Windows
Analysis Report
ZciowjM9hN
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- ZciowjM9hN.exe (PID: 6328 cmdline:
"C:\Users\ user\Deskt op\ZciowjM 9hN.exe" MD5: 4015330DA10DE30BCDF2B65F7F98BAEB) - ZciowjM9hN.exe (PID: 6976 cmdline:
C:\Users\u ser\Deskto p\ZciowjM9 hN.exe MD5: 4015330DA10DE30BCDF2B65F7F98BAEB)
- cleanup
{"C2 list": ["http://kbfvzoboss.bid/alien/fre.php", "http://alphastand.trade/alien/fre.php", "http://alphastand.win/alien/fre.php", "http://alphastand.top/alien/fre.php", "http://vmopahtqdf84hfvsqepalcbcch63gdyvah.ml/BN2/fre.php"]}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | ||
Lokibot | detect Lokibot in memory | JPCERT/CC Incident Response Group |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 47 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
SUSP_XORed_URL_in_EXE | Detects an XORed URL in an executable | Florian Roth |
| |
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
JoeSecurity_aPLib_compressed_binary | Yara detected aPLib compressed binary | Joe Security | ||
JoeSecurity_Lokibot | Yara detected Lokibot | Joe Security | ||
INDICATOR_SUSPICIOUS_GENInfoStealer | Detects executables containing common artifcats observed in infostealers | ditekSHen |
| |
Click to see the 101 entries |
Timestamp: | 192.168.2.3188.114.97.649751802021641 06/09/22-12:18:53.097950 |
SID: | 2021641 |
Source Port: | 49751 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749800802024313 06/09/22-12:20:00.829408 |
SID: | 2024313 |
Source Port: | 49800 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749774802825766 06/09/22-12:19:21.474099 |
SID: | 2825766 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649824802024313 06/09/22-12:20:22.688767 |
SID: | 2024313 |
Source Port: | 49824 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749810802024313 06/09/22-12:20:16.253890 |
SID: | 2024313 |
Source Port: | 49810 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649820802825766 06/09/22-12:20:20.867617 |
SID: | 2825766 |
Source Port: | 49820 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749770802021641 06/09/22-12:19:14.041674 |
SID: | 2021641 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749785802021641 06/09/22-12:19:42.634597 |
SID: | 2021641 |
Source Port: | 49785 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749773802024313 06/09/22-12:19:20.082461 |
SID: | 2024313 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749767802021641 06/09/22-12:19:08.800960 |
SID: | 2021641 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749844802025381 06/09/22-12:20:27.377021 |
SID: | 2025381 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749752802021641 06/09/22-12:18:54.883061 |
SID: | 2021641 |
Source Port: | 49752 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749793802021641 06/09/22-12:19:50.509118 |
SID: | 2021641 |
Source Port: | 49793 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649776802021641 06/09/22-12:19:23.957128 |
SID: | 2021641 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749799802025381 06/09/22-12:19:59.356295 |
SID: | 2025381 |
Source Port: | 49799 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749804802021641 06/09/22-12:20:07.542975 |
SID: | 2021641 |
Source Port: | 49804 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749782802025381 06/09/22-12:19:30.781711 |
SID: | 2025381 |
Source Port: | 49782 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649764802024313 06/09/22-12:19:02.212367 |
SID: | 2024313 |
Source Port: | 49764 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749798802024313 06/09/22-12:19:58.002191 |
SID: | 2024313 |
Source Port: | 49798 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749799802825766 06/09/22-12:19:59.356295 |
SID: | 2825766 |
Source Port: | 49799 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749745802024312 06/09/22-12:18:46.752225 |
SID: | 2024312 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649820802025381 06/09/22-12:20:20.867617 |
SID: | 2025381 |
Source Port: | 49820 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749782802825766 06/09/22-12:19:30.781711 |
SID: | 2825766 |
Source Port: | 49782 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749766802025381 06/09/22-12:19:06.967493 |
SID: | 2025381 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649775802025381 06/09/22-12:19:22.604146 |
SID: | 2025381 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749783802024313 06/09/22-12:19:36.273915 |
SID: | 2024313 |
Source Port: | 49783 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749772802025381 06/09/22-12:19:18.470177 |
SID: | 2025381 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749797802825766 06/09/22-12:19:56.597737 |
SID: | 2825766 |
Source Port: | 49797 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649792802024313 06/09/22-12:19:45.858683 |
SID: | 2024313 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749817802024313 06/09/22-12:20:18.206399 |
SID: | 2024313 |
Source Port: | 49817 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649778802025381 06/09/22-12:19:26.733758 |
SID: | 2025381 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749748802825766 06/09/22-12:18:50.155870 |
SID: | 2825766 |
Source Port: | 49748 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649801802021641 06/09/22-12:20:02.469935 |
SID: | 2021641 |
Source Port: | 49801 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749803802025381 06/09/22-12:20:05.555366 |
SID: | 2025381 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749761802024313 06/09/22-12:18:59.590864 |
SID: | 2024313 |
Source Port: | 49761 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749779802025381 06/09/22-12:19:28.006927 |
SID: | 2025381 |
Source Port: | 49779 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749796802024313 06/09/22-12:19:54.857506 |
SID: | 2024313 |
Source Port: | 49796 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749807802021641 06/09/22-12:20:13.436189 |
SID: | 2021641 |
Source Port: | 49807 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749784802825766 06/09/22-12:19:39.004620 |
SID: | 2825766 |
Source Port: | 49784 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749832802021641 06/09/22-12:20:23.981118 |
SID: | 2021641 |
Source Port: | 49832 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749802802021641 06/09/22-12:20:04.084401 |
SID: | 2021641 |
Source Port: | 49802 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749774802025381 06/09/22-12:19:21.474099 |
SID: | 2025381 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649771802825766 06/09/22-12:19:17.236324 |
SID: | 2825766 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749748802024312 06/09/22-12:18:50.155870 |
SID: | 2024312 |
Source Port: | 49748 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749832802025381 06/09/22-12:20:23.981118 |
SID: | 2025381 |
Source Port: | 49832 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649751802024313 06/09/22-12:18:53.097950 |
SID: | 2024313 |
Source Port: | 49751 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649768802825766 06/09/22-12:19:10.383861 |
SID: | 2825766 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749752802025381 06/09/22-12:18:54.883061 |
SID: | 2025381 |
Source Port: | 49752 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649776802025381 06/09/22-12:19:23.957128 |
SID: | 2025381 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749777802825766 06/09/22-12:19:25.204896 |
SID: | 2825766 |
Source Port: | 49777 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749785802024313 06/09/22-12:19:42.634597 |
SID: | 2024313 |
Source Port: | 49785 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749770802024313 06/09/22-12:19:14.041674 |
SID: | 2024313 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749773802021641 06/09/22-12:19:20.082461 |
SID: | 2021641 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749786802825766 06/09/22-12:19:44.361044 |
SID: | 2825766 |
Source Port: | 49786 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.749765802825766 06/09/22-12:19:04.748877 |
SID: | 2825766 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749767802024313 06/09/22-12:19:08.800960 |
SID: | 2024313 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749752802825766 06/09/22-12:18:54.883061 |
SID: | 2825766 |
Source Port: | 49752 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649768802021641 06/09/22-12:19:10.383861 |
SID: | 2021641 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749800802021641 06/09/22-12:20:00.829408 |
SID: | 2021641 |
Source Port: | 49800 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749800802825766 06/09/22-12:20:00.829408 |
SID: | 2825766 |
Source Port: | 49800 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.749765802021641 06/09/22-12:19:04.748877 |
SID: | 2021641 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749794802025381 06/09/22-12:19:52.723950 |
SID: | 2025381 |
Source Port: | 49794 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749745802021641 06/09/22-12:18:46.752225 |
SID: | 2021641 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749786802024313 06/09/22-12:19:44.361044 |
SID: | 2024313 |
Source Port: | 49786 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749774802021641 06/09/22-12:19:21.474099 |
SID: | 2021641 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749777802021641 06/09/22-12:19:25.204896 |
SID: | 2021641 |
Source Port: | 49777 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749819802825766 06/09/22-12:20:19.468606 |
SID: | 2825766 |
Source Port: | 49819 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749769802025381 06/09/22-12:19:11.569140 |
SID: | 2025381 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749805802024313 06/09/22-12:20:10.598374 |
SID: | 2024313 |
Source Port: | 49805 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749784802025381 06/09/22-12:19:39.004620 |
SID: | 2025381 |
Source Port: | 49784 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649771802021641 06/09/22-12:19:17.236324 |
SID: | 2021641 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649778802825766 06/09/22-12:19:26.733758 |
SID: | 2825766 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749799802021641 06/09/22-12:19:59.356295 |
SID: | 2021641 |
Source Port: | 49799 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649824802025381 06/09/22-12:20:22.688767 |
SID: | 2025381 |
Source Port: | 49824 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649775802825766 06/09/22-12:19:22.604146 |
SID: | 2825766 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749803802825766 06/09/22-12:20:05.555366 |
SID: | 2825766 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749810802025381 06/09/22-12:20:16.253890 |
SID: | 2025381 |
Source Port: | 49810 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749796802021641 06/09/22-12:19:54.857506 |
SID: | 2021641 |
Source Port: | 49796 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749761802021641 06/09/22-12:18:59.590864 |
SID: | 2021641 |
Source Port: | 49761 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749804802025381 06/09/22-12:20:07.542975 |
SID: | 2025381 |
Source Port: | 49804 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749844802021641 06/09/22-12:20:27.377021 |
SID: | 2021641 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749844802825766 06/09/22-12:20:27.377021 |
SID: | 2825766 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749851802025381 06/09/22-12:20:29.327641 |
SID: | 2025381 |
Source Port: | 49851 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749819802021641 06/09/22-12:20:19.468606 |
SID: | 2021641 |
Source Port: | 49819 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749797802025381 06/09/22-12:19:56.597737 |
SID: | 2025381 |
Source Port: | 49797 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749761802825766 06/09/22-12:18:59.590864 |
SID: | 2825766 |
Source Port: | 49761 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749796802825766 06/09/22-12:19:54.857506 |
SID: | 2825766 |
Source Port: | 49796 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649778802021641 06/09/22-12:19:26.733758 |
SID: | 2021641 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749783802021641 06/09/22-12:19:36.273915 |
SID: | 2021641 |
Source Port: | 49783 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749839802025381 06/09/22-12:20:25.206676 |
SID: | 2025381 |
Source Port: | 49839 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749802802024313 06/09/22-12:20:04.084401 |
SID: | 2024313 |
Source Port: | 49802 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749798802025381 06/09/22-12:19:58.002191 |
SID: | 2025381 |
Source Port: | 49798 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749748802021641 06/09/22-12:18:50.155870 |
SID: | 2021641 |
Source Port: | 49748 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649778802024313 06/09/22-12:19:26.733758 |
SID: | 2024313 |
Source Port: | 49778 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749797802024313 06/09/22-12:19:56.597737 |
SID: | 2024313 |
Source Port: | 49797 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749794802021641 06/09/22-12:19:52.723950 |
SID: | 2021641 |
Source Port: | 49794 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749769802024313 06/09/22-12:19:11.569140 |
SID: | 2024313 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749782802024313 06/09/22-12:19:30.781711 |
SID: | 2024313 |
Source Port: | 49782 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749783802825766 06/09/22-12:19:36.273915 |
SID: | 2825766 |
Source Port: | 49783 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749803802021641 06/09/22-12:20:05.555366 |
SID: | 2021641 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649764802025381 06/09/22-12:19:02.212367 |
SID: | 2025381 |
Source Port: | 49764 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749817802025381 06/09/22-12:20:18.206399 |
SID: | 2025381 |
Source Port: | 49817 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649801802025381 06/09/22-12:20:02.469935 |
SID: | 2025381 |
Source Port: | 49801 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749802802825766 06/09/22-12:20:04.084401 |
SID: | 2825766 |
Source Port: | 49802 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749798802825766 06/09/22-12:19:58.002191 |
SID: | 2825766 |
Source Port: | 49798 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749779802024313 06/09/22-12:19:28.006927 |
SID: | 2024313 |
Source Port: | 49779 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749839802024313 06/09/22-12:20:25.206676 |
SID: | 2024313 |
Source Port: | 49839 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649768802024313 06/09/22-12:19:10.383861 |
SID: | 2024313 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749817802825766 06/09/22-12:20:18.206399 |
SID: | 2825766 |
Source Port: | 49817 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649764802825766 06/09/22-12:19:02.212367 |
SID: | 2825766 |
Source Port: | 49764 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749802802025381 06/09/22-12:20:04.084401 |
SID: | 2025381 |
Source Port: | 49802 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749793802825766 06/09/22-12:19:50.509118 |
SID: | 2825766 |
Source Port: | 49793 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.749765802024313 06/09/22-12:19:04.748877 |
SID: | 2024313 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749786802021641 06/09/22-12:19:44.361044 |
SID: | 2021641 |
Source Port: | 49786 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649801802825766 06/09/22-12:20:02.469935 |
SID: | 2825766 |
Source Port: | 49801 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749783802025381 06/09/22-12:19:36.273915 |
SID: | 2025381 |
Source Port: | 49783 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749807802025381 06/09/22-12:20:13.436189 |
SID: | 2025381 |
Source Port: | 49807 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649775802021641 06/09/22-12:19:22.604146 |
SID: | 2021641 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749777802024313 06/09/22-12:19:25.204896 |
SID: | 2024313 |
Source Port: | 49777 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749800802025381 06/09/22-12:20:00.829408 |
SID: | 2025381 |
Source Port: | 49800 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749805802021641 06/09/22-12:20:10.598374 |
SID: | 2021641 |
Source Port: | 49805 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749810802825766 06/09/22-12:20:16.253890 |
SID: | 2825766 |
Source Port: | 49810 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649820802021641 06/09/22-12:20:20.867617 |
SID: | 2021641 |
Source Port: | 49820 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749774802024313 06/09/22-12:19:21.474099 |
SID: | 2024313 |
Source Port: | 49774 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749770802825766 06/09/22-12:19:14.041674 |
SID: | 2825766 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749807802825766 06/09/22-12:20:13.436189 |
SID: | 2825766 |
Source Port: | 49807 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749804802825766 06/09/22-12:20:07.542975 |
SID: | 2825766 |
Source Port: | 49804 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749745802825766 06/09/22-12:18:46.752225 |
SID: | 2825766 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649771802024313 06/09/22-12:19:17.236324 |
SID: | 2024313 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749851802021641 06/09/22-12:20:29.327641 |
SID: | 2021641 |
Source Port: | 49851 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749844802024313 06/09/22-12:20:27.377021 |
SID: | 2024313 |
Source Port: | 49844 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749793802025381 06/09/22-12:19:50.509118 |
SID: | 2025381 |
Source Port: | 49793 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749796802025381 06/09/22-12:19:54.857506 |
SID: | 2025381 |
Source Port: | 49796 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749799802024313 06/09/22-12:19:59.356295 |
SID: | 2024313 |
Source Port: | 49799 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749832802825766 06/09/22-12:20:23.981118 |
SID: | 2825766 |
Source Port: | 49832 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749784802021641 06/09/22-12:19:39.004620 |
SID: | 2021641 |
Source Port: | 49784 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749785802025381 06/09/22-12:19:42.634597 |
SID: | 2025381 |
Source Port: | 49785 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749805802025381 06/09/22-12:20:10.598374 |
SID: | 2025381 |
Source Port: | 49805 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749766802024313 06/09/22-12:19:06.967493 |
SID: | 2024313 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649751802025381 06/09/22-12:18:53.097950 |
SID: | 2025381 |
Source Port: | 49751 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749772802024313 06/09/22-12:19:18.470177 |
SID: | 2024313 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649792802025381 06/09/22-12:19:45.858683 |
SID: | 2025381 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749767802825766 06/09/22-12:19:08.800960 |
SID: | 2825766 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749819802024313 06/09/22-12:20:19.468606 |
SID: | 2024313 |
Source Port: | 49819 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749773802825766 06/09/22-12:19:20.082461 |
SID: | 2825766 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749851802825766 06/09/22-12:20:29.327641 |
SID: | 2825766 |
Source Port: | 49851 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749786802025381 06/09/22-12:19:44.361044 |
SID: | 2025381 |
Source Port: | 49786 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749839802825766 06/09/22-12:20:25.206676 |
SID: | 2825766 |
Source Port: | 49839 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749797802021641 06/09/22-12:19:56.597737 |
SID: | 2021641 |
Source Port: | 49797 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749794802024313 06/09/22-12:19:52.723950 |
SID: | 2024313 |
Source Port: | 49794 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749769802021641 06/09/22-12:19:11.569140 |
SID: | 2021641 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749803802024313 06/09/22-12:20:05.555366 |
SID: | 2024313 |
Source Port: | 49803 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749782802021641 06/09/22-12:19:30.781711 |
SID: | 2021641 |
Source Port: | 49782 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749810802021641 06/09/22-12:20:16.253890 |
SID: | 2021641 |
Source Port: | 49810 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649824802021641 06/09/22-12:20:22.688767 |
SID: | 2021641 |
Source Port: | 49824 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749805802825766 06/09/22-12:20:10.598374 |
SID: | 2825766 |
Source Port: | 49805 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749770802025381 06/09/22-12:19:14.041674 |
SID: | 2025381 |
Source Port: | 49770 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749761802025381 06/09/22-12:18:59.590864 |
SID: | 2025381 |
Source Port: | 49761 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749769802825766 06/09/22-12:19:11.569140 |
SID: | 2825766 |
Source Port: | 49769 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749793802024313 06/09/22-12:19:50.509118 |
SID: | 2024313 |
Source Port: | 49793 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649824802825766 06/09/22-12:20:22.688767 |
SID: | 2825766 |
Source Port: | 49824 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649771802025381 06/09/22-12:19:17.236324 |
SID: | 2025381 |
Source Port: | 49771 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649776802024313 06/09/22-12:19:23.957128 |
SID: | 2024313 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749819802025381 06/09/22-12:20:19.468606 |
SID: | 2025381 |
Source Port: | 49819 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749839802021641 06/09/22-12:20:25.206676 |
SID: | 2021641 |
Source Port: | 49839 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749752802024313 06/09/22-12:18:54.883061 |
SID: | 2024313 |
Source Port: | 49752 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749779802021641 06/09/22-12:19:28.006927 |
SID: | 2021641 |
Source Port: | 49779 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749804802024313 06/09/22-12:20:07.542975 |
SID: | 2024313 |
Source Port: | 49804 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649764802021641 06/09/22-12:19:02.212367 |
SID: | 2021641 |
Source Port: | 49764 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749798802021641 06/09/22-12:19:58.002191 |
SID: | 2021641 |
Source Port: | 49798 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649776802825766 06/09/22-12:19:23.957128 |
SID: | 2825766 |
Source Port: | 49776 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749777802025381 06/09/22-12:19:25.204896 |
SID: | 2025381 |
Source Port: | 49777 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649775802024313 06/09/22-12:19:22.604146 |
SID: | 2024313 |
Source Port: | 49775 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649792802021641 06/09/22-12:19:45.858683 |
SID: | 2021641 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749785802825766 06/09/22-12:19:42.634597 |
SID: | 2825766 |
Source Port: | 49785 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649751802825766 06/09/22-12:18:53.097950 |
SID: | 2825766 |
Source Port: | 49751 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749794802825766 06/09/22-12:19:52.723950 |
SID: | 2825766 |
Source Port: | 49794 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649820802024313 06/09/22-12:20:20.867617 |
SID: | 2024313 |
Source Port: | 49820 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749779802825766 06/09/22-12:19:28.006927 |
SID: | 2825766 |
Source Port: | 49779 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.749765802025381 06/09/22-12:19:04.748877 |
SID: | 2025381 |
Source Port: | 49765 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749817802021641 06/09/22-12:20:18.206399 |
SID: | 2021641 |
Source Port: | 49817 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749748802025381 06/09/22-12:18:50.155870 |
SID: | 2025381 |
Source Port: | 49748 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749851802024313 06/09/22-12:20:29.327641 |
SID: | 2024313 |
Source Port: | 49851 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649801802024313 06/09/22-12:20:02.469935 |
SID: | 2024313 |
Source Port: | 49801 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649768802025381 06/09/22-12:19:10.383861 |
SID: | 2025381 |
Source Port: | 49768 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749766802825766 06/09/22-12:19:06.967493 |
SID: | 2825766 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749773802025381 06/09/22-12:19:20.082461 |
SID: | 2025381 |
Source Port: | 49773 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749772802825766 06/09/22-12:19:18.470177 |
SID: | 2825766 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749767802025381 06/09/22-12:19:08.800960 |
SID: | 2025381 |
Source Port: | 49767 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749807802024313 06/09/22-12:20:13.436189 |
SID: | 2024313 |
Source Port: | 49807 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749784802024313 06/09/22-12:19:39.004620 |
SID: | 2024313 |
Source Port: | 49784 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.97.649792802825766 06/09/22-12:19:45.858683 |
SID: | 2825766 |
Source Port: | 49792 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749832802024313 06/09/22-12:20:23.981118 |
SID: | 2024313 |
Source Port: | 49832 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749766802021641 06/09/22-12:19:06.967493 |
SID: | 2021641 |
Source Port: | 49766 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749745802025381 06/09/22-12:18:46.752225 |
SID: | 2025381 |
Source Port: | 49745 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.3188.114.96.749772802021641 06/09/22-12:19:18.470177 |
SID: | 2021641 |
Source Port: | 49772 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link | ||
Source: | ReversingLabs: |
Source: | Avira URL Cloud: | ||
Source: | Avira URL Cloud: |
Source: | Virustotal: | Perma Link | ||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Malware Configuration Extractor: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Code function: | 9_2_00403D74 |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: | ||
Source: | URLs: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | Code function: | 9_2_00404ED4 |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_010EC344 | |
Source: | Code function: | 0_2_010EE701 | |
Source: | Code function: | 0_2_010EE710 | |
Source: | Code function: | 9_2_0040549C | |
Source: | Code function: | 9_2_004029D4 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Virustotal: | ||
Source: | ReversingLabs: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Code function: | 9_2_0040650A |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Code function: | 9_2_0040434D |
Source: | Static file information: | |||
Source: | Section loaded: | Jump to behavior |
Source: | Mutant created: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Code function: | 9_2_00402AD4 | |
Source: | Code function: | 9_2_00402AFC |
Source: | Static PE information: |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior |
Source: | Code function: | 9_2_00403D74 |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Code function: | 9_2_00402B7C |
Source: | Process token adjusted: | Jump to behavior |
Source: | Code function: | 9_2_0040317B |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Memory written: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 9_2_00406069 |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | Key opened: | Jump to behavior | ||
Source: | Key opened: | Jump to behavior |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | Code function: | 9_2_0040D069 | |
Source: | Code function: | 9_2_0040D069 |
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 2 Command and Scripting Interpreter | Path Interception | 1 Access Token Manipulation | 1 Masquerading | 2 OS Credential Dumping | 111 Security Software Discovery | Remote Services | 1 Email Collection | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 111 Process Injection | 1 Disable or Modify Tools | 2 Credentials in Registry | 21 Virtualization/Sandbox Evasion | Remote Desktop Protocol | 1 Archive Collected Data | Exfiltration Over Bluetooth | 3 Ingress Tool Transfer | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 21 Virtualization/Sandbox Evasion | Security Account Manager | 1 Account Discovery | SMB/Windows Admin Shares | 2 Data from Local System | Automated Exfiltration | 3 Non-Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 1 Access Token Manipulation | NTDS | 1 System Owner/User Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 113 Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 111 Process Injection | LSA Secrets | 1 Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 1 Deobfuscate/Decode Files or Information | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | 3 Obfuscated Files or Information | DCSync | 13 System Information Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | 2 Software Packing | Proc Filesystem | Network Service Scanning | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
58% | Virustotal | Browse | ||
65% | ReversingLabs | ByteCode-MSIL.Trojan.FormBook | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File | ||
100% | Avira | TR/Crypt.XPACK.Gen | Download File |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
17% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
100% | Avira URL Cloud | phishing | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
19% | Virustotal | Browse | ||
100% | Avira URL Cloud | phishing | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
vmopahtqdf84hfvsqepalcbcch63gdyvah.ml | 188.114.96.7 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown | |
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
true |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
188.114.97.7 | unknown | European Union | 13335 | CLOUDFLARENETUS | true | |
188.114.96.7 | vmopahtqdf84hfvsqepalcbcch63gdyvah.ml | European Union | 13335 | CLOUDFLARENETUS | true | |
188.114.97.6 | unknown | European Union | 13335 | CLOUDFLARENETUS | true |
IP |
---|
192.168.2.1 |
Joe Sandbox Version: | 35.0.0 Citrine |
Analysis ID: | 642374 |
Start date and time: 09/06/202212:17:07 | 2022-06-09 12:17:07 +02:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 9m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | ZciowjM9hN (renamed file extension from none to exe) |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 26 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal100.troj.spyw.evad.winEXE@3/3@49/4 |
EGA Information: |
|
HDC Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, BackgroundTransferHost.exe, backgroundTaskHost.exe, SgrmBroker.exe, conhost.exe, WmiPrvSE.exe, svchost.exe, wuapihost.exe
- Excluded domains from analysis (whitelisted): www.bing.com, ris.api.iris.microsoft.com, fs.microsoft.com, store-images.s-microsoft.com, login.live.com, sls.update.microsoft.com, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, arc.msn.com
- Not all processes where analyzed, report is missing behavior information
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtDeviceIoControlFile calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
12:18:32 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
188.114.97.7 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
vmopahtqdf84hfvsqepalcbcch63gdyvah.ml | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
CLOUDFLARENETUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Process: | C:\Users\user\Desktop\ZciowjM9hN.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1308 |
Entropy (8bit): | 5.345811588615766 |
Encrypted: | false |
SSDEEP: | 24:MLUE4K5E4Ks2E1qE4qXKDE4KhK3VZ9pKhPKIE4oKFKHKoZAE4Kzr7FE4x84FsXE8:MIHK5HKXE1qHiYHKhQnoPtHoxHhAHKzu |
MD5: | 2E016B886BDB8389D2DD0867BE55F87B |
SHA1: | 25D28EF2ACBB41764571E06E11BF4C05DD0E2F8B |
SHA-256: | 1D037CF00A8849E6866603297F85D3DABE09535E72EDD2636FB7D0F6C7DA3427 |
SHA-512: | C100729153954328AA2A77EECB2A3CBD03CB7E8E23D736000F890B17AAA50BA87745E30FB9E2B0D61E16DCA45694C79B4CE09B9F4475220BEB38CAEA546CFC2A |
Malicious: | true |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\ZciowjM9hN.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:U:U |
MD5: | C4CA4238A0B923820DCC509A6F75849B |
SHA1: | 356A192B7913B04C54574D18C28D46E6395428AB |
SHA-256: | 6B86B273FF34FCE19D6B804EFF5A3F5747ADA4EAA22F1D49C01E52DDB7875B4B |
SHA-512: | 4DFF4EA340F0A823F15D3F4F01AB62EAE0E5DA579CCB851F8DB9DFE84C58B2B37B89903A740E1EE172DA793A6E79D560E5F7F9BD058A12A280433ED6FA46510A |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-3853321935-2125563209-4053062332-1002\414045e2d09286d5db2581e0d955d358_d06ed635-68f6-4e9a-955c-4899f5f57b9a
Download File
Process: | C:\Users\user\Desktop\ZciowjM9hN.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 46 |
Entropy (8bit): | 0.0 |
Encrypted: | false |
SSDEEP: | 3:: |
MD5: | D898504A722BFF1524134C6AB6A5EAA5 |
SHA1: | E0FDC90C2CA2A0219C99D2758E68C18875A3E11E |
SHA-256: | 878F32F76B159494F5A39F9321616C6068CDB82E88DF89BCC739BBC1EA78E1F9 |
SHA-512: | 26A4398BFFB0C0AEF9A6EC53CD3367A2D0ABF2F70097F711BBBF1E9E32FD9F1A72121691BB6A39EEB55D596EDD527934E541B4DEFB3B1426B1D1A6429804DC61 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 7.621340788440396 |
TrID: |
|
File name: | ZciowjM9hN.exe |
File size: | 621056 |
MD5: | 4015330da10de30bcdf2b65f7f98baeb |
SHA1: | bae6c45444103bab44973983c444e7293a5d30ca |
SHA256: | 9838ba34c89432853bf5f65e0dd54f4f5ca540e886a18b31ab96b007dcbf05d5 |
SHA512: | cf40441cc6f16c265452a3f6659ae7522af4e3bae22807964153651b7f163e28f23b64945ca8bdfa8b0b751ed61bcdbeae486a00f573ebf589ad99c1dad2c994 |
SSDEEP: | 12288:aJyx609qGBvtAxm5mBDoPc+fUwET5GqhzVQdhF3iLWUlnK:Myx6018UcAHQGqhzadhZuWUl |
TLSH: | A9D4C090B3BA9F71F27963F26420A00817F4391E95E4D13A9ECDB0CE62A1F4259F1E57 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......b..............0..L...,......Bj... ........@.. ....................................@................................ |
Icon Hash: | cc01ecc4b6e400c4 |
Entrypoint: | 0x496a42 |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x629EB484 [Tue Jun 7 02:14:28 2022 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
dec esp |
add byte ptr [edi+00h], ch |
popad |
add byte ptr [eax+eax+00h], ah |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x969f0 | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x98000 | 0x29a4 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x9c000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x94a50 | 0x94c00 | False | 0.7955734637605042 | data | 7.624251253975701 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rsrc | 0x98000 | 0x29a4 | 0x2a00 | False | 0.9035528273809523 | data | 7.67690596368935 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x9c000 | 0xc | 0x200 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x980c8 | 0x2511 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | ||
RT_GROUP_ICON | 0x9a5ec | 0x14 | data | ||
RT_VERSION | 0x9a610 | 0x390 | data |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.3188.114.97.649751802021641 06/09/22-12:18:53.097950 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749800802024313 06/09/22-12:20:00.829408 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749774802825766 06/09/22-12:19:21.474099 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649824802024313 06/09/22-12:20:22.688767 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749810802024313 06/09/22-12:20:16.253890 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649820802825766 06/09/22-12:20:20.867617 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749770802021641 06/09/22-12:19:14.041674 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749785802021641 06/09/22-12:19:42.634597 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749773802024313 06/09/22-12:19:20.082461 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749767802021641 06/09/22-12:19:08.800960 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749844802025381 06/09/22-12:20:27.377021 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749752802021641 06/09/22-12:18:54.883061 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749793802021641 06/09/22-12:19:50.509118 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649776802021641 06/09/22-12:19:23.957128 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749799802025381 06/09/22-12:19:59.356295 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749804802021641 06/09/22-12:20:07.542975 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749782802025381 06/09/22-12:19:30.781711 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649764802024313 06/09/22-12:19:02.212367 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749798802024313 06/09/22-12:19:58.002191 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749799802825766 06/09/22-12:19:59.356295 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749745802024312 06/09/22-12:18:46.752225 | TCP | 2024312 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649820802025381 06/09/22-12:20:20.867617 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749782802825766 06/09/22-12:19:30.781711 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749766802025381 06/09/22-12:19:06.967493 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649775802025381 06/09/22-12:19:22.604146 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749783802024313 06/09/22-12:19:36.273915 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749772802025381 06/09/22-12:19:18.470177 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749797802825766 06/09/22-12:19:56.597737 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649792802024313 06/09/22-12:19:45.858683 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749817802024313 06/09/22-12:20:18.206399 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649778802025381 06/09/22-12:19:26.733758 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749748802825766 06/09/22-12:18:50.155870 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649801802021641 06/09/22-12:20:02.469935 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749803802025381 06/09/22-12:20:05.555366 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749761802024313 06/09/22-12:18:59.590864 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749779802025381 06/09/22-12:19:28.006927 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749796802024313 06/09/22-12:19:54.857506 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749807802021641 06/09/22-12:20:13.436189 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749784802825766 06/09/22-12:19:39.004620 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749832802021641 06/09/22-12:20:23.981118 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749802802021641 06/09/22-12:20:04.084401 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749774802025381 06/09/22-12:19:21.474099 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649771802825766 06/09/22-12:19:17.236324 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749748802024312 06/09/22-12:18:50.155870 | TCP | 2024312 | ET TROJAN LokiBot Application/Credential Data Exfiltration Detected M1 | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749832802025381 06/09/22-12:20:23.981118 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649751802024313 06/09/22-12:18:53.097950 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649768802825766 06/09/22-12:19:10.383861 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749752802025381 06/09/22-12:18:54.883061 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649776802025381 06/09/22-12:19:23.957128 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749777802825766 06/09/22-12:19:25.204896 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749785802024313 06/09/22-12:19:42.634597 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749770802024313 06/09/22-12:19:14.041674 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749773802021641 06/09/22-12:19:20.082461 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749786802825766 06/09/22-12:19:44.361044 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.749765802825766 06/09/22-12:19:04.748877 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
192.168.2.3188.114.96.749767802024313 06/09/22-12:19:08.800960 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749752802825766 06/09/22-12:18:54.883061 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649768802021641 06/09/22-12:19:10.383861 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749800802021641 06/09/22-12:20:00.829408 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749800802825766 06/09/22-12:20:00.829408 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.749765802021641 06/09/22-12:19:04.748877 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
192.168.2.3188.114.96.749794802025381 06/09/22-12:19:52.723950 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749745802021641 06/09/22-12:18:46.752225 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749786802024313 06/09/22-12:19:44.361044 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749774802021641 06/09/22-12:19:21.474099 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749777802021641 06/09/22-12:19:25.204896 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749819802825766 06/09/22-12:20:19.468606 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749769802025381 06/09/22-12:19:11.569140 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749805802024313 06/09/22-12:20:10.598374 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749784802025381 06/09/22-12:19:39.004620 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649771802021641 06/09/22-12:19:17.236324 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649778802825766 06/09/22-12:19:26.733758 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749799802021641 06/09/22-12:19:59.356295 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649824802025381 06/09/22-12:20:22.688767 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649775802825766 06/09/22-12:19:22.604146 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749803802825766 06/09/22-12:20:05.555366 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749810802025381 06/09/22-12:20:16.253890 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749796802021641 06/09/22-12:19:54.857506 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749761802021641 06/09/22-12:18:59.590864 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749804802025381 06/09/22-12:20:07.542975 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749844802021641 06/09/22-12:20:27.377021 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749844802825766 06/09/22-12:20:27.377021 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749851802025381 06/09/22-12:20:29.327641 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749819802021641 06/09/22-12:20:19.468606 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749797802025381 06/09/22-12:19:56.597737 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749761802825766 06/09/22-12:18:59.590864 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749796802825766 06/09/22-12:19:54.857506 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649778802021641 06/09/22-12:19:26.733758 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749783802021641 06/09/22-12:19:36.273915 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749839802025381 06/09/22-12:20:25.206676 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749802802024313 06/09/22-12:20:04.084401 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749798802025381 06/09/22-12:19:58.002191 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749748802021641 06/09/22-12:18:50.155870 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649778802024313 06/09/22-12:19:26.733758 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749797802024313 06/09/22-12:19:56.597737 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749794802021641 06/09/22-12:19:52.723950 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749769802024313 06/09/22-12:19:11.569140 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749782802024313 06/09/22-12:19:30.781711 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749783802825766 06/09/22-12:19:36.273915 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749803802021641 06/09/22-12:20:05.555366 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649764802025381 06/09/22-12:19:02.212367 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749817802025381 06/09/22-12:20:18.206399 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649801802025381 06/09/22-12:20:02.469935 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749802802825766 06/09/22-12:20:04.084401 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749798802825766 06/09/22-12:19:58.002191 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749779802024313 06/09/22-12:19:28.006927 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749839802024313 06/09/22-12:20:25.206676 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649768802024313 06/09/22-12:19:10.383861 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749817802825766 06/09/22-12:20:18.206399 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649764802825766 06/09/22-12:19:02.212367 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749802802025381 06/09/22-12:20:04.084401 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749793802825766 06/09/22-12:19:50.509118 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.749765802024313 06/09/22-12:19:04.748877 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
192.168.2.3188.114.96.749786802021641 06/09/22-12:19:44.361044 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649801802825766 06/09/22-12:20:02.469935 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749783802025381 06/09/22-12:19:36.273915 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749807802025381 06/09/22-12:20:13.436189 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649775802021641 06/09/22-12:19:22.604146 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749777802024313 06/09/22-12:19:25.204896 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749800802025381 06/09/22-12:20:00.829408 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749805802021641 06/09/22-12:20:10.598374 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749810802825766 06/09/22-12:20:16.253890 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649820802021641 06/09/22-12:20:20.867617 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749774802024313 06/09/22-12:19:21.474099 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749770802825766 06/09/22-12:19:14.041674 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749807802825766 06/09/22-12:20:13.436189 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749804802825766 06/09/22-12:20:07.542975 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749745802825766 06/09/22-12:18:46.752225 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649771802024313 06/09/22-12:19:17.236324 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749851802021641 06/09/22-12:20:29.327641 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749844802024313 06/09/22-12:20:27.377021 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749793802025381 06/09/22-12:19:50.509118 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749796802025381 06/09/22-12:19:54.857506 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749799802024313 06/09/22-12:19:59.356295 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749832802825766 06/09/22-12:20:23.981118 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749784802021641 06/09/22-12:19:39.004620 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749785802025381 06/09/22-12:19:42.634597 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749805802025381 06/09/22-12:20:10.598374 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749766802024313 06/09/22-12:19:06.967493 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649751802025381 06/09/22-12:18:53.097950 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749772802024313 06/09/22-12:19:18.470177 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649792802025381 06/09/22-12:19:45.858683 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749767802825766 06/09/22-12:19:08.800960 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749819802024313 06/09/22-12:20:19.468606 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749773802825766 06/09/22-12:19:20.082461 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749851802825766 06/09/22-12:20:29.327641 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749786802025381 06/09/22-12:19:44.361044 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749839802825766 06/09/22-12:20:25.206676 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749797802021641 06/09/22-12:19:56.597737 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749794802024313 06/09/22-12:19:52.723950 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749769802021641 06/09/22-12:19:11.569140 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749803802024313 06/09/22-12:20:05.555366 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749782802021641 06/09/22-12:19:30.781711 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749810802021641 06/09/22-12:20:16.253890 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649824802021641 06/09/22-12:20:22.688767 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749805802825766 06/09/22-12:20:10.598374 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749770802025381 06/09/22-12:19:14.041674 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749761802025381 06/09/22-12:18:59.590864 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749769802825766 06/09/22-12:19:11.569140 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749793802024313 06/09/22-12:19:50.509118 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649824802825766 06/09/22-12:20:22.688767 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649771802025381 06/09/22-12:19:17.236324 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649776802024313 06/09/22-12:19:23.957128 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749819802025381 06/09/22-12:20:19.468606 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749839802021641 06/09/22-12:20:25.206676 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749752802024313 06/09/22-12:18:54.883061 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749779802021641 06/09/22-12:19:28.006927 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749804802024313 06/09/22-12:20:07.542975 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649764802021641 06/09/22-12:19:02.212367 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749798802021641 06/09/22-12:19:58.002191 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649776802825766 06/09/22-12:19:23.957128 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749777802025381 06/09/22-12:19:25.204896 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649775802024313 06/09/22-12:19:22.604146 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649792802021641 06/09/22-12:19:45.858683 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749785802825766 06/09/22-12:19:42.634597 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649751802825766 06/09/22-12:18:53.097950 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749794802825766 06/09/22-12:19:52.723950 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649820802024313 06/09/22-12:20:20.867617 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749779802825766 06/09/22-12:19:28.006927 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.749765802025381 06/09/22-12:19:04.748877 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
192.168.2.3188.114.96.749817802021641 06/09/22-12:20:18.206399 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749748802025381 06/09/22-12:18:50.155870 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749851802024313 06/09/22-12:20:29.327641 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649801802024313 06/09/22-12:20:02.469935 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.97.649768802025381 06/09/22-12:19:10.383861 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749766802825766 06/09/22-12:19:06.967493 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749773802025381 06/09/22-12:19:20.082461 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749772802825766 06/09/22-12:19:18.470177 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749767802025381 06/09/22-12:19:08.800960 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749807802024313 06/09/22-12:20:13.436189 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749784802024313 06/09/22-12:19:39.004620 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.97.649792802825766 06/09/22-12:19:45.858683 | TCP | 2825766 | ETPRO TROJAN LokiBot Checkin M2 | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
192.168.2.3188.114.96.749832802024313 06/09/22-12:20:23.981118 | TCP | 2024313 | ET TROJAN LokiBot Request for C2 Commands Detected M1 | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749766802021641 06/09/22-12:19:06.967493 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749745802025381 06/09/22-12:18:46.752225 | TCP | 2025381 | ET TROJAN LokiBot Checkin | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
192.168.2.3188.114.96.749772802021641 06/09/22-12:19:18.470177 | TCP | 2021641 | ET TROJAN LokiBot User-Agent (Charon/Inferno) | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 9, 2022 12:18:46.722642899 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.739614964 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:46.739777088 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.752224922 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.769190073 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:46.769325018 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.786222935 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:46.913125038 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:46.913345098 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.917885065 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:46.918070078 CEST | 49745 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:46.930108070 CEST | 80 | 49745 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.126954079 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:50.143925905 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.144165039 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:50.155869961 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:50.172988892 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.173213959 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:50.190064907 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.320050955 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.320457935 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:50.337321043 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.541769028 CEST | 80 | 49748 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:50.541960001 CEST | 49748 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:53.077223063 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.094029903 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:53.094158888 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.097949982 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.114700079 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:53.114986897 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.131730080 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:53.248898029 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:53.249108076 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.250098944 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:53.250163078 CEST | 49751 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:18:53.265929937 CEST | 80 | 49751 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:18:54.853734970 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:54.871198893 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:54.871303082 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:54.883060932 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:54.900161028 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:54.900248051 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:54.917493105 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:55.062665939 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:55.062786102 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:55.079822063 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:55.283999920 CEST | 80 | 49752 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:55.284086943 CEST | 49752 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.570873022 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.588036060 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:59.588152885 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.590863943 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.607566118 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:59.607702017 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.624660015 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:59.765675068 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:59.765849113 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.775964022 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:18:59.776042938 CEST | 49761 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:18:59.782598019 CEST | 80 | 49761 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:02.176585913 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.193496943 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:02.196374893 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.212367058 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.229312897 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:02.229402065 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.246309042 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:02.588592052 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:02.590812922 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:02.590919971 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.591222048 CEST | 49764 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:02.607995987 CEST | 80 | 49764 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:04.727431059 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.744517088 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:04.744724035 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.748877048 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.765814066 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:04.765901089 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.782810926 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:04.892672062 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:04.892708063 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:04.892796993 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.892842054 CEST | 49765 | 80 | 192.168.2.3 | 188.114.97.7 |
Jun 9, 2022 12:19:04.909717083 CEST | 80 | 49765 | 188.114.97.7 | 192.168.2.3 |
Jun 9, 2022 12:19:06.939806938 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:06.956624985 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:06.956788063 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:06.967493057 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:06.984337091 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:06.984461069 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:07.001257896 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:07.076062918 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:07.076317072 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:07.078284979 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:07.078403950 CEST | 49766 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:07.093228102 CEST | 80 | 49766 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.770730019 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.787811041 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.787977934 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.800960064 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.817998886 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.819365978 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.836330891 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.912668943 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.912826061 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.915999889 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:08.916122913 CEST | 49767 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:08.929964066 CEST | 80 | 49767 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:10.361852884 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.379029989 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:10.379163027 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.383861065 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.401034117 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:10.401235104 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.418576956 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:10.548271894 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:10.548470974 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.553881884 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:10.553976059 CEST | 49768 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:10.565515995 CEST | 80 | 49768 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:11.542246103 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.559205055 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:11.559344053 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.569139957 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.585979939 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:11.588557005 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.605528116 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:11.716733932 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:11.716979980 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.718008041 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:11.718101025 CEST | 49769 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:11.733890057 CEST | 80 | 49769 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.021713972 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:14.038721085 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.038820982 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:14.041673899 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:14.058566093 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.058743954 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:14.075639963 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.153940916 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.183177948 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:14.200035095 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.376456976 CEST | 80 | 49770 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:14.376646042 CEST | 49770 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:17.214972973 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.232867002 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:17.232964039 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.236324072 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.253494024 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:17.253592014 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.270687103 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:17.360335112 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:17.360383987 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:17.360644102 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.360683918 CEST | 49771 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:17.377933025 CEST | 80 | 49771 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:18.443608999 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.460721016 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:18.460871935 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.470176935 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.487611055 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:18.487781048 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.504848957 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:18.584544897 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:18.584706068 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.592962980 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:18.593053102 CEST | 49772 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:18.601775885 CEST | 80 | 49772 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.061490059 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.078824043 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.078934908 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.082461119 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.101676941 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.101741076 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.120584965 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.237472057 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.237507105 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:20.237606049 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.237675905 CEST | 49773 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:20.255795002 CEST | 80 | 49773 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.453573942 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.470484018 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.470609903 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.474098921 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.490910053 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.490986109 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.507762909 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.592752934 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.592957020 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.598436117 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:21.598588943 CEST | 49774 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:21.609750986 CEST | 80 | 49774 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:22.580971003 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.601336956 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:22.601501942 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.604146004 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.620934010 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:22.621094942 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.637943029 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:22.945173979 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:22.945430040 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.949002028 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:22.949074030 CEST | 49775 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:22.962268114 CEST | 80 | 49775 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:23.934212923 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:23.951124907 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:23.952655077 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:23.957128048 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:23.974138021 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:23.974256992 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:23.991144896 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:24.182347059 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:24.182523012 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:24.199412107 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:24.405680895 CEST | 80 | 49776 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:24.406487942 CEST | 49776 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:25.163582087 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.198369980 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:25.198616982 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.204895973 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.222054958 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:25.222219944 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.239320040 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:25.556766987 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:25.556876898 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.560843945 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:25.560933113 CEST | 49777 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:25.573885918 CEST | 80 | 49777 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:26.704847097 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:26.722086906 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:26.722201109 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:26.733757973 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:26.751036882 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:26.751442909 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:26.768537998 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:26.890752077 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:26.891000032 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:26.908199072 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:27.115027905 CEST | 80 | 49778 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:27.116353035 CEST | 49778 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:27.987236023 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:28.004040003 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.004196882 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:28.006927013 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:28.023806095 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.023961067 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:28.040790081 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.178622007 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.178792000 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:28.195605993 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.397413015 CEST | 80 | 49779 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:28.397559881 CEST | 49779 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.759402990 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.776289940 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:30.776431084 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.781711102 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.798563004 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:30.798774958 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.815563917 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:30.919230938 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:30.919357061 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.919470072 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:30.919523954 CEST | 49782 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:30.936145067 CEST | 80 | 49782 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.252208948 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.269196987 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.269325972 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.273915052 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.290786982 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.290921926 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.307768106 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.381258965 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.381405115 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.385018110 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:36.385082960 CEST | 49783 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:36.398168087 CEST | 80 | 49783 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:38.982912064 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:38.999821901 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:39.000009060 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:39.004620075 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:39.021780968 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:39.021857977 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:39.038593054 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:39.411545992 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:39.411669016 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:39.419692039 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:39.419774055 CEST | 49784 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:39.428354025 CEST | 80 | 49784 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.582942009 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.600228071 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.602312088 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.634597063 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.651849031 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.651922941 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.669039965 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.788748980 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.788887978 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.793615103 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:42.793735027 CEST | 49785 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:42.805931091 CEST | 80 | 49785 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.335510015 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:44.352749109 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.352864027 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:44.361043930 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:44.378196001 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.378279924 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:44.395291090 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.643172979 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.643297911 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:44.660331964 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.861840963 CEST | 80 | 49786 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:44.861924887 CEST | 49786 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:45.836286068 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.853403091 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:45.853585958 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.858683109 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.876003981 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:45.876180887 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.893044949 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:45.962203979 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:45.962380886 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.965529919 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:45.965625048 CEST | 49792 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:19:45.979268074 CEST | 80 | 49792 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:19:50.488595963 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.505527020 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:50.505652905 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.509118080 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.526077032 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:50.526200056 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.543004036 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:50.626293898 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:50.626399040 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.631148100 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:50.631206989 CEST | 49793 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:50.643160105 CEST | 80 | 49793 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:52.703378916 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:52.720305920 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:52.720393896 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:52.723949909 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:52.740783930 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:52.741095066 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:52.757891893 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:52.869291067 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:52.869484901 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:52.886282921 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:53.090385914 CEST | 80 | 49794 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:53.090487957 CEST | 49794 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:54.837229013 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:54.854654074 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:54.854806900 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:54.857506037 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:54.874870062 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:54.875508070 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:54.893039942 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:55.001300097 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:55.005203009 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:55.005348921 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:55.005379915 CEST | 49796 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:55.022332907 CEST | 80 | 49796 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.577960968 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.594923973 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.595025063 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.597737074 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.614602089 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.614737988 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.631561995 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.728569984 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.728739977 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.728759050 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:56.728828907 CEST | 49797 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:56.745501041 CEST | 80 | 49797 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:57.981875896 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:57.999315023 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:57.999437094 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:58.002191067 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:58.019268990 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:58.019359112 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:58.036389112 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:58.143650055 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:58.143800974 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:58.160957098 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:58.369812012 CEST | 80 | 49798 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:58.371476889 CEST | 49798 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.335609913 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.352436066 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:59.352571011 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.356295109 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.373097897 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:59.373226881 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.390129089 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:59.465481997 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:59.465641022 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:19:59.465650082 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.465720892 CEST | 49799 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:19:59.482424021 CEST | 80 | 49799 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.754971027 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.771867037 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.773791075 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.829407930 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.846271038 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.846927881 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.863792896 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.950195074 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.950227976 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:00.950318098 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.950359106 CEST | 49800 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:00.967267036 CEST | 80 | 49800 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:02.342312098 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.359740019 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:02.361860037 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.469934940 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.486787081 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:02.486865044 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.503736973 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:02.583328962 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:02.583445072 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:02.583587885 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.583679914 CEST | 49801 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:02.600524902 CEST | 80 | 49801 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:04.029702902 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.046838999 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:04.047013044 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.084400892 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.101612091 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:04.101706028 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.118892908 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:04.228653908 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:04.228724957 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:04.228817940 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.228853941 CEST | 49802 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:04.246030092 CEST | 80 | 49802 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.444933891 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.467056990 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.468657970 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.555366039 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.572211027 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.572520018 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.589159012 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.664393902 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.664552927 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.669153929 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:05.669239044 CEST | 49803 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:05.681411982 CEST | 80 | 49803 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.438045025 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:07.454986095 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.455106020 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:07.542974949 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:07.559683084 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.559847116 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:07.576662064 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.654144049 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.709064007 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:07.879829884 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:07.879909039 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:08.047424078 CEST | 49804 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:08.064300060 CEST | 80 | 49804 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.577955961 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.595006943 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.595140934 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.598373890 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.615386009 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.615540981 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.632536888 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.712814093 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.715125084 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.717983961 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:10.718080997 CEST | 49805 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:10.732115030 CEST | 80 | 49805 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.338217020 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.355299950 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.355441093 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.436188936 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.453286886 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.453449965 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.470510006 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.591089010 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.591221094 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.594422102 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:13.594501972 CEST | 49807 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:13.608201981 CEST | 80 | 49807 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.233618021 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:16.250448942 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.250562906 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:16.253890038 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:16.270783901 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.270906925 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:16.287662983 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.367387056 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.367506027 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:16.384238958 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.589589119 CEST | 80 | 49810 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:16.589670897 CEST | 49810 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.179527044 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.196300983 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:18.196494102 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.206398964 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.223120928 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:18.223212957 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.239923954 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:18.321571112 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:18.321686029 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.323549032 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:18.323647976 CEST | 49817 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:18.338377953 CEST | 80 | 49817 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.447664022 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:19.464756012 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.464859962 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:19.468605995 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:19.485603094 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.485657930 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:19.502621889 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.651838064 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.652024031 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:19.669224024 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.870147943 CEST | 80 | 49819 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:19.870239973 CEST | 49819 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:20.847016096 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:20.864243031 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:20.864358902 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:20.867616892 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:20.884805918 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:20.884880066 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:20.902081013 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:21.059680939 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:21.059714079 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:21.059819937 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:21.060834885 CEST | 49820 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:21.077909946 CEST | 80 | 49820 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.668685913 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.685655117 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.685779095 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.688766956 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.705775023 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.705862999 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.722696066 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.830317020 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.830532074 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.832551003 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:22.832680941 CEST | 49824 | 80 | 192.168.2.3 | 188.114.97.6 |
Jun 9, 2022 12:20:22.847379923 CEST | 80 | 49824 | 188.114.97.6 | 192.168.2.3 |
Jun 9, 2022 12:20:23.961297035 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:23.978221893 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:23.978319883 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:23.981117964 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:23.998279095 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:23.998447895 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:24.015305042 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:24.125456095 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:24.125608921 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:24.125622034 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:24.125667095 CEST | 49832 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:24.142852068 CEST | 80 | 49832 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.186321974 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.203450918 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.203594923 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.206676006 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.223751068 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.223875999 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.240885019 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.361783028 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.361867905 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:25.361893892 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.361941099 CEST | 49839 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:25.379086018 CEST | 80 | 49839 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.356450081 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.373245001 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.373344898 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.377021074 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.393747091 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.393836975 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.410582066 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.494107008 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.494256020 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.494360924 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:27.494412899 CEST | 49844 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:27.511152983 CEST | 80 | 49844 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.307107925 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.323877096 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.324093103 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.327641010 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.344423056 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.346561909 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.363325119 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.443782091 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.444286108 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.444533110 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Jun 9, 2022 12:20:29.444591999 CEST | 49851 | 80 | 192.168.2.3 | 188.114.96.7 |
Jun 9, 2022 12:20:29.461112976 CEST | 80 | 49851 | 188.114.96.7 | 192.168.2.3 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Jun 9, 2022 12:18:46.320662975 CEST | 55923 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:18:46.654654026 CEST | 53 | 55923 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:18:49.792571068 CEST | 57723 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:18:50.125027895 CEST | 53 | 57723 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:18:52.732420921 CEST | 57421 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:18:53.071388960 CEST | 53 | 57421 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:18:54.779560089 CEST | 65358 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:18:54.799858093 CEST | 53 | 65358 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:18:59.222264051 CEST | 53802 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:18:59.558743000 CEST | 53 | 53802 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:02.150631905 CEST | 63548 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:02.171612024 CEST | 53 | 63548 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:04.390835047 CEST | 49327 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:04.723588943 CEST | 53 | 49327 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:06.908921003 CEST | 51391 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:06.937489986 CEST | 53 | 51391 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:08.748076916 CEST | 58981 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:08.768929958 CEST | 53 | 58981 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:10.330476999 CEST | 64452 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:10.359749079 CEST | 53 | 64452 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:11.511810064 CEST | 61380 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:11.540854931 CEST | 53 | 61380 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:13.989813089 CEST | 63146 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:14.018810987 CEST | 53 | 63146 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:17.191728115 CEST | 52985 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:17.213033915 CEST | 53 | 52985 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:18.413028955 CEST | 58625 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:18.441941023 CEST | 53 | 58625 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:20.001535892 CEST | 52810 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:20.022313118 CEST | 53 | 52810 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:21.429740906 CEST | 50778 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:21.450298071 CEST | 53 | 50778 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:22.543773890 CEST | 55151 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:22.572666883 CEST | 53 | 55151 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:23.907179117 CEST | 59795 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:23.927850008 CEST | 53 | 59795 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:25.131369114 CEST | 59390 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:25.160787106 CEST | 53 | 59390 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:26.673069954 CEST | 64816 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:26.702125072 CEST | 53 | 64816 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:27.965425968 CEST | 64996 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:27.985680103 CEST | 53 | 64996 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:30.728729963 CEST | 52096 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:30.757725954 CEST | 53 | 52096 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:36.213679075 CEST | 60640 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:36.243210077 CEST | 53 | 60640 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:38.952038050 CEST | 49844 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:38.981350899 CEST | 53 | 49844 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:42.560014009 CEST | 63861 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:42.580615997 CEST | 53 | 63861 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:44.318942070 CEST | 51518 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:44.334171057 CEST | 53 | 51518 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:45.814466000 CEST | 52581 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:45.835082054 CEST | 53 | 52581 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:50.471400023 CEST | 50152 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:50.486875057 CEST | 53 | 50152 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:52.678580999 CEST | 56639 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:52.699559927 CEST | 53 | 56639 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:54.802884102 CEST | 50450 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:54.832241058 CEST | 53 | 50450 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:56.552596092 CEST | 52427 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:56.576721907 CEST | 53 | 52427 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:57.959706068 CEST | 62724 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:57.980577946 CEST | 53 | 62724 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:19:59.305026054 CEST | 64941 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:19:59.334050894 CEST | 53 | 64941 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:00.732938051 CEST | 55403 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:00.753479958 CEST | 53 | 55403 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:02.290066957 CEST | 54960 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:02.319335938 CEST | 53 | 54960 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:04.004287004 CEST | 61877 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:04.028419971 CEST | 53 | 61877 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:05.426645041 CEST | 64624 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:05.442060947 CEST | 53 | 64624 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:07.413156033 CEST | 64412 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:07.436849117 CEST | 53 | 64412 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:10.561003923 CEST | 51779 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:10.576389074 CEST | 53 | 51779 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:13.265501976 CEST | 50608 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:13.294228077 CEST | 53 | 50608 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:16.198606968 CEST | 62756 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:16.227924109 CEST | 53 | 62756 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:18.146718025 CEST | 58497 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:18.170475960 CEST | 53 | 58497 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:19.424609900 CEST | 62701 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:19.444677114 CEST | 53 | 62701 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:20.821300030 CEST | 53524 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:20.845380068 CEST | 53 | 53524 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:22.610430956 CEST | 61555 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:22.631125927 CEST | 53 | 61555 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:23.934340954 CEST | 62547 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:23.955482960 CEST | 53 | 62547 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:25.155899048 CEST | 57829 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:25.184815884 CEST | 53 | 57829 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:27.339462042 CEST | 57442 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:27.354715109 CEST | 53 | 57442 | 8.8.8.8 | 192.168.2.3 |
Jun 9, 2022 12:20:29.285346031 CEST | 51994 | 53 | 192.168.2.3 | 8.8.8.8 |
Jun 9, 2022 12:20:29.305778027 CEST | 53 | 51994 | 8.8.8.8 | 192.168.2.3 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class |
---|---|---|---|---|---|---|---|
Jun 9, 2022 12:18:46.320662975 CEST | 192.168.2.3 | 8.8.8.8 | 0x63fb | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:18:49.792571068 CEST | 192.168.2.3 | 8.8.8.8 | 0x3b2d | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:18:52.732420921 CEST | 192.168.2.3 | 8.8.8.8 | 0xdbee | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:18:54.779560089 CEST | 192.168.2.3 | 8.8.8.8 | 0x9ef | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:18:59.222264051 CEST | 192.168.2.3 | 8.8.8.8 | 0x9fff | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:02.150631905 CEST | 192.168.2.3 | 8.8.8.8 | 0x18e8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:04.390835047 CEST | 192.168.2.3 | 8.8.8.8 | 0x9a4a | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:06.908921003 CEST | 192.168.2.3 | 8.8.8.8 | 0x1441 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:08.748076916 CEST | 192.168.2.3 | 8.8.8.8 | 0xd355 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:10.330476999 CEST | 192.168.2.3 | 8.8.8.8 | 0x979 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:11.511810064 CEST | 192.168.2.3 | 8.8.8.8 | 0x6953 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:13.989813089 CEST | 192.168.2.3 | 8.8.8.8 | 0xa08e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:17.191728115 CEST | 192.168.2.3 | 8.8.8.8 | 0x918c | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:18.413028955 CEST | 192.168.2.3 | 8.8.8.8 | 0xf6c6 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:20.001535892 CEST | 192.168.2.3 | 8.8.8.8 | 0x6115 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:21.429740906 CEST | 192.168.2.3 | 8.8.8.8 | 0x61a9 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:22.543773890 CEST | 192.168.2.3 | 8.8.8.8 | 0x34fd | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:23.907179117 CEST | 192.168.2.3 | 8.8.8.8 | 0x51b0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:25.131369114 CEST | 192.168.2.3 | 8.8.8.8 | 0x118e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:26.673069954 CEST | 192.168.2.3 | 8.8.8.8 | 0x8244 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:27.965425968 CEST | 192.168.2.3 | 8.8.8.8 | 0x304c | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:30.728729963 CEST | 192.168.2.3 | 8.8.8.8 | 0x5289 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:36.213679075 CEST | 192.168.2.3 | 8.8.8.8 | 0xa975 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:38.952038050 CEST | 192.168.2.3 | 8.8.8.8 | 0xc035 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:42.560014009 CEST | 192.168.2.3 | 8.8.8.8 | 0xd816 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:44.318942070 CEST | 192.168.2.3 | 8.8.8.8 | 0x25ec | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:45.814466000 CEST | 192.168.2.3 | 8.8.8.8 | 0x2e8b | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:50.471400023 CEST | 192.168.2.3 | 8.8.8.8 | 0x8aeb | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:52.678580999 CEST | 192.168.2.3 | 8.8.8.8 | 0x223e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:54.802884102 CEST | 192.168.2.3 | 8.8.8.8 | 0xcec8 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:56.552596092 CEST | 192.168.2.3 | 8.8.8.8 | 0x2bf0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:57.959706068 CEST | 192.168.2.3 | 8.8.8.8 | 0x5e55 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:19:59.305026054 CEST | 192.168.2.3 | 8.8.8.8 | 0xe373 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:00.732938051 CEST | 192.168.2.3 | 8.8.8.8 | 0x4d36 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:02.290066957 CEST | 192.168.2.3 | 8.8.8.8 | 0x20cd | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:04.004287004 CEST | 192.168.2.3 | 8.8.8.8 | 0xa367 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:05.426645041 CEST | 192.168.2.3 | 8.8.8.8 | 0x4af5 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:07.413156033 CEST | 192.168.2.3 | 8.8.8.8 | 0xc229 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:10.561003923 CEST | 192.168.2.3 | 8.8.8.8 | 0xbe0 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:13.265501976 CEST | 192.168.2.3 | 8.8.8.8 | 0x96e4 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:16.198606968 CEST | 192.168.2.3 | 8.8.8.8 | 0x3b2f | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:18.146718025 CEST | 192.168.2.3 | 8.8.8.8 | 0x9deb | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:19.424609900 CEST | 192.168.2.3 | 8.8.8.8 | 0x63e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:20.821300030 CEST | 192.168.2.3 | 8.8.8.8 | 0xc81a | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:22.610430956 CEST | 192.168.2.3 | 8.8.8.8 | 0xd04d | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:23.934340954 CEST | 192.168.2.3 | 8.8.8.8 | 0x5a2e | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:25.155899048 CEST | 192.168.2.3 | 8.8.8.8 | 0xbeb6 | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:27.339462042 CEST | 192.168.2.3 | 8.8.8.8 | 0x751b | Standard query (0) | A (IP address) | IN (0x0001) | |
Jun 9, 2022 12:20:29.285346031 CEST | 192.168.2.3 | 8.8.8.8 | 0xd85e | Standard query (0) | A (IP address) | IN (0x0001) |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class |
---|---|---|---|---|---|---|---|---|---|
Jun 9, 2022 12:18:46.654654026 CEST | 8.8.8.8 | 192.168.2.3 | 0x63fb | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:46.654654026 CEST | 8.8.8.8 | 192.168.2.3 | 0x63fb | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:50.125027895 CEST | 8.8.8.8 | 192.168.2.3 | 0x3b2d | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:50.125027895 CEST | 8.8.8.8 | 192.168.2.3 | 0x3b2d | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:53.071388960 CEST | 8.8.8.8 | 192.168.2.3 | 0xdbee | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:53.071388960 CEST | 8.8.8.8 | 192.168.2.3 | 0xdbee | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:54.799858093 CEST | 8.8.8.8 | 192.168.2.3 | 0x9ef | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:54.799858093 CEST | 8.8.8.8 | 192.168.2.3 | 0x9ef | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:59.558743000 CEST | 8.8.8.8 | 192.168.2.3 | 0x9fff | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:18:59.558743000 CEST | 8.8.8.8 | 192.168.2.3 | 0x9fff | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:02.171612024 CEST | 8.8.8.8 | 192.168.2.3 | 0x18e8 | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:02.171612024 CEST | 8.8.8.8 | 192.168.2.3 | 0x18e8 | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:04.723588943 CEST | 8.8.8.8 | 192.168.2.3 | 0x9a4a | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:04.723588943 CEST | 8.8.8.8 | 192.168.2.3 | 0x9a4a | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:06.937489986 CEST | 8.8.8.8 | 192.168.2.3 | 0x1441 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:06.937489986 CEST | 8.8.8.8 | 192.168.2.3 | 0x1441 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:08.768929958 CEST | 8.8.8.8 | 192.168.2.3 | 0xd355 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:08.768929958 CEST | 8.8.8.8 | 192.168.2.3 | 0xd355 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:10.359749079 CEST | 8.8.8.8 | 192.168.2.3 | 0x979 | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:10.359749079 CEST | 8.8.8.8 | 192.168.2.3 | 0x979 | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:11.540854931 CEST | 8.8.8.8 | 192.168.2.3 | 0x6953 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:11.540854931 CEST | 8.8.8.8 | 192.168.2.3 | 0x6953 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:14.018810987 CEST | 8.8.8.8 | 192.168.2.3 | 0xa08e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:14.018810987 CEST | 8.8.8.8 | 192.168.2.3 | 0xa08e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:17.213033915 CEST | 8.8.8.8 | 192.168.2.3 | 0x918c | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:17.213033915 CEST | 8.8.8.8 | 192.168.2.3 | 0x918c | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:18.441941023 CEST | 8.8.8.8 | 192.168.2.3 | 0xf6c6 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:18.441941023 CEST | 8.8.8.8 | 192.168.2.3 | 0xf6c6 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:20.022313118 CEST | 8.8.8.8 | 192.168.2.3 | 0x6115 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:20.022313118 CEST | 8.8.8.8 | 192.168.2.3 | 0x6115 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:21.450298071 CEST | 8.8.8.8 | 192.168.2.3 | 0x61a9 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:21.450298071 CEST | 8.8.8.8 | 192.168.2.3 | 0x61a9 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:22.572666883 CEST | 8.8.8.8 | 192.168.2.3 | 0x34fd | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:22.572666883 CEST | 8.8.8.8 | 192.168.2.3 | 0x34fd | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:23.927850008 CEST | 8.8.8.8 | 192.168.2.3 | 0x51b0 | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:23.927850008 CEST | 8.8.8.8 | 192.168.2.3 | 0x51b0 | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:25.160787106 CEST | 8.8.8.8 | 192.168.2.3 | 0x118e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:25.160787106 CEST | 8.8.8.8 | 192.168.2.3 | 0x118e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:26.702125072 CEST | 8.8.8.8 | 192.168.2.3 | 0x8244 | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:26.702125072 CEST | 8.8.8.8 | 192.168.2.3 | 0x8244 | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:27.985680103 CEST | 8.8.8.8 | 192.168.2.3 | 0x304c | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:27.985680103 CEST | 8.8.8.8 | 192.168.2.3 | 0x304c | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:30.757725954 CEST | 8.8.8.8 | 192.168.2.3 | 0x5289 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:30.757725954 CEST | 8.8.8.8 | 192.168.2.3 | 0x5289 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:36.243210077 CEST | 8.8.8.8 | 192.168.2.3 | 0xa975 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:36.243210077 CEST | 8.8.8.8 | 192.168.2.3 | 0xa975 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:38.981350899 CEST | 8.8.8.8 | 192.168.2.3 | 0xc035 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:38.981350899 CEST | 8.8.8.8 | 192.168.2.3 | 0xc035 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:42.580615997 CEST | 8.8.8.8 | 192.168.2.3 | 0xd816 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:42.580615997 CEST | 8.8.8.8 | 192.168.2.3 | 0xd816 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:44.334171057 CEST | 8.8.8.8 | 192.168.2.3 | 0x25ec | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:44.334171057 CEST | 8.8.8.8 | 192.168.2.3 | 0x25ec | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:45.835082054 CEST | 8.8.8.8 | 192.168.2.3 | 0x2e8b | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:45.835082054 CEST | 8.8.8.8 | 192.168.2.3 | 0x2e8b | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:50.486875057 CEST | 8.8.8.8 | 192.168.2.3 | 0x8aeb | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:50.486875057 CEST | 8.8.8.8 | 192.168.2.3 | 0x8aeb | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:52.699559927 CEST | 8.8.8.8 | 192.168.2.3 | 0x223e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:52.699559927 CEST | 8.8.8.8 | 192.168.2.3 | 0x223e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:54.832241058 CEST | 8.8.8.8 | 192.168.2.3 | 0xcec8 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:54.832241058 CEST | 8.8.8.8 | 192.168.2.3 | 0xcec8 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:56.576721907 CEST | 8.8.8.8 | 192.168.2.3 | 0x2bf0 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:56.576721907 CEST | 8.8.8.8 | 192.168.2.3 | 0x2bf0 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:57.980577946 CEST | 8.8.8.8 | 192.168.2.3 | 0x5e55 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:57.980577946 CEST | 8.8.8.8 | 192.168.2.3 | 0x5e55 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:59.334050894 CEST | 8.8.8.8 | 192.168.2.3 | 0xe373 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:19:59.334050894 CEST | 8.8.8.8 | 192.168.2.3 | 0xe373 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:00.753479958 CEST | 8.8.8.8 | 192.168.2.3 | 0x4d36 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:00.753479958 CEST | 8.8.8.8 | 192.168.2.3 | 0x4d36 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:02.319335938 CEST | 8.8.8.8 | 192.168.2.3 | 0x20cd | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:02.319335938 CEST | 8.8.8.8 | 192.168.2.3 | 0x20cd | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:04.028419971 CEST | 8.8.8.8 | 192.168.2.3 | 0xa367 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:04.028419971 CEST | 8.8.8.8 | 192.168.2.3 | 0xa367 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:05.442060947 CEST | 8.8.8.8 | 192.168.2.3 | 0x4af5 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:05.442060947 CEST | 8.8.8.8 | 192.168.2.3 | 0x4af5 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:07.436849117 CEST | 8.8.8.8 | 192.168.2.3 | 0xc229 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:07.436849117 CEST | 8.8.8.8 | 192.168.2.3 | 0xc229 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:10.576389074 CEST | 8.8.8.8 | 192.168.2.3 | 0xbe0 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:10.576389074 CEST | 8.8.8.8 | 192.168.2.3 | 0xbe0 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:13.294228077 CEST | 8.8.8.8 | 192.168.2.3 | 0x96e4 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:13.294228077 CEST | 8.8.8.8 | 192.168.2.3 | 0x96e4 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:16.227924109 CEST | 8.8.8.8 | 192.168.2.3 | 0x3b2f | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:16.227924109 CEST | 8.8.8.8 | 192.168.2.3 | 0x3b2f | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:18.170475960 CEST | 8.8.8.8 | 192.168.2.3 | 0x9deb | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:18.170475960 CEST | 8.8.8.8 | 192.168.2.3 | 0x9deb | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:19.444677114 CEST | 8.8.8.8 | 192.168.2.3 | 0x63e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:19.444677114 CEST | 8.8.8.8 | 192.168.2.3 | 0x63e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:20.845380068 CEST | 8.8.8.8 | 192.168.2.3 | 0xc81a | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:20.845380068 CEST | 8.8.8.8 | 192.168.2.3 | 0xc81a | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:22.631125927 CEST | 8.8.8.8 | 192.168.2.3 | 0xd04d | No error (0) | 188.114.97.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:22.631125927 CEST | 8.8.8.8 | 192.168.2.3 | 0xd04d | No error (0) | 188.114.96.6 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:23.955482960 CEST | 8.8.8.8 | 192.168.2.3 | 0x5a2e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:23.955482960 CEST | 8.8.8.8 | 192.168.2.3 | 0x5a2e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:25.184815884 CEST | 8.8.8.8 | 192.168.2.3 | 0xbeb6 | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:25.184815884 CEST | 8.8.8.8 | 192.168.2.3 | 0xbeb6 | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:27.354715109 CEST | 8.8.8.8 | 192.168.2.3 | 0x751b | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:27.354715109 CEST | 8.8.8.8 | 192.168.2.3 | 0x751b | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:29.305778027 CEST | 8.8.8.8 | 192.168.2.3 | 0xd85e | No error (0) | 188.114.96.7 | A (IP address) | IN (0x0001) | ||
Jun 9, 2022 12:20:29.305778027 CEST | 8.8.8.8 | 192.168.2.3 | 0xd85e | No error (0) | 188.114.97.7 | A (IP address) | IN (0x0001) |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.3 | 49745 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:18:46.752224922 CEST | 1142 | OUT | |
Jun 9, 2022 12:18:46.769325018 CEST | 1143 | OUT | |
Jun 9, 2022 12:18:46.913125038 CEST | 1143 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.3 | 49748 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:18:50.155869961 CEST | 1144 | OUT | |
Jun 9, 2022 12:18:50.173213959 CEST | 1145 | OUT | |
Jun 9, 2022 12:18:50.320050955 CEST | 1145 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
10 | 192.168.2.3 | 49769 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:11.569139957 CEST | 1331 | OUT | |
Jun 9, 2022 12:19:11.588557005 CEST | 1331 | OUT | |
Jun 9, 2022 12:19:11.716733932 CEST | 1332 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
11 | 192.168.2.3 | 49770 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:14.041673899 CEST | 1333 | OUT | |
Jun 9, 2022 12:19:14.058743954 CEST | 1333 | OUT | |
Jun 9, 2022 12:19:14.153940916 CEST | 1334 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
12 | 192.168.2.3 | 49771 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:17.236324072 CEST | 1335 | OUT | |
Jun 9, 2022 12:19:17.253592014 CEST | 1335 | OUT | |
Jun 9, 2022 12:19:17.360335112 CEST | 1336 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
13 | 192.168.2.3 | 49772 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:18.470176935 CEST | 1336 | OUT | |
Jun 9, 2022 12:19:18.487781048 CEST | 1337 | OUT | |
Jun 9, 2022 12:19:18.584544897 CEST | 1337 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
14 | 192.168.2.3 | 49773 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:20.082461119 CEST | 1338 | OUT | |
Jun 9, 2022 12:19:20.101741076 CEST | 1339 | OUT | |
Jun 9, 2022 12:19:20.237472057 CEST | 1339 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
15 | 192.168.2.3 | 49774 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:21.474098921 CEST | 1340 | OUT | |
Jun 9, 2022 12:19:21.490986109 CEST | 1341 | OUT | |
Jun 9, 2022 12:19:21.592752934 CEST | 1341 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
16 | 192.168.2.3 | 49775 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:22.604146004 CEST | 1342 | OUT | |
Jun 9, 2022 12:19:22.621094942 CEST | 1343 | OUT | |
Jun 9, 2022 12:19:22.945173979 CEST | 1343 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
17 | 192.168.2.3 | 49776 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:23.957128048 CEST | 1344 | OUT | |
Jun 9, 2022 12:19:23.974256992 CEST | 1344 | OUT | |
Jun 9, 2022 12:19:24.182347059 CEST | 1345 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
18 | 192.168.2.3 | 49777 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:25.204895973 CEST | 1346 | OUT | |
Jun 9, 2022 12:19:25.222219944 CEST | 1346 | OUT | |
Jun 9, 2022 12:19:25.556766987 CEST | 1347 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
19 | 192.168.2.3 | 49778 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:26.733757973 CEST | 1348 | OUT | |
Jun 9, 2022 12:19:26.751442909 CEST | 1348 | OUT | |
Jun 9, 2022 12:19:26.890752077 CEST | 1349 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.3 | 49751 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:18:53.097949982 CEST | 1154 | OUT | |
Jun 9, 2022 12:18:53.114986897 CEST | 1155 | OUT | |
Jun 9, 2022 12:18:53.248898029 CEST | 1155 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
20 | 192.168.2.3 | 49779 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:28.006927013 CEST | 1350 | OUT | |
Jun 9, 2022 12:19:28.023961067 CEST | 1350 | OUT | |
Jun 9, 2022 12:19:28.178622007 CEST | 1351 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
21 | 192.168.2.3 | 49782 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:30.781711102 CEST | 1372 | OUT | |
Jun 9, 2022 12:19:30.798774958 CEST | 1372 | OUT | |
Jun 9, 2022 12:19:30.919230938 CEST | 1399 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
22 | 192.168.2.3 | 49783 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:36.273915052 CEST | 1400 | OUT | |
Jun 9, 2022 12:19:36.290921926 CEST | 1400 | OUT | |
Jun 9, 2022 12:19:36.381258965 CEST | 1401 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
23 | 192.168.2.3 | 49784 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:39.004620075 CEST | 1402 | OUT | |
Jun 9, 2022 12:19:39.021857977 CEST | 1402 | OUT | |
Jun 9, 2022 12:19:39.411545992 CEST | 1403 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
24 | 192.168.2.3 | 49785 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:42.634597063 CEST | 1404 | OUT | |
Jun 9, 2022 12:19:42.651922941 CEST | 1404 | OUT | |
Jun 9, 2022 12:19:42.788748980 CEST | 1405 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
25 | 192.168.2.3 | 49786 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:44.361043930 CEST | 1405 | OUT | |
Jun 9, 2022 12:19:44.378279924 CEST | 1406 | OUT | |
Jun 9, 2022 12:19:44.643172979 CEST | 1407 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
26 | 192.168.2.3 | 49792 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:45.858683109 CEST | 3942 | OUT | |
Jun 9, 2022 12:19:45.876180887 CEST | 3943 | OUT | |
Jun 9, 2022 12:19:45.962203979 CEST | 3945 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
27 | 192.168.2.3 | 49793 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:50.509118080 CEST | 8624 | OUT | |
Jun 9, 2022 12:19:50.526200056 CEST | 8624 | OUT | |
Jun 9, 2022 12:19:50.626293898 CEST | 8625 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
28 | 192.168.2.3 | 49794 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:52.723949909 CEST | 8626 | OUT | |
Jun 9, 2022 12:19:52.741095066 CEST | 8626 | OUT | |
Jun 9, 2022 12:19:52.869291067 CEST | 8627 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
29 | 192.168.2.3 | 49796 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:54.857506037 CEST | 9109 | OUT | |
Jun 9, 2022 12:19:54.875508070 CEST | 9109 | OUT | |
Jun 9, 2022 12:19:55.001300097 CEST | 9110 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.3 | 49752 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:18:54.883060932 CEST | 1156 | OUT | |
Jun 9, 2022 12:18:54.900248051 CEST | 1156 | OUT | |
Jun 9, 2022 12:18:55.062665939 CEST | 1157 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
30 | 192.168.2.3 | 49797 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:56.597737074 CEST | 9111 | OUT | |
Jun 9, 2022 12:19:56.614737988 CEST | 9111 | OUT | |
Jun 9, 2022 12:19:56.728569984 CEST | 9112 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
31 | 192.168.2.3 | 49798 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:58.002191067 CEST | 9113 | OUT | |
Jun 9, 2022 12:19:58.019359112 CEST | 9113 | OUT | |
Jun 9, 2022 12:19:58.143650055 CEST | 9114 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
32 | 192.168.2.3 | 49799 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:59.356295109 CEST | 9115 | OUT | |
Jun 9, 2022 12:19:59.373226881 CEST | 9115 | OUT | |
Jun 9, 2022 12:19:59.465481997 CEST | 9116 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
33 | 192.168.2.3 | 49800 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:00.829407930 CEST | 9116 | OUT | |
Jun 9, 2022 12:20:00.846927881 CEST | 9117 | OUT | |
Jun 9, 2022 12:20:00.950195074 CEST | 9117 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
34 | 192.168.2.3 | 49801 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:02.469934940 CEST | 9118 | OUT | |
Jun 9, 2022 12:20:02.486865044 CEST | 9119 | OUT | |
Jun 9, 2022 12:20:02.583328962 CEST | 9119 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
35 | 192.168.2.3 | 49802 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:04.084400892 CEST | 9120 | OUT | |
Jun 9, 2022 12:20:04.101706028 CEST | 9121 | OUT | |
Jun 9, 2022 12:20:04.228653908 CEST | 9121 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
36 | 192.168.2.3 | 49803 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:05.555366039 CEST | 9122 | OUT | |
Jun 9, 2022 12:20:05.572520018 CEST | 9123 | OUT | |
Jun 9, 2022 12:20:05.664393902 CEST | 9123 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
37 | 192.168.2.3 | 49804 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:07.542974949 CEST | 9124 | OUT | |
Jun 9, 2022 12:20:07.559847116 CEST | 9125 | OUT | |
Jun 9, 2022 12:20:07.654144049 CEST | 9125 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
38 | 192.168.2.3 | 49805 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:10.598373890 CEST | 9126 | OUT | |
Jun 9, 2022 12:20:10.615540981 CEST | 9127 | OUT | |
Jun 9, 2022 12:20:10.712814093 CEST | 9127 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
39 | 192.168.2.3 | 49807 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:13.436188936 CEST | 9133 | OUT | |
Jun 9, 2022 12:20:13.453449965 CEST | 9133 | OUT | |
Jun 9, 2022 12:20:13.591089010 CEST | 9134 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.3 | 49761 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:18:59.590863943 CEST | 1274 | OUT | |
Jun 9, 2022 12:18:59.607702017 CEST | 1274 | OUT | |
Jun 9, 2022 12:18:59.765675068 CEST | 1290 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
40 | 192.168.2.3 | 49810 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:16.253890038 CEST | 9145 | OUT | |
Jun 9, 2022 12:20:16.270906925 CEST | 9146 | OUT | |
Jun 9, 2022 12:20:16.367387056 CEST | 9147 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
41 | 192.168.2.3 | 49817 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:18.206398964 CEST | 9162 | OUT | |
Jun 9, 2022 12:20:18.223212957 CEST | 9162 | OUT | |
Jun 9, 2022 12:20:18.321571112 CEST | 9163 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
42 | 192.168.2.3 | 49819 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:19.468605995 CEST | 9166 | OUT | |
Jun 9, 2022 12:20:19.485657930 CEST | 9167 | OUT | |
Jun 9, 2022 12:20:19.651838064 CEST | 9167 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
43 | 192.168.2.3 | 49820 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:20.867616892 CEST | 9168 | OUT | |
Jun 9, 2022 12:20:20.884880066 CEST | 9169 | OUT | |
Jun 9, 2022 12:20:21.059680939 CEST | 9169 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
44 | 192.168.2.3 | 49824 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:22.688766956 CEST | 9176 | OUT | |
Jun 9, 2022 12:20:22.705862999 CEST | 9177 | OUT | |
Jun 9, 2022 12:20:22.830317020 CEST | 9182 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
45 | 192.168.2.3 | 49832 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:23.981117964 CEST | 9232 | OUT | |
Jun 9, 2022 12:20:23.998447895 CEST | 9232 | OUT | |
Jun 9, 2022 12:20:24.125456095 CEST | 9240 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
46 | 192.168.2.3 | 49839 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:25.206676006 CEST | 9292 | OUT | |
Jun 9, 2022 12:20:25.223875999 CEST | 9292 | OUT | |
Jun 9, 2022 12:20:25.361783028 CEST | 9294 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
47 | 192.168.2.3 | 49844 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:27.377021074 CEST | 9413 | OUT | |
Jun 9, 2022 12:20:27.393836975 CEST | 9414 | OUT | |
Jun 9, 2022 12:20:27.494107008 CEST | 9419 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
48 | 192.168.2.3 | 49851 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:20:29.327641010 CEST | 9639 | OUT | |
Jun 9, 2022 12:20:29.346561909 CEST | 9639 | OUT | |
Jun 9, 2022 12:20:29.443782091 CEST | 9640 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
5 | 192.168.2.3 | 49764 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:02.212367058 CEST | 1320 | OUT | |
Jun 9, 2022 12:19:02.229402065 CEST | 1320 | OUT | |
Jun 9, 2022 12:19:02.588592052 CEST | 1321 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
6 | 192.168.2.3 | 49765 | 188.114.97.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:04.748877048 CEST | 1322 | OUT | |
Jun 9, 2022 12:19:04.765901089 CEST | 1323 | OUT | |
Jun 9, 2022 12:19:04.892672062 CEST | 1323 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
7 | 192.168.2.3 | 49766 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:06.967493057 CEST | 1325 | OUT | |
Jun 9, 2022 12:19:06.984461069 CEST | 1325 | OUT | |
Jun 9, 2022 12:19:07.076062918 CEST | 1326 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
8 | 192.168.2.3 | 49767 | 188.114.96.7 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:08.800960064 CEST | 1327 | OUT | |
Jun 9, 2022 12:19:08.819365978 CEST | 1327 | OUT | |
Jun 9, 2022 12:19:08.912668943 CEST | 1328 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
9 | 192.168.2.3 | 49768 | 188.114.97.6 | 80 | C:\Users\user\Desktop\ZciowjM9hN.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Jun 9, 2022 12:19:10.383861065 CEST | 1329 | OUT | |
Jun 9, 2022 12:19:10.401235104 CEST | 1329 | OUT | |
Jun 9, 2022 12:19:10.548271894 CEST | 1330 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 12:18:20 |
Start date: | 09/06/2022 |
Path: | C:\Users\user\Desktop\ZciowjM9hN.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x810000 |
File size: | 621056 bytes |
MD5 hash: | 4015330DA10DE30BCDF2B65F7F98BAEB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Target ID: | 9 |
Start time: | 12:18:40 |
Start date: | 09/06/2022 |
Path: | C:\Users\user\Desktop\ZciowjM9hN.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0xec0000 |
File size: | 621056 bytes |
MD5 hash: | 4015330DA10DE30BCDF2B65F7F98BAEB |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Yara matches: |
|
Reputation: | low |
Execution Graph
Execution Coverage: | 16.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 180 |
Total number of Limit Nodes: | 3 |
Graph
Function 010E9530 Relevance: 1.7, APIs: 1, Instructions: 191COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 051C0040 Relevance: 1.6, APIs: 1, Instructions: 113COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010E5364 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010E3E08 Relevance: 1.6, APIs: 1, Instructions: 96COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 051C2600 Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EBB11 Relevance: 1.6, APIs: 1, Instructions: 88COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EAC5C Relevance: 1.6, APIs: 1, Instructions: 65COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EBA49 Relevance: 1.6, APIs: 1, Instructions: 61COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010E8A90 Relevance: 1.6, APIs: 1, Instructions: 55libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010E9990 Relevance: 1.6, APIs: 1, Instructions: 54libraryCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010E9710 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 051C0288 Relevance: 1.5, APIs: 1, Instructions: 44COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EE710 Relevance: .3, Instructions: 315COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EC344 Relevance: .3, Instructions: 265COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 010EE701 Relevance: .2, Instructions: 221COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403D74 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 200fileCOMMON
Control-flow Graph
C-Code - Quality: 85% |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 78% |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402B7C Relevance: 3.0, APIs: 2, Instructions: 20memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406069 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404ED4 Relevance: 1.5, APIs: 1, Instructions: 9networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
C-Code - Quality: 75% |
|
APIs |
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404E17 Relevance: 7.6, APIs: 5, Instructions: 72networkCOMMON
Control-flow Graph
C-Code - Quality: 37% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004040BB Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 129filememoryCOMMON
Control-flow Graph
C-Code - Quality: 74% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 79% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004042CF Relevance: 4.6, APIs: 3, Instructions: 60fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00412D31 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 178threadCOMMON
C-Code - Quality: 34% |
|
APIs |
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402C03 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 13libraryloaderCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 92% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402BAB Relevance: 3.0, APIs: 2, Instructions: 11memoryCOMMON
C-Code - Quality: 100% |
|
APIs |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004060BD Relevance: 1.6, APIs: 1, Instructions: 53COMMON
C-Code - Quality: 40% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C62 Relevance: 1.5, APIs: 1, Instructions: 24COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040642C Relevance: 1.5, APIs: 1, Instructions: 18COMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404EEA Relevance: 1.5, APIs: 1, Instructions: 16networkCOMMON
C-Code - Quality: 37% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BD0 Relevance: 1.5, APIs: 1, Instructions: 14COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404DF3 Relevance: 1.5, APIs: 1, Instructions: 13networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040427D Relevance: 1.5, APIs: 1, Instructions: 13COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C40 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403C08 Relevance: 1.5, APIs: 1, Instructions: 12fileCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00402C1F Relevance: 1.5, APIs: 1, Instructions: 12libraryCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BEF Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403BB7 Relevance: 1.5, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403B64 Relevance: 1.5, APIs: 1, Instructions: 11COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00404DE5 Relevance: 1.5, APIs: 1, Instructions: 6COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00403F9E Relevance: 1.3, APIs: 1, Instructions: 16COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00406472 Relevance: 1.3, APIs: 1, Instructions: 12sleepCOMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 004058EA Relevance: 1.3, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00405924 Relevance: 1.3, APIs: 1, Instructions: 12COMMON
C-Code - Quality: 100% |
|
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040D069 Relevance: 12.6, Strings: 10, Instructions: 138COMMON
C-Code - Quality: 88% |
|
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0040317B Relevance: .0, Instructions: 46COMMON
C-Code - Quality: 90% |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Yara matches |
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |