Windows
Analysis Report
nwY3YpWQVx.exe
Overview
General Information
Detection
Score: | 93 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- nwY3YpWQVx.exe (PID: 5996 cmdline:
C:\Users\u ser\Deskto p\nwY3YpWQ Vx.exe MD5: 0D43B051C7C73233C85697219BC9A4F4) - Zip.exe (PID: 4588 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\Zip.ex e" MD5: AF07E88EC22CC90CEBFDA29517F101B9)
- update_222410.exe (PID: 1576 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\update _222410.ex e" / start MD5: 0D43B051C7C73233C85697219BC9A4F4)
- update_222410.exe (PID: 3964 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\update _222410.ex e" / start MD5: 0D43B051C7C73233C85697219BC9A4F4)
- update_222410.exe (PID: 3424 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\update _222410.ex e" / start MD5: 0D43B051C7C73233C85697219BC9A4F4)
- update_222410.exe (PID: 5928 cmdline:
"C:\Users\ user\AppDa ta\Local\T emp\update _222410.ex e" / start MD5: 0D43B051C7C73233C85697219BC9A4F4)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Predator | Yara detected Predator | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
INDICATOR_SUSPICIOUS_EXE_References_VPN | Detects executables referencing many VPN software clients. Observed in infosteslers | ditekSHen |
| |
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
| |
JoeSecurity_Predator | Yara detected Predator | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
| |
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
| |
Click to see the 7 entries |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
| |
Windows_Trojan_Lucifer_ce9d4cc8 | unknown | unknown |
| |
JoeSecurity_Predator | Yara detected Predator | Joe Security | ||
JoeSecurity_GenericDownloader_1 | Yara detected Generic Downloader | Joe Security | ||
JoeSecurity_CredentialStealer | Yara detected Credential Stealer | Joe Security | ||
Click to see the 22 entries |
Timestamp: | 192.168.2.513.90.128.25349698802022986 11/24/22-10:05:39.916527 |
SID: | 2022986 |
Source Port: | 49698 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349701802022818 11/24/22-10:05:49.419418 |
SID: | 2022818 |
Source Port: | 49701 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349696802022986 11/24/22-10:05:31.007346 |
SID: | 2022986 |
Source Port: | 49696 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349692802022986 11/24/22-10:05:25.056792 |
SID: | 2022986 |
Source Port: | 49692 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349698802022818 11/24/22-10:05:39.916527 |
SID: | 2022818 |
Source Port: | 49698 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349701802022986 11/24/22-10:05:49.419418 |
SID: | 2022986 |
Source Port: | 49701 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349696802022818 11/24/22-10:05:31.007346 |
SID: | 2022818 |
Source Port: | 49696 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.513.90.128.25349692802022818 11/24/22-10:05:25.056792 |
SID: | 2022818 |
Source Port: | 49692 |
Destination Port: | 80 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Avira: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Virustotal: | Perma Link |
Source: | ReversingLabs: |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Avira: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF9A63CD2E7 | |
Source: | Code function: | 0_2_00007FF9A63CA1A9 | |
Source: | Code function: | 0_2_00007FF9A63CDAEB | |
Source: | Code function: | 1_2_00007FF9A63D9DB9 | |
Source: | Code function: | 7_2_00007FF9A63C6EEE | |
Source: | Code function: | 12_2_00007FF9A63C6EEE |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: | ||
Source: | DNS query: |
Source: | HTTP traffic detected: |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | ASN Name: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: | ||
Source: | TCP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | HTTP traffic detected: |
Source: | DNS traffic detected: |
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: | ||
Source: | HTTP traffic detected: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00007FF9A63B41C0 | |
Source: | Code function: | 0_2_00007FF9A63BA283 | |
Source: | Code function: | 0_2_00007FF9A63BEB81 | |
Source: | Code function: | 0_2_00007FF9A63BD68D | |
Source: | Code function: | 0_2_00007FF9A63C2CF6 | |
Source: | Code function: | 0_2_00007FF9A63C3AA2 | |
Source: | Code function: | 1_2_00007FF9A63D2D26 | |
Source: | Code function: | 1_2_00007FF9A63D3AD2 | |
Source: | Code function: | 7_2_00007FF9A63C2CF6 | |
Source: | Code function: | 7_2_00007FF9A63B3510 | |
Source: | Code function: | 7_2_00007FF9A63C3AA2 | |
Source: | Code function: | 7_2_00007FF9A63B42AE | |
Source: | Code function: | 7_2_00007FF9A63BA283 | |
Source: | Code function: | 12_2_00007FF9A63BA283 | |
Source: | Code function: | 12_2_00007FF9A63BEB81 | |
Source: | Code function: | 12_2_00007FF9A63BD68D | |
Source: | Code function: | 12_2_00007FF9A63C3AA2 | |
Source: | Code function: | 12_2_00007FF9A63C2CF6 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | File read: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Static file information: | |||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Mutant created: |
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior | ||
Source: | File read: | Jump to behavior |
Source: | Automated click: | ||
Source: | Automated click: |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF9A63B61CD | |
Source: | Code function: | 0_2_00007FF9A63B81ED | |
Source: | Code function: | 0_2_00007FF9A63B81DD | |
Source: | Code function: | 1_2_00007FF9A63D731A | |
Source: | Code function: | 1_2_00007FF9A63C724D | |
Source: | Code function: | 1_2_00007FF9A63C725D | |
Source: | Code function: | 7_2_00007FF9A63B61CD | |
Source: | Code function: | 7_2_00007FF9A63B81DD | |
Source: | Code function: | 7_2_00007FF9A63B764D | |
Source: | Code function: | 7_2_00007FF9A63B765D | |
Source: | Code function: | 7_2_00007FF9A63B81ED | |
Source: | Code function: | 12_2_00007FF9A63B61CD | |
Source: | Code function: | 12_2_00007FF9A63B81ED | |
Source: | Code function: | 12_2_00007FF9A63B81DD |
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file | ||
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Hooking and other Techniques for Hiding and Protection |
---|
Source: | File moved: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Dropped PE file which has not been started: | Jump to dropped file | ||
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior | ||
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | WMI Queries: | ||
Source: | WMI Queries: |
Source: | Binary or memory string: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior | ||
Source: | File opened: | Jump to behavior |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Valid Accounts | 21 Windows Management Instrumentation | 1 Registry Run Keys / Startup Folder | 11 Process Injection | 11 Masquerading | 1 OS Credential Dumping | 131 Security Software Discovery | Remote Services | 1 Archive Collected Data | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Eavesdrop on Insecure Network Communication | Remotely Track Device Without Authorization | Modify System Partition |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 1 Registry Run Keys / Startup Folder | 1 Disable or Modify Tools | LSASS Memory | 1 Process Discovery | Remote Desktop Protocol | 1 Data from Local System | Exfiltration Over Bluetooth | 1 Ingress Tool Transfer | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Device Lockout |
Domain Accounts | At (Linux) | Logon Script (Windows) | Logon Script (Windows) | 31 Virtualization/Sandbox Evasion | Security Account Manager | 31 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 3 Non-Application Layer Protocol | Exploit SS7 to Track Device Location | Obtain Device Cloud Backups | Delete Device Data |
Local Accounts | At (Windows) | Logon Script (Mac) | Logon Script (Mac) | 11 Process Injection | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Scheduled Transfer | 13 Application Layer Protocol | SIM Card Swap | Carrier Billing Fraud | |
Cloud Accounts | Cron | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 Remote System Discovery | SSH | Keylogging | Data Transfer Size Limits | Fallback Channels | Manipulate Device Communication | Manipulate App Store Rankings or Ratings | |
Replication Through Removable Media | Launchd | Rc.common | Rc.common | 1 Software Packing | Cached Domain Credentials | 1 System Network Configuration Discovery | VNC | GUI Input Capture | Exfiltration Over C2 Channel | Multiband Communication | Jamming or Denial of Service | Abuse Accessibility Features | |
External Remote Services | Scheduled Task | Startup Items | Startup Items | Compile After Delivery | DCSync | 1 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Exfiltration Over Alternative Protocol | Commonly Used Port | Rogue Wi-Fi Access Points | Data Encrypted for Impact | |
Drive-by Compromise | Command and Scripting Interpreter | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 13 System Information Discovery | Shared Webroot | Credential API Hooking | Exfiltration Over Symmetric Encrypted Non-C2 Protocol | Application Layer Protocol | Downgrade to Insecure Protocols | Generate Fraudulent Advertising Revenue |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
88% | ReversingLabs | ByteCode-MSIL.Trojan.RedLineStealer | ||
73% | Virustotal | Browse | ||
100% | Avira | TR/Dropper.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Joe Sandbox ML | |||
0% | ReversingLabs | |||
77% | ReversingLabs | ByteCode-MSIL.Trojan.Oskistelaer | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link | Download |
---|---|---|---|---|---|
100% | Avira | TR/Dropper.Gen | Download File |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
7% | Virustotal | Browse | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
ip-api.com | 208.95.112.1 | true | false | high |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown | |
true |
| unknown | |
false | high | ||
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| low | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| low | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
208.95.112.1 | ip-api.com | United States | 53334 | TUT-ASUS | false | |
13.90.128.253 | unknown | United States | 8075 | MICROSOFT-CORP-MSN-AS-BLOCKUS | true |
Joe Sandbox Version: | 36.0.0 Rainbow Opal |
Analysis ID: | 753097 |
Start date and time: | 2022-11-24 10:04:08 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 7m 54s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Sample file name: | nwY3YpWQVx.exe |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 1 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Detection: | MAL |
Classification: | mal93.troj.spyw.winEXE@7/10@10/2 |
EGA Information: |
|
HDC Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, consent.exe, WMIADAP.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ctldl.windowsupdate.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
10:05:04 | API Interceptor | |
10:05:16 | Autostart | |
10:05:24 | API Interceptor | |
