Windows Analysis Report yVhvGnsUpL
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
Process Tree |
---|
|
Malware Configuration |
---|
Threatname: Remcos |
---|
{"Version": "3.2.1 Pro", "Host:Port:Password": "twistednerd.dvrlists.com:8618:1", "Assigned name": "Sept", "Connect interval": "1", "Install flag": "Disable", "Setup HKCU\\Run": "Enable", "Setup HKLM\\Run": "Disable", "Install path": "AppData", "Copy file": "remcos.exe", "Startup value": "Remcos", "Hide file": "Disable", "Mutex": "Sept-AITAB5", "Keylog flag": "0", "Keylog path": "AppData", "Keylog file": "logs.dat", "Keylog crypt": "Disable", "Hide keylog file": "Disable", "Screenshot flag": "Disable", "Screenshot time": "10", "Take Screenshot option": "Disable", "Take screenshot title": "notepad;solitaire;", "Take screenshot time": "5", "Screenshot path": "AppData", "Screenshot file": "Screenshots", "Screenshot crypt": "Disable", "Mouse option": "Disable", "Delete file": "Disable", "Audio record time": "5", "Audio path": "AppData", "Audio folder": "MicRecords", "Connect delay": "0", "Copy folder": "Remcos", "Keylog folder": "remcos", "Keylog file max size": "20000"}
Yara Overview |
---|
Dropped Files |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Methodology_Contains_Shortcut_OtherURIhandlers | Detects possible shortcut usage for .URL persistence | @itsreallynick (Nick Carr) |
|
Memory Dumps |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
REMCOS_RAT_variants | unknown | unknown |
| |
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
REMCOS_RAT_variants | unknown | unknown |
| |
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
Click to see the 13 entries |
Unpacked PEs |
---|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
REMCOS_RAT_variants | unknown | unknown |
| |
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
REMCOS_RAT_variants | unknown | unknown |
| |
JoeSecurity_Remcos | Yara detected Remcos RAT | Joe Security | ||
Click to see the 31 entries |
Sigma Overview |
---|
No Sigma rule has matched |
---|
Jbx Signature Overview |
---|
Click to jump to signature section
AV Detection: |
---|
Found malware configuration | Show sources |
Source: | Malware Configuration Extractor: |
Multi AV Scanner detection for submitted file | Show sources |
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Yara detected Remcos RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Multi AV Scanner detection for dropped file | Show sources |
Source: | ReversingLabs: |
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: | ||
Source: | Avira: |
Source: | Code function: | 12_2_0042E5CA | |
Source: | Code function: | 28_2_006FE5CA |
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Code function: | 12_2_0040A012 | |
Source: | Code function: | 12_2_004061C3 | |
Source: | Code function: | 12_2_0040A22D | |
Source: | Code function: | 12_2_004153F5 | |
Source: | Code function: | 28_2_006DA012 | |
Source: | Code function: | 28_2_006D61C3 | |
Source: | Code function: | 28_2_006DA22D | |
Source: | Code function: | 28_2_006E53F5 | |
Source: | Code function: | 28_2_006E7754 | |
Source: | Code function: | 28_2_006D77EC | |
Source: | Code function: | 28_2_00716AF9 | |
Source: | Code function: | 28_2_006D7C55 |
Source: | Code function: | 28_2_006D697D |
Networking: |
---|
C2 URLs / IPs found in malware configuration | Show sources |
Source: | URLs: |
Source: | TCP traffic: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Source: | Code function: | 12_2_00422251 |
Source: | Code function: | 28_2_006D9BD9 |
Source: | Code function: | 28_2_006D89BA |
Source: | Code function: | 28_2_006D9BD9 |
E-Banking Fraud: |
---|
Yara detected Remcos RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Spam, unwanted Advertisements and Ransom Demands: |
---|
Contains functionalty to change the wallpaper | Show sources |
Source: | Code function: | 28_2_006E7F10 |
System Summary: |
---|
Malicious sample detected (through community Yara rule) | Show sources |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 28_2_006E2BE1 |
Source: | Code function: | 12_2_004340D5 | |
Source: | Code function: | 12_2_00423098 | |
Source: | Code function: | 12_2_00411205 | |
Source: | Code function: | 12_2_0043820B | |
Source: | Code function: | 12_2_004223C0 | |
Source: | Code function: | 12_2_0044D3FA | |
Source: | Code function: | 12_2_0043843A | |
Source: | Code function: | 28_2_007040D5 | |
Source: | Code function: | 28_2_006F3098 | |
Source: | Code function: | 28_2_006E1205 | |
Source: | Code function: | 28_2_0070820B | |
Source: | Code function: | 28_2_0071D3FA | |
Source: | Code function: | 28_2_006F23C0 | |
Source: | Code function: | 28_2_0070843A | |
Source: | Code function: | 28_2_006E9521 | |
Source: | Code function: | 28_2_0070450A | |
Source: | Code function: | 28_2_0071B5AB | |
Source: | Code function: | 28_2_00701670 | |
Source: | Code function: | 28_2_007216E0 | |
Source: | Code function: | 28_2_006FE6D5 | |
Source: | Code function: | 28_2_007037C1 | |
Source: | Code function: | 28_2_006F28B7 | |
Source: | Code function: | 28_2_0070493F | |
Source: | Code function: | 28_2_0070FA50 | |
Source: | Code function: | 28_2_006EAAA0 | |
Source: | Code function: | 28_2_00700BBE | |
Source: | Code function: | 28_2_0071BCC9 | |
Source: | Code function: | 28_2_00703CBD | |
Source: | Code function: | 28_2_006F2F55 | |
Source: | Code function: | 28_2_00707FDC | |
Source: | Code function: | 28_2_105B3233 | |
Source: | Code function: | 28_2_105AA394 | |
Source: | Code function: | 28_2_105C24E3 | |
Source: | Code function: | 28_2_105BF548 | |
Source: | Code function: | 28_2_10591638 | |
Source: | Code function: | 28_2_105C4634 | |
Source: | Code function: | 28_2_105B372A |
Source: | Code function: | 12_2_0041412B |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Process created: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 28_2_006E3958 |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Code function: | 12_2_004163AD |
Source: | Code function: | 12_2_0040D211 |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | Code function: | 28_2_006E6C39 |
Source: | Process created: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Window detected: |
Source: | Static file information: |
Source: | Code function: | 12_2_004510C6 | |
Source: | Code function: | 12_2_0045844E | |
Source: | Code function: | 23_3_03B7D3BC | |
Source: | Code function: | 23_3_03B7CFFE | |
Source: | Code function: | 23_3_03B7C93D | |
Source: | Code function: | 23_3_03B7EB5D | |
Source: | Code function: | 23_3_03B7D0BA | |
Source: | Code function: | 23_3_03B7C2FB | |
Source: | Code function: | 23_3_03B7F2EF | |
Source: | Code function: | 23_3_03B7F6E4 | |
Source: | Code function: | 23_3_03B7EA4B | |
Source: | Code function: | 23_3_03B7E213 | |
Source: | Code function: | 23_3_03B7EE7B | |
Source: | Code function: | 24_3_03CB9848 | |
Source: | Code function: | 24_3_03CBB200 | |
Source: | Code function: | 24_3_03CBC7BF | |
Source: | Code function: | 24_3_03CB917C | |
Source: | Code function: | 24_3_03CB909E | |
Source: | Code function: | 24_3_03CB9496 | |
Source: | Code function: | 24_3_03CBAEA9 | |
Source: | Code function: | 24_3_03CBC2A8 | |
Source: | Code function: | 24_3_03CB9848 | |
Source: | Code function: | 24_3_03CBB005 | |
Source: | Code function: | 28_2_007210C6 | |
Source: | Code function: | 28_2_0072844E | |
Source: | Code function: | 28_2_00720799 | |
Source: | Code function: | 28_2_006FFBB9 |
Source: | Code function: | 12_2_0040CD09 |
Source: | File created: | Jump to dropped file |
Source: | Code function: | 28_2_006D5C8B |
Source: | Code function: | 12_2_004163AD |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Code function: | 12_2_0040CD09 |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion: |
---|
Delayed program exit found | Show sources |
Source: | Code function: | 12_2_0040D0B5 | |
Source: | Code function: | 28_2_006DD0B5 |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: | ||
Source: | Last function: |
Source: | Code function: | 12_2_004160DB | |
Source: | Code function: | 28_2_006E60DB |
Source: | Code function: | 12_2_0040A012 | |
Source: | Code function: | 12_2_004061C3 | |
Source: | Code function: | 12_2_0040A22D | |
Source: | Code function: | 12_2_004153F5 | |
Source: | Code function: | 28_2_006DA012 | |
Source: | Code function: | 28_2_006D61C3 | |
Source: | Code function: | 28_2_006DA22D | |
Source: | Code function: | 28_2_006E53F5 | |
Source: | Code function: | 28_2_006E7754 | |
Source: | Code function: | 28_2_006D77EC | |
Source: | Code function: | 28_2_00716AF9 | |
Source: | Code function: | 28_2_006D7C55 |
Source: | Code function: | 28_2_006D697D |
Source: | Code function: | 28_2_006FF727 |
Source: | Code function: | 12_2_0040CD09 |
Source: | Code function: | 12_2_0040F15D |
Source: | Code function: | 28_2_0070CB4E | |
Source: | Code function: | 28_2_1059111E | |
Source: | Code function: | 28_2_1059111E |
Source: | Code function: | 23_3_03B80B99 |
Source: | Code function: | 12_2_0042F8B9 | |
Source: | Code function: | 28_2_006FF8B9 | |
Source: | Code function: | 28_2_006FF727 | |
Source: | Code function: | 28_2_00706793 | |
Source: | Code function: | 28_2_006FFD2C |
HIPS / PFW / Operating System Protection Evasion: |
---|
Writes to foreign memory regions | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Injects a PE file into a foreign processes | Show sources |
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior | ||
Source: | Memory written: | Jump to behavior |
Contains functionality to inject code into remote processes | Show sources |
Source: | Code function: | 12_2_0041412B |
Creates a thread in another existing process (thread injection) | Show sources |
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior | ||
Source: | Thread created: | Jump to behavior |
Source: | Code function: | 28_2_006DFAC7 |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 28_2_006E4F84 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 12_2_0044A1D0 | |
Source: | Code function: | 12_2_0040D1E5 | |
Source: | Code function: | 12_2_0044A21B | |
Source: | Code function: | 12_2_0044A2B6 | |
Source: | Code function: | 12_2_0044A343 | |
Source: | Code function: | 12_2_004423BA | |
Source: | Code function: | 28_2_006DD1E5 | |
Source: | Code function: | 28_2_0071A1D0 | |
Source: | Code function: | 28_2_0071A21B | |
Source: | Code function: | 28_2_0071A2B6 | |
Source: | Code function: | 28_2_0071A343 | |
Source: | Code function: | 28_2_007123BA | |
Source: | Code function: | 28_2_0071A593 | |
Source: | Code function: | 28_2_0071A6BC | |
Source: | Code function: | 28_2_0071A7C3 | |
Source: | Code function: | 28_2_0071A890 | |
Source: | Code function: | 28_2_00711ED1 | |
Source: | Code function: | 28_2_00719F58 |
Source: | Code function: | 28_2_006FF9B4 |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 12_2_00442424 |
Source: | Code function: | 28_2_00712C8E |
Source: | Code function: | 12_2_00416D9E |
Stealing of Sensitive Information: |
---|
Yara detected Remcos RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Contains functionality to steal Firefox passwords or cookies | Show sources |
Source: | Code function: | 12_2_0040A012 | |
Source: | Code function: | 12_2_0040A012 | |
Source: | Code function: | 28_2_006DA012 | |
Source: | Code function: | 28_2_006DA012 |
Contains functionality to steal Chrome passwords or cookies | Show sources |
Source: | Code function: | 28_2_006D9EF4 |
Remote Access Functionality: |
---|
Yara detected Remcos RAT | Show sources |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Detected Remcos RAT | Show sources |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 28_2_006D55EA |
Mitre Att&ck Matrix |
---|
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | Scripting1 | Application Shimming1 | Application Shimming1 | Deobfuscate/Decode Files or Information1 | OS Credential Dumping1 | System Time Discovery2 | Remote Services | Archive Collected Data11 | Exfiltration Over Other Network Medium | Ingress Tool Transfer11 | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | System Shutdown/Reboot1 |
Default Accounts | Native API1 | Windows Service1 | Access Token Manipulation1 | Scripting1 | Input Capture11 | Account Discovery1 | Remote Desktop Protocol | Input Capture11 | Exfiltration Over Bluetooth | Encrypted Channel2 | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Defacement1 |
Domain Accounts | Command and Scripting Interpreter1 | Registry Run Keys / Startup Folder1 | Windows Service1 | Obfuscated Files or Information2 | Credentials In Files2 | System Service Discovery1 | SMB/Windows Admin Shares | Clipboard Data2 | Automated Exfiltration | Non-Standard Port1 | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | Service Execution2 | Logon Script (Mac) | Process Injection422 | Software Packing1 | NTDS | File and Directory Discovery2 | Distributed Component Object Model | Input Capture | Scheduled Transfer | Remote Access Software1 | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Registry Run Keys / Startup Folder1 | Masquerading1 | LSA Secrets | System Information Discovery33 | SSH | Keylogging | Data Transfer Size Limits | Non-Application Layer Protocol1 | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | Modify Registry1 | Cached Domain Credentials | Security Software Discovery12 | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Application Layer Protocol11 | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Virtualization/Sandbox Evasion1 | DCSync | Virtualization/Sandbox Evasion1 | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Access Token Manipulation1 | Proc Filesystem | Process Discovery2 | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue | |
Exploit Public-Facing Application | PowerShell | At (Linux) | At (Linux) | Process Injection422 | /etc/passwd and /etc/shadow | System Owner/User Discovery1 | Software Deployment Tools | Data Staged | Exfiltration Over Asymmetric Encrypted Non-C2 Protocol | Web Protocols | Rogue Cellular Base Station | Data Destruction | |
Supply Chain Compromise | AppleScript | At (Windows) | At (Windows) | Invalid Code Signature | Network Sniffing | Remote System Discovery1 | Taint Shared Content | Local Data Staging | Exfiltration Over Unencrypted/Obfuscated Non-C2 Protocol | File Transfer Protocols | Data Encrypted for Impact |
Behavior Graph |
---|
Screenshots |
---|
Thumbnails
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Antivirus, Machine Learning and Genetic Malware Detection |
---|
Initial Sample |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
18% | Virustotal | Browse | ||
13% | ReversingLabs | Win32.Backdoor.Androm |
Dropped Files |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
13% | ReversingLabs | Win32.Backdoor.Androm |
Unpacked PE Files |
---|
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Dropper.Gen | Download File | ||
100% | Avira | HEUR/AGEN.1141389 | Download File | ||
100% | Avira | TR/Dropper.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | HEUR/AGEN.1141389 | Download File | ||
100% | Avira | HEUR/AGEN.1141389 | Download File | ||
100% | Avira | TR/Dropper.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.ZPACK.Gen | Download File |
Domains |
---|
No Antivirus matches |
---|
URLs |
---|
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Domains and IPs |
---|
Contacted Domains |
---|
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
twistednerd.dvrlists.com | 31.3.152.100 | true | false | high | |
onedrive.live.com | unknown | unknown | false | high | |
qcisaa.sn.files.1drv.com | unknown | unknown | false | high |
Contacted URLs |
---|
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
URLs from Memory and Binaries |
---|
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
Contacted IPs |
---|
General Information |
---|
Joe Sandbox Version: | 33.0.0 White Diamond |
Analysis ID: | 487629 |
Start date: | 21.09.2021 |
Start time: | 22:13:55 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 13m 24s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | yVhvGnsUpL (renamed file extension from none to exe) |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 37 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.rans.troj.spyw.evad.winEXE@23/10@75/2 |
EGA Information: | Failed |
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
Warnings: | Show All
|
Simulations |
---|
Behavior and APIs |
---|
Time | Type | Description |
---|---|---|
22:14:57 | API Interceptor | |
22:15:19 | Autostart | |
22:15:27 | Autostart | |
22:15:28 | API Interceptor |
Joe Sandbox View / Context |
---|
Created / dropped Files |
---|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 155 |
Entropy (8bit): | 4.687076340713226 |
Encrypted: | false |
SSDEEP: | 3:LjT5LJJFIf9oM3KN6QNb3DM9bWQqA5SkrF2VCceGAFddGeWLCXlRA3+OR:rz81R3KnMMQ75ieGgdEYlRA/R |
MD5: | 213C60ADF1C9EF88DC3C9B2D579959D2 |
SHA1: | E4D2AD7B22B1A8B5B1F7A702B303C7364B0EE021 |
SHA-256: | 37C59C8398279916CFCE45F8C5E3431058248F5E3BEF4D9F5C0F44A7D564F82E |
SHA-512: | FE897D9CAA306B0E761B2FD61BB5DC32A53BFAAD1CE767C6860AF4E3AD59C8F3257228A6E1072DAB0F990CB51C59C648084BA419AC6BC5C0A99BDFFA569217B7 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1133568 |
Entropy (8bit): | 6.333495513346421 |
Encrypted: | false |
SSDEEP: | 12288:lIspEfnP8N/seflQTshT8aqeTW39KqyeoAdrL7SUbDz5Zp:320N/seflZhTmiW3AirPzz5Z |
MD5: | CF98D2D4D4555323842C8371DB09347E |
SHA1: | 2BD28F09D3EA7C08BAE3A90DD32C28335488EB43 |
SHA-256: | 8FA72E87ADDEAD9671E573D7CB843CA784A10CFBF6ACF5B6BC4830DF66FE0BF0 |
SHA-512: | 972271FF4B87A3EE8217FD0F13EA9D0464124A117E96B09B6B96F49A7B21CF1076115F6E7BDA753866BDE4CFE9170A0EA7F9EAD75DDA695B3B29150FD29E4849 |
Malicious: | true |
Antivirus: |
|
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 96 |
Entropy (8bit): | 4.77898063752017 |
Encrypted: | false |
SSDEEP: | 3:HRAbABGQYmTWAX+rSF55i0XMR52XHvsGKd6ov:HRYFVmTWDyzqwHvsbDv |
MD5: | F7FE80CDDDABC41175A9174062BF9FB4 |
SHA1: | EA61F6248EAEF211BD5F08091C691E468161C847 |
SHA-256: | 6B3C535B354D7C67C9A4840F8ACCD2AA9B2DFF80FF3C90BE66D944AA8A8E6F81 |
SHA-512: | A49CF21FD89CDFB5716BE3BBD38E91073804FB3B66D9F5AC34D0C3E86E2C4563D027986C4A2A2FE33991A2A652FE4DD3578411234B29FB81826079370C7FD926 |
Malicious: | false |
Yara Hits: |
|
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 34 |
Entropy (8bit): | 4.314972767530033 |
Encrypted: | false |
SSDEEP: | 3:LjTnaHF5wlM:rnaHSM |
MD5: | 4068C9F69FCD8A171C67F81D4A952A54 |
SHA1: | 4D2536A8C28CDCC17465E20D6693FB9E8E713B36 |
SHA-256: | 24222300C78180B50ED1F8361BA63CB27316EC994C1C9079708A51B4A1A9D810 |
SHA-512: | A64F9319ACC51FFFD0491C74DCD9C9084C2783B82F95727E4BFE387A8528C6DCF68F11418E88F1E133D115DAF907549C86DD7AD866B2A7938ADD5225FBB2811D |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 250 |
Entropy (8bit): | 4.865356627324657 |
Encrypted: | false |
SSDEEP: | 6:rgnMXd1CQnMXd1COm8hnaHNHIXUnMXd1CoD9c1uOw1H1gOvOBAn:rgamIHIXUaXe1uOeVqy |
MD5: | EAF8D967454C3BBDDBF2E05A421411F8 |
SHA1: | 6170880409B24DE75C2DC3D56A506FBFF7F6622C |
SHA-256: | F35F2658455A2E40F151549A7D6465A836C33FA9109E67623916F889849EAC56 |
SHA-512: | FE5BE5C673E99F70C93019D01ABB0A29DD2ECF25B2D895190FF551F020C28E7D8F99F65007F440F0F76C5BCAC343B2A179A94D190C938EA3B9E1197890A412E9 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 9 |
Entropy (8bit): | 3.169925001442312 |
Encrypted: | false |
SSDEEP: | 3:cvn:cv |
MD5: | 64120803774747F6A0E65FBF68864DB9 |
SHA1: | 2D19E04E427F41A57A40C45C8E15D7BD7FEFF91F |
SHA-256: | 4BC0305150E635DF5014B49EFB911171F08137F187564E8EC69148525100498F |
SHA-512: | C57320C1EA459F360BDFAECB4F23882B7850A93F894B14C4356FE88B64FE397FF27CA2E9E52EA30484DEEF088AAB8970B98C8E73BB92C397552AA6A02BDAFC64 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 53 |
Entropy (8bit): | 4.263285494083192 |
Encrypted: | false |
SSDEEP: | 3:LjT9fnMXdemzCK0vn:rZnMXd1CV |
MD5: | 8ADA51400B7915DE2124BAAF75E3414C |
SHA1: | 1A7B9DB12184AB7FD7FCE1C383F9670A00ADB081 |
SHA-256: | 45AA3957C29865260A78F03EEF18AE9AEBDBF7BEA751ECC88BE4A799F2BB46C7 |
SHA-512: | 9AFC138157A4565294CA49942579CDB6F5D8084E56F9354738DE62B585F4C0FA3E7F2CBC9541827F2084E3FF36C46EED29B46F5DD2444062FFCD05C599992E68 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 844800 |
Entropy (8bit): | 7.998270300086775 |
Encrypted: | true |
SSDEEP: | 24576:V0SUUlISC/pYz/bZ5ut74t8Ld/xUjdqJZ:VwUK7cEestxUj0H |
MD5: | 35CD77E767A6005B26709CE820FB50A6 |
SHA1: | 3322111384C098DFDE8B8CDDF60CA078C642CB35 |
SHA-256: | 4CA74BAB815601FB1A29D46116F084663A9722A403431CE59B9305DF3A86E785 |
SHA-512: | 3A331821D2945E7A49BED2F9638738172FFC2758028DFEF58AAAF4D1DB960B42422A21A308859985CAB993FB4754E162A586CC18BFC09AEBD71290F30E8A2431 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\Public\Libraries\Srakjle\Srakjle.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 844800 |
Entropy (8bit): | 7.998270300086775 |
Encrypted: | true |
SSDEEP: | 24576:V0SUUlISC/pYz/bZ5ut74t8Ld/xUjdqJZ:VwUK7cEestxUj0H |
MD5: | 35CD77E767A6005B26709CE820FB50A6 |
SHA1: | 3322111384C098DFDE8B8CDDF60CA078C642CB35 |
SHA-256: | 4CA74BAB815601FB1A29D46116F084663A9722A403431CE59B9305DF3A86E785 |
SHA-512: | 3A331821D2945E7A49BED2F9638738172FFC2758028DFEF58AAAF4D1DB960B42422A21A308859985CAB993FB4754E162A586CC18BFC09AEBD71290F30E8A2431 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Process: | C:\Users\Public\Libraries\Srakjle\Srakjle.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 844800 |
Entropy (8bit): | 7.998270300086775 |
Encrypted: | true |
SSDEEP: | 24576:V0SUUlISC/pYz/bZ5ut74t8Ld/xUjdqJZ:VwUK7cEestxUj0H |
MD5: | 35CD77E767A6005B26709CE820FB50A6 |
SHA1: | 3322111384C098DFDE8B8CDDF60CA078C642CB35 |
SHA-256: | 4CA74BAB815601FB1A29D46116F084663A9722A403431CE59B9305DF3A86E785 |
SHA-512: | 3A331821D2945E7A49BED2F9638738172FFC2758028DFEF58AAAF4D1DB960B42422A21A308859985CAB993FB4754E162A586CC18BFC09AEBD71290F30E8A2431 |
Malicious: | false |
Reputation: | unknown |
Preview: |
|
Static File Info |
---|
General | |
---|---|
File type: | |
Entropy (8bit): | 6.333495513346421 |
TrID: |
|
File name: | yVhvGnsUpL.exe |
File size: | 1133568 |
MD5: | cf98d2d4d4555323842c8371db09347e |
SHA1: | 2bd28f09d3ea7c08bae3a90dd32c28335488eb43 |
SHA256: | 8fa72e87addead9671e573d7cb843ca784a10cfbf6acf5b6bc4830df66fe0bf0 |
SHA512: | 972271ff4b87a3ee8217fd0f13ea9d0464124a117e96b09b6b96f49a7b21cf1076115f6e7bda753866bde4cfe9170a0ea7f9ead75dda695b3b29150fd29e4849 |
SSDEEP: | 12288:lIspEfnP8N/seflQTshT8aqeTW39KqyeoAdrL7SUbDz5Zp:320N/seflZhTmiW3AirPzz5Z |
File Content Preview: | MZP.....................@...............................................!..L.!..This program must be run under Win32..$7....................................................................................................................................... |
File Icon |
---|
Icon Hash: | 8dcd2c37ab968be4 |
Static PE Info |
---|
General | |
---|---|
Entrypoint: | 0x46ac6c |
Entrypoint Section: | .itext |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, BYTES_REVERSED_LO, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, BYTES_REVERSED_HI |
DLL Characteristics: | |
Time Stamp: | 0x2A425E19 [Fri Jun 19 22:22:17 1992 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | bc8cc1eea5c25ce2056d7da92bd98134 |
Entrypoint Preview |
---|
Instruction |
---|
push ebp |
mov ebp, esp |
add esp, FFFFFFF0h |
push ebx |
mov eax, 00468F74h |
call 00007FB8FCBB7D88h |
mov ebx, dword ptr [004F9A3Ch] |
mov eax, dword ptr [ebx] |
call 00007FB8FCC0F2EBh |
mov eax, dword ptr [ebx] |
mov edx, 0046ACE4h |
call 00007FB8FCC0ED77h |
mov ecx, dword ptr [004F97C0h] |
mov eax, dword ptr [ebx] |
mov edx, dword ptr [00466F4Ch] |
call 00007FB8FCC0F2E4h |
mov ecx, dword ptr [004F988Ch] |
mov eax, dword ptr [ebx] |
mov edx, dword ptr [00466B90h] |
call 00007FB8FCC0F2D1h |
mov ecx, dword ptr [004F9898h] |
mov eax, dword ptr [ebx] |
mov edx, dword ptr [004669C4h] |
call 00007FB8FCC0F2BEh |
mov eax, dword ptr [ebx] |
call 00007FB8FCC0F337h |
pop ebx |
call 00007FB8FCBB5B19h |
Data Directories |
---|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xfe000 | 0x2a66 | .idata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x10b000 | 0x12600 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x103000 | 0x76f4 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x102000 | 0x18 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0xfe7d4 | 0x694 | .idata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Sections |
---|
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x681dc | 0x68200 | False | 0.523299163415 | data | 6.55816841142 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.itext | 0x6a000 | 0xcf0 | 0xe00 | False | 0.557477678571 | data | 5.90308719076 | IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_READ |
.data | 0x6b000 | 0x8ebe4 | 0x8ec00 | False | 0.272558422723 | data | 4.83463412807 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.bss | 0xfa000 | 0x392c | 0x0 | False | 0 | empty | 0.0 | IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.idata | 0xfe000 | 0x2a66 | 0x2c00 | False | 0.310635653409 | data | 5.15464071518 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.tls | 0x101000 | 0x34 | 0x0 | False | 0 | empty | 0.0 | IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ |
.rdata | 0x102000 | 0x18 | 0x200 | False | 0.05078125 | data | 0.205445628135 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x103000 | 0x76f4 | 0x7800 | False | 0.6095703125 | data | 6.66305090438 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
.rsrc | 0x10b000 | 0x12600 | 0x12600 | False | 0.401387117347 | data | 5.13864467631 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Resources |
---|
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_CURSOR | 0x10bb4c | 0x134 | data | English | United States |
RT_CURSOR | 0x10bc80 | 0x134 | data | English | United States |
RT_CURSOR | 0x10bdb4 | 0x134 | data | English | United States |
RT_CURSOR | 0x10bee8 | 0x134 | data | English | United States |
RT_CURSOR | 0x10c01c | 0x134 | data | English | United States |
RT_CURSOR | 0x10c150 | 0x134 | data | English | United States |
RT_CURSOR | 0x10c284 | 0x134 | data | English | United States |
RT_BITMAP | 0x10c3b8 | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10c588 | 0x1e4 | data | English | United States |
RT_BITMAP | 0x10c76c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10c93c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10cb0c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10ccdc | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10ceac | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10d07c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10d24c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10d41c | 0x1d0 | data | English | United States |
RT_BITMAP | 0x10d5ec | 0xe8 | GLS_BINARY_LSB_FIRST | English | United States |
RT_ICON | 0x10d6d4 | 0x468 | GLS_BINARY_LSB_FIRST | English | United States |
RT_ICON | 0x10db3c | 0x10a8 | data | English | United States |
RT_ICON | 0x10ebe4 | 0x25a8 | data | English | United States |
RT_ICON | 0x11118c | 0x94a8 | data | English | United States |
RT_DIALOG | 0x11a634 | 0x52 | data | ||
RT_DIALOG | 0x11a688 | 0x52 | data | ||
RT_STRING | 0x11a6dc | 0x10c | data | ||
RT_STRING | 0x11a7e8 | 0x390 | data | ||
RT_STRING | 0x11ab78 | 0x188 | data | ||
RT_STRING | 0x11ad00 | 0xc8 | data | ||
RT_STRING | 0x11adc8 | 0x118 | data | ||
RT_STRING | 0x11aee0 | 0x39c | data | ||
RT_STRING | 0x11b27c | 0x3a8 | data | ||
RT_STRING | 0x11b624 | 0x354 | data | ||
RT_STRING | 0x11b978 | 0x3cc | data | ||
RT_STRING | 0x11bd44 | 0x214 | data | ||
RT_STRING | 0x11bf58 | 0xcc | data | ||
RT_STRING | 0x11c024 | 0x194 | data | ||
RT_STRING | 0x11c1b8 | 0x3c4 | data | ||
RT_STRING | 0x11c57c | 0x338 | data | ||
RT_STRING | 0x11c8b4 | 0x294 | data | ||
RT_RCDATA | 0x11cb48 | 0x10 | data | ||
RT_RCDATA | 0x11cb58 | 0x318 | data | ||
RT_RCDATA | 0x11ce70 | 0x697 | Delphi compiled form 'T__3773734381' | ||
RT_GROUP_CURSOR | 0x11d508 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d51c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d530 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d544 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d558 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d56c | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_CURSOR | 0x11d580 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States |
RT_GROUP_ICON | 0x11d594 | 0x3e | data | English | United States |
Imports |
---|
DLL | Import |
---|---|
oleaut32.dll | SysFreeString, SysReAllocStringLen, SysAllocStringLen |
advapi32.dll | RegQueryValueExA, RegOpenKeyExA, RegCloseKey |
user32.dll | GetKeyboardType, DestroyWindow, LoadStringA, MessageBoxA, CharNextA |
kernel32.dll | GetACP, Sleep, VirtualFree, VirtualAlloc, GetCurrentThreadId, InterlockedDecrement, InterlockedIncrement, VirtualQuery, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, lstrcpynA, LoadLibraryExA, GetThreadLocale, GetStartupInfoA, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLastError, GetCommandLineA, FreeLibrary, FindFirstFileA, FindClose, ExitProcess, ExitThread, CreateThread, CompareStringA, WriteFile, UnhandledExceptionFilter, SetFilePointer, SetEndOfFile, RtlUnwind, ReadFile, RaiseException, GetStdHandle, GetFileSize, GetFileType, CreateFileA, CloseHandle |
kernel32.dll | TlsSetValue, TlsGetValue, LocalAlloc, GetModuleHandleA |
user32.dll | CreateWindowExA, WindowFromPoint, WaitMessage, UpdateWindow, UnregisterClassA, UnhookWindowsHookEx, TranslateMessage, TranslateMDISysAccel, TrackPopupMenu, SystemParametersInfoA, ShowWindow, ShowScrollBar, ShowOwnedPopups, SetWindowsHookExA, SetWindowTextA, SetWindowPos, SetWindowPlacement, SetWindowLongW, SetWindowLongA, SetTimer, SetScrollRange, SetScrollPos, SetScrollInfo, SetRect, SetPropA, SetParent, SetMenuItemInfoA, SetMenu, SetForegroundWindow, SetFocus, SetCursor, SetClassLongA, SetCapture, SetActiveWindow, SendMessageW, SendMessageA, ScrollWindow, ScreenToClient, RemovePropA, RemoveMenu, ReleaseDC, ReleaseCapture, RegisterWindowMessageA, RegisterClipboardFormatA, RegisterClassA, RedrawWindow, PtInRect, PostQuitMessage, PostMessageA, PeekMessageW, PeekMessageA, OffsetRect, OemToCharA, MsgWaitForMultipleObjects, MessageBoxA, MapWindowPoints, MapVirtualKeyA, LoadStringA, LoadKeyboardLayoutA, LoadIconA, LoadCursorA, LoadBitmapA, KillTimer, IsZoomed, IsWindowVisible, IsWindowUnicode, IsWindowEnabled, IsWindow, IsRectEmpty, IsIconic, IsDialogMessageW, IsDialogMessageA, IsChild, InvalidateRect, IntersectRect, InsertMenuItemA, InsertMenuA, InflateRect, GetWindowThreadProcessId, GetWindowTextA, GetWindowRect, GetWindowPlacement, GetWindowLongW, GetWindowLongA, GetWindowDC, GetTopWindow, GetSystemMetrics, GetSystemMenu, GetSysColorBrush, GetSysColor, GetSubMenu, GetScrollRange, GetScrollPos, GetScrollInfo, GetPropA, GetParent, GetWindow, GetMessageTime, GetMessagePos, GetMenuStringA, GetMenuState, GetMenuItemInfoA, GetMenuItemID, GetMenuItemCount, GetMenu, GetLastActivePopup, GetKeyboardState, GetKeyboardLayoutNameA, GetKeyboardLayoutList, GetKeyboardLayout, GetKeyState, GetKeyNameTextA, GetIconInfo, GetForegroundWindow, GetFocus, GetDesktopWindow, GetDCEx, GetDC, GetCursorPos, GetCursor, GetClipboardData, GetClientRect, GetClassLongA, GetClassInfoA, GetCapture, GetActiveWindow, FrameRect, FindWindowA, FillRect, EqualRect, EnumWindows, EnumThreadWindows, EnumChildWindows, EndPaint, EnableWindow, EnableScrollBar, EnableMenuItem, DrawTextA, DrawMenuBar, DrawIconEx, DrawIcon, DrawFrameControl, DrawFocusRect, DrawEdge, DispatchMessageW, DispatchMessageA, DestroyWindow, DestroyMenu, DestroyIcon, DestroyCursor, DeleteMenu, DefWindowProcA, DefMDIChildProcA, DefFrameProcA, CreatePopupMenu, CreateMenu, CreateIcon, ClientToScreen, CheckMenuItem, CallWindowProcA, CallNextHookEx, BeginPaint, CharNextA, CharLowerBuffA, CharLowerA, CharToOemA, AdjustWindowRectEx, ActivateKeyboardLayout |
gdi32.dll | UnrealizeObject, StretchBlt, SetWindowOrgEx, SetWinMetaFileBits, SetViewportOrgEx, SetTextColor, SetStretchBltMode, SetROP2, SetPixel, SetMapMode, SetEnhMetaFileBits, SetDIBColorTable, SetBrushOrgEx, SetBkMode, SetBkColor, SelectPalette, SelectObject, SaveDC, RestoreDC, RectVisible, RealizePalette, Polyline, PlayEnhMetaFile, PatBlt, MoveToEx, MaskBlt, LineTo, LPtoDP, IntersectClipRect, GetWindowOrgEx, GetWinMetaFileBits, GetTextMetricsA, GetTextExtentPoint32A, GetSystemPaletteEntries, GetStockObject, GetRgnBox, GetPixel, GetPaletteEntries, GetObjectA, GetEnhMetaFilePaletteEntries, GetEnhMetaFileHeader, GetEnhMetaFileDescriptionA, GetEnhMetaFileBits, GetDeviceCaps, GetDIBits, GetDIBColorTable, GetDCOrgEx, GetCurrentPositionEx, GetClipBox, GetBrushOrgEx, GetBitmapBits, ExtTextOutA, ExcludeClipRect, DeleteObject, DeleteEnhMetaFile, DeleteDC, CreateSolidBrush, CreatePenIndirect, CreatePalette, CreateHalftonePalette, CreateFontIndirectA, CreateEnhMetaFileA, CreateDIBitmap, CreateDIBSection, CreateCompatibleDC, CreateCompatibleBitmap, CreateBrushIndirect, CreateBitmap, CopyEnhMetaFileA, CloseEnhMetaFile, BitBlt |
version.dll | VerQueryValueA, GetFileVersionInfoSizeA, GetFileVersionInfoA |
kernel32.dll | lstrcpyA, WriteFile, WaitForSingleObject, VirtualQuery, VirtualProtect, VirtualAlloc, SizeofResource, SetThreadPriority, SetThreadLocale, SetFilePointer, SetEvent, SetErrorMode, SetEndOfFile, ResumeThread, ResetEvent, ReadFile, MultiByteToWideChar, MulDiv, LockResource, LoadResource, LoadLibraryA, LeaveCriticalSection, InitializeCriticalSection, GlobalUnlock, GlobalSize, GlobalLock, GlobalFree, GlobalFindAtomA, GlobalDeleteAtom, GlobalAlloc, GlobalAddAtomA, GetVersionExA, GetVersion, GetUserDefaultLCID, GetTickCount, GetThreadLocale, GetStdHandle, GetProcAddress, GetModuleHandleA, GetModuleFileNameA, GetLocaleInfoA, GetLocalTime, GetLastError, GetFullPathNameA, GetExitCodeThread, GetDiskFreeSpaceA, GetDateFormatA, GetCurrentThreadId, GetCurrentProcessId, GetCPInfo, FreeResource, InterlockedIncrement, InterlockedExchange, InterlockedDecrement, FreeLibrary, FormatMessageA, FindResourceA, EnumCalendarInfoA, EnterCriticalSection, DeleteCriticalSection, CreateThread, CreateFileA, CreateEventA, CompareStringA, CloseHandle |
advapi32.dll | RegQueryValueExA, RegOpenKeyExA, RegFlushKey, RegCloseKey |
oleaut32.dll | GetErrorInfo, SysFreeString |
ole32.dll | CreateStreamOnHGlobal, IsAccelerator, OleDraw, OleSetMenuDescriptor, CoCreateInstance, CoGetClassObject, CoUninitialize, CoInitialize, IsEqualGUID |
kernel32.dll | Sleep |
oleaut32.dll | SafeArrayPtrOfIndex, SafeArrayGetUBound, SafeArrayGetLBound, SafeArrayCreate, VariantChangeType, VariantCopy, VariantClear, VariantInit |
comctl32.dll | _TrackMouseEvent, ImageList_SetIconSize, ImageList_GetIconSize, ImageList_Write, ImageList_Read, ImageList_DragShowNolock, ImageList_DragMove, ImageList_DragLeave, ImageList_DragEnter, ImageList_EndDrag, ImageList_BeginDrag, ImageList_Remove, ImageList_DrawEx, ImageList_Draw, ImageList_GetBkColor, ImageList_SetBkColor, ImageList_Add, ImageList_GetImageCount, ImageList_Destroy, ImageList_Create |
Possible Origin |
---|
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Network Behavior |
---|
Network Port Distribution |
---|
TCP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 21, 2021 22:15:24.613734007 CEST | 49745 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:24.751717091 CEST | 8618 | 49745 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:24.751888990 CEST | 49745 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:24.783202887 CEST | 49745 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:24.906296015 CEST | 8618 | 49745 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:24.906488895 CEST | 49745 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:24.921248913 CEST | 8618 | 49745 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:26.064784050 CEST | 49746 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:26.203125954 CEST | 8618 | 49746 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:26.203290939 CEST | 49746 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:26.224236965 CEST | 49746 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:26.376194954 CEST | 8618 | 49746 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:27.547672987 CEST | 49747 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:27.687455893 CEST | 8618 | 49747 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:27.688791990 CEST | 49747 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:27.757275105 CEST | 49747 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:27.843734980 CEST | 8618 | 49747 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:27.843837023 CEST | 49747 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:27.896439075 CEST | 8618 | 49747 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:29.004395962 CEST | 49748 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:29.143774986 CEST | 8618 | 49748 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:29.143904924 CEST | 49748 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:29.169800997 CEST | 49748 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:29.295085907 CEST | 8618 | 49748 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:29.295233011 CEST | 49748 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:29.307466030 CEST | 8618 | 49748 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:30.454725027 CEST | 49750 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:30.592880011 CEST | 8618 | 49750 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:30.593014002 CEST | 49750 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:30.759493113 CEST | 8618 | 49750 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:30.763283014 CEST | 49750 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:31.384521961 CEST | 49750 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:31.522545099 CEST | 8618 | 49750 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:32.527832031 CEST | 49753 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:32.665703058 CEST | 8618 | 49753 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:32.665811062 CEST | 49753 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:32.689991951 CEST | 49753 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:32.819757938 CEST | 8618 | 49753 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:32.819926023 CEST | 49753 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:32.828126907 CEST | 8618 | 49753 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:33.965059996 CEST | 49755 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:34.103287935 CEST | 8618 | 49755 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:34.103487015 CEST | 49755 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:34.116167068 CEST | 49755 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:34.259490013 CEST | 8618 | 49755 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:35.412877083 CEST | 49756 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:35.551476955 CEST | 8618 | 49756 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:35.551582098 CEST | 49756 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:35.564091921 CEST | 49756 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:35.707160950 CEST | 8618 | 49756 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:36.855359077 CEST | 49757 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:36.993679047 CEST | 8618 | 49757 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:36.994240999 CEST | 49757 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:37.004719019 CEST | 49757 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:37.161500931 CEST | 8618 | 49757 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:38.343151093 CEST | 49758 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:38.484560013 CEST | 8618 | 49758 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:38.484704971 CEST | 49758 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:38.501545906 CEST | 49758 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:38.651274920 CEST | 8618 | 49758 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:39.892988920 CEST | 49760 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:40.031867981 CEST | 8618 | 49760 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:40.034013033 CEST | 49760 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:40.056803942 CEST | 49760 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:40.238890886 CEST | 8618 | 49760 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:41.216905117 CEST | 8618 | 49760 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:42.376811028 CEST | 49764 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:42.516700983 CEST | 8618 | 49764 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:42.516844034 CEST | 49764 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:42.534593105 CEST | 49764 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:42.720221996 CEST | 8618 | 49764 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:43.235270977 CEST | 8618 | 49764 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:44.374934912 CEST | 49767 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:44.514785051 CEST | 8618 | 49767 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:44.515480042 CEST | 49767 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:44.601079941 CEST | 49767 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:44.686033964 CEST | 8618 | 49767 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:44.688954115 CEST | 49767 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:44.740065098 CEST | 8618 | 49767 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:45.850467920 CEST | 49768 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:45.988744974 CEST | 8618 | 49768 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:45.992671013 CEST | 49768 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:46.011203051 CEST | 49768 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:46.147255898 CEST | 8618 | 49768 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:46.147397995 CEST | 49768 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:46.149030924 CEST | 8618 | 49768 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:47.325964928 CEST | 49769 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:47.465816021 CEST | 8618 | 49769 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:47.465953112 CEST | 49769 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:47.484496117 CEST | 49769 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:47.635716915 CEST | 8618 | 49769 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:49.601264000 CEST | 49770 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:49.740910053 CEST | 8618 | 49770 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:49.742752075 CEST | 49770 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:49.776230097 CEST | 49770 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:49.911698103 CEST | 8618 | 49770 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:49.914995909 CEST | 8618 | 49770 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:49.915126085 CEST | 49770 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:51.232203960 CEST | 49771 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:51.373131990 CEST | 8618 | 49771 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:51.373276949 CEST | 49771 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:51.409593105 CEST | 49771 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:51.536712885 CEST | 8618 | 49771 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:51.536880970 CEST | 49771 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:51.550023079 CEST | 8618 | 49771 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:52.692353010 CEST | 49772 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:52.830801010 CEST | 8618 | 49772 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:52.830996990 CEST | 49772 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:52.995690107 CEST | 8618 | 49772 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:52.995817900 CEST | 49772 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:53.019932032 CEST | 49772 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:53.162178993 CEST | 8618 | 49772 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:54.211904049 CEST | 49773 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:54.349869013 CEST | 8618 | 49773 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:54.350363016 CEST | 49773 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:54.373811960 CEST | 49773 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:54.511625051 CEST | 8618 | 49773 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:54.511771917 CEST | 8618 | 49773 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:56.215975046 CEST | 49774 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:56.354239941 CEST | 8618 | 49774 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:56.354366064 CEST | 49774 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:56.384660006 CEST | 49774 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:56.516669035 CEST | 8618 | 49774 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:56.517155886 CEST | 49774 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:56.527187109 CEST | 8618 | 49774 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:58.762396097 CEST | 49775 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:58.900434971 CEST | 8618 | 49775 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:58.900552988 CEST | 49775 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:59.063746929 CEST | 8618 | 49775 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:15:59.064213991 CEST | 49775 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:59.205215931 CEST | 49775 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:15:59.345170975 CEST | 8618 | 49775 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:00.643064976 CEST | 49776 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:00.781160116 CEST | 8618 | 49776 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:00.781356096 CEST | 49776 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:00.795571089 CEST | 49776 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:00.937536955 CEST | 8618 | 49776 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:02.097805023 CEST | 49781 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:02.236059904 CEST | 8618 | 49781 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:02.236212015 CEST | 49781 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:02.246505976 CEST | 49781 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:02.392913103 CEST | 8618 | 49781 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:03.533512115 CEST | 49787 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:03.673784018 CEST | 8618 | 49787 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:03.673896074 CEST | 49787 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:03.748552084 CEST | 49787 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:03.843848944 CEST | 8618 | 49787 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:03.844218016 CEST | 49787 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:03.886662006 CEST | 8618 | 49787 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:04.986072063 CEST | 49794 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:05.124696970 CEST | 8618 | 49794 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:05.124793053 CEST | 49794 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:05.154484034 CEST | 49794 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:05.281218052 CEST | 8618 | 49794 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:05.281331062 CEST | 49794 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:05.292586088 CEST | 8618 | 49794 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:06.822614908 CEST | 49800 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:06.960599899 CEST | 8618 | 49800 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:06.960679054 CEST | 49800 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:07.049168110 CEST | 49800 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:07.118736982 CEST | 8618 | 49800 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:07.118812084 CEST | 49800 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:07.187104940 CEST | 8618 | 49800 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:08.269994974 CEST | 49803 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:08.408776999 CEST | 8618 | 49803 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:08.408885002 CEST | 49803 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:08.456069946 CEST | 49803 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:08.558537006 CEST | 8618 | 49803 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:08.562597990 CEST | 49803 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:08.594547987 CEST | 8618 | 49803 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:10.125642061 CEST | 49804 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:10.265976906 CEST | 8618 | 49804 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:10.266091108 CEST | 49804 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:10.278898001 CEST | 49804 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:10.425595999 CEST | 8618 | 49804 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:11.692096949 CEST | 49812 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:11.830797911 CEST | 8618 | 49812 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:11.833331108 CEST | 49812 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:11.845546961 CEST | 49812 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:12.022861958 CEST | 8618 | 49812 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:13.178185940 CEST | 49825 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:13.317519903 CEST | 8618 | 49825 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:13.332580090 CEST | 49825 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:13.458340883 CEST | 49825 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:13.484997034 CEST | 8618 | 49825 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:13.486346006 CEST | 49825 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:13.596049070 CEST | 8618 | 49825 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:14.679626942 CEST | 49827 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:14.819849014 CEST | 8618 | 49827 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:14.820338964 CEST | 49827 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:14.835733891 CEST | 49827 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:14.976038933 CEST | 8618 | 49827 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:16.115502119 CEST | 49829 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:16.254302979 CEST | 8618 | 49829 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:16.254448891 CEST | 49829 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:16.260951996 CEST | 49829 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:16.413753986 CEST | 8618 | 49829 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:17.553184986 CEST | 49830 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:17.690963030 CEST | 8618 | 49830 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:17.691061020 CEST | 49830 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:17.700707912 CEST | 49830 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:17.886909008 CEST | 8618 | 49830 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:17.911153078 CEST | 8618 | 49830 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:19.059405088 CEST | 49831 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:19.197684050 CEST | 8618 | 49831 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:19.198810101 CEST | 49831 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:19.239770889 CEST | 49831 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:19.354612112 CEST | 8618 | 49831 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:19.355429888 CEST | 49831 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:19.378868103 CEST | 8618 | 49831 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:20.494899988 CEST | 49832 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:20.634028912 CEST | 8618 | 49832 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:20.634145021 CEST | 49832 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:20.642668962 CEST | 49832 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:20.797064066 CEST | 8618 | 49832 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:21.949410915 CEST | 49833 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:22.087493896 CEST | 8618 | 49833 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:22.087616920 CEST | 49833 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:22.096548080 CEST | 49833 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:22.250467062 CEST | 8618 | 49833 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:23.433232069 CEST | 49834 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:23.571595907 CEST | 8618 | 49834 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:23.577337027 CEST | 49834 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:23.589168072 CEST | 49834 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:23.747860909 CEST | 8618 | 49834 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:24.912126064 CEST | 49835 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:25.050409079 CEST | 8618 | 49835 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:25.050656080 CEST | 49835 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:25.064784050 CEST | 49835 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:25.251916885 CEST | 8618 | 49835 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:25.263648987 CEST | 8618 | 49835 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:27.157732964 CEST | 49836 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:27.295625925 CEST | 8618 | 49836 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:27.297693968 CEST | 49836 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:27.308172941 CEST | 49836 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:27.448641062 CEST | 8618 | 49836 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:28.609532118 CEST | 49837 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:28.750436068 CEST | 8618 | 49837 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:28.750648975 CEST | 49837 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:28.776165009 CEST | 49837 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:28.901355028 CEST | 8618 | 49837 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:28.901607037 CEST | 49837 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:28.915056944 CEST | 8618 | 49837 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:30.064330101 CEST | 49838 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:30.202029943 CEST | 8618 | 49838 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:30.202420950 CEST | 49838 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:30.232950926 CEST | 49838 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:30.365991116 CEST | 8618 | 49838 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:30.366178989 CEST | 49838 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:30.370999098 CEST | 8618 | 49838 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:31.505953074 CEST | 49839 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:31.646661997 CEST | 8618 | 49839 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:31.646995068 CEST | 49839 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:31.667562962 CEST | 49839 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:31.826571941 CEST | 8618 | 49839 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:32.980344057 CEST | 49840 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:33.117995977 CEST | 8618 | 49840 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:33.118130922 CEST | 49840 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:33.144499063 CEST | 49840 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:33.274204016 CEST | 8618 | 49840 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:33.279401064 CEST | 49840 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:33.282468081 CEST | 8618 | 49840 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:34.436629057 CEST | 49841 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:34.575421095 CEST | 8618 | 49841 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:34.575664997 CEST | 49841 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:34.585706949 CEST | 49841 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:34.726032019 CEST | 8618 | 49841 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:35.866450071 CEST | 49842 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:36.008327007 CEST | 8618 | 49842 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:36.008445978 CEST | 49842 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:36.016613960 CEST | 49842 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:36.204257011 CEST | 8618 | 49842 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:36.849234104 CEST | 8618 | 49842 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:38.033641100 CEST | 49843 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:38.171638966 CEST | 8618 | 49843 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:38.172161102 CEST | 49843 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:38.184686899 CEST | 49843 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:38.326219082 CEST | 8618 | 49843 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:39.477659941 CEST | 49845 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:39.615307093 CEST | 8618 | 49845 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:39.615540981 CEST | 49845 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:39.626179934 CEST | 49845 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:39.801764965 CEST | 8618 | 49845 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:40.949672937 CEST | 49850 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:41.088536024 CEST | 8618 | 49850 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:41.088852882 CEST | 49850 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:41.099371910 CEST | 49850 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:41.283108950 CEST | 8618 | 49850 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:41.292016029 CEST | 8618 | 49850 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:42.516666889 CEST | 49858 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:42.659941912 CEST | 8618 | 49858 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:42.667284012 CEST | 49858 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:42.693928957 CEST | 49858 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:42.825663090 CEST | 8618 | 49858 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:42.825879097 CEST | 49858 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:42.831651926 CEST | 8618 | 49858 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:44.030746937 CEST | 49866 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:44.168741941 CEST | 8618 | 49866 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:44.172888994 CEST | 49866 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:44.328027010 CEST | 8618 | 49866 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:44.328257084 CEST | 49866 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:44.424846888 CEST | 49866 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:44.563138962 CEST | 8618 | 49866 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:45.864420891 CEST | 49870 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:46.005435944 CEST | 8618 | 49870 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:46.005547047 CEST | 49870 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:46.047153950 CEST | 49870 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:46.164721966 CEST | 8618 | 49870 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:46.164808989 CEST | 49870 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:46.186281919 CEST | 8618 | 49870 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:47.448649883 CEST | 49873 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:47.587826967 CEST | 8618 | 49873 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:47.587986946 CEST | 49873 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:47.599541903 CEST | 49873 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:47.747620106 CEST | 8618 | 49873 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:48.899048090 CEST | 49875 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:49.037157059 CEST | 8618 | 49875 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:49.037377119 CEST | 49875 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:49.052481890 CEST | 49875 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:49.196381092 CEST | 8618 | 49875 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:50.359335899 CEST | 49876 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:50.496972084 CEST | 8618 | 49876 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:50.497108936 CEST | 49876 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:50.505295038 CEST | 49876 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:50.662307978 CEST | 8618 | 49876 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:51.810425043 CEST | 49877 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:51.948681116 CEST | 8618 | 49877 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:51.948844910 CEST | 49877 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:51.962057114 CEST | 49877 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:52.116298914 CEST | 8618 | 49877 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:53.262610912 CEST | 49878 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:53.400566101 CEST | 8618 | 49878 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:53.402676105 CEST | 49878 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:53.411948919 CEST | 49878 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:53.562161922 CEST | 8618 | 49878 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:54.716289043 CEST | 49879 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:54.854212046 CEST | 8618 | 49879 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:54.856750011 CEST | 49879 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:54.870035887 CEST | 49879 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:55.007710934 CEST | 8618 | 49879 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:55.007865906 CEST | 49879 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:55.008524895 CEST | 8618 | 49879 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:56.160233021 CEST | 49880 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:56.299182892 CEST | 8618 | 49880 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:56.302000999 CEST | 49880 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:56.314503908 CEST | 49880 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:56.458022118 CEST | 8618 | 49880 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:57.701575994 CEST | 49881 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:57.839539051 CEST | 8618 | 49881 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:57.839679956 CEST | 49881 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:57.856561899 CEST | 49881 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:58.000297070 CEST | 8618 | 49881 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:59.152896881 CEST | 49882 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:59.291796923 CEST | 8618 | 49882 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:16:59.291944027 CEST | 49882 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:59.302822113 CEST | 49882 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:16:59.463773012 CEST | 8618 | 49882 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:00.602782965 CEST | 49883 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:00.743309975 CEST | 8618 | 49883 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:00.743484974 CEST | 49883 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:00.751540899 CEST | 49883 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:00.894351959 CEST | 8618 | 49883 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:02.036940098 CEST | 49884 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:02.174793959 CEST | 8618 | 49884 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:02.175132036 CEST | 49884 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:02.181062937 CEST | 49884 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:02.376132011 CEST | 8618 | 49884 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:02.398453951 CEST | 8618 | 49884 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:03.539516926 CEST | 49885 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:03.678653955 CEST | 8618 | 49885 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:03.678802967 CEST | 49885 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:03.822181940 CEST | 49885 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:03.865979910 CEST | 8618 | 49885 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:03.869450092 CEST | 49885 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:03.961211920 CEST | 8618 | 49885 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:05.092715025 CEST | 49886 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:05.231043100 CEST | 8618 | 49886 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:05.231215000 CEST | 49886 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:05.237633944 CEST | 49886 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:05.411750078 CEST | 8618 | 49886 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:06.776956081 CEST | 49887 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:06.918227911 CEST | 8618 | 49887 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:06.918375969 CEST | 49887 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:06.924138069 CEST | 49887 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:07.086177111 CEST | 8618 | 49887 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:08.225198030 CEST | 49888 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:08.363306046 CEST | 8618 | 49888 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:08.363521099 CEST | 49888 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:08.379692078 CEST | 49888 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:08.518527985 CEST | 8618 | 49888 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:09.661597967 CEST | 49889 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:09.801161051 CEST | 8618 | 49889 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:09.801364899 CEST | 49889 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:09.810553074 CEST | 49889 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:09.969782114 CEST | 8618 | 49889 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:11.119174957 CEST | 49890 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:11.257997036 CEST | 8618 | 49890 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:11.258151054 CEST | 49890 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:11.267208099 CEST | 49890 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:11.442771912 CEST | 8618 | 49890 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:12.599644899 CEST | 49893 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:12.737704039 CEST | 8618 | 49893 | 31.3.152.100 | 192.168.2.7 |
Sep 21, 2021 22:17:12.738337040 CEST | 49893 | 8618 | 192.168.2.7 | 31.3.152.100 |
Sep 21, 2021 22:17:12.771708965 CEST | 49893 | 8618 | 192.168.2.7 | 31.3.152.100 |
UDP Packets |
---|
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Sep 21, 2021 22:14:57.777713060 CEST | 55411 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:14:57.801346064 CEST | 53 | 55411 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:14:58.781821012 CEST | 63668 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:14:58.828301907 CEST | 53 | 63668 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:02.354393005 CEST | 54640 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:02.397396088 CEST | 53 | 54640 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:22.285887957 CEST | 58739 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:22.307286024 CEST | 53 | 58739 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:24.460186005 CEST | 60338 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:24.592149019 CEST | 53 | 60338 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:25.918236971 CEST | 58717 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:26.049549103 CEST | 53 | 58717 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:27.402903080 CEST | 59762 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:27.536968946 CEST | 53 | 59762 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:28.868668079 CEST | 54329 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:29.001437902 CEST | 53 | 54329 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:30.266515970 CEST | 58052 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:30.289251089 CEST | 53 | 58052 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:30.316066980 CEST | 54008 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:30.446945906 CEST | 53 | 54008 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:31.276998043 CEST | 59451 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:31.332803965 CEST | 53 | 59451 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:32.396702051 CEST | 52914 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:32.526783943 CEST | 53 | 52914 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:33.825437069 CEST | 64569 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:33.956198931 CEST | 53 | 64569 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:35.281374931 CEST | 52816 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:35.411300898 CEST | 53 | 52816 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:36.714895964 CEST | 50781 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:36.847167969 CEST | 53 | 50781 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:38.206924915 CEST | 54230 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:38.337232113 CEST | 53 | 54230 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:39.561489105 CEST | 54911 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:39.582477093 CEST | 53 | 54911 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:39.755319118 CEST | 49958 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:39.890031099 CEST | 53 | 49958 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:40.236155033 CEST | 50860 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:40.258913994 CEST | 53 | 50860 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:42.242314100 CEST | 50452 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:42.375560999 CEST | 53 | 50452 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:43.148154974 CEST | 59730 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:43.171030045 CEST | 53 | 59730 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:43.221607924 CEST | 59310 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:43.243535995 CEST | 53 | 59310 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:44.241054058 CEST | 51919 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:44.372531891 CEST | 53 | 51919 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:45.717200994 CEST | 64296 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:45.848701954 CEST | 53 | 64296 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:47.189383984 CEST | 56680 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:47.322001934 CEST | 53 | 56680 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:49.464931011 CEST | 58820 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:49.596828938 CEST | 53 | 58820 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:51.093660116 CEST | 60983 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:51.229094982 CEST | 53 | 60983 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:52.554011106 CEST | 49247 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:52.689614058 CEST | 53 | 49247 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:54.077721119 CEST | 52286 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:54.209207058 CEST | 53 | 52286 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:56.061069965 CEST | 56064 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:56.198120117 CEST | 53 | 56064 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:15:58.621579885 CEST | 63744 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:15:58.752718925 CEST | 53 | 63744 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:00.508239031 CEST | 61457 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:00.639976978 CEST | 53 | 61457 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:00.866947889 CEST | 58367 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:00.888254881 CEST | 53 | 58367 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:01.862231016 CEST | 60599 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:01.882474899 CEST | 53 | 60599 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:01.966074944 CEST | 59571 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:02.096715927 CEST | 53 | 59571 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:02.515985966 CEST | 52689 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:02.536603928 CEST | 53 | 52689 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:03.042509079 CEST | 50290 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:03.066989899 CEST | 60427 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:03.070544958 CEST | 53 | 50290 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:03.087017059 CEST | 53 | 60427 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:03.399343967 CEST | 56209 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:03.531050920 CEST | 53 | 56209 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:04.142199993 CEST | 59582 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:04.166423082 CEST | 53 | 59582 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:04.852277994 CEST | 60949 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:04.984008074 CEST | 53 | 60949 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:05.290129900 CEST | 58542 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:05.310076952 CEST | 53 | 58542 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:06.688348055 CEST | 59179 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:06.819529057 CEST | 53 | 59179 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:07.282896996 CEST | 60927 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:07.303368092 CEST | 53 | 60927 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:08.135153055 CEST | 57854 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:08.267622948 CEST | 53 | 57854 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:09.993916035 CEST | 62026 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:10.124789000 CEST | 53 | 62026 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:10.576878071 CEST | 59453 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:10.661528111 CEST | 53 | 59453 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:11.559062004 CEST | 62468 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:11.671216965 CEST | 52563 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:11.690999985 CEST | 53 | 62468 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:11.692545891 CEST | 53 | 52563 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:12.122994900 CEST | 54721 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:12.141154051 CEST | 53 | 54721 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:12.677517891 CEST | 62826 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:12.698688984 CEST | 53 | 62826 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:13.042880058 CEST | 62046 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:13.173664093 CEST | 53 | 62046 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:14.545365095 CEST | 51223 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:14.678241968 CEST | 53 | 51223 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:15.980515957 CEST | 63908 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:16.113316059 CEST | 53 | 63908 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:17.420207977 CEST | 49226 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:17.552184105 CEST | 53 | 49226 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:18.925055027 CEST | 60212 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:19.057770967 CEST | 53 | 60212 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:20.364007950 CEST | 58867 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:20.494051933 CEST | 53 | 58867 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:21.818285942 CEST | 50864 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:21.947622061 CEST | 53 | 50864 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:23.286195993 CEST | 61504 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:23.415009022 CEST | 53 | 61504 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:24.779416084 CEST | 60231 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:24.910470009 CEST | 53 | 60231 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:27.011946917 CEST | 50095 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:27.142555952 CEST | 53 | 50095 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:28.469935894 CEST | 59654 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:28.602499008 CEST | 53 | 59654 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:29.931039095 CEST | 58233 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:30.061834097 CEST | 53 | 58233 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:31.374743938 CEST | 56822 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:31.504631042 CEST | 53 | 56822 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:32.843729973 CEST | 62572 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:32.975001097 CEST | 53 | 62572 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:34.302947044 CEST | 57179 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:34.435005903 CEST | 53 | 57179 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:35.734312057 CEST | 56124 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:35.865314960 CEST | 53 | 56124 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:37.896574974 CEST | 62287 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:38.031744957 CEST | 53 | 62287 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:38.492863894 CEST | 54644 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:38.523652077 CEST | 53 | 54644 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:39.344706059 CEST | 59159 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:39.476430893 CEST | 53 | 59159 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:39.902637005 CEST | 57924 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:39.937939882 CEST | 53 | 57924 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:40.816515923 CEST | 51712 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:40.947170019 CEST | 53 | 51712 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:42.382486105 CEST | 58865 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:42.515451908 CEST | 53 | 58865 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:43.892992020 CEST | 64337 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:44.025924921 CEST | 53 | 64337 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:45.695313931 CEST | 50407 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:45.825886965 CEST | 53 | 50407 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:47.302278996 CEST | 61075 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:47.432734013 CEST | 53 | 61075 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:48.766875029 CEST | 54952 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:48.898102045 CEST | 53 | 54952 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:50.227271080 CEST | 59186 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:50.358386993 CEST | 53 | 59186 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:51.676893950 CEST | 52280 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:51.807924032 CEST | 53 | 52280 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:53.129528046 CEST | 51794 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:53.258599997 CEST | 53 | 51794 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:54.584326029 CEST | 50815 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:54.715018034 CEST | 53 | 50815 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:56.018671989 CEST | 58498 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:56.151295900 CEST | 53 | 58498 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:57.570435047 CEST | 56862 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:57.700181007 CEST | 53 | 56862 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:16:59.018603086 CEST | 61807 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:16:59.150486946 CEST | 53 | 61807 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:00.469460011 CEST | 52009 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:00.601574898 CEST | 53 | 52009 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:01.905966043 CEST | 58648 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:02.036047935 CEST | 53 | 58648 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:03.404933929 CEST | 59337 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:03.537657976 CEST | 53 | 59337 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:04.934432030 CEST | 59269 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:05.091638088 CEST | 53 | 59269 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:06.638662100 CEST | 49802 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:06.771140099 CEST | 53 | 49802 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:08.093183041 CEST | 50706 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:08.223980904 CEST | 53 | 50706 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:09.530169964 CEST | 55153 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:09.661106110 CEST | 53 | 55153 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:10.985491037 CEST | 59744 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:11.117923021 CEST | 53 | 59744 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:12.152389050 CEST | 59987 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:12.189990044 CEST | 53 | 59987 | 8.8.8.8 | 192.168.2.7 |
Sep 21, 2021 22:17:12.456861019 CEST | 61272 | 53 | 192.168.2.7 | 8.8.8.8 |
Sep 21, 2021 22:17:12.589910030 CEST | 53 | 61272 | 8.8.8.8 | 192.168.2.7 |
DNS Queries |
---|
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Sep 21, 2021 22:14:57.777713060 CEST | 192.168.2.7 | 8.8.8.8 | 0x4910 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:14:58.781821012 CEST | 192.168.2.7 | 8.8.8.8 | 0x9105 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:24.460186005 CEST | 192.168.2.7 | 8.8.8.8 | 0xb34b | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:25.918236971 CEST | 192.168.2.7 | 8.8.8.8 | 0x527b | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:27.402903080 CEST | 192.168.2.7 | 8.8.8.8 | 0xda9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:28.868668079 CEST | 192.168.2.7 | 8.8.8.8 | 0x7943 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:30.266515970 CEST | 192.168.2.7 | 8.8.8.8 | 0x268b | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:30.316066980 CEST | 192.168.2.7 | 8.8.8.8 | 0xa0cd | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:31.276998043 CEST | 192.168.2.7 | 8.8.8.8 | 0x1c6e | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:32.396702051 CEST | 192.168.2.7 | 8.8.8.8 | 0x6a9d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:33.825437069 CEST | 192.168.2.7 | 8.8.8.8 | 0x93ee | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:35.281374931 CEST | 192.168.2.7 | 8.8.8.8 | 0x8d53 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:36.714895964 CEST | 192.168.2.7 | 8.8.8.8 | 0xdf7f | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:38.206924915 CEST | 192.168.2.7 | 8.8.8.8 | 0xb202 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:39.561489105 CEST | 192.168.2.7 | 8.8.8.8 | 0x5ace | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:39.755319118 CEST | 192.168.2.7 | 8.8.8.8 | 0x22d3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:40.236155033 CEST | 192.168.2.7 | 8.8.8.8 | 0x7cec | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:42.242314100 CEST | 192.168.2.7 | 8.8.8.8 | 0x9f88 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:44.241054058 CEST | 192.168.2.7 | 8.8.8.8 | 0x4d65 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:45.717200994 CEST | 192.168.2.7 | 8.8.8.8 | 0xce7a | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:47.189383984 CEST | 192.168.2.7 | 8.8.8.8 | 0x60ee | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:49.464931011 CEST | 192.168.2.7 | 8.8.8.8 | 0xf470 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:51.093660116 CEST | 192.168.2.7 | 8.8.8.8 | 0xd4bd | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:52.554011106 CEST | 192.168.2.7 | 8.8.8.8 | 0x53bb | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:54.077721119 CEST | 192.168.2.7 | 8.8.8.8 | 0xe6f1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:56.061069965 CEST | 192.168.2.7 | 8.8.8.8 | 0xfa91 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:15:58.621579885 CEST | 192.168.2.7 | 8.8.8.8 | 0xc4ac | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:00.508239031 CEST | 192.168.2.7 | 8.8.8.8 | 0xa02c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:01.966074944 CEST | 192.168.2.7 | 8.8.8.8 | 0x9826 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:03.399343967 CEST | 192.168.2.7 | 8.8.8.8 | 0x2245 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:04.852277994 CEST | 192.168.2.7 | 8.8.8.8 | 0x760d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:06.688348055 CEST | 192.168.2.7 | 8.8.8.8 | 0x95d4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:08.135153055 CEST | 192.168.2.7 | 8.8.8.8 | 0xa131 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:09.993916035 CEST | 192.168.2.7 | 8.8.8.8 | 0x6e88 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:11.559062004 CEST | 192.168.2.7 | 8.8.8.8 | 0x9067 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:13.042880058 CEST | 192.168.2.7 | 8.8.8.8 | 0x3cc4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:14.545365095 CEST | 192.168.2.7 | 8.8.8.8 | 0x10b1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:15.980515957 CEST | 192.168.2.7 | 8.8.8.8 | 0xc2dc | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:17.420207977 CEST | 192.168.2.7 | 8.8.8.8 | 0x684c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:18.925055027 CEST | 192.168.2.7 | 8.8.8.8 | 0x2834 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:20.364007950 CEST | 192.168.2.7 | 8.8.8.8 | 0xd34e | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:21.818285942 CEST | 192.168.2.7 | 8.8.8.8 | 0x7593 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:23.286195993 CEST | 192.168.2.7 | 8.8.8.8 | 0xb7a5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:24.779416084 CEST | 192.168.2.7 | 8.8.8.8 | 0x4071 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:27.011946917 CEST | 192.168.2.7 | 8.8.8.8 | 0x9fb6 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:28.469935894 CEST | 192.168.2.7 | 8.8.8.8 | 0xb6b8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:29.931039095 CEST | 192.168.2.7 | 8.8.8.8 | 0xa294 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:31.374743938 CEST | 192.168.2.7 | 8.8.8.8 | 0x3dad | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:32.843729973 CEST | 192.168.2.7 | 8.8.8.8 | 0xbcce | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:34.302947044 CEST | 192.168.2.7 | 8.8.8.8 | 0x401d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:35.734312057 CEST | 192.168.2.7 | 8.8.8.8 | 0xb093 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:37.896574974 CEST | 192.168.2.7 | 8.8.8.8 | 0xb8e1 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:39.344706059 CEST | 192.168.2.7 | 8.8.8.8 | 0x723e | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:40.816515923 CEST | 192.168.2.7 | 8.8.8.8 | 0xad60 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:42.382486105 CEST | 192.168.2.7 | 8.8.8.8 | 0xf8ac | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:43.892992020 CEST | 192.168.2.7 | 8.8.8.8 | 0x42fe | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:45.695313931 CEST | 192.168.2.7 | 8.8.8.8 | 0x4c86 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:47.302278996 CEST | 192.168.2.7 | 8.8.8.8 | 0x8ea9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:48.766875029 CEST | 192.168.2.7 | 8.8.8.8 | 0x786a | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:50.227271080 CEST | 192.168.2.7 | 8.8.8.8 | 0xe138 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:51.676893950 CEST | 192.168.2.7 | 8.8.8.8 | 0x7d08 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:53.129528046 CEST | 192.168.2.7 | 8.8.8.8 | 0xfd61 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:54.584326029 CEST | 192.168.2.7 | 8.8.8.8 | 0x58d3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:56.018671989 CEST | 192.168.2.7 | 8.8.8.8 | 0x1e78 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:57.570435047 CEST | 192.168.2.7 | 8.8.8.8 | 0xf320 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:16:59.018603086 CEST | 192.168.2.7 | 8.8.8.8 | 0x1b6c | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:00.469460011 CEST | 192.168.2.7 | 8.8.8.8 | 0xac6d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:01.905966043 CEST | 192.168.2.7 | 8.8.8.8 | 0x4dc3 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:03.404933929 CEST | 192.168.2.7 | 8.8.8.8 | 0x9474 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:04.934432030 CEST | 192.168.2.7 | 8.8.8.8 | 0xbf93 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:06.638662100 CEST | 192.168.2.7 | 8.8.8.8 | 0x6b1b | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:08.093183041 CEST | 192.168.2.7 | 8.8.8.8 | 0xa300 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:09.530169964 CEST | 192.168.2.7 | 8.8.8.8 | 0x8b1d | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:10.985491037 CEST | 192.168.2.7 | 8.8.8.8 | 0x3079 | Standard query (0) | A (IP address) | IN (0x0001) | |
Sep 21, 2021 22:17:12.456861019 CEST | 192.168.2.7 | 8.8.8.8 | 0x5a4e | Standard query (0) | A (IP address) | IN (0x0001) |
DNS Answers |
---|
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Sep 21, 2021 22:14:57.801346064 CEST | 8.8.8.8 | 192.168.2.7 | 0x4910 | No error (0) | odc-web-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:14:58.828301907 CEST | 8.8.8.8 | 192.168.2.7 | 0x9105 | No error (0) | sn-files.fe.1drv.com | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:14:58.828301907 CEST | 8.8.8.8 | 192.168.2.7 | 0x9105 | No error (0) | odc-sn-files-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:24.592149019 CEST | 8.8.8.8 | 192.168.2.7 | 0xb34b | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:26.049549103 CEST | 8.8.8.8 | 192.168.2.7 | 0x527b | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:27.536968946 CEST | 8.8.8.8 | 192.168.2.7 | 0xda9 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:29.001437902 CEST | 8.8.8.8 | 192.168.2.7 | 0x7943 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:30.289251089 CEST | 8.8.8.8 | 192.168.2.7 | 0x268b | No error (0) | odc-web-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:30.446945906 CEST | 8.8.8.8 | 192.168.2.7 | 0xa0cd | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:31.332803965 CEST | 8.8.8.8 | 192.168.2.7 | 0x1c6e | No error (0) | sn-files.fe.1drv.com | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:31.332803965 CEST | 8.8.8.8 | 192.168.2.7 | 0x1c6e | No error (0) | odc-sn-files-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:32.526783943 CEST | 8.8.8.8 | 192.168.2.7 | 0x6a9d | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:33.956198931 CEST | 8.8.8.8 | 192.168.2.7 | 0x93ee | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:35.411300898 CEST | 8.8.8.8 | 192.168.2.7 | 0x8d53 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:36.847167969 CEST | 8.8.8.8 | 192.168.2.7 | 0xdf7f | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:38.337232113 CEST | 8.8.8.8 | 192.168.2.7 | 0xb202 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:39.582477093 CEST | 8.8.8.8 | 192.168.2.7 | 0x5ace | No error (0) | odc-web-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:39.890031099 CEST | 8.8.8.8 | 192.168.2.7 | 0x22d3 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:40.258913994 CEST | 8.8.8.8 | 192.168.2.7 | 0x7cec | No error (0) | sn-files.fe.1drv.com | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:40.258913994 CEST | 8.8.8.8 | 192.168.2.7 | 0x7cec | No error (0) | odc-sn-files-geo.onedrive.akadns.net | CNAME (Canonical name) | IN (0x0001) | ||
Sep 21, 2021 22:15:42.375560999 CEST | 8.8.8.8 | 192.168.2.7 | 0x9f88 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:44.372531891 CEST | 8.8.8.8 | 192.168.2.7 | 0x4d65 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:45.848701954 CEST | 8.8.8.8 | 192.168.2.7 | 0xce7a | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:47.322001934 CEST | 8.8.8.8 | 192.168.2.7 | 0x60ee | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:49.596828938 CEST | 8.8.8.8 | 192.168.2.7 | 0xf470 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:51.229094982 CEST | 8.8.8.8 | 192.168.2.7 | 0xd4bd | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:52.689614058 CEST | 8.8.8.8 | 192.168.2.7 | 0x53bb | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:54.209207058 CEST | 8.8.8.8 | 192.168.2.7 | 0xe6f1 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:56.198120117 CEST | 8.8.8.8 | 192.168.2.7 | 0xfa91 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:15:58.752718925 CEST | 8.8.8.8 | 192.168.2.7 | 0xc4ac | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:00.639976978 CEST | 8.8.8.8 | 192.168.2.7 | 0xa02c | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:02.096715927 CEST | 8.8.8.8 | 192.168.2.7 | 0x9826 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:03.531050920 CEST | 8.8.8.8 | 192.168.2.7 | 0x2245 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:04.984008074 CEST | 8.8.8.8 | 192.168.2.7 | 0x760d | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:06.819529057 CEST | 8.8.8.8 | 192.168.2.7 | 0x95d4 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:08.267622948 CEST | 8.8.8.8 | 192.168.2.7 | 0xa131 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:10.124789000 CEST | 8.8.8.8 | 192.168.2.7 | 0x6e88 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:11.690999985 CEST | 8.8.8.8 | 192.168.2.7 | 0x9067 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:13.173664093 CEST | 8.8.8.8 | 192.168.2.7 | 0x3cc4 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:14.678241968 CEST | 8.8.8.8 | 192.168.2.7 | 0x10b1 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:16.113316059 CEST | 8.8.8.8 | 192.168.2.7 | 0xc2dc | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:17.552184105 CEST | 8.8.8.8 | 192.168.2.7 | 0x684c | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:19.057770967 CEST | 8.8.8.8 | 192.168.2.7 | 0x2834 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:20.494051933 CEST | 8.8.8.8 | 192.168.2.7 | 0xd34e | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:21.947622061 CEST | 8.8.8.8 | 192.168.2.7 | 0x7593 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:23.415009022 CEST | 8.8.8.8 | 192.168.2.7 | 0xb7a5 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:24.910470009 CEST | 8.8.8.8 | 192.168.2.7 | 0x4071 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:27.142555952 CEST | 8.8.8.8 | 192.168.2.7 | 0x9fb6 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:28.602499008 CEST | 8.8.8.8 | 192.168.2.7 | 0xb6b8 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:30.061834097 CEST | 8.8.8.8 | 192.168.2.7 | 0xa294 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:31.504631042 CEST | 8.8.8.8 | 192.168.2.7 | 0x3dad | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:32.975001097 CEST | 8.8.8.8 | 192.168.2.7 | 0xbcce | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:34.435005903 CEST | 8.8.8.8 | 192.168.2.7 | 0x401d | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:35.865314960 CEST | 8.8.8.8 | 192.168.2.7 | 0xb093 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:38.031744957 CEST | 8.8.8.8 | 192.168.2.7 | 0xb8e1 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:39.476430893 CEST | 8.8.8.8 | 192.168.2.7 | 0x723e | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:40.947170019 CEST | 8.8.8.8 | 192.168.2.7 | 0xad60 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:42.515451908 CEST | 8.8.8.8 | 192.168.2.7 | 0xf8ac | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:44.025924921 CEST | 8.8.8.8 | 192.168.2.7 | 0x42fe | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:45.825886965 CEST | 8.8.8.8 | 192.168.2.7 | 0x4c86 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:47.432734013 CEST | 8.8.8.8 | 192.168.2.7 | 0x8ea9 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:48.898102045 CEST | 8.8.8.8 | 192.168.2.7 | 0x786a | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:50.358386993 CEST | 8.8.8.8 | 192.168.2.7 | 0xe138 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:51.807924032 CEST | 8.8.8.8 | 192.168.2.7 | 0x7d08 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:53.258599997 CEST | 8.8.8.8 | 192.168.2.7 | 0xfd61 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:54.715018034 CEST | 8.8.8.8 | 192.168.2.7 | 0x58d3 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:56.151295900 CEST | 8.8.8.8 | 192.168.2.7 | 0x1e78 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:57.700181007 CEST | 8.8.8.8 | 192.168.2.7 | 0xf320 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:16:59.150486946 CEST | 8.8.8.8 | 192.168.2.7 | 0x1b6c | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:00.601574898 CEST | 8.8.8.8 | 192.168.2.7 | 0xac6d | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:02.036047935 CEST | 8.8.8.8 | 192.168.2.7 | 0x4dc3 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:03.537657976 CEST | 8.8.8.8 | 192.168.2.7 | 0x9474 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:05.091638088 CEST | 8.8.8.8 | 192.168.2.7 | 0xbf93 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:06.771140099 CEST | 8.8.8.8 | 192.168.2.7 | 0x6b1b | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:08.223980904 CEST | 8.8.8.8 | 192.168.2.7 | 0xa300 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:09.661106110 CEST | 8.8.8.8 | 192.168.2.7 | 0x8b1d | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:11.117923021 CEST | 8.8.8.8 | 192.168.2.7 | 0x3079 | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) | ||
Sep 21, 2021 22:17:12.589910030 CEST | 8.8.8.8 | 192.168.2.7 | 0x5a4e | No error (0) | 31.3.152.100 | A (IP address) | IN (0x0001) |
Code Manipulations |
---|
Statistics |
---|
CPU Usage |
---|
Click to jump to process
Memory Usage |
---|
Click to jump to process
High Level Behavior Distribution |
---|
back
Click to dive into process behavior distribution
Behavior |
---|
Click to jump to process
System Behavior |
---|
General |
---|
Start time: | 22:14:56 |
Start date: | 21/09/2021 |
Path: | C:\Users\user\Desktop\yVhvGnsUpL.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1133568 bytes |
MD5 hash: | CF98D2D4D4555323842C8371DB09347E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Borland Delphi |
Reputation: | low |
General |
---|
Start time: | 22:15:18 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\DpiScaling.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xb30000 |
File size: | 77312 bytes |
MD5 hash: | 302B1BBDBF4D96BEE99C6B45680CEB5E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | moderate |
General |
---|
Start time: | 22:15:24 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x870000 |
File size: | 232960 bytes |
MD5 hash: | F3BDBE3BB6F734E357235F4D5898582D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 22:15:24 |
Start date: | 21/09/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 22:15:25 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x870000 |
File size: | 232960 bytes |
MD5 hash: | F3BDBE3BB6F734E357235F4D5898582D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 22:15:25 |
Start date: | 21/09/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
General |
---|
Start time: | 22:15:25 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\cmd.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x870000 |
File size: | 232960 bytes |
MD5 hash: | F3BDBE3BB6F734E357235F4D5898582D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
General |
---|
Start time: | 22:15:26 |
Start date: | 21/09/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
General |
---|
Start time: | 22:15:26 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\reg.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x11a0000 |
File size: | 59392 bytes |
MD5 hash: | CEE2A7E57DF2A159A065A34913A055C2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
General |
---|
Start time: | 22:15:27 |
Start date: | 21/09/2021 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff774ee0000 |
File size: | 625664 bytes |
MD5 hash: | EA777DEEA782E8B4D7C7C33BBF8A4496 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
General |
---|
Start time: | 22:15:27 |
Start date: | 21/09/2021 |
Path: | C:\Users\Public\Libraries\Srakjle\Srakjle.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1133568 bytes |
MD5 hash: | CF98D2D4D4555323842C8371DB09347E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Borland Delphi |
Antivirus matches: |
|
General |
---|
Start time: | 22:15:36 |
Start date: | 21/09/2021 |
Path: | C:\Users\Public\Libraries\Srakjle\Srakjle.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 1133568 bytes |
MD5 hash: | CF98D2D4D4555323842C8371DB09347E |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | Borland Delphi |
General |
---|
Start time: | 22:15:58 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\mobsync.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1160000 |
File size: | 93184 bytes |
MD5 hash: | 44C19378FA529DD88674BAF647EBDC3C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
General |
---|
Start time: | 22:16:14 |
Start date: | 21/09/2021 |
Path: | C:\Windows\SysWOW64\mobsync.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1160000 |
File size: | 93184 bytes |
MD5 hash: | 44C19378FA529DD88674BAF647EBDC3C |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Disassembly |
---|
Code Analysis |
---|
Executed Functions |
---|
Function 0040CD09, Relevance: 84.1, APIs: 28, Strings: 20, Instructions: 98libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D0B5, Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 88sleepCOMMON
C-Code - Quality: 46% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 71% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00416D9E, Relevance: 3.0, APIs: 2, Instructions: 41COMMON
C-Code - Quality: 82% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0042F8B9, Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040C2BE, Relevance: 63.8, APIs: 16, Strings: 20, Instructions: 774synchronizationCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00411929, Relevance: 30.5, APIs: 6, Strings: 11, Instructions: 743sleepnetworkthreadCOMMON
C-Code - Quality: 85% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 84% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404A08, Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 60networkCOMMON
C-Code - Quality: 60% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043D15F, Relevance: 4.6, APIs: 3, Instructions: 115COMMON
C-Code - Quality: 84% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 77% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 66% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044765D, Relevance: 4.5, APIs: 3, Instructions: 37COMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043F9DA, Relevance: 3.0, APIs: 2, Instructions: 44memoryCOMMON
C-Code - Quality: 96% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401646, Relevance: 3.0, APIs: 2, Instructions: 36COMMON
C-Code - Quality: 80% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043CFE1, Relevance: 3.0, APIs: 2, Instructions: 35COMMON
C-Code - Quality: 92% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043D03A, Relevance: 3.0, APIs: 2, Instructions: 34COMMON
C-Code - Quality: 91% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402D0D, Relevance: 1.6, APIs: 1, Instructions: 89COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00448354, Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043F348, Relevance: 1.5, APIs: 1, Instructions: 39memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043F98C, Relevance: 1.5, APIs: 1, Instructions: 32memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
C-Code - Quality: 86% |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040A012, Relevance: 24.7, APIs: 8, Strings: 6, Instructions: 152fileCOMMON
C-Code - Quality: 95% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040A22D, Relevance: 22.9, APIs: 8, Strings: 5, Instructions: 143fileCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 94% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004163AD, Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 42serviceCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00411205, Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 479registrylibraryloaderCOMMONCrypto
C-Code - Quality: 78% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044D3FA, Relevance: 10.1, APIs: 1, Strings: 4, Instructions: 1381COMMONCrypto
C-Code - Quality: 77% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044A343, Relevance: 4.7, APIs: 3, Instructions: 205COMMON
C-Code - Quality: 92% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00442424, Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 30timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004153F5, Relevance: 3.2, APIs: 2, Instructions: 245fileCOMMON
C-Code - Quality: 90% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004061C3, Relevance: 3.1, APIs: 2, Instructions: 86fileCOMMON
C-Code - Quality: 82% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004223C0, Relevance: 1.6, Strings: 1, Instructions: 342COMMON
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044A21B, Relevance: 1.6, APIs: 1, Instructions: 63COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044A2B6, Relevance: 1.5, APIs: 1, Instructions: 42COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044A1D0, Relevance: 1.5, APIs: 1, Instructions: 31COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D1E5, Relevance: 1.5, APIs: 1, Instructions: 20COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043820B, Relevance: 1.5, Strings: 1, Instructions: 214COMMON
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004340D5, Relevance: .3, Instructions: 331COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043843A, Relevance: .2, Instructions: 237COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00423098, Relevance: .2, Instructions: 195COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040F15D, Relevance: .1, Instructions: 90COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040B0E2, Relevance: 40.5, APIs: 6, Strings: 17, Instructions: 280registryCOMMON
C-Code - Quality: 98% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004064A2, Relevance: 24.8, APIs: 9, Strings: 5, Instructions: 345fileCOMMON
C-Code - Quality: 77% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00449546, Relevance: 19.6, APIs: 13, Instructions: 114COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 41% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00409195, Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 156sleepCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004053ED, Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 155windowmemoryCOMMON
C-Code - Quality: 76% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 93% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 83% |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004062D8, Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 106fileCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00410305, Relevance: 10.9, APIs: 5, Strings: 1, Instructions: 374filesleepCOMMON
C-Code - Quality: 94% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 75% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004501D3, Relevance: 10.6, APIs: 7, Instructions: 80COMMON
C-Code - Quality: 90% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0044917A, Relevance: 10.6, APIs: 7, Instructions: 65COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004350B5, Relevance: 10.6, APIs: 7, Instructions: 60COMMON
C-Code - Quality: 95% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040511B, Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 38synchronizationCOMMON
C-Code - Quality: 86% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043F14E, Relevance: 9.2, APIs: 6, Instructions: 200COMMON
C-Code - Quality: 80% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004093AD, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 65threadCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D3F7, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 46processCOMMON
C-Code - Quality: 50% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040519B, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 44synchronizationCOMMON
C-Code - Quality: 83% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043B2BA, Relevance: 7.7, APIs: 5, Instructions: 222COMMON
C-Code - Quality: 96% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404486, Relevance: 7.7, APIs: 1, Strings: 4, Instructions: 208sleepCOMMON
C-Code - Quality: 68% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043E550, Relevance: 7.7, APIs: 5, Instructions: 187COMMON
C-Code - Quality: 77% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004493AC, Relevance: 7.6, APIs: 5, Instructions: 110COMMON
C-Code - Quality: 81% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004013AD, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401468, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00401485, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0045029A, Relevance: 6.2, APIs: 4, Instructions: 152COMMON
C-Code - Quality: 94% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043C481, Relevance: 6.1, APIs: 4, Instructions: 133COMMON
C-Code - Quality: 95% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043D288, Relevance: 6.1, APIs: 4, Instructions: 63COMMON
C-Code - Quality: 82% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0043D307, Relevance: 6.1, APIs: 4, Instructions: 59COMMON
C-Code - Quality: 82% |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 95% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 92% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 96% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040414D, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 93sleepCOMMON
C-Code - Quality: 90% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040F4FE, Relevance: 5.1, APIs: 4, Instructions: 124COMMON
C-Code - Quality: 55% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Executed Functions |
---|
Non-executed Functions |
---|
Function 03B80B99, Relevance: .0, Instructions: 13COMMON
Memory Dump Source |
|
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Executed Functions |
---|
Function 0070CB4E, Relevance: 4.5, APIs: 3, Instructions: 20COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 18% |
|
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006FF8B9, Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DC2BE, Relevance: 55.0, APIs: 15, Strings: 16, Instructions: 774synchronizationCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Non-executed Functions |
---|
C-Code - Quality: 81% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DFAC7, Relevance: 31.7, APIs: 7, Strings: 11, Instructions: 194threadCOMMON
C-Code - Quality: 82% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 79% |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D55EA, Relevance: 30.0, APIs: 15, Strings: 2, Instructions: 283pipesleepfileCOMMON
C-Code - Quality: 81% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DA012, Relevance: 24.7, APIs: 8, Strings: 6, Instructions: 152fileCOMMON
C-Code - Quality: 95% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DA22D, Relevance: 22.9, APIs: 8, Strings: 5, Instructions: 143fileCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00712C8E, Relevance: 16.1, APIs: 7, Strings: 2, Instructions: 370timeCOMMON
C-Code - Quality: 76% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 86% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E7754, Relevance: 13.6, APIs: 9, Instructions: 147fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E1205, Relevance: 11.0, APIs: 4, Strings: 2, Instructions: 479registrylibraryloaderCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E2BE1, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 97libraryloadershutdownCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9EF4, Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 49fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D77EC, Relevance: 9.3, APIs: 6, Instructions: 324fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DD0B5, Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 88sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D7C55, Relevance: 7.7, APIs: 5, Instructions: 246fileCOMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0071A890, Relevance: 7.7, APIs: 5, Instructions: 188COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00719F58, Relevance: 6.2, APIs: 4, Instructions: 236COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D5C8B, Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 226filenetworkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DCD09, Relevance: 82.3, APIs: 28, Strings: 19, Instructions: 98libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E4906, Relevance: 49.3, APIs: 27, Strings: 1, Instructions: 298windowmemoryCOMMON
C-Code - Quality: 81% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DFD95, Relevance: 40.4, APIs: 17, Strings: 6, Instructions: 181synchronizationCOMMON
C-Code - Quality: 94% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DB0E2, Relevance: 38.8, APIs: 6, Strings: 16, Instructions: 280registryCOMMON
C-Code - Quality: 98% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E69CC, Relevance: 38.7, APIs: 12, Strings: 10, Instructions: 185synchronizationCOMMON
C-Code - Quality: 86% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D1A64, Relevance: 35.2, APIs: 16, Strings: 4, Instructions: 155fileCOMMON
C-Code - Quality: 95% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DA987, Relevance: 30.1, APIs: 7, Strings: 10, Instructions: 324fileCOMMON
C-Code - Quality: 95% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007176AD, Relevance: 27.4, APIs: 18, Instructions: 419COMMON
C-Code - Quality: 87% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D64A2, Relevance: 24.8, APIs: 9, Strings: 5, Instructions: 345fileCOMMON
C-Code - Quality: 77% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E2CEE, Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 83clipboardmemoryCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E8E5A, Relevance: 22.8, APIs: 12, Strings: 1, Instructions: 74windowCOMMON
C-Code - Quality: 64% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070F5AB, Relevance: 22.8, APIs: 15, Instructions: 296COMMON
C-Code - Quality: 91% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E7C05, Relevance: 21.2, APIs: 5, Strings: 7, Instructions: 212registryCOMMON
C-Code - Quality: 63% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00719546, Relevance: 19.6, APIs: 13, Instructions: 114COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 105DA3B9, Relevance: 19.6, APIs: 13, Instructions: 114COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DCE44, Relevance: 19.4, APIs: 7, Strings: 4, Instructions: 186processsynchronizationCOMMON
C-Code - Quality: 97% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00718880, Relevance: 18.4, APIs: 12, Instructions: 376COMMON
C-Code - Quality: 97% |
|
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 41% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9195, Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 156sleepCOMMON
C-Code - Quality: 89% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070558A, Relevance: 16.6, APIs: 11, Instructions: 116COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D53ED, Relevance: 15.9, APIs: 6, Strings: 3, Instructions: 155windowmemoryCOMMON
C-Code - Quality: 76% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 84% |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E8F59, Relevance: 15.8, APIs: 3, Strings: 6, Instructions: 89memoryCOMMON
C-Code - Quality: 59% |
|
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E2D6D, Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 49clipboardCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00711BEE, Relevance: 15.1, APIs: 10, Instructions: 54COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E5938, Relevance: 14.2, APIs: 6, Strings: 2, Instructions: 176sleeptimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00714B6E, Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 152fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E3673, Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 112sleepfileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D8892, Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 63windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E8D28, Relevance: 14.0, APIs: 7, Strings: 1, Instructions: 48windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00716532, Relevance: 13.8, APIs: 9, Instructions: 300COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0071E8D5, Relevance: 13.8, APIs: 9, Instructions: 268COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E3D1B, Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 108filesynchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D62D8, Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 106fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E65DD, Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 67serviceCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E650F, Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 45serviceCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E63AD, Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 42serviceCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007145EF, Relevance: 12.2, APIs: 8, Instructions: 216COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E0305, Relevance: 10.9, APIs: 5, Strings: 1, Instructions: 374filesleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00718CA5, Relevance: 10.7, APIs: 7, Instructions: 204COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00712E63, Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 171timeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D4FAD, Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 112timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D4E9A, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 96timethreadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007201D3, Relevance: 10.6, APIs: 7, Instructions: 80COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DE7E5, Relevance: 10.6, APIs: 7, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9634, Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 74timeCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E6F19, Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 71sleeplibraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E7947, Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 69fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0071917A, Relevance: 10.6, APIs: 7, Instructions: 65COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007050B5, Relevance: 10.6, APIs: 7, Instructions: 60COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9F83, Relevance: 10.5, APIs: 2, Strings: 4, Instructions: 49fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D511B, Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 38synchronizationCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E6737, Relevance: 10.5, APIs: 4, Strings: 2, Instructions: 30sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00705799, Relevance: 9.3, APIs: 6, Instructions: 284COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 105C660C, Relevance: 9.3, APIs: 6, Instructions: 284COMMON
C-Code - Quality: 70% |
|
APIs |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070F14E, Relevance: 9.2, APIs: 6, Instructions: 200COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D8C71, Relevance: 9.2, APIs: 6, Instructions: 168sleepCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00711CE2, Relevance: 9.0, APIs: 6, Instructions: 50COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D8742, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 70threadCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D93AD, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 65threadCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E8DDA, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 57registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DD3F7, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 46processCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D519B, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 44synchronizationCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070CB8F, Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 38libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070B2BA, Relevance: 7.7, APIs: 5, Instructions: 222COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D4486, Relevance: 7.7, APIs: 1, Strings: 4, Instructions: 208sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070E550, Relevance: 7.7, APIs: 5, Instructions: 187COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070D66D, Relevance: 7.6, APIs: 5, Instructions: 129COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 105CE4E0, Relevance: 7.6, APIs: 5, Instructions: 129COMMON
C-Code - Quality: 83% |
|
APIs |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 105C63FD, Relevance: 7.6, APIs: 5, Instructions: 116COMMON
C-Code - Quality: 22% |
|
APIs |
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007193AC, Relevance: 7.6, APIs: 5, Instructions: 110COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DA523, Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 103sleepCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D1BCD, Relevance: 7.6, APIs: 5, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 007175DA, Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00711D66, Relevance: 7.6, APIs: 5, Instructions: 53COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00718C3C, Relevance: 7.5, APIs: 5, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070D8BC, Relevance: 7.5, APIs: 5, Instructions: 30COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E0D8E, Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 179registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E576E, Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 128fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E0A30, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 42registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E094E, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 40registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E0B4C, Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 39registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D13AD, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D1468, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D1485, Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 7libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00713812, Relevance: 6.3, APIs: 4, Instructions: 305COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0072029A, Relevance: 6.2, APIs: 4, Instructions: 152COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070C481, Relevance: 6.1, APIs: 4, Instructions: 133COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 105CD2F4, Relevance: 6.1, APIs: 4, Instructions: 133COMMON
C-Code - Quality: 95% |
|
Memory Dump Source |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D4CAB, Relevance: 6.1, APIs: 4, Instructions: 128synchronizationthreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D8A51, Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 82sleepCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070D288, Relevance: 6.1, APIs: 4, Instructions: 63COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070D307, Relevance: 6.1, APIs: 4, Instructions: 59COMMON
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E79DC, Relevance: 6.1, APIs: 4, Instructions: 52fileCOMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00701D01, Relevance: 6.0, APIs: 4, Instructions: 14COMMON
APIs |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D414D, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 93sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D4A08, Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 60networkCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006E2A86, Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 60sleepfilenetworkCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9B11, Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 32keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006D9B6B, Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 24keyboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
Strings |
|
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0070ABB8, Relevance: 5.1, APIs: 4, Instructions: 139COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006DF4FE, Relevance: 5.1, APIs: 4, Instructions: 124COMMON
APIs |
Memory Dump Source |
|
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |