20, 2021 16:17:52.416878939 CEST | 14444 | 49771 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:52.417114019 CEST | 49771 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:52.445516109 CEST | 14444 | 49777 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.478595972 CEST | 10128 | 49778 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:52.478776932 CEST | 49778 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.479053974 CEST | 10128 | 49773 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.479249954 CEST | 10128 | 49773 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.481148005 CEST | 49773 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.497462988 CEST | 10128 | 49761 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.500452995 CEST | 49773 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.504730940 CEST | 49783 | 14444 | 192.168.2.6 | 151.80.144.188 |
Sep 20, 2021 16:17:52.520884037 CEST | 14444 | 49762 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:52.534373045 CEST | 14444 | 49783 | 151.80.144.188 | 192.168.2.6 |
Sep 20, 2021 16:17:52.538832903 CEST | 49783 | 14444 | 192.168.2.6 | 151.80.144.188 |
Sep 20, 2021 16:17:52.544931889 CEST | 49774 | 14444 | 192.168.2.6 | 45.76.65.223 |
Sep 20, 2021 16:17:52.552155972 CEST | 49784 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.553210974 CEST | 49785 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.553215981 CEST | 49776 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.553536892 CEST | 49786 | 14444 | 192.168.2.6 | 51.15.54.102 |
Sep 20, 2021 16:17:52.554349899 CEST | 49780 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.560213089 CEST | 49778 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.561534882 CEST | 49771 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:52.573821068 CEST | 14444 | 49777 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.573916912 CEST | 49777 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.574265003 CEST | 10128 | 49784 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.574376106 CEST | 49784 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.575391054 CEST | 10128 | 49785 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.575488091 CEST | 49785 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.576670885 CEST | 49777 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.586025953 CEST | 49787 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.603434086 CEST | 14444 | 49786 | 51.15.54.102 | 192.168.2.6 |
Sep 20, 2021 16:17:52.604995012 CEST | 49788 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.607436895 CEST | 14444 | 49786 | 51.15.54.102 | 192.168.2.6 |
Sep 20, 2021 16:17:52.607533932 CEST | 49786 | 14444 | 192.168.2.6 | 51.15.54.102 |
Sep 20, 2021 16:17:52.608247042 CEST | 10128 | 49787 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.608385086 CEST | 49787 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.614157915 CEST | 49787 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.621543884 CEST | 49789 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.624202013 CEST | 49790 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.636483908 CEST | 10128 | 49787 | 195.201.124.214 | 192.168.2.6 |
Sep 20, 2021 16:17:52.636687994 CEST | 49787 | 10128 | 192.168.2.6 | 195.201.124.214 |
Sep 20, 2021 16:17:52.639036894 CEST | 10128 | 49773 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.681196928 CEST | 14444 | 49777 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.691720963 CEST | 10128 | 49776 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.691771984 CEST | 10128 | 49776 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.691895962 CEST | 49776 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.693979979 CEST | 49776 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.705698967 CEST | 14444 | 49774 | 45.76.65.223 | 192.168.2.6 |
Sep 20, 2021 16:17:52.711085081 CEST | 14444 | 49764 | 139.99.102.73 | 192.168.2.6 |
Sep 20, 2021 16:17:52.711220980 CEST | 49764 | 14444 | 192.168.2.6 | 139.99.102.73 |
Sep 20, 2021 16:17:52.711536884 CEST | 49764 | 14444 | 192.168.2.6 | 139.99.102.73 |
Sep 20, 2021 16:17:52.720571041 CEST | 49791 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.736377001 CEST | 14444 | 49790 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.736572027 CEST | 49790 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.737924099 CEST | 10128 | 49780 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:52.738282919 CEST | 10128 | 49780 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:52.738415956 CEST | 49780 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.739923000 CEST | 49780 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.761229038 CEST | 10128 | 49789 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.767771006 CEST | 10128 | 49788 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.768254042 CEST | 49789 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.768265963 CEST | 49788 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.789037943 CEST | 49790 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.790163040 CEST | 49789 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.792912006 CEST | 49792 | 14444 | 192.168.2.6 | 139.99.102.71 |
Sep 20, 2021 16:17:52.793332100 CEST | 49788 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.811856031 CEST | 10128 | 49778 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:52.814977884 CEST | 10128 | 49778 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:52.815205097 CEST | 49778 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.817315102 CEST | 49778 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.829108953 CEST | 14444 | 49771 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:52.833894014 CEST | 10128 | 49776 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.834604979 CEST | 49793 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:52.844989061 CEST | 14444 | 49774 | 45.76.65.223 | 192.168.2.6 |
Sep 20, 2021 16:17:52.845083952 CEST | 49774 | 14444 | 192.168.2.6 | 45.76.65.223 |
Sep 20, 2021 16:17:52.848684072 CEST | 49774 | 14444 | 192.168.2.6 | 45.76.65.223 |
Sep 20, 2021 16:17:52.860451937 CEST | 10128 | 49791 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.860632896 CEST | 49791 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.890803099 CEST | 14444 | 49764 | 139.99.102.73 | 192.168.2.6 |
Sep 20, 2021 16:17:52.900564909 CEST | 14444 | 49790 | 192.99.69.170 | 192.168.2.6 |
Sep 20, 2021 16:17:52.900692940 CEST | 49790 | 14444 | 192.168.2.6 | 192.99.69.170 |
Sep 20, 2021 16:17:52.923387051 CEST | 10128 | 49780 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:52.928874969 CEST | 10128 | 49789 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:52.929052114 CEST | 49789 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.932750940 CEST | 49791 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:52.945130110 CEST | 49794 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:52.955575943 CEST | 10128 | 49788 | 54.255.104.167 | 192.168.2.6 |
Sep 20, 2021 16:17:52.955672026 CEST | 49788 | 10128 | 192.168.2.6 | 54.255.104.167 |
Sep 20, 2021 16:17:52.970412016 CEST | 14444 | 49792 | 139.99.102.71 | 192.168.2.6 |
Sep 20, 2021 16:17:52.970623970 CEST | 49792 | 14444 | 192.168.2.6 | 139.99.102.71 |
Sep 20, 2021 16:17:52.972738981 CEST | 49792 | 14444 | 192.168.2.6 | 139.99.102.71 |
Sep 20, 2021 16:17:52.974052906 CEST | 49795 | 14444 | 192.168.2.6 | 207.246.100.198 |
Sep 20, 2021 16:17:53.003247023 CEST | 14444 | 49762 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:53.003439903 CEST | 49762 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.004786968 CEST | 49762 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.009660006 CEST | 14444 | 49774 | 45.76.65.223 | 192.168.2.6 |
Sep 20, 2021 16:17:53.011285067 CEST | 10128 | 49793 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:53.014724016 CEST | 49793 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:53.027707100 CEST | 49793 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:53.036449909 CEST | 49796 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.069094896 CEST | 10128 | 49778 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:53.072335958 CEST | 10128 | 49791 | 18.210.126.40 | 192.168.2.6 |
Sep 20, 2021 16:17:53.072487116 CEST | 49791 | 10128 | 192.168.2.6 | 18.210.126.40 |
Sep 20, 2021 16:17:53.143088102 CEST | 14444 | 49795 | 207.246.100.198 | 192.168.2.6 |
Sep 20, 2021 16:17:53.143183947 CEST | 49795 | 14444 | 192.168.2.6 | 207.246.100.198 |
Sep 20, 2021 16:17:53.143737078 CEST | 49795 | 14444 | 192.168.2.6 | 207.246.100.198 |
Sep 20, 2021 16:17:53.150230885 CEST | 14444 | 49792 | 139.99.102.71 | 192.168.2.6 |
Sep 20, 2021 16:17:53.150669098 CEST | 49792 | 14444 | 192.168.2.6 | 139.99.102.71 |
Sep 20, 2021 16:17:53.161814928 CEST | 14444 | 49771 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:53.161936045 CEST | 49771 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.176122904 CEST | 49771 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.192399025 CEST | 10128 | 49794 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:53.192560911 CEST | 49794 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:53.195945024 CEST | 49794 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:53.207277060 CEST | 10128 | 49793 | 54.188.223.206 | 192.168.2.6 |
Sep 20, 2021 16:17:53.207432985 CEST | 49793 | 10128 | 192.168.2.6 | 54.188.223.206 |
Sep 20, 2021 16:17:53.216011047 CEST | 49797 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.283715963 CEST | 14444 | 49762 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:53.314872980 CEST | 14444 | 49795 | 207.246.100.198 | 192.168.2.6 |
Sep 20, 2021 16:17:53.316987038 CEST | 49795 | 14444 | 192.168.2.6 | 207.246.100.198 |
Sep 20, 2021 16:17:53.364274025 CEST | 14444 | 49796 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:53.364491940 CEST | 49796 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.373915911 CEST | 49796 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.443991899 CEST | 10128 | 49794 | 18.180.72.219 | 192.168.2.6 |
Sep 20, 2021 16:17:53.444020987 CEST | 14444 | 49771 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:53.444216967 CEST | 49794 | 10128 | 192.168.2.6 | 18.180.72.219 |
Sep 20, 2021 16:17:53.485385895 CEST | 14444 | 49797 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:53.485847950 CEST | 49797 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.498188019 CEST | 49797 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.644325018 CEST | 14444 | 49796 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:53.710896015 CEST | 14444 | 49796 | 139.162.112.195 | 192.168.2.6 |
Sep 20, 2021 16:17:53.711175919 CEST | 49796 | 14444 | 192.168.2.6 | 139.162.112.195 |
Sep 20, 2021 16:17:53.763684988 CEST | 49798 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.767709017 CEST | 14444 | 49797 | 139.99.156.30 | 192.168.2.6 |
Sep 20, 2021 16:17:53.771138906 CEST | 49797 | 14444 | 192.168.2.6 | 139.99.156.30 |
Sep 20, 2021 16:17:53.834419012 CEST | 2222 | 49798 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.834613085 CEST | 49798 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.835741043 CEST | 49798 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.856431007 CEST | 2222 | 49798 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.856477022 CEST | 2222 | 49798 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.856547117 CEST | 49798 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.857264042 CEST | 49798 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.858444929 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.883502007 CEST | 2222 | 49798 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.883536100 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.883824110 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.891510010 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:17:53.961555004 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:53.961602926 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:17:54.108755112 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:09.006793022 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:09.031537056 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:24.075234890 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:24.075387001 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:24.095772028 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:24.114953995 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:39.174562931 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:39.174747944 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:39.196208954 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:39.215625048 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:42.069931984 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:18:42.211564064 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:57.097727060 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:18:57.116755962 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:12.198472977 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:12.198647022 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:12.200865984 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:12.219885111 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:27.302557945 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:27.302675009 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:27.311629057 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:27.330636978 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:42.408170938 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:42.408369064 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:42.416271925 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:42.440712929 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:44.489917994 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:44.508955002 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:44.515300989 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:19:44.614588976 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:59.717089891 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:19:59.738501072 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
Sep 20, 2021 16:20:14.834855080 CEST | 49799 | 2222 | 192.168.2.6 | 51.89.96.41 |
Sep 20, 2021 16:20:14.860850096 CEST | 2222 | 49799 | 51.89.96.41 | 192.168.2.6 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 20, 2021 16:16:52.690994024 CEST | 51774 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:52.716610909 CEST | 53 | 51774 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:53.202148914 CEST | 56023 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:53.221410036 CEST | 53 | 56023 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:53.882023096 CEST | 58384 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:53.908582926 CEST | 53 | 58384 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:54.443977118 CEST | 60261 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:54.466253042 CEST | 53 | 60261 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:55.081995964 CEST | 56061 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:55.101425886 CEST | 53 | 56061 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:55.120183945 CEST | 58336 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:55.139838934 CEST | 53 | 58336 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:55.738073111 CEST | 53781 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:55.762558937 CEST | 53 | 53781 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:56.322972059 CEST | 54064 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:56.340677023 CEST | 53 | 54064 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:56.789344072 CEST | 52811 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:56.809426069 CEST | 53 | 52811 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:57.846765041 CEST | 55299 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:57.865994930 CEST | 53 | 55299 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:58.355138063 CEST | 63745 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:58.379867077 CEST | 53 | 63745 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:59.004910946 CEST | 50055 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:59.023938894 CEST | 53 | 50055 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:16:59.559504986 CEST | 61374 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:16:59.580396891 CEST | 53 | 61374 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:00.161885977 CEST | 50339 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:00.183552980 CEST | 53 | 50339 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:00.712143898 CEST | 63307 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:00.731367111 CEST | 53 | 63307 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:01.225557089 CEST | 49694 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:01.244127035 CEST | 53 | 49694 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:04.723160028 CEST | 54982 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:04.742355108 CEST | 53 | 54982 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:29.368942976 CEST | 50010 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:29.388577938 CEST | 53 | 50010 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:51.903198957 CEST | 63718 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:51.934108973 CEST | 53 | 63718 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:51.947235107 CEST | 62116 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:51.969907999 CEST | 53 | 62116 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:51.994895935 CEST | 63816 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.003196001 CEST | 55014 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.018109083 CEST | 53 | 63816 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.025985956 CEST | 53 | 55014 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.051062107 CEST | 62208 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.070298910 CEST | 57574 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.074810028 CEST | 53 | 62208 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.077537060 CEST | 51818 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.086899042 CEST | 56628 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.092935085 CEST | 53 | 57574 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.097189903 CEST | 60778 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.104028940 CEST | 53 | 51818 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.110338926 CEST | 53 | 56628 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.111187935 CEST | 53799 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.119496107 CEST | 53 | 60778 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.126595020 CEST | 54683 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.136374950 CEST | 59329 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.137234926 CEST | 53 | 53799 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.150861025 CEST | 64021 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.153669119 CEST | 53 | 54683 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.159672976 CEST | 53 | 59329 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.164228916 CEST | 56129 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.175367117 CEST | 58177 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.180890083 CEST | 50700 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.182756901 CEST | 53 | 64021 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.185822964 CEST | 54069 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.186543941 CEST | 61178 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.189826012 CEST | 53 | 56129 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.194297075 CEST | 57017 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.198137999 CEST | 53 | 58177 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.207367897 CEST | 53 | 50700 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.208287001 CEST | 53 | 54069 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.210130930 CEST | 53 | 61178 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.216962099 CEST | 53 | 57017 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.260853052 CEST | 56327 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.268893957 CEST | 50243 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.279581070 CEST | 62055 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.286338091 CEST | 53 | 56327 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.286393881 CEST | 61249 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.290338039 CEST | 65252 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.292814970 CEST | 53 | 50243 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.303519964 CEST | 53 | 62055 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.308511972 CEST | 53 | 65252 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.308804989 CEST | 53 | 61249 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.553639889 CEST | 64367 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.573263884 CEST | 55066 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.580248117 CEST | 53 | 64367 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.582072973 CEST | 60211 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.593519926 CEST | 56570 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.602947950 CEST | 53 | 55066 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.609555960 CEST | 53 | 60211 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.616808891 CEST | 53 | 56570 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.699759007 CEST | 58454 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.717638969 CEST | 55180 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.719399929 CEST | 53 | 58454 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.741450071 CEST | 53 | 55180 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.794611931 CEST | 58721 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.821621895 CEST | 53 | 58721 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.829865932 CEST | 57691 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.851711035 CEST | 53 | 57691 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:52.944770098 CEST | 52943 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:52.967212915 CEST | 53 | 52943 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:53.011312962 CEST | 59489 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:53.033525944 CEST | 53 | 59489 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:53.188441992 CEST | 64022 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:53.211309910 CEST | 53 | 64022 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:53.710664034 CEST | 64023 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:53.733613968 CEST | 53 | 64023 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:53.736651897 CEST | 64024 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:53.756797075 CEST | 53 | 64024 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:55.433001995 CEST | 60023 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:55.466562986 CEST | 53 | 60023 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:56.088000059 CEST | 57193 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:56.111979961 CEST | 53 | 57193 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:56.724848032 CEST | 50248 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:56.746889114 CEST | 53 | 50248 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:57.080260038 CEST | 64413 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:57.106569052 CEST | 53 | 64413 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:57.659800053 CEST | 60429 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:57.683654070 CEST | 53 | 60429 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:58.107853889 CEST | 60345 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:58.129864931 CEST | 53 | 60345 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:58.995580912 CEST | 58730 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:59.051291943 CEST | 53 | 58730 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:17:59.946217060 CEST | 53830 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:17:59.966351032 CEST | 53 | 53830 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:18:00.790568113 CEST | 57226 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:18:00.810148954 CEST | 53 | 57226 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:18:01.250684977 CEST | 57880 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:18:01.270885944 CEST | 53 | 57880 | 8.8.8.8 | 192.168.2.6 |
Sep 20, 2021 16:18:19.175335884 CEST | 60850 | 53 | 192.168.2.6 | 8.8.8.8 |
Sep 20, 2021 16:18:19.196850061 CEST | 53 | 60850 | 8.8.8.8 | 192.168.2.6 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Sep 20, 2021 16:17:51.903198957 CEST | 192.168.2.6 | 8.8.8.8 | 0x1ec2 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:51.947235107 CEST | 192.168.2.6 | 8.8.8.8 | 0xd50c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:51.994895935 CEST | 192.168.2.6 | 8.8.8.8 | 0xe936 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.003196001 CEST | 192.168.2.6 | 8.8.8.8 | 0x6567 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.051062107 CEST | 192.168.2.6 | 8.8.8.8 | 0x28 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.070298910 CEST | 192.168.2.6 | 8.8.8.8 | 0xdde5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.077537060 CEST | 192.168.2.6 | 8.8.8.8 | 0x991c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.086899042 CEST | 192.168.2.6 | 8.8.8.8 | 0xad2c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.097189903 CEST | 192.168.2.6 | 8.8.8.8 | 0x4009 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.111187935 CEST | 192.168.2.6 | 8.8.8.8 | 0x3bb6 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.126595020 CEST | 192.168.2.6 | 8.8.8.8 | 0xfe69 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.136374950 CEST | 192.168.2.6 | 8.8.8.8 | 0x3314 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.150861025 CEST | 192.168.2.6 | 8.8.8.8 | 0x8660 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.164228916 CEST | 192.168.2.6 | 8.8.8.8 | 0xb83f | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.175367117 CEST | 192.168.2.6 | 8.8.8.8 | 0xf765 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.180890083 CEST | 192.168.2.6 | 8.8.8.8 | 0x16ab | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.185822964 CEST | 192.168.2.6 | 8.8.8.8 | 0x3f15 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.186543941 CEST | 192.168.2.6 | 8.8.8.8 | 0xd77e | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.194297075 CEST | 192.168.2.6 | 8.8.8.8 | 0x70de | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.260853052 CEST | 192.168.2.6 | 8.8.8.8 | 0xceb0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.268893957 CEST | 192.168.2.6 | 8.8.8.8 | 0x8f3a | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.279581070 CEST | 192.168.2.6 | 8.8.8.8 | 0xc707 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.286393881 CEST | 192.168.2.6 | 8.8.8.8 | 0x12ed | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.290338039 CEST | 192.168.2.6 | 8.8.8.8 | 0x789e | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.553639889 CEST | 192.168.2.6 | 8.8.8.8 | 0xb3d3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.573263884 CEST | 192.168.2.6 | 8.8.8.8 | 0xb540 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.582072973 CEST | 192.168.2.6 | 8.8.8.8 | 0xb036 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.593519926 CEST | 192.168.2.6 | 8.8.8.8 | 0xd01c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.699759007 CEST | 192.168.2.6 | 8.8.8.8 | 0x3c90 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.717638969 CEST | 192.168.2.6 | 8.8.8.8 | 0xa6ab | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.794611931 CEST | 192.168.2.6 | 8.8.8.8 | 0xa53f | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.829865932 CEST | 192.168.2.6 | 8.8.8.8 | 0xff1d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:52.944770098 CEST | 192.168.2.6 | 8.8.8.8 | 0x9c32 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:53.011312962 CEST | 192.168.2.6 | 8.8.8.8 | 0x7b3c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:53.188441992 CEST | 192.168.2.6 | 8.8.8.8 | 0xb719 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 20, 2021 16:17:53.710664034 CEST | 192.168.2.6 | 8.8.8.8 | 0x5401 | Standard query (0) | 28 | IN (0x0001) | |
Sep 20, 2021 16:17:53.736651897 CEST | 192.168.2.6 | 8.8.8.8 | 0x4cc1 | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Sep 20, 2021 16:17:51.934108973 CEST | 8.8.8.8 | 192.168.2.6 | 0x1ec2 | No error (0) | 54.255.104.167 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:51.969907999 CEST | 8.8.8.8 | 192.168.2.6 | 0xd50c | No error (0) | 139.162.112.195 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:51.969907999 CEST | 8.8.8.8 | 192.168.2.6 | 0xd50c | No error (0) | 172.105.211.250 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:51.969907999 CEST | 8.8.8.8 | 192.168.2.6 | 0xd50c | No error (0) | 139.162.81.90 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.102.73 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.102.71 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.102.74 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 103.3.62.64 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.102.70 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 172.104.165.191 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.101.198 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.101.197 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.101.232 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.018109083 CEST | 8.8.8.8 | 192.168.2.6 | 0xe936 | No error (0) | 139.99.102.72 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.025985956 CEST | 8.8.8.8 | 192.168.2.6 | 0x6567 | No error (0) | 51.89.96.41 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.074810028 CEST | 8.8.8.8 | 192.168.2.6 | 0x28 | No error (0) | 51.83.61.76 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 51.255.34.79 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 51.255.34.80 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 51.15.67.17 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 151.80.144.188 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 51.15.55.100 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 213.32.74.157 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.092935085 CEST | 8.8.8.8 | 192.168.2.6 | 0xdde5 | No error (0) | 51.15.55.162 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.104028940 CEST | 8.8.8.8 | 192.168.2.6 | 0x991c | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 185.71.66.31 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.68.143.81 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.15.54.102 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.83.33.228 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.15.69.136 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 135.125.238.108 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.255.34.118 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.15.65.182 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.15.58.224 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 51.15.78.68 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 217.182.169.148 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.110338926 CEST | 8.8.8.8 | 192.168.2.6 | 0xad2c | No error (0) | 46.105.31.147 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.119496107 CEST | 8.8.8.8 | 192.168.2.6 | 0x4009 | No error (0) | 139.99.156.30 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.137234926 CEST | 8.8.8.8 | 192.168.2.6 | 0x3bb6 | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.153669119 CEST | 8.8.8.8 | 192.168.2.6 | 0xfe69 | No error (0) | 18.210.126.40 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 45.76.65.223 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 149.28.212.250 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 66.42.105.146 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 104.238.180.207 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 207.246.100.198 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.159672976 CEST | 8.8.8.8 | 192.168.2.6 | 0x3314 | No error (0) | 45.32.71.82 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.182756901 CEST | 8.8.8.8 | 192.168.2.6 | 0x8660 | No error (0) | monerooceans.stream | CNAME (Canonical name) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.182756901 CEST | 8.8.8.8 | 192.168.2.6 | 0x8660 | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.189826012 CEST | 8.8.8.8 | 192.168.2.6 | 0xb83f | No error (0) | 18.210.126.40 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.198137999 CEST | 8.8.8.8 | 192.168.2.6 | 0xf765 | No error (0) | 192.99.69.170 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.198137999 CEST | 8.8.8.8 | 192.168.2.6 | 0xf765 | No error (0) | 144.217.14.109 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.198137999 CEST | 8.8.8.8 | 192.168.2.6 | 0xf765 | No error (0) | 142.44.243.6 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.198137999 CEST | 8.8.8.8 | 192.168.2.6 | 0xf765 | No error (0) | 142.44.242.100 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.198137999 CEST | 8.8.8.8 | 192.168.2.6 | 0xf765 | No error (0) | 144.217.14.139 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.207367897 CEST | 8.8.8.8 | 192.168.2.6 | 0x16ab | No error (0) | 54.188.223.206 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.208287001 CEST | 8.8.8.8 | 192.168.2.6 | 0x3f15 | No error (0) | 18.180.72.219 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.210130930 CEST | 8.8.8.8 | 192.168.2.6 | 0xd77e | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.216962099 CEST | 8.8.8.8 | 192.168.2.6 | 0x70de | No error (0) | 51.89.96.41 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.286338091 CEST | 8.8.8.8 | 192.168.2.6 | 0xceb0 | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 151.80.144.188 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 51.255.34.79 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 213.32.74.157 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 51.15.55.162 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 51.15.55.100 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 51.255.34.80 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.292814970 CEST | 8.8.8.8 | 192.168.2.6 | 0x8f3a | No error (0) | 51.15.67.17 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.303519964 CEST | 8.8.8.8 | 192.168.2.6 | 0xc707 | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308511972 CEST | 8.8.8.8 | 192.168.2.6 | 0x789e | No error (0) | monerooceans.stream | CNAME (Canonical name) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308511972 CEST | 8.8.8.8 | 192.168.2.6 | 0x789e | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.15.54.102 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 135.125.238.108 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.15.78.68 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.255.34.118 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.83.33.228 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.15.65.182 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.68.143.81 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.15.58.224 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 217.182.169.148 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 46.105.31.147 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 51.15.69.136 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.308804989 CEST | 8.8.8.8 | 192.168.2.6 | 0x12ed | No error (0) | 185.71.66.31 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.580248117 CEST | 8.8.8.8 | 192.168.2.6 | 0xb3d3 | No error (0) | 195.201.124.214 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.602947950 CEST | 8.8.8.8 | 192.168.2.6 | 0xb540 | No error (0) | 54.255.104.167 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.609555960 CEST | 8.8.8.8 | 192.168.2.6 | 0xb036 | No error (0) | 18.210.126.40 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.616808891 CEST | 8.8.8.8 | 192.168.2.6 | 0xd01c | No error (0) | 192.99.69.170 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.616808891 CEST | 8.8.8.8 | 192.168.2.6 | 0xd01c | No error (0) | 142.44.242.100 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.616808891 CEST | 8.8.8.8 | 192.168.2.6 | 0xd01c | No error (0) | 144.217.14.109 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.616808891 CEST | 8.8.8.8 | 192.168.2.6 | 0xd01c | No error (0) | 142.44.243.6 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.616808891 CEST | 8.8.8.8 | 192.168.2.6 | 0xd01c | No error (0) | 144.217.14.139 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.719399929 CEST | 8.8.8.8 | 192.168.2.6 | 0x3c90 | No error (0) | 18.210.126.40 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.102.71 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.101.232 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.102.70 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.102.72 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 172.104.165.191 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.101.198 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.102.74 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.102.73 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 103.3.62.64 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.741450071 CEST | 8.8.8.8 | 192.168.2.6 | 0xa6ab | No error (0) | 139.99.101.197 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.821621895 CEST | 8.8.8.8 | 192.168.2.6 | 0xa53f | No error (0) | 54.188.223.206 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.851711035 CEST | 8.8.8.8 | 192.168.2.6 | 0xff1d | No error (0) | 18.180.72.219 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 207.246.100.198 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 66.42.105.146 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 45.76.65.223 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 149.28.212.250 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 104.238.180.207 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:52.967212915 CEST | 8.8.8.8 | 192.168.2.6 | 0x9c32 | No error (0) | 45.32.71.82 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:53.033525944 CEST | 8.8.8.8 | 192.168.2.6 | 0x7b3c | No error (0) | 139.162.112.195 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:53.033525944 CEST | 8.8.8.8 | 192.168.2.6 | 0x7b3c | No error (0) | 172.105.211.250 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:53.033525944 CEST | 8.8.8.8 | 192.168.2.6 | 0x7b3c | No error (0) | 139.162.81.90 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:53.211309910 CEST | 8.8.8.8 | 192.168.2.6 | 0xb719 | No error (0) | 139.99.156.30 | A (IP address) | IN (0x0001) | ||
Sep 20, 2021 16:17:53.733613968 CEST | 8.8.8.8 | 192.168.2.6 | 0x5401 | No error (0) | 28 | IN (0x0001) | |||
Sep 20, 2021 16:17:53.756797075 CEST | 8.8.8.8 | 192.168.2.6 | 0x4cc1 | No error (0) | 51.89.96.41 | A (IP address) | IN (0x0001) |
HTTP Packets |
---|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.6 | 49767 | 51.83.61.76 | 80 | C:\Users\user\Desktop\dllhost.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Sep 20, 2021 16:17:52.167704105 CEST | 1065 | OUT | |
Sep 20, 2021 16:17:52.199449062 CEST | 1070 | IN | |
Sep 20, 2021 16:17:52.206331968 CEST | 1072 | OUT | |
Sep 20, 2021 16:17:52.207072973 CEST | 1072 | OUT | |
Sep 20, 2021 16:17:52.232741117 CEST | 1075 | IN |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 16:17:21 |
Start date: | 20/09/2021 |
Path: | C:\Users\user\Desktop\dllhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e50b0000 |
File size: | 67306240 bytes |
MD5 hash: | FB4C1F5EC7701209F0A1DCD0726DC403 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
General |
---|
Start time: | 16:17:30 |
Start date: | 20/09/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61de10000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Disassembly |
---|
Code Analysis |
---|