10:05:25 | Autostart | |
10:05:31 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
208.95.112.1 | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
ip-api.com | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
MICROSOFT-CORP-MSN-AS-BLOCKUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
TUT-ASUS | Get hash | malicious | Browse |
| |
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
| ||
Get hash | malicious | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Link | Context |
---|---|---|---|---|---|
C:\Users\user\AppData\Local\Temp\Newtonsoft.Json.dll | Get hash | malicious | Browse | ||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse | |||
Get hash | malicious | Browse |
Process: | C:\Users\user\AppData\Local\Temp\Zip.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2343 |
Entropy (8bit): | 5.374204171243879 |
Encrypted: | false |
SSDEEP: | 48:MxHKEYHKGD8Ao6+vxpNl1qHGiD0HKeGitHTG1hAHKKPJAmHKoAPHZHpH+5HK+HKs:iqEYqGgAo9ZPlwmI0qertzG1eqKPJ/qo |
MD5: | 3F114A073575263E59307B55548FD5F4 |
SHA1: | 971459D541646C4C6B382F06AAFA9F4147716568 |
SHA-256: | 2417EC96E49CF7352D91892438478E961D8DC870FEB8E8821C732383CD9351F2 |
SHA-512: | EA7B613DF726F230ADFEF841E4C8A753228B3AFAE7F2D2FDC2704892910F18254F2D9B31AA5E7D4C993137BCAE92B0FF77D9D31503E96D605DBF0589E42AD809 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\update_222410.exe |
File Type: | |
Category: | modified |
Size (bytes): | 2140 |
Entropy (8bit): | 5.371730832466707 |
Encrypted: | false |
SSDEEP: | 48:MxHKEYHKGD8Ao6+vxpNl1qHGiD0HKeGitHTG1hAHKKPJAmHKoAPHZHpH+Y:iqEYqGgAo9ZPlwmI0qertzG1eqKPJ/q3 |
MD5: | 8D5284E805C10D2F4ABEEC24A26DDECA |
SHA1: | 22CC84B3067C6E457FAB34B7792E96AC3FA1E743 |
SHA-256: | 760309005EBFE01DC4FCADAFE45DC919BFCB0C9EF08981671243C403DC8516D1 |
SHA-512: | CD1C073BC90984DB2A883857DF0649DDD41A6ECEAECC4068145FE30819305CD041E916304E08F33C74682E74CD3806F5B294E80601A35964F25B24B6A38047FE |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\AppData\Local\Temp\Zip.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 794314 |
Entropy (8bit): | 7.99790575619382 |
Encrypted: | true |
SSDEEP: | 12288:fuYQj7BcRv6cg3Ogp15K5AsJ5SblD+fdutrlYzq8RL6U+5VAmni6Pk0x/Do7S:0hGO3bgasJ5Sb5WYxYW8Rzeni6c0xboG |
MD5: | 6F1AF199F1516FD5A1F2152037FB0E6E |
SHA1: | FDFE22891214ACCB0EFD935D2241DA9D9F283C45 |
SHA-256: | 3427BA90A6A417BFC15A91ABBD17F04072BBDC7B14A38F7B6FB4F326D9B2262F |
SHA-512: | DF9EEEF673A42515E98C7B8551D5685138B561FA470A3C65A1C52347519D5708C68FC75A74305A22CC2AFA85EFEB2C126131144ADB1C3BF7E485C15826BCAA15 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1364 |
Entropy (8bit): | 5.065215317933012 |
Encrypted: | false |
SSDEEP: | 24:c4cxPUwdVScxPUXUcxSTcHocxMocxtOtocxPUWEcxPUaptcxPUv9p1cxPUPbYcx9:x0PPdVS0PGU0WcHo0Mo0Uto0PHE0PFpJ |
MD5: | 187D97F5AAFF4553BDCE050BEFD951A2 |
SHA1: | 596BE74C875F8C9CA08209F696060F03AFDA2E36 |
SHA-256: | 43F6D6C018A8DC4837153C78124BFDAEF772FF00D67028A46DFCAFEABCEC18EF |
SHA-512: | FC608F5E80755ED97DEB818B9B37BBCC7C70EC46E7D6C62B97F4C408DD345190413026FB1C57B3600602421E4174E5E102D73C930F377109CE2B50D8788288D2 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2039 |
Entropy (8bit): | 4.401972084162776 |
Encrypted: | false |
SSDEEP: | 12:jXRoh/qqqh/qqE6EtKtMqqh/qcqq1HrylHgMqh/qqgpyqqqMJqqqqEh8MU/qA8Y8:+ycXFLa806iyd/3c9KgENulX |
MD5: | F30DD78EA37C24D319D37C24B4806547 |
SHA1: | 90FA81BF69BA3B7B30C2D2B3EF870BF729B1D7D7 |
SHA-256: | EA1E16975BA2D18AC4BA922654B6C941950C45FEA6015C76E78C218DB920291E |
SHA-512: | 94CD705716C5FCA60DCAFB62884AE1FBA61DA9A3A34364774EC6BAC9035594E5F8A6DD1CA6F6676EC0D63A29544F3FFA67524849543FD91714170F95A3AF33F8 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 801693 |
Entropy (8bit): | 7.942220878003351 |
Encrypted: | false |
SSDEEP: | 12288:FchCNYef+K53hGHoJvERCi11YbbXAZUdkZfxhSf3E7jMxPHyPzRpT5G:FchCNHH5c0vQCi1CDKtxG3E7oaPzRG |
MD5: | 0DF6137A048583B83B6AFE5F74DF95C4 |
SHA1: | D6406349760E23AEB215E59FEA5F2BB90704891C |
SHA-256: | 2988EDD06E3948C9A709C7CE12D92A816585EE3985D7B9D5E6736076BC6604CF |
SHA-512: | 3254192DDB512CFDEC6730CAC27F59FA57C4885801FE8B93539A6328E8C4502AD4AB4167E3E8261B7721F2FC326A8E971B98CCF66328DFBC829165D76B8DBEB2 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 4.579461777700594 |
Encrypted: | false |
SSDEEP: | 6:9lz4GgCF2Rpj1hx0+A7JRXWQuGsLf15Ro1WcEuo8T:fzbHIpxXKRXWQzsLN5RJcfV |
MD5: | D338D82D19E20999074FEFCDA1A7FB6D |
SHA1: | 8DB0F38EE591A3C13C38D6C939D1EDD2BDCFFC56 |
SHA-256: | E81890683B8875A6F24FE28847E67EAFC6F066D80B1C9F919F89196D5C650362 |
SHA-512: | C6B06E9921BD660434EA5B8B66243D6C55DB015622E262EE3B948F9C89D040362C0C5AA283AD91CA1CA809A39C1C04486DC2C4EFE0BCAF0166AA97F5E09E1741 |
Malicious: | false |
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | modified |
Size (bytes): | 407776 |
Entropy (8bit): | 6.080910017085125 |
Encrypted: | false |
SSDEEP: | 6144:/+BWmtpZQYS2PjCLfjSCpkALDUbr0tJ0nzbWk:WPw2PjCLe3a6Q70zbR |
MD5: | F75FE8D06448D07720D5456F2A327F08 |
SHA1: | DBA5D60848A7C24CE837225709D9E23690BB5CB3 |
SHA-256: | 977998AEC486395EABA6CE5661648425A1A181CE18C2C87C6288AF62B87D5ECA |
SHA-512: | EB05696F92881A698B7DEF0F8852286212A5EB235A2FF8A41460DEDBC6AE1964BFBEF613D3BEC736DF66525BF6E5A6C95FF5E0A71C904FA70B5C6675E2275A34 |
Malicious: | false |
Antivirus: |
|
Joe Sandbox View: |
|
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 32256 |
Entropy (8bit): | 5.050531187823917 |
Encrypted: | false |
SSDEEP: | 384:KfkVQ748aUKN6C8/3g2L4QDL0Lk24jXPlfLoem/xYUIoPBsNJc:RW7PTKF8fPdDL42XPUIc |
MD5: | AF07E88EC22CC90CEBFDA29517F101B9 |
SHA1: | A9E6F4AE24ABF76966D7DB03AF9C802E83760143 |
SHA-256: | 1632FBFF8EDC50F2C7EF7BB2FE9B2C17E6472094F0D365A98E0DEC2A12FA8EC2 |
SHA-512: | B4575AF98071FC8D46C022E24BFB2C1567D7E5F3DE0D8FB5FEE6F876985C7780A5B145F645725FF27A15367162AA08490AC2F8DD59D705663094FE4E1EEEC7BC |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Preview: |
Process: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 407776 |
Entropy (8bit): | 6.080910017085125 |
Encrypted: | false |
SSDEEP: | 6144:/+BWmtpZQYS2PjCLfjSCpkALDUbr0tJ0nzbWk:WPw2PjCLe3a6Q70zbR |
MD5: | F75FE8D06448D07720D5456F2A327F08 |
SHA1: | DBA5D60848A7C24CE837225709D9E23690BB5CB3 |
SHA-256: | 977998AEC486395EABA6CE5661648425A1A181CE18C2C87C6288AF62B87D5ECA |
SHA-512: | EB05696F92881A698B7DEF0F8852286212A5EB235A2FF8A41460DEDBC6AE1964BFBEF613D3BEC736DF66525BF6E5A6C95FF5E0A71C904FA70B5C6675E2275A34 |
Malicious: | false |
Antivirus: |
|
Preview: |
File type: | |
Entropy (8bit): | 5.979535587715002 |
TrID: |
|
File name: | nwY3YpWQVx.exe |
File size: | 547374 |
MD5: | 0d43b051c7c73233c85697219bc9a4f4 |
SHA1: | 0568c7d1b2f340b743f8799166e3c45b7ebf87ef |
SHA256: | 30c03c8a3bb6dc168a799d3399b06863c579e6c22e66a649a8162fa7ca7e370c |
SHA512: | 75bf59168569419c61b1c53d5672ea65534f5589a354d17543c55bca0c9fb602827625e59d18135c61653a34f62fd2d40d96877ab2ff5ffcaa4fb2d7b787bf36 |
SSDEEP: | 6144:z+BWmtpZQYS2PjCLfjSCpkALDUbr0tJ0nzbWdG/Wow7+JO:SPw2PjCLe3a6Q70zbYow6s |
TLSH: | 74C45A0223FC4BA5E5FE2B31A631464543F6FD46657AE70D0D80E6EA4C777829E203A7 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....u.a.....................8.......=... ...@....@.. ....................................@................................ |
Icon Hash: | 41455554545445a2 |
Entrypoint: | 0x483dee |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x618475C5 [Fri Nov 5 00:07:33 2021 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x83d98 | 0x53 | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x86000 | 0x3223 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x8a000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x84000 | 0x1c | .sdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x81df4 | 0x81e00 | False | 0.39599186417228105 | data | 6.007710958121938 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.sdata | 0x84000 | 0x138 | 0x200 | False | 0.2421875 | data | 2.1996594710852864 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x86000 | 0x3223 | 0x3400 | False | 0.1035907451923077 | data | 3.5288775377080097 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x8a000 | 0xc | 0x200 | False | 0.044921875 | data | 0.10191042566270775 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country |
---|---|---|---|---|---|
RT_ICON | 0x86250 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 512 | ||
RT_ICON | 0x86538 | 0x128 | Device independent bitmap graphic, 16 x 32 x 4, image size 128 | ||
RT_ICON | 0x86660 | 0x8a8 | Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colors | ||
RT_ICON | 0x86f08 | 0x568 | Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colors | ||
RT_ICON | 0x87470 | 0x353 | PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced | ||
RT_ICON | 0x877c4 | 0x10a8 | Device independent bitmap graphic, 32 x 64 x 32, image size 4224 | ||
RT_ICON | 0x8886c | 0x468 | Device independent bitmap graphic, 16 x 32 x 32, image size 1088 | ||
RT_GROUP_ICON | 0x88cd4 | 0x68 | data | ||
RT_VERSION | 0x88d3c | 0x2f0 | SysEx File - IDP | ||
RT_MANIFEST | 0x8902c | 0x1f7 | XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.513.90.128.25349698802022986 11/24/22-10:05:39.916527 | TCP | 2022986 | ET TROJAN Generic Request to gate.php Dotted-Quad | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349701802022818 11/24/22-10:05:49.419418 | TCP | 2022818 | ET TROJAN Generic gate .php GET with minimal headers | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349696802022986 11/24/22-10:05:31.007346 | TCP | 2022986 | ET TROJAN Generic Request to gate.php Dotted-Quad | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349692802022986 11/24/22-10:05:25.056792 | TCP | 2022986 | ET TROJAN Generic Request to gate.php Dotted-Quad | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349698802022818 11/24/22-10:05:39.916527 | TCP | 2022818 | ET TROJAN Generic gate .php GET with minimal headers | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349701802022986 11/24/22-10:05:49.419418 | TCP | 2022986 | ET TROJAN Generic Request to gate.php Dotted-Quad | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349696802022818 11/24/22-10:05:31.007346 | TCP | 2022818 | ET TROJAN Generic gate .php GET with minimal headers | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
192.168.2.513.90.128.25349692802022818 11/24/22-10:05:25.056792 | TCP | 2022818 | ET TROJAN Generic gate .php GET with minimal headers | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 24, 2022 10:05:03.994479895 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:04.026755095 CET | 80 | 49688 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:04.026866913 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:04.028804064 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:04.061831951 CET | 80 | 49688 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:04.102684021 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:11.913038969 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:11.945188999 CET | 80 | 49688 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:11.945281029 CET | 49688 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:11.961788893 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:11.994003057 CET | 80 | 49689 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:11.994191885 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:11.995855093 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:12.028294086 CET | 80 | 49689 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:12.071954966 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.053586960 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.086812019 CET | 80 | 49689 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:14.086971045 CET | 49689 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.114914894 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.147301912 CET | 80 | 49690 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:14.147495031 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.147728920 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:14.181540966 CET | 80 | 49690 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:14.228399992 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:23.511710882 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:23.543901920 CET | 80 | 49691 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:23.544029951 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:23.544753075 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:23.579479933 CET | 80 | 49691 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:23.619889975 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:24.940659046 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:24.942090034 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:24.972805023 CET | 80 | 49690 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:24.976339102 CET | 49690 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:25.043502092 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:25.049285889 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:25.056792021 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:25.158010960 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:25.227658033 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:25.416857958 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:25.769961119 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:25.870934963 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:25.876641035 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:25.916852951 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:29.175508022 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:29.207568884 CET | 80 | 49693 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:29.207690954 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:29.208549976 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:29.242099047 CET | 80 | 49693 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:29.323426008 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.166615963 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.198693037 CET | 80 | 49691 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:30.198816061 CET | 49691 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.251305103 CET | 49694 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.283247948 CET | 80 | 49694 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:30.283442020 CET | 49694 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.283818960 CET | 49694 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.317295074 CET | 80 | 49694 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:30.417273998 CET | 49694 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.672163010 CET | 49695 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.704122066 CET | 80 | 49695 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:30.704407930 CET | 49695 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.704683065 CET | 49695 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:30.759912014 CET | 80 | 49695 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:30.877736092 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:30.877823114 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:30.901930094 CET | 49692 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:30.903006077 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:30.917299032 CET | 49695 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:31.003175020 CET | 80 | 49692 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:31.006994963 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:31.007124901 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:31.007345915 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:31.108366013 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:31.170663118 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:31.323575974 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:34.650249004 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:34.751559019 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:34.803006887 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:35.027559042 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:39.180665970 CET | 49695 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.181086063 CET | 49694 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.378040075 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.407625914 CET | 80 | 49697 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:39.407780886 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.421231031 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.459541082 CET | 80 | 49697 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:39.605515957 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:39.805701971 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:39.806757927 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:39.811291933 CET | 49696 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:39.813853979 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:39.913072109 CET | 80 | 49696 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:39.916162968 CET | 80 | 49698 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:39.916273117 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:39.916527033 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:40.018237114 CET | 80 | 49698 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:40.072050095 CET | 80 | 49698 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:40.214972019 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:41.967474937 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:41.999300957 CET | 80 | 49693 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:41.999398947 CET | 49693 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:42.040324926 CET | 49699 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:42.070235968 CET | 80 | 49699 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:42.070327997 CET | 49699 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:42.070610046 CET | 49699 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:42.108103037 CET | 80 | 49699 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:42.230731010 CET | 49699 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:43.076862097 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.077802896 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.178035021 CET | 80 | 49698 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.178160906 CET | 49698 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.179263115 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.179658890 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.179892063 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.284292936 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.356317997 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.367906094 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.469566107 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.471673012 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.475372076 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.475536108 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.475636959 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.577122927 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.577157021 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.577341080 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.577456951 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.678909063 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.678985119 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.679028034 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.679069042 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.679079056 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.679152966 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.679181099 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.679234028 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.679234028 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.679275036 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.679275036 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.723428011 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.723536968 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.781045914 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781104088 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781119108 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781137943 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781148911 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781219959 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781239033 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781250954 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781341076 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.781449080 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781467915 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781482935 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781495094 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781675100 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.781765938 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.781812906 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781830072 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781846046 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.781851053 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.781924963 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.782008886 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.782058954 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.782075882 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.782088995 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.782202959 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.782310009 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.782402992 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.782516956 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.825047970 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.825202942 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.883162975 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883192062 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883208036 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883224964 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883241892 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883259058 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883275032 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883337021 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883354902 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883367062 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883440018 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883459091 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.883549929 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883567095 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883583069 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883599997 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883618116 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883635044 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883713007 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883759022 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.883833885 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883851051 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883878946 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883898973 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883913994 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.883964062 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884006023 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884021997 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884069920 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884119034 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884135962 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884151936 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884167910 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884172916 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884262085 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884274960 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884277105 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884366989 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884397030 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884413004 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884428978 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884454966 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884475946 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884491920 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884557009 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884613991 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884630919 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884641886 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884643078 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884654999 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.884757042 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884843111 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.884963036 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885061979 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885165930 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885270119 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885364056 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885463953 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885560989 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.885641098 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.929234028 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.930016994 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.943057060 CET | 49699 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:43.986202955 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.986233950 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.986476898 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.987565041 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987581015 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987617016 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987761974 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.987782955 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987797976 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987812996 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987859964 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.987889051 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987901926 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987919092 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.987973928 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.987979889 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.987979889 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.988044977 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.988044977 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.988061905 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.988065004 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.988070965 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.988099098 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.988179922 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.989347935 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989367962 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989386082 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989403009 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989420891 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989438057 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989454985 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:43.989511967 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.989562035 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:43.989629030 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.031397104 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.031452894 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.031559944 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.031646013 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088150978 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088223934 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088267088 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088306904 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088347912 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088390112 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088430882 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088434935 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088471889 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088512897 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088529110 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088552952 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088573933 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088573933 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088593006 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088629961 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088633060 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088629961 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088679075 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088679075 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088723898 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088723898 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088732004 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088772058 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088861942 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088905096 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.088936090 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.088978052 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089016914 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089061022 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089066029 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:44.089101076 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089284897 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089327097 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089504004 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.089545965 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.090061903 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.091180086 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.091892004 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.091932058 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092044115 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092086077 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092128038 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092166901 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092279911 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092320919 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092360973 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092401028 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092441082 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092617989 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092658997 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092699051 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092742920 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.092782974 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093048096 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093091011 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093132019 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093173981 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093430042 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093451023 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093470097 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093487978 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093507051 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093525887 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093544960 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093563080 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093674898 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093693018 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093712091 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093791962 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093811035 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093947887 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093966961 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.093987942 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094006062 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094027042 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094046116 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094063997 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094172955 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094191074 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.094441891 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.134279966 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.134310007 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190258980 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190306902 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190340996 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190370083 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190478086 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190510988 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190654993 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190685034 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190789938 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190820932 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.190983057 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191015959 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191046953 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191178083 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191210985 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191298962 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191330910 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191427946 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.191458941 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192101002 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192131996 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192166090 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192222118 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192322016 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192362070 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192629099 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192658901 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192687035 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192728996 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192774057 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.192805052 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.193439007 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.193474054 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.193504095 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.193800926 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.193835974 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.194102049 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.195411921 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.195445061 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.195549011 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196079016 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196113110 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196171999 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196214914 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196254015 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.196687937 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.249612093 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:44.418423891 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.250013113 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:49.250092030 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.303539991 CET | 49700 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.318043947 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.404802084 CET | 80 | 49700 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:49.418869972 CET | 80 | 49701 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:49.418970108 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.419418097 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:49.520118952 CET | 80 | 49701 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:49.575807095 CET | 80 | 49701 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:49.715740919 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.772262096 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.777414083 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.803467989 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:52.833399057 CET | 80 | 49697 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:52.833667040 CET | 49697 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:52.873838902 CET | 80 | 49701 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:52.874046087 CET | 49701 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.879545927 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:52.879667997 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.879879951 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:52.973582983 CET | 49704 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:52.981043100 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.003945112 CET | 80 | 49704 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:53.004139900 CET | 49704 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:53.004415035 CET | 49704 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:53.039249897 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.042753935 CET | 80 | 49704 | 208.95.112.1 | 192.168.2.5 |
Nov 24, 2022 10:05:53.216110945 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:53.216190100 CET | 49704 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:53.346751928 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:53.447854996 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.542736053 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.622396946 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:53.660933018 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:53.762218952 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.771998882 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:53.825514078 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:54.253127098 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:54.397829056 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:54.401341915 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:54.528636932 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:54.529164076 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:54.630000114 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:54.635700941 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:54.716250896 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:54.940526962 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:55.048121929 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:55.145344973 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:55.213009119 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:55.354645014 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:55.466600895 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:55.573147058 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:55.685446024 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:55.798619032 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:55.904236078 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.016099930 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.019697905 CET | 49704 | 80 | 192.168.2.5 | 208.95.112.1 |
Nov 24, 2022 10:05:56.122536898 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.122852087 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.265774965 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.276272058 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.406706095 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.507683039 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.518187046 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.638665915 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.748296022 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:56.825737000 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.866013050 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:56.980732918 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.028875113 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.091743946 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.233922005 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.254293919 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.325783014 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.357608080 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.458760977 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.468750000 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.528912067 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.577466965 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.692078114 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:57.795171022 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:57.907229900 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.013896942 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.157640934 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.202336073 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.310642004 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.413201094 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.421519995 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.529004097 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.529437065 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.639164925 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.716541052 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.748105049 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:58.857167959 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:58.966923952 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:59.109796047 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.132725954 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.248868942 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:59.350146055 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.355093956 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.467259884 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:59.575210094 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.685913086 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:05:59.796618938 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:05:59.904557943 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:00.049839020 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.304919958 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.359575033 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:26.406785011 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:26.508022070 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.601267099 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.656641960 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:26.723223925 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:26.824193001 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.836591005 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:26.890786886 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:26.938206911 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.048418999 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.094065905 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.157444000 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.302031994 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.315444946 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.359757900 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.422898054 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.523958921 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.530560970 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.578330040 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.641423941 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.752068996 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:27.797142982 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.860275030 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:27.979752064 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.031513929 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.094470024 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.238220930 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.255086899 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.312772036 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.367805004 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.469238997 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.476284981 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.517688036 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.585969925 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.695064068 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.734680891 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.797561884 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:28.928524971 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:28.984842062 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:29.188267946 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:29.334059000 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:29.470705032 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:29.516021967 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:29.622708082 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:29.745826960 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:29.745882034 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:29.797316074 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.177222013 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.322473049 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:30.330084085 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:30.375579119 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.438369989 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.540405989 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:30.547013998 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:30.594202995 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.709228039 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.818365097 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:30.859910011 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:30.927628040 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.034219027 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:31.078677893 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.378030062 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.521699905 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:31.532601118 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:31.578689098 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.650194883 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.751296043 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:31.774255037 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:31.828701019 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.876197100 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:31.983685970 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.031949043 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.094784021 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.237997055 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.250843048 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.297596931 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.382090092 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.483324051 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.489087105 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.531872034 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.594750881 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.705264091 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.750842094 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.814179897 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:32.925527096 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:32.969597101 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.032474041 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.174148083 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.187192917 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.235161066 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.298073053 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.399271011 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.404689074 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.454020977 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.516836882 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.634458065 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.688388109 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.735600948 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.843596935 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:33.891554117 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:33.954220057 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:34.097799063 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:34.107176065 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Nov 24, 2022 10:06:34.157001972 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:34.220388889 CET | 49703 | 80 | 192.168.2.5 | 13.90.128.253 |
Nov 24, 2022 10:06:34.321566105 CET | 80 | 49703 | 13.90.128.253 | 192.168.2.5 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 24, 2022 10:05:03.955020905 CET | 54949 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:03.972485065 CET | 53 | 54949 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:11.936229944 CET | 58218 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:11.957767010 CET | 53 | 58218 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:14.093523026 CET | 60998 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:14.112740993 CET | 53 | 60998 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:23.455259085 CET | 56953 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:23.477333069 CET | 53 | 56953 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:29.131742954 CET | 59287 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:29.151164055 CET | 53 | 59287 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:30.232311010 CET | 58648 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:30.249808073 CET | 53 | 58648 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:30.631279945 CET | 56894 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:30.658508062 CET | 53 | 56894 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:39.309519053 CET | 50295 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:39.327297926 CET | 53 | 50295 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:42.011234999 CET | 60841 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:42.030308008 CET | 53 | 60841 | 8.8.8.8 | 192.168.2.5 |
Nov 24, 2022 10:05:52.942070007 CET | 60649 | 53 | 192.168.2.5 | 8.8.8.8 |
Nov 24, 2022 10:05:52.959813118 CET | 53 | 60649 | 8.8.8.8 | 192.168.2.5 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 24, 2022 10:05:03.955020905 CET | 192.168.2.5 | 8.8.8.8 | 0x4d76 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:11.936229944 CET | 192.168.2.5 | 8.8.8.8 | 0x242 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:14.093523026 CET | 192.168.2.5 | 8.8.8.8 | 0x3ce2 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:23.455259085 CET | 192.168.2.5 | 8.8.8.8 | 0x78e8 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:29.131742954 CET | 192.168.2.5 | 8.8.8.8 | 0xd2b6 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:30.232311010 CET | 192.168.2.5 | 8.8.8.8 | 0xf5cc | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:30.631279945 CET | 192.168.2.5 | 8.8.8.8 | 0x281a | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:39.309519053 CET | 192.168.2.5 | 8.8.8.8 | 0x8a3 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:42.011234999 CET | 192.168.2.5 | 8.8.8.8 | 0xe706 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 24, 2022 10:05:52.942070007 CET | 192.168.2.5 | 8.8.8.8 | 0x40d0 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 24, 2022 10:05:03.972485065 CET | 8.8.8.8 | 192.168.2.5 | 0x4d76 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:11.957767010 CET | 8.8.8.8 | 192.168.2.5 | 0x242 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:14.112740993 CET | 8.8.8.8 | 192.168.2.5 | 0x3ce2 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:23.477333069 CET | 8.8.8.8 | 192.168.2.5 | 0x78e8 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:29.151164055 CET | 8.8.8.8 | 192.168.2.5 | 0xd2b6 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:30.249808073 CET | 8.8.8.8 | 192.168.2.5 | 0xf5cc | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:30.658508062 CET | 8.8.8.8 | 192.168.2.5 | 0x281a | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:39.327297926 CET | 8.8.8.8 | 192.168.2.5 | 0x8a3 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:42.030308008 CET | 8.8.8.8 | 192.168.2.5 | 0xe706 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false | ||
Nov 24, 2022 10:05:52.959813118 CET | 8.8.8.8 | 192.168.2.5 | 0x40d0 | No error (0) | 208.95.112.1 | A (IP address) | IN (0x0001) | false |
|
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
0 | 192.168.2.5 | 49688 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:04.028804064 CET | 0 | OUT | |
Nov 24, 2022 10:05:04.061831951 CET | 0 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
1 | 192.168.2.5 | 49689 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:11.995855093 CET | 1 | OUT | |
Nov 24, 2022 10:05:12.028294086 CET | 2 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
10 | 192.168.2.5 | 49698 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:39.916527033 CET | 12 | OUT | |
Nov 24, 2022 10:05:40.072050095 CET | 12 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
11 | 192.168.2.5 | 49699 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:42.070610046 CET | 13 | OUT | |
Nov 24, 2022 10:05:42.108103037 CET | 14 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
12 | 192.168.2.5 | 49700 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:43.179892063 CET | 14 | OUT | |
Nov 24, 2022 10:05:43.356317997 CET | 14 | IN | |
Nov 24, 2022 10:05:43.367906094 CET | 15 | OUT | |
Nov 24, 2022 10:05:43.471673012 CET | 15 | IN | |
Nov 24, 2022 10:05:43.475372076 CET | 15 | OUT | |
Nov 24, 2022 10:05:43.475536108 CET | 23 | OUT | |
Nov 24, 2022 10:05:43.475636959 CET | 27 | OUT | |
Nov 24, 2022 10:05:43.577341080 CET | 43 | OUT | |
Nov 24, 2022 10:05:43.577456951 CET | 51 | OUT | |
Nov 24, 2022 10:05:43.679079056 CET | 66 | OUT | |
Nov 24, 2022 10:05:43.679181099 CET | 79 | OUT | |
Nov 24, 2022 10:05:43.679234028 CET | 84 | OUT | |
Nov 24, 2022 10:05:43.679234028 CET | 92 | OUT | |
Nov 24, 2022 10:05:43.679275036 CET | 96 | OUT | |
Nov 24, 2022 10:05:44.249612093 CET | 806 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
13 | 192.168.2.5 | 49701 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:49.419418097 CET | 808 | OUT | |
Nov 24, 2022 10:05:49.575807095 CET | 817 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
14 | 192.168.2.5 | 49703 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:52.879879951 CET | 819 | OUT | |
Nov 24, 2022 10:05:53.039249897 CET | 820 | IN | |
Nov 24, 2022 10:05:53.346751928 CET | 821 | OUT | |
Nov 24, 2022 10:05:53.542736053 CET | 821 | IN | |
Nov 24, 2022 10:05:53.660933018 CET | 821 | OUT | |
Nov 24, 2022 10:05:53.771998882 CET | 822 | IN | |
Nov 24, 2022 10:05:54.253127098 CET | 822 | OUT | |
Nov 24, 2022 10:05:54.401341915 CET | 822 | IN | |
Nov 24, 2022 10:05:54.529164076 CET | 822 | OUT | |
Nov 24, 2022 10:05:54.635700941 CET | 823 | IN | |
Nov 24, 2022 10:05:54.940526962 CET | 823 | OUT | |
Nov 24, 2022 10:05:55.048121929 CET | 823 | IN | |
Nov 24, 2022 10:05:55.213009119 CET | 823 | OUT | |
Nov 24, 2022 10:05:55.354645014 CET | 824 | IN | |
Nov 24, 2022 10:05:55.466600895 CET | 824 | OUT | |
Nov 24, 2022 10:05:55.573147058 CET | 824 | IN | |
Nov 24, 2022 10:05:55.685446024 CET | 824 | OUT | |
Nov 24, 2022 10:05:55.798619032 CET | 825 | IN | |
Nov 24, 2022 10:05:55.904236078 CET | 825 | OUT | |
Nov 24, 2022 10:05:56.016099930 CET | 825 | IN | |
Nov 24, 2022 10:05:56.122852087 CET | 825 | OUT | |
Nov 24, 2022 10:05:56.276272058 CET | 826 | IN | |
Nov 24, 2022 10:05:56.406706095 CET | 826 | OUT | |
Nov 24, 2022 10:05:56.518187046 CET | 826 | IN | |
Nov 24, 2022 10:05:56.638665915 CET | 826 | OUT | |
Nov 24, 2022 10:05:56.748296022 CET | 827 | IN | |
Nov 24, 2022 10:05:56.866013050 CET | 827 | OUT | |
Nov 24, 2022 10:05:56.980732918 CET | 827 | IN | |
Nov 24, 2022 10:05:57.091743946 CET | 827 | OUT | |
Nov 24, 2022 10:05:57.254293919 CET | 828 | IN | |
Nov 24, 2022 10:05:57.357608080 CET | 828 | OUT | |
Nov 24, 2022 10:05:57.468750000 CET | 828 | IN | |
Nov 24, 2022 10:05:57.577466965 CET | 828 | OUT | |
Nov 24, 2022 10:05:57.692078114 CET | 829 | IN | |
Nov 24, 2022 10:05:57.795171022 CET | 829 | OUT | |
Nov 24, 2022 10:05:57.907229900 CET | 829 | IN | |
Nov 24, 2022 10:05:58.013896942 CET | 829 | OUT | |
Nov 24, 2022 10:05:58.202336073 CET | 830 | IN | |
Nov 24, 2022 10:05:58.310642004 CET | 830 | OUT | |
Nov 24, 2022 10:05:58.421519995 CET | 830 | IN | |
Nov 24, 2022 10:05:58.529437065 CET | 830 | OUT | |
Nov 24, 2022 10:05:58.639164925 CET | 831 | IN | |
Nov 24, 2022 10:05:58.748105049 CET | 831 | OUT | |
Nov 24, 2022 10:05:58.857167959 CET | 831 | IN | |
Nov 24, 2022 10:05:58.966923952 CET | 832 | OUT | |
Nov 24, 2022 10:05:59.132725954 CET | 832 | IN | |
Nov 24, 2022 10:05:59.248868942 CET | 832 | OUT | |
Nov 24, 2022 10:05:59.355093956 CET | 832 | IN | |
Nov 24, 2022 10:05:59.467259884 CET | 833 | OUT | |
Nov 24, 2022 10:05:59.575210094 CET | 833 | IN | |
Nov 24, 2022 10:05:59.685913086 CET | 833 | OUT | |
Nov 24, 2022 10:05:59.796618938 CET | 833 | IN | |
Nov 24, 2022 10:05:59.904557943 CET | 833 | OUT | |
Nov 24, 2022 10:06:26.304919958 CET | 834 | IN | |
Nov 24, 2022 10:06:26.406785011 CET | 834 | OUT | |
Nov 24, 2022 10:06:26.601267099 CET | 834 | IN | |
Nov 24, 2022 10:06:26.723223925 CET | 835 | OUT | |
Nov 24, 2022 10:06:26.836591005 CET | 835 | IN | |
Nov 24, 2022 10:06:26.938206911 CET | 835 | OUT | |
Nov 24, 2022 10:06:27.048418999 CET | 835 | IN | |
Nov 24, 2022 10:06:27.157444000 CET | 836 | OUT | |
Nov 24, 2022 10:06:27.315444946 CET | 836 | IN | |
Nov 24, 2022 10:06:27.422898054 CET | 836 | OUT | |
Nov 24, 2022 10:06:27.530560970 CET | 837 | IN | |
Nov 24, 2022 10:06:27.641423941 CET | 837 | OUT | |
Nov 24, 2022 10:06:27.752068996 CET | 837 | IN | |
Nov 24, 2022 10:06:27.860275030 CET | 837 | OUT | |
Nov 24, 2022 10:06:27.979752064 CET | 838 | IN | |
Nov 24, 2022 10:06:28.094470024 CET | 838 | OUT | |
Nov 24, 2022 10:06:28.255086899 CET | 838 | IN | |
Nov 24, 2022 10:06:28.367805004 CET | 838 | OUT | |
Nov 24, 2022 10:06:28.476284981 CET | 839 | IN | |
Nov 24, 2022 10:06:28.585969925 CET | 839 | OUT | |
Nov 24, 2022 10:06:28.695064068 CET | 839 | IN | |
Nov 24, 2022 10:06:28.797561884 CET | 839 | OUT | |
Nov 24, 2022 10:06:28.928524971 CET | 840 | IN | |
Nov 24, 2022 10:06:29.188267946 CET | 840 | OUT | |
Nov 24, 2022 10:06:29.470705032 CET | 840 | IN | |
Nov 24, 2022 10:06:29.622708082 CET | 840 | OUT | |
Nov 24, 2022 10:06:29.745882034 CET | 841 | IN | |
Nov 24, 2022 10:06:30.177222013 CET | 841 | OUT | |
Nov 24, 2022 10:06:30.330084085 CET | 841 | IN | |
Nov 24, 2022 10:06:30.438369989 CET | 842 | OUT | |
Nov 24, 2022 10:06:30.547013998 CET | 842 | IN | |
Nov 24, 2022 10:06:30.709228039 CET | 842 | OUT | |
Nov 24, 2022 10:06:30.818365097 CET | 842 | IN | |
Nov 24, 2022 10:06:30.927628040 CET | 843 | OUT | |
Nov 24, 2022 10:06:31.034219027 CET | 843 | IN | |
Nov 24, 2022 10:06:31.378030062 CET | 843 | OUT | |
Nov 24, 2022 10:06:31.532601118 CET | 843 | IN | |
Nov 24, 2022 10:06:31.650194883 CET | 844 | OUT | |
Nov 24, 2022 10:06:31.774255037 CET | 844 | IN | |
Nov 24, 2022 10:06:31.876197100 CET | 844 | OUT | |
Nov 24, 2022 10:06:31.983685970 CET | 845 | IN | |
Nov 24, 2022 10:06:32.094784021 CET | 845 | OUT | |
Nov 24, 2022 10:06:32.250843048 CET | 845 | IN | |
Nov 24, 2022 10:06:32.382090092 CET | 845 | OUT | |
Nov 24, 2022 10:06:32.489087105 CET | 846 | IN | |
Nov 24, 2022 10:06:32.594750881 CET | 846 | OUT | |
Nov 24, 2022 10:06:32.705264091 CET | 846 | IN | |
Nov 24, 2022 10:06:32.814179897 CET | 846 | OUT | |
Nov 24, 2022 10:06:32.925527096 CET | 847 | IN | |
Nov 24, 2022 10:06:33.032474041 CET | 847 | OUT | |
Nov 24, 2022 10:06:33.187192917 CET | 847 | IN | |
Nov 24, 2022 10:06:33.298073053 CET | 847 | OUT | |
Nov 24, 2022 10:06:33.404689074 CET | 848 | IN | |
Nov 24, 2022 10:06:33.516836882 CET | 848 | OUT | |
Nov 24, 2022 10:06:33.634458065 CET | 848 | IN | |
Nov 24, 2022 10:06:33.735600948 CET | 848 | OUT | |
Nov 24, 2022 10:06:33.843596935 CET | 849 | IN | |
Nov 24, 2022 10:06:33.954220057 CET | 849 | OUT | |
Nov 24, 2022 10:06:34.107176065 CET | 849 | IN | |
Nov 24, 2022 10:06:34.220388889 CET | 850 | OUT |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
15 | 192.168.2.5 | 49704 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:53.004415035 CET | 820 | OUT | |
Nov 24, 2022 10:05:53.042753935 CET | 820 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
2 | 192.168.2.5 | 49690 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:14.147728920 CET | 2 | OUT | |
Nov 24, 2022 10:05:14.181540966 CET | 3 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
3 | 192.168.2.5 | 49691 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:23.544753075 CET | 3 | OUT | |
Nov 24, 2022 10:05:23.579479933 CET | 4 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
4 | 192.168.2.5 | 49692 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:25.056792021 CET | 4 | OUT | |
Nov 24, 2022 10:05:25.227658033 CET | 5 | IN | |
Nov 24, 2022 10:05:25.769961119 CET | 5 | OUT | |
Nov 24, 2022 10:05:25.876641035 CET | 5 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
5 | 192.168.2.5 | 49693 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:29.208549976 CET | 6 | OUT | |
Nov 24, 2022 10:05:29.242099047 CET | 6 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
6 | 192.168.2.5 | 49694 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:30.283818960 CET | 7 | OUT | |
Nov 24, 2022 10:05:30.317295074 CET | 8 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
7 | 192.168.2.5 | 49695 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:30.704683065 CET | 8 | OUT | |
Nov 24, 2022 10:05:30.759912014 CET | 9 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
8 | 192.168.2.5 | 49696 | 13.90.128.253 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:31.007345915 CET | 9 | OUT | |
Nov 24, 2022 10:05:31.170663118 CET | 10 | IN | |
Nov 24, 2022 10:05:34.650249004 CET | 10 | OUT | |
Nov 24, 2022 10:05:34.803006887 CET | 10 | IN |
Session ID | Source IP | Source Port | Destination IP | Destination Port | Process |
---|---|---|---|---|---|
9 | 192.168.2.5 | 49697 | 208.95.112.1 | 80 | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Timestamp | kBytes transferred | Direction | Data |
---|---|---|---|
Nov 24, 2022 10:05:39.421231031 CET | 11 | OUT | |
Nov 24, 2022 10:05:39.459541082 CET | 11 | IN |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 10:05:01 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\Desktop\nwY3YpWQVx.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x630000 |
File size: | 547374 bytes |
MD5 hash: | 0D43B051C7C73233C85697219BC9A4F4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Target ID: | 1 |
Start time: | 10:05:21 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\AppData\Local\Temp\Zip.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x1c391990000 |
File size: | 32256 bytes |
MD5 hash: | AF07E88EC22CC90CEBFDA29517F101B9 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Antivirus matches: |
|
Reputation: | moderate |
Target ID: | 2 |
Start time: | 10:05:25 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\AppData\Local\Temp\update_222410.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x840000 |
File size: | 547374 bytes |
MD5 hash: | 0D43B051C7C73233C85697219BC9A4F4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 7 |
Start time: | 10:05:26 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\AppData\Local\Temp\update_222410.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x6b0000 |
File size: | 547374 bytes |
MD5 hash: | 0D43B051C7C73233C85697219BC9A4F4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Target ID: | 8 |
Start time: | 10:05:33 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\AppData\Local\Temp\update_222410.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x790000 |
File size: | 547374 bytes |
MD5 hash: | 0D43B051C7C73233C85697219BC9A4F4 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | low |
Target ID: | 12 |
Start time: | 10:05:37 |
Start date: | 24/11/2022 |
Path: | C:\Users\user\AppData\Local\Temp\update_222410.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x6e0000 |
File size: | 547374 bytes |
MD5 hash: | 0D43B051C7C73233C85697219BC9A4F4 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Execution Graph
Execution Coverage: | 18% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BD68D Relevance: 1.2, Instructions: 1229COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B41C0 Relevance: .6, Instructions: 612COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CA1A9 Relevance: .6, Instructions: 564COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C2CF6 Relevance: .5, Instructions: 477COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CD2E7 Relevance: .5, Instructions: 476COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C3AA2 Relevance: .5, Instructions: 463COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C4200 Relevance: 1.1, Instructions: 1060COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C79E1 Relevance: .4, Instructions: 423COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3488 Relevance: .4, Instructions: 377COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C9AAD Relevance: .4, Instructions: 352COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0320 Relevance: .3, Instructions: 297COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0D64 Relevance: .3, Instructions: 288COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0DC1 Relevance: .3, Instructions: 271COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CABF5 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6C65 Relevance: .2, Instructions: 231COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1A30 Relevance: .2, Instructions: 231COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C7FED Relevance: .2, Instructions: 228COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C9FA5 Relevance: .2, Instructions: 206COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C05EC Relevance: .2, Instructions: 195COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3E44 Relevance: .2, Instructions: 194COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE38C Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B03B5 Relevance: .2, Instructions: 173COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C77C1 Relevance: .2, Instructions: 172COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C9925 Relevance: .2, Instructions: 166COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B03C8 Relevance: .2, Instructions: 163COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1AAA Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0780 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BF721 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B63A1 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1C58 Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1411 Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B481C Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CAC50 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A628F2F0 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C995E Relevance: .1, Instructions: 117COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B5FB5 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6CE9 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6EEE Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE8C5 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1569 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CAD30 Relevance: .1, Instructions: 101COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C9806 Relevance: .1, Instructions: 95COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6C35 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE8E0 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B64C5 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3AB0 Relevance: .1, Instructions: 82COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B5EFD Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C9859 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3470 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3848 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CAD27 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B64F5 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BDE38 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6D48 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B4BDD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0859 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C984B Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CE47A Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B04D1 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3A69 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B168A Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C8D58 Relevance: .0, Instructions: 39COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C82E1 Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CD35B Relevance: .0, Instructions: 28COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0D90 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1A38 Relevance: .0, Instructions: 22COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6E23 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3B90 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3480 Relevance: .0, Instructions: 1COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BA283 Relevance: .2, Instructions: 158COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63CDAEB Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 11.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A629F051 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 14% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A628F2F0 Relevance: .1, Instructions: 133COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 17.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 3 |
Total number of Limit Nodes: | 0 |
Graph
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BD68D Relevance: 1.2, Instructions: 1226COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C2CF6 Relevance: .5, Instructions: 473COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C3AA2 Relevance: .5, Instructions: 459COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
Strings |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C4200 Relevance: 1.1, Instructions: 1060COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C5C18 Relevance: 1.0, Instructions: 1015COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C5C10 Relevance: .8, Instructions: 786COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C5C30 Relevance: .8, Instructions: 771COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C5C90 Relevance: .7, Instructions: 725COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C5C98 Relevance: .7, Instructions: 719COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3488 Relevance: .5, Instructions: 493COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0320 Relevance: .3, Instructions: 297COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0D64 Relevance: .3, Instructions: 288COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3818 Relevance: .3, Instructions: 286COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0DC1 Relevance: .3, Instructions: 271COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6C65 Relevance: .2, Instructions: 230COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3E44 Relevance: .2, Instructions: 197COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C05EC Relevance: .2, Instructions: 195COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE38C Relevance: .2, Instructions: 176COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1AAA Relevance: .2, Instructions: 162COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0780 Relevance: .2, Instructions: 160COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BF721 Relevance: .2, Instructions: 157COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B63A1 Relevance: .1, Instructions: 147COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1C58 Relevance: .1, Instructions: 143COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1411 Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B481C Relevance: .1, Instructions: 135COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3AB0 Relevance: .1, Instructions: 134COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A628F2F0 Relevance: .1, Instructions: 132COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B34C8 Relevance: .1, Instructions: 122COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B5FB5 Relevance: .1, Instructions: 115COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B03A8 Relevance: .1, Instructions: 113COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6CE9 Relevance: .1, Instructions: 110COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE8C5 Relevance: .1, Instructions: 103COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B1569 Relevance: .1, Instructions: 102COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B03C8 Relevance: .1, Instructions: 100COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6C35 Relevance: .1, Instructions: 87COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BE8E0 Relevance: .1, Instructions: 85COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B64C5 Relevance: .1, Instructions: 83COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B5EFD Relevance: .1, Instructions: 80COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3470 Relevance: .1, Instructions: 77COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3848 Relevance: .1, Instructions: 74COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B64F5 Relevance: .1, Instructions: 73COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63BDE38 Relevance: .1, Instructions: 70COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6D48 Relevance: .1, Instructions: 67COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B4BDD Relevance: .1, Instructions: 66COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0859 Relevance: .1, Instructions: 61COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3A69 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B04D1 Relevance: .1, Instructions: 58COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B168A Relevance: .0, Instructions: 46COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B0D90 Relevance: .0, Instructions: 25COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3459 Relevance: .0, Instructions: 23COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63C6F90 Relevance: .0, Instructions: 21COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B6E23 Relevance: .0, Instructions: 17COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00007FF9A63B3B90 Relevance: .0, Instructions: 9COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